Pentagon Reviews GPS Policies After Fitness Trackers Reveal Locations (npr.org)
An anonymous reader quotes a report from NPR: Locations and activity of U.S. military bases; jogging and patrol routes of American soldiers -- experts say those details are among the GPS data shared by the exercise tracking company Strava, whose Heat Map reflects more than a billion exercise activities globally. The Pentagon says it's looking at adding new training and policies to address security concerns. "Recent data releases emphasize the need for situational awareness when members of the military share personal information," Pentagon spokesman Major Adrian J.T. Rankine-Galloway of the U.S. Marine Corps said in a statement about the implications of the Strava data that has made international headlines. Strava -- which includes an option for keeping users' workout data private -- published the updated Heat Map late last year. The California-based company calls itself "the social network for athletes," saying that its mobile apps and website connect millions of people every day. Using data from fitness trackers such as the Fitbit, Strava's map shows millions of users' runs, walks, and bike trips from 2015 to September of 2017 -- and in some countries, the activities of military and aid personnel are seen in stark contrast, as their outposts shine brightly among the comparative darkness of their surroundings.
If you wear a tracking GPS...it might track where you are. Film at 11.
Just tell our soldiers and sailors that their comrade/shipmate's activities may conjure some inbound and the "new guy with the pretty watch" problem should take care of itself.
Even the external "secure" provision of cloud services itself allows predictive location of military and intel assets. Just the traffic flow itself allows you to pinpoint this, even if it's time-delay GPS data from "I turned my cell/smartphone/fitbit/watch off, sergeant!" health data.
We can back extrapolate locations and pinpoint internal corridors and access points - for example, knowing people stop at a door for x minutes/seconds tells us what the security protocol is for the access point, and knowing the elevation information from other ping services drops except at stairwells tells us what is and what is not secure within the installation.
-- Tigger warning: This post may contain tiggers! --
The DOD, the grand master of the GPS system, decided to start jamming GPS signal on its own bases...
... is the lack of foresight on the part of American military.
We used to be better than this.
It little behooves the best of us to comment on the rest of us.
All military personnel must enable the "Privacy" mode on all portable electronic devices when out of CONUS. Because those privacy modes are disabled by default.
No personal devices, done. 20 years ago they wouldn't have had cell phones, now they all do. If they are deployed, depending on where and what the mission is, they either get no contact with home or the internet, or they only get access to home and the internet via a shared workstation setup centrally located on the base. Anyone caught deploying with any sort of electronic device besides possibly an approved MP3 or DVD player should be subject to "other than honorable discharge". There is no reason for them to have them when deployed. You want to keep a secret you don't let people talk. Allowing people access to the internet will leak information 100% of the time.
All that technology will eventually backfire. It's just a matter of time.
I am American and know that policy was put in under Democrat Obama leader. This is all part of Uranium GPS plot to undermine Trump and hand control of country over to cultural marxists. To stop this, agree with me in donating to NRA and Trump 2020 campagnes now.
Does this map show that the US military is patrolling from my neighbors house to my house and then conducting a physical assessment in my bedroom when I'm at work? My wife is home then so I'll ask her.
Governments are keen to tell us that metadata doesn't need protecting etc.
Cake and eat it?
Because of all the onsite nuclear waste storage right
...Strava -- which includes an option for keeping users' workout data private...
The data are still on Strava's servers. Do those servers pass the military security requirements for protecting troop locations? What else does Strava do with the data?
All those orbiting satellites pumping out GPS signals? The Pentagon put 'em there.
Yes, it's user error, but .. WHAT. THE. FUCK. The diagnosis is so wrong that .. that .. I can't think of a stupid metaphor, and I'm usually pretty good at stupid metaphors.
Uploading sensitive information to a completely untrusted third party and then remembering to "mark it private" is like [oh good, I've still "got it" as long as a simile will suffice] sending plaintext email and being surprised that someone intercepted the plaintext because they weren't supposed to do that, shame on those naughty spies.
Strava owes jack shit to the military, and therefore, the military has no reason to trust Strava (either their intent, nor the security of their database even if Strava's intent is good.)
The correct thing to do is not send the data to third parties. It doesn't matter how you mark it, because even if you mark it private, you have still disclosed the sensitive information.
This shouldn't be a surprise to anyone, anyway. The most common sense way for these devices to work is to transmit the data to the user's own computer. But so much of today's IoT is made to lock people in services for recurring revenue, that they're made to send data to company servers (a.k.a. "the cloud") instead. Users are supposed to Just Say No with their wallets but discouragingly, people are still buying this type of obvious garbage that they know is garbage before the sale.
So yeah, I'd say user error. They shouldn't have bought the device, but they did. Then they allowed it to transmit their locations to third parties, which was a major major fuckup. Then ok, cherry on top, they didn't mark it private. But it was already a shocking display of stupidity long before that point.
I really dislike this idea that the user is supposed to use some privacy setting to tell Strava "this is military data, so I humbly request that you please not share it with the enemy." So fucking wrong. Don't give the data to Strava in the first place.
... until they realize how much Alexa has recorded.
Oh and by the way -- don't Russians run?
No. It's because while many people may have heard fanciful stories about what might be there, no one can truthfully claim to have seen what's inside. Those that have seen inside have sworn to never speak of it.
n/t
Create a law were companies can not share data --- fixed
GPS takes some powerful circuitry, and can take up to 15 minutes to first get a usable location. But the MAC addresses, and power, of local wifi access points, and id and location of local cell phone towers, is much more likely to be available on power up, and to be enabled as someone travels with a portable device of almost any kind. Even FitBits can cooperate with the "location gateway" some location services provide, and receive or publish their location to a central service. And they can't *get* that location without publishing their request to the upstream server, which makes them traceable unless the server goes through a great deal of revenue burning work to anonymize the data.
Good luck turning that kind of service off. The Internet of Things genie has been out of the lamp granting wishes to intelligence agencies for *years*.
you have to buy your afn satellite receiver to get afn.
And here I GENUINELY thought when soldiers were sent to "off the map" places they had to leave all that stuff at the main base in the US where they left from. I thought it was something like prison. It makes no logical sense to use a mobile device at these bases that are supposed to be hidden. If I check my phones location history it will tell me exactly where I was, how long I was there and what other places I might visit next time in the area once it gets a data connection. Hell even logging on to something like facebook or google will geo-track you.
I thought they were only allowed to use the computers on base because they encrypted the internet data or something to prevent geo-tracking. It is the military, they are capable of at least that aren't they?
My understanding was you sign up for a free ride with the military (paid school, salary, housing, etc.) in exchange for giving your dedication AKA you are going to an "open prison" its just run by the military because they aren't giving free handouts.
If I understand correctly, there's nothing wrong. It's IOT devices that send everything to a remote that isn't under the user's control.