Hi everyone,
This week on Shared Security, we’re talking about a major privacy issue hiding in plain sight: your phone’s location history.
The U.S. Supreme Court says constitutional privacy protections can apply to cellphone location history and geofence warrant data. The case came out of a Virginia bank robbery investigation where police used a geofence warrant to ask Google for information about devices near the bank at the time of the crime.
That’s the big privacy concern with geofence warrants: they start with a place, not a suspect. Instead of asking for information about a specific person, law enforcement can potentially sweep up data from everyone near a location — including people who had nothing to do with the crime.
Tom and Scott discuss what this ruling means, why location data is so revealing, and how this connects to the bigger privacy problem of apps, data brokers, ad networks, weather apps, navigation apps, and always-on permissions collecting and sharing where we go.
The practical takeaway is simple: review your phone’s location settings, limit apps to “while using” location access when possible, delete old location history where appropriate, and think about location data as part of your personal threat model.
Your location history can reveal where you live, work, worship, get healthcare, spend time, and who you associate with. That is not “just metadata.”
Links from the episode
AP News: Supreme Court / Okello Chatrie geofence warrant coverage — https://apnews.com/article/supreme-court-okello-chatrie-geofence-warrants-a3adee8a3fd32b8ea1b42eb72cbcc35f
EFF: Victory! Supreme Court Says the Constitution Protects People’s Location Data — https://www.eff.org/deeplinks/2026/06/victory-supreme-court-says-constitution-protects-peoples-location-data
CyberScoop: Supreme Court geofence warrant ruling — https://cyberscoop.com/supreme-court-geofence-warrant-ruling-phone-privacy-chatrie/
New York Times: Supreme Court geofence warrant / cellphone location coverage — https://www.nytimes.com/2026/06/29/us/politics/supreme-court-geofence-warrant-cell-phones.html
Previous Shared Security episode: Google Geofence Warrants — https://sharedsecurity.net/2020/03/25/click-armor-demo-podcast-survey-results-google-geofence-warrants/
Previous Shared Security episode: Top 3 Location Tracking Apps: Do They Sell Your Data? — https://sharedsecurity.net/2022/03/21/top-3-location-tracking-apps-do-they-sell-your-data/
Quote from this week’s episode
Your location history is not just metadata — it can reveal where you live, work, worship, get medical care, and spend your life.
— Tom Eston
Tom’s take
Location privacy is one of those issues that feels abstract until you realize how much of your life your phone quietly maps. This ruling matters because it recognizes that location history can be deeply personal, even when it’s stored by a company instead of sitting directly on your phone. But court rulings are only one part of the picture. We still need to pay attention to app permissions, location dashboards, data brokers, and the everyday convenience tradeoffs that make tracking feel normal.
Also worth your attention this week
Medtronic breach affects millions of patients — Medtronic has been notifying people affected by an April cyberattack, with reporting indicating millions may be impacted and exposed data potentially including personal identifiers and health-related information. Medical data is different from a credit card number: you can monitor and freeze accounts, but you cannot replace your health history. Sources: https://www.securityweek.com/medtronic-data-breach-impacts-3-8-million-people/ and https://www.hipaajournal.com/medical-device-maker-medtronic-data-breach/
Madison Square Garden, facial recognition, and surveillance critics — Reporting around Madison Square Garden’s data exposure and alleged tracking of privacy activists is a reminder that private venues can build large dossiers too, especially when biometric surveillance, ticketing systems, customer data, and critic lists collide. Source: https://www.cnet.com/home/security/madison-square-garden-targeted-privacy-activists-and-surveillance-critics/
The KIDS Act and age checks for the internet — EFF is warning that the KIDS Act could push websites and apps toward age verification before people can read, message, or participate online. It’s another example of “protect the kids” policy that can create broad privacy and speech consequences for everyone. Source: https://www.eff.org/deeplinks/2026/06/kids-act-would-require-age-checks-get-online
Listen / Watch
🎧 Audio Podcast: https://sharedsecurity.net/2026/07/06/the-supreme-court-just-put-limits-on-geofence-warrants/
▶️ YouTube Version: https://youtu.be/jCtdE72ymII
We’d love your feedback
Have you reviewed your phone’s location permissions recently? Reply to this email or leave a comment on YouTube and tell us which apps surprised you the most.
Thank you to our sponsors!
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT! Visit: https://slnt.com and use discount code "sharedsecurity" at checkout.
Closing
If this episode was useful, please support Shared Security by subscribing on YouTube, becoming a YouTube channel member, following the show on your preferred podcast app, leaving a rating or review, and sharing the episode with someone who still leaves every app set to “always allow” location access.
Stay safe, stay secure, and stay private.
Tom Eston
Founder and Host, Shared Security Podcast

