US Military disables ad trackers on troops' phones

2 days ago (theguardian.com)

It sounds like they disabled the "advertising ID" OS feature, but there are many other ways to fingerprint a device for advertising. Maybe this will lead to real privacy reform, now that the true risks are apparent. Not to mention ICE using the same data against civilians.

Does it make sense to give the troops special phones instead of their own? I always find it weird that soldiers can take their own phones into the base.

  • Most of what goes on on most bases is as unsecret as it gets. The rooms where sensitive things happen have security measures in place and they keep you from bringing your phone in there. Usually a little locker is provided where you store your phone while you are inside the protected area. In some very sensitive places there may be additional active and passive measures but usually people with access to those areas police themselves.

    • Do the security measures extend to the top leadership? Or are they exempt as long as they say "We are currently clean on OPSEC"?

    • Like a lot of data collection, the meta data gets you pretty far. The who's and where's can be hoovered up with tracking data buys and essentially get you a nice list of who has access to certain areas, which can be used for targeting individuals.

    • Unless your Matt Gaetz and co, in which case you just storm into the SCIF with a recording device and are allowed to get away with it.

  • It allows fun things like locating aircraft carriers on Strava.

    I don't think the Iranians have direct targeting tech for individual mobiles for decapitation strikes yet, that's an Israeli capability.

Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?

It should be obvious that the US military has good reasons why this would be the death for many military strategies. So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?

  • There are MANY problems that are too politically or practically difficult to tackle for the US Military and personal cellphones aren't close to the top ten. It's far easier to force everyone to register their cells to be automatically blacklisted from data collection than it is to justify tens of thousands of NJPs and court martials every year, many of which will include officers and senior enlisted.

    The US Military doesn't win through stealth or secrets either. Their advantage from the beginning until now has always been funding and logistics. With the Internet, satellites, and now AI, OPSEC is a fool's errand outside of very specific operations anyhow.

  • Probably because the intelligence community is also at the other side of this equation. The strategic advantage of a smartphone duopoly completely inside US jurisdiction is immeasurable.

  • > Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?

    By this logic, why keep anyone around after the SF86 hack[0]? Simple answer: Costs. It's a lot more expensive to lay off everyone with a security clearance (especially, if they're regular employees) and make a whole new batch of people go through the security background checks. We're probably talking billions - not to mention the issue with downtime of no one being around to do anything.

    > So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?

    ...because they (they being the military, in general) have - relatively - planned for this in places that they physically control (and the threats levels demand it) by essentially making all buildings that need to be secure giant faraday cages[1].

    What that doesn't account for is people outside of the buildings[2], which is probably what they're hoping to address with this change. (Too little, too late, I think - as that data's already out there.)

    0 - https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

    1 - https://en.wikipedia.org/wiki/Sensitive_compartmented_inform...

    2 - https://www.wired.com/story/phone-data-us-soldiers-spies-nuc...

Wait until they realize that military spouses and children might also need this, and government employees, and sensitive contractors, etc. It’s almost as if “ad trackers” shouldn’t exist at all.

The US government used to love this stuff when it was the only one who could abuse it. There might be a different outlook now that the tables have turned.

  • It seems like stalking laws in most jurisdictions should already cover this. Is there any legal precedent that could help without the need for new laws?

    • In a different legal environment this would be a good approach, but currently I don’t think the courts would accept this argument, as they are trying to push Congress to legislate rules on things like this (which Congress steadfastly refuses to do). Prior courts were more willing to “legislate from the bench” but current justices have expressed concern that Congress is abdicating its rulemaking responsibility.

      4 replies →

    • i am not a lawyer, but to the best of my knowledge there are specific criteria for "stalking", one of which being that the stalking causes fear or distress.

      the average person (i.e. a "reasonable person" by legal definition, even if us tech folk don't consider it reasonable) is not particularly scared or distressed by targeted ads. some people even like them.

      a good lawyer might be able to make something out of it, but i'm not convinced that stalking laws are the right avenue.

      1 reply →

    • I don’t think stalking laws cover it. Laws are largely about intent and I don’t think anyone could say that Google is planning to attack everyone.

      Law isn’t code. You can’t reduce stalking laws down to “it’s illegal to track people” and then extrapolate back up into ad tech. That’s what gets you “we should jail surgeons for cutting people with knives”. Context and intent matter.

    • Laws won't help against foreign actors, which are, after all, the main adversaries of the military.

This is probably a smart move. Especially finger printing is more and more intelligent. If foreign actors are using exercise tracking apps to track US Military personnel and positions. It seems reasonable that they would want to block something that is much lower effort for tracking.

Wow, it's like there should be a law that allows anyone to disable all data tracking about then, not just anonymize it.

This is a large conversation about Consent, which is a concept Silicon Valley refuses to acknowledge.

  • To them, the consent is using the device/service/whatever.

    You see it in various bits of EULA and ToS all the time. "Continued use of <insert thing here> implies agreement with the license terms".

    Now, is that at all feasible when you need a smartphone to do things like pay for parking in cities or to read menus at restaurants? No. Do the people in SV who think this way also try to wedge their products and services in every single nook, cranny, and crevice of our lives as a way to increase their net worth? Yes. Is this indicative that these people have severe antisocial or sociopathic tendencies that we, as a society, need to handle? I'm not a psychologist.

    • >To them, the consent is using the device/service/whatever.

      exactly. the problem is the missing qualifying word.

      when consumers say consent, it's almost always referring to informed consent.

      when companies say consent, it's almost always referring to implied consent.

    • What's their excuse with Flock-like surveillance? Leaving the house is consent to their tracking. Let's be real: they don't value consent in any form.

      I wouldn't be surprised one of those big-tech product managers gets tried for not understanding sexual consent either.

Feels like this should have been done long ago. Like I would just assume that ad tracking (any kind of tracking) for military is always gonna be a bad idea.

Could probably get a lot of actionable military information about troop locations by running targeted ads for subprime auto loans and divorce lawyers and collecting location information, discarding any US locations.

These things need to include more details. What is the report that ads were used to target deployed troops? What is the device use policy as of today? FOBs and semi-permanent installations are not secret locations. They're extremely obvious, have marked fences, gates, and guards in uniform. They're on satellite and aerial photos, sometimes on maps, depending on how long they've been in place. During patrols and any other movements in which unit locations are meant to be secret, as of 15 years ago when I was still serving, phones or any other kind of personal electronic device were not allowed. Even in training exercises, as far back as 2009 that I experienced, and probably further back than that, SIGINT units used radio triangulation to find and kill you when you used a phone during an exercise, which resulted in both removal from the exercise and reprimand because you weren't supposed to have a phone with you in the first place. They also captured and publicly shamed shit like getting nudes from your girlfriend or even just exchanging text messages.

If deployed personnel are sharing videos of their deployment activities to social media, how is that allowed? It can't be, right? They're violating some policy in doing that. Unit commanders have your social media accounts and monitor what you do there. Uniformed servicemembers have never had any expectation of privacy. UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice. All communications can and will be intercepted and read.

  • >Unit commanders have your social media accounts and monitor what you do there.

    I’m prior Air Force, so never been deployed to a FOB, but I have never had a commander ask me for my social media accounts. I’m not sure how this is even possible. I couldn’t even tell you all my social media accounts if you define social media as a platform where people communicate directly with one another publicly (forums, marketplaces like Craigslist, etc.) You can correct me if I’m wrong, but I have never seen it happen and it seems like a pretty weak enforcement mechanism.

    > UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice.

    That’s a bit of an overstatement. For housing or computer systems owned by the military, yes, you have no expectation of privacy and they can be searched without probable cause. However, personal effects such as your phone or laptop do have protections against unauthorized searches. Commanders and military judges must have a reason for authorizing a search, that search must be narrowly tailored, and if the search does not meet these requirements the evidence can be suppressed during court martial proceedings. Good example would be US v. Nieto

    https://law.justia.com/cases/federal/appellate-courts/caaf/1...

    • That's entirely fair. It is an overstatement. What I meant was, when deployed or during an exercise, any radio communications you make, letters you write, television shows you watch, can be intercepted and read. It's not the case that 100% will be. Back in garrison, it depends on if you live in barracks or not. If you're off post, nobody is busting into your house in the middle of the night with no notice.

      As for social media, it's not that they universally ask for access, but they know what is happening. I was commissioned and we knew when Soldiers shit talked us on social media. I didn't care most of the time and didn't do anything about it other than give a few warnings here and there for really egregious shit, but we knew. We can get the contents of what you post from your existing friends.

  • The US military hasn't yet been in a military altercation with a peer adversary that can actually exploit that information. The war in Ukraine shows that these information leaks can have severe tactical consequences.

    • China APTs are in our telecoms and no one is willing to fix that. China helps Russia, Russia helps Iran

Could also you know just ban invasive tracking and adtech bullshit…

  • This is basically impossible to do on a global scale. And even within a jurisdiction, there is a great risk of overregulation, see e.g. Europe.

    Disclaimer: I am a Linux and GrapheneOS user, running my own DNS with filtering for trackers, etc.

    • >This is basically impossible to do on a global scale.

      Is it though? Brussels effect and USB adoption tells me it is possible to affect global outcomes even in hard things like hardware if a heavyweight decides to put their finger on the scale

      1 reply →

If they can do it effectively, that would be impressive. There are so many ways phones and other devices are tracked. Do they prevent users from installing apps?

For example, I was reading Apple's Platform Security guide, a technical, detailed manual: There are so many identifiers, before any applications are installed - really, before the OS is fully loaded - that it's hard to keep track of them, manage them, or even form a mental picture of what's going on. Apple in many ways requires you to send those identifiers to them in order to use the device.

Apple is trying to protect consumers by operating the Root of Trust for the consumer devices, something consumers can't do effectively for themselves. And maybe Apple provides large customers with means to become their own root of trust; some of Apple's keys are embedded during manufacturing but other vendors allow large customers to substitute their own keys at that stage.

Regardless, it makes Apple an incredibly valuable target for highly resourced attackers, like the kind targeting the US military: Gain the right authority at Apple and you can monitor and control Apple devices worldwide. I'm not sure how the US military protects themselves without highly managed, locked down, customized devices.

This is just happening now? Shouldn't this have been done for troop security a long time ago?

  • The US is currently not deploying troops against an adversary that can make use of that information.

    • Why would they need to be deployed for an adversary to make use of that information? Sure it's more valuable on deployment, but wouldn't we also want to, you know, not give information on mobilization or lack thereof?

      1 reply →

Hopefully they aren't forcing the military to install Trump's spyware White House app

  • The rules for DoD phones are different than the rest of the Executive Branch. I don't know if it will eventually roll out to DoD phones; but, that was what we were told and we haven't seen it yet.