Abstract: In 2012, my group showed that an attacker can check if a victim is within an area (up to 1 km x 1 km accuracy) without permission from Telcos in 3G cellular networks. Since then, several papers have been published to show that the same attack works for 4G LTE networks. In addition to this location privacy issues, researchers have shown that 3GPP standards are leaking a lot of information. For example, an unprivileged 3rd party can 1) track RNTI (a temporary radio ID) and TMSI (a temporary ID associated with the victim) and 2) obtain scheduling information of a particular user from messages broadcasted from cell towers. In the first part of the talk, I will explain how this is possible. In the second part, I will explain how this information could be used for 1) fingerprinting apps and movies a victim uses or 2) precise (< 15 m accuracy) physical localization of the victim’s smartphone.