Urgent.News

What's breaking now, across thousands of outlets.

Tech

US troops can still be tracked by purchased location data, and Congress wants to know why

DoD controls on mobile ad identifiers haven't stopped military location data turning up for sale

US troops can still be tracked by purchased location data, and Congress wants to know why

US troops remain vulnerable to location tracking despite efforts by the military to prevent it, prompting lawmakers to question why the threat persists. US Senator Ron Wyden (D-OR) and Rep. Pat Harrigan (R-NC) have requested an investigation by the Defense Department Inspector General into the policies that have only partially addressed the issue.

In May, Wyden, Harrigan, and a bipartisan group of 12 other members of Congress revealed how commercially purchased location data, often captured by mobile apps and advertising SDKs, can be used to track military personnel. The Defense Department has been aware of this threat since at least 2016, and lawmakers have urged Defense Department CIO Kirsten A. Davies to mitigate the risk by turning off advertising identifiers on DoD smartphones and issuing policies requiring the disabling of such identifiers on personal devices brought into DoD facilities.

While several military branches have taken these steps, the availability of location data tied to US military personnel has not been entirely eliminated. Wyden and Harrigan are concerned about the continued presence of commercial location data originating from DoD facilities and speculate on the reasons behind the policy shortfall.

One possibility is that some parts of the DoD only recently turned off their advertising identifiers in July, another is that disabling ad identifiers may no longer be sufficient, and the third is that the location data is coming from the personal devices of DoD personnel and contractors. Staff threat researcher Zach Edwards from Infoblox stated that it's positive to see all military branches disabling advertising IDs on their phones, as it enhances the safety of military personnel and their families, especially those serving in combat zones overseas.

Edwards noted that while mobile advertising identifiers (MAIDs) have been used by data brokers for bulk sales, the disabling of such identifiers on government devices will prevent military data from being available for sale through these brokers. However, Edwards also pointed out that the MAIDs were being broadcast to all ad systems participating in auctions, and companies in Russia and China, which have obligations to share data with the state without appeal, could still access this information.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Whisper.cpp Vulkan on Arch: A Detective Story With No Crime

A six-week journey through source builds, CI pipelines, and one package pacman never mentioned. TL;DR: pacman -S whisper-cpp ggml-vulkan . That's it. That's the whole answer.

  • Author investigates six-week mystery of whisper.cpp CPU usage
  • Vulkan support missing in official extra/whisper-cpp package
  • Custom PKGBUILD created for Vulkan-enabled whisper-cpp

Why QR Pairing Beats IP Addresses for Local-First Device Sync

A local-first app still needs a good answer to one basic question: how does a person know that the phone in their hand is connecting to the right computer? For iWinBridge, the answer is a QR code.

  • QR pairing replaces IP addresses for device sync.
  • QR codes provide clear user confirmation during pairing.
  • QR pairing ensures safe data exchange in local networks.

More from Sunday 6 September →