It sounds like they disabled the "advertising ID" OS feature, but there are many other ways to fingerprint a device for advertising. Maybe this will lead to real privacy reform, now that the true risks are apparent. Not to mention ICE using the same data against civilians.
Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones. Apple doesn't allow SDKs which attempt to bypass this, so the app would have to have a first party auth of some type.
>Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones.
You got this flipped. The whole point of "fingerprinting" is to build a stable identifier that works even if a explicit identifier (IMEI or advertising ID) isn't available. And yes, there are shady SDKs that do this without facing repercussions.
That may have been true initially but meta has enough information to heuristically observe unidentified users and compare their behaviors with known consumers. It only takes a few actions to uniquely identify a consumer with a high degree of confidence.
Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?
It should be obvious that the US military has good reasons why this would be the death for many military strategies. So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?
There are MANY problems that are too politically or practically difficult to tackle for the US Military and personal cellphones aren't close to the top ten. It's far easier to force everyone to register their cells to be automatically blacklisted from data collection than it is to justify tens of thousands of NJPs and court martials every year, many of which will include officers and senior enlisted.
The US Military doesn't win through stealth or secrets either. Their advantage from the beginning until now has always been funding and logistics. With the Internet, satellites, and now AI, OPSEC is a fool's errand outside of very specific operations anyhow.
Does it make sense to give the troops special phones instead of their own? I always find it weird that soldiers can take their own phones into the base.
Most of what goes on on most bases is as unsecret as it gets. The rooms where sensitive things happen have security measures in place and they keep you from bringing your phone in there. Usually a little locker is provided where you store your phone while you are inside the protected area. In some very sensitive places there may be additional active and passive measures but usually people with access to those areas police themselves.
Like a lot of data collection, the meta data gets you pretty far. The who's and where's can be hoovered up with tracking data buys and essentially get you a nice list of who has access to certain areas, which can be used for targeting individuals.
This is probably a smart move. Especially finger printing is more and more intelligent. If foreign actors are using exercise tracking apps to track US Military personnel and positions. It seems reasonable that they would want to block something that is much lower effort for tracking.
Feels like this should have been done long ago. Like I would just assume that ad tracking (any kind of tracking) for military is always gonna be a bad idea.
Wait until they realize that military spouses and children might also need this, and government employees, and sensitive contractors, etc. It’s almost as if “ad trackers” shouldn’t exist at all.
The US government used to love this stuff when it was the only one who could abuse it. There might be a different outlook now that the tables have turned.
It seems like stalking laws in most jurisdictions should already cover this. Is there any legal precedent that could help without the need for new laws?
In a different legal environment this would be a good approach, but currently I don’t think the courts would accept this argument, as they are trying to push Congress to legislate rules on things like this (which Congress steadfastly refuses to do). Prior courts were more willing to “legislate from the bench” but current justices have expressed concern that Congress is abdicating its rulemaking responsibility.
Yes. The majority of their decisions seem to bear that out. While the current court isn’t run by strict constitutionalists, the direction of the court seems to be in favor of rolling back previous precedent that overstepped constitutional boundaries and restoring constitutional balances based on originalist interpretations. This doesn’t please anybody, of course, because both political “teams” have lost major fights in this process.
Not that every decision bears this out, of course, and it’s also a slow process.
IMO this restoration is a necessary step in restoring the operation of the constitution. As a country we need to decide if we’re going to actually follow it (including making use of the long-dead amendment process) or throw it out (amounting to a revolution). Selectively ignoring parts of it depending on who is in power, or based on whatever the bipartisan intelligence/defense agenda requires, is unworkable and needs to end ASAP.
I don’t think stalking laws cover it. Laws are largely about intent and I don’t think anyone could say that Google is planning to attack everyone.
Law isn’t code. You can’t reduce stalking laws down to “it’s illegal to track people” and then extrapolate back up into ad tech. That’s what gets you “we should jail surgeons for cutting people with knives”. Context and intent matter.
i am not a lawyer, but to the best of my knowledge there are specific criteria for "stalking", one of which being that the stalking causes fear or distress.
the average person (i.e. a "reasonable person" by legal definition, even if us tech folk don't consider it reasonable) is not particularly scared or distressed by targeted ads. some people even like them.
a good lawyer might be able to make something out of it, but i'm not convinced that stalking laws are the right avenue.
Not to mention you “opted in” by the terms and conditions of the service, which would certainly argue that if you didn’t agree to the terms, you didn’t have to use their website.
To them, the consent is using the device/service/whatever.
You see it in various bits of EULA and ToS all the time. "Continued use of <insert thing here> implies agreement with the license terms".
Now, is that at all feasible when you need a smartphone to do things like pay for parking in cities or to read menus at restaurants? No. Do the people in SV who think this way also try to wedge their products and services in every single nook, cranny, and crevice of our lives as a way to increase their net worth? Yes. Is this indicative that these people have severe antisocial or sociopathic tendencies that we, as a society, need to handle? I'm not a psychologist.
Could probably get a lot of actionable military information about troop locations by running targeted ads for subprime auto loans and divorce lawyers and collecting location information, discarding any US locations.
Probably not anything more than you could find via publicly accessible information and then the movements you do care about (deploying to go fight in a war) you'd get via your satellites and so forth.
It's unfortunate that predatory businesses exist (payday loans and furniture rental anyone - you could run ads for those in certain communities :o ) but it's a tough and demanding lifestyle that's a bit unstable since our military actually does things and there are a lot of predatory auto companies and banks out there praying on regular people (most of them from poorer, working class, and/or minority communities) who aren't as well educated as the rest of us on things like interest rates and loans and all of those things.
These things need to include more details. What is the report that ads were used to target deployed troops? What is the device use policy as of today? FOBs and semi-permanent installations are not secret locations. They're extremely obvious, have marked fences, gates, and guards in uniform. They're on satellite and aerial photos, sometimes on maps, depending on how long they've been in place. During patrols and any other movements in which unit locations are meant to be secret, as of 15 years ago when I was still serving, phones or any other kind of personal electronic device were not allowed. Even in training exercises, as far back as 2009 that I experienced, and probably further back than that, SIGINT units used radio triangulation to find and kill you when you used a phone during an exercise, which resulted in both removal from the exercise and reprimand because you weren't supposed to have a phone with you in the first place. They also captured and publicly shamed shit like getting nudes from your girlfriend or even just exchanging text messages.
If deployed personnel are sharing videos of their deployment activities to social media, how is that allowed? It can't be, right? They're violating some policy in doing that. Unit commanders have your social media accounts and monitor what you do there. Uniformed servicemembers have never had any expectation of privacy. UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice. All communications can and will be intercepted and read.
>Unit commanders have your social media accounts and monitor what you do there.
I’m prior Air Force, so never been deployed to a FOB, but I have never had a commander ask me for my social media accounts. I’m not sure how this is even possible. I couldn’t even tell you all my social media accounts if you define social media as a platform where people communicate directly with one another publicly (forums, marketplaces like Craigslist, etc.) You can correct me if I’m wrong, but I have never seen it happen and it seems like a pretty weak enforcement mechanism.
> UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice.
That’s a bit of an overstatement. For housing or computer systems owned by the military, yes, you have no expectation of privacy and they can be searched without probable cause. However, personal effects such as your phone or laptop do have protections against unauthorized searches. Commanders and military judges must have a reason for authorizing a search, that search must be narrowly tailored, and if the search does not meet these requirements the evidence can be suppressed during court martial proceedings. Good example would be US v. Nieto
That's entirely fair. It is an overstatement. What I meant was, when deployed or during an exercise, any radio communications you make, letters you write, television shows you watch, can be intercepted and read. It's not the case that 100% will be. Back in garrison, it depends on if you live in barracks or not. If you're off post, nobody is busting into your house in the middle of the night with no notice.
As for social media, it's not that they universally ask for access, but they know what is happening. I was commissioned and we knew when Soldiers shit talked us on social media. I didn't care most of the time and didn't do anything about it other than give a few warnings here and there for really egregious shit, but we knew. We can get the contents of what you post from your existing friends.
The US military hasn't yet been in a military altercation with a peer adversary that can actually exploit that information. The war in Ukraine shows that these information leaks can have severe tactical consequences.
If they can do it effectively, that would be impressive. There are so many ways phones and other devices are tracked. Do they prevent users from installing apps?
For example, I was reading Apple's Platform Security guide, a technical, detailed manual: There are so many identifiers, before any applications are installed - really, before the OS is fully loaded - that it's hard to keep track of them, manage them, or even form a mental picture of what's going on. Apple in many ways requires you to send those identifiers to them in order to use the device.
Apple is trying to protect consumers by operating the Root of Trust for the consumer devices, something consumers can't do effectively for themselves. And maybe Apple provides large customers with means to become their own root of trust; some of Apple's keys are embedded during manufacturing but other vendors allow large customers to substitute their own keys at that stage.
Regardless, it makes Apple an incredibly valuable target for highly resourced attackers, like the kind targeting the US military: Gain the right authority at Apple and you can monitor and control Apple devices worldwide. I'm not sure how the US military protects themselves without highly managed, locked down, customized devices.
>This is basically impossible to do on a global scale.
Is it though? Brussels effect and USB adoption tells me it is possible to affect global outcomes even in hard things like hardware if a heavyweight decides to put their finger on the scale
Why would they need to be deployed for an adversary to make use of that information? Sure it's more valuable on deployment, but wouldn't we also want to, you know, not give information on mobilization or lack thereof?
The rules for DoD phones are different than the rest of the Executive Branch. I don't know if it will eventually roll out to DoD phones; but, that was what we were told and we haven't seen it yet.
It sounds like they disabled the "advertising ID" OS feature, but there are many other ways to fingerprint a device for advertising. Maybe this will lead to real privacy reform, now that the true risks are apparent. Not to mention ICE using the same data against civilians.
Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones. Apple doesn't allow SDKs which attempt to bypass this, so the app would have to have a first party auth of some type.
>Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones.
You got this flipped. The whole point of "fingerprinting" is to build a stable identifier that works even if a explicit identifier (IMEI or advertising ID) isn't available. And yes, there are shady SDKs that do this without facing repercussions.
https://www.buchodi.com/i-broke-applovins-mediation-cipher-p...
Dude, FAANG still manage to do it, day in day out.
IIRC they actually don't and it materially reduced Meta's profit when Apple rolled out the advertiser ID system.
"Facebook says Apple iOS privacy change will result in $10 billion revenue hit this year" (2022):
* https://www.cnbc.com/2022/02/02/facebook-says-apple-ios-priv...
See also perhaps "It’s not Meta - its APPLE who have screwed us small advertisers":
* https://www.reddit.com/r/FacebookAds/comments/1o85w2q/
Wow that number is line an order of magnitude or more than I expected it would be
Won't someone please think of the poor advertisers? /s
That may have been true initially but meta has enough information to heuristically observe unidentified users and compare their behaviors with known consumers. It only takes a few actions to uniquely identify a consumer with a high degree of confidence.
Yes, it was temporary and Meta revenue and profit at all time high (before data center buildout).
Everything they do is a framework for consumer protection laws.
Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?
It should be obvious that the US military has good reasons why this would be the death for many military strategies. So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?
There are MANY problems that are too politically or practically difficult to tackle for the US Military and personal cellphones aren't close to the top ten. It's far easier to force everyone to register their cells to be automatically blacklisted from data collection than it is to justify tens of thousands of NJPs and court martials every year, many of which will include officers and senior enlisted.
The US Military doesn't win through stealth or secrets either. Their advantage from the beginning until now has always been funding and logistics. With the Internet, satellites, and now AI, OPSEC is a fool's errand outside of very specific operations anyhow.
Does it make sense to give the troops special phones instead of their own? I always find it weird that soldiers can take their own phones into the base.
Most of what goes on on most bases is as unsecret as it gets. The rooms where sensitive things happen have security measures in place and they keep you from bringing your phone in there. Usually a little locker is provided where you store your phone while you are inside the protected area. In some very sensitive places there may be additional active and passive measures but usually people with access to those areas police themselves.
Like a lot of data collection, the meta data gets you pretty far. The who's and where's can be hoovered up with tracking data buys and essentially get you a nice list of who has access to certain areas, which can be used for targeting individuals.
Guess what people talk (and write) about after meetings.
If you talk and/or write about what happened in one of those places, you can face consequences from discipline up to prison.
Yes, it happens. No, it better not happen much, and it's not supposed to happen at all.
Unless your Matt Gaetz and co, in which case you just storm into the SCIF with a recording device and are allowed to get away with it.
It allows fun things like locating aircraft carriers on Strava.
I don't think the Iranians have direct targeting tech for individual mobiles for decapitation strikes yet, that's an Israeli capability.
The base is where people live 24/7. You'd be banning them from having phones.
Oh boy, what an easy way to see if the phone's user is military or not.
Exactly.
The abscence of an indicator that is expected is itself an indicator.
Just throwing this link out into the void:
https://www.wired.com/story/how-pentagon-learned-targeted-ad...
Wonder why it took the Pentagon so long to take the ads risk seriously.
This is probably a smart move. Especially finger printing is more and more intelligent. If foreign actors are using exercise tracking apps to track US Military personnel and positions. It seems reasonable that they would want to block something that is much lower effort for tracking.
Feels like this should have been done long ago. Like I would just assume that ad tracking (any kind of tracking) for military is always gonna be a bad idea.
Wait until they realize that military spouses and children might also need this, and government employees, and sensitive contractors, etc. It’s almost as if “ad trackers” shouldn’t exist at all.
The US government used to love this stuff when it was the only one who could abuse it. There might be a different outlook now that the tables have turned.
It seems like stalking laws in most jurisdictions should already cover this. Is there any legal precedent that could help without the need for new laws?
In a different legal environment this would be a good approach, but currently I don’t think the courts would accept this argument, as they are trying to push Congress to legislate rules on things like this (which Congress steadfastly refuses to do). Prior courts were more willing to “legislate from the bench” but current justices have expressed concern that Congress is abdicating its rulemaking responsibility.
That’s a hilarious idea. Given the Supreme Court of today, afraid of legislating from the bench? Are you serious?
Yes. The majority of their decisions seem to bear that out. While the current court isn’t run by strict constitutionalists, the direction of the court seems to be in favor of rolling back previous precedent that overstepped constitutional boundaries and restoring constitutional balances based on originalist interpretations. This doesn’t please anybody, of course, because both political “teams” have lost major fights in this process.
Not that every decision bears this out, of course, and it’s also a slow process.
IMO this restoration is a necessary step in restoring the operation of the constitution. As a country we need to decide if we’re going to actually follow it (including making use of the long-dead amendment process) or throw it out (amounting to a revolution). Selectively ignoring parts of it depending on who is in power, or based on whatever the bipartisan intelligence/defense agenda requires, is unworkable and needs to end ASAP.
Most of the contentious SCOTUS decisions these days are the opposite of that, where they defer to Congress or the executive.
Yes. Why do you disagree?
I don’t think stalking laws cover it. Laws are largely about intent and I don’t think anyone could say that Google is planning to attack everyone.
Law isn’t code. You can’t reduce stalking laws down to “it’s illegal to track people” and then extrapolate back up into ad tech. That’s what gets you “we should jail surgeons for cutting people with knives”. Context and intent matter.
i am not a lawyer, but to the best of my knowledge there are specific criteria for "stalking", one of which being that the stalking causes fear or distress.
the average person (i.e. a "reasonable person" by legal definition, even if us tech folk don't consider it reasonable) is not particularly scared or distressed by targeted ads. some people even like them.
a good lawyer might be able to make something out of it, but i'm not convinced that stalking laws are the right avenue.
Not to mention you “opted in” by the terms and conditions of the service, which would certainly argue that if you didn’t agree to the terms, you didn’t have to use their website.
Laws won't help against foreign actors, which are, after all, the main adversaries of the military.
Why do deployed troops have cell phones at all? Seems like a huge security risk
Wow, it's like there should be a law that allows anyone to disable all data tracking about then, not just anonymize it.
This is a large conversation about Consent, which is a concept Silicon Valley refuses to acknowledge.
Ironically, the US Miliary appears to be supporting the GDPR.
To them, the consent is using the device/service/whatever.
You see it in various bits of EULA and ToS all the time. "Continued use of <insert thing here> implies agreement with the license terms".
Now, is that at all feasible when you need a smartphone to do things like pay for parking in cities or to read menus at restaurants? No. Do the people in SV who think this way also try to wedge their products and services in every single nook, cranny, and crevice of our lives as a way to increase their net worth? Yes. Is this indicative that these people have severe antisocial or sociopathic tendencies that we, as a society, need to handle? I'm not a psychologist.
>To them, the consent is using the device/service/whatever.
exactly. the problem is the missing qualifying word.
when consumers say consent, it's almost always referring to informed consent.
when companies say consent, it's almost always referring to implied consent.
What's their excuse with Flock-like surveillance? Leaving the house is consent to their tracking. Let's be real: they don't value consent in any form.
I wouldn't be surprised one of those big-tech product managers gets tried for not understanding sexual consent either.
Could probably get a lot of actionable military information about troop locations by running targeted ads for subprime auto loans and divorce lawyers and collecting location information, discarding any US locations.
Or Kalshi bets.
https://www.justice.gov/opa/pr/us-soldier-charged-using-clas...
Or run tracking.
https://www.theguardian.com/world/2018/jan/28/fitness-tracki...
Probably not anything more than you could find via publicly accessible information and then the movements you do care about (deploying to go fight in a war) you'd get via your satellites and so forth.
It's unfortunate that predatory businesses exist (payday loans and furniture rental anyone - you could run ads for those in certain communities :o ) but it's a tough and demanding lifestyle that's a bit unstable since our military actually does things and there are a lot of predatory auto companies and banks out there praying on regular people (most of them from poorer, working class, and/or minority communities) who aren't as well educated as the rest of us on things like interest rates and loans and all of those things.
Oh, this is an old trick the US has used for a long time:
https://www.wired.com/story/how-pentagon-learned-targeted-ad...
You say that like it’s not already happening.
I have no doubt it’s already being used if it was the first thought that popped into my head.
It’s less obvious than looking at Strava maps, but still low hanging fruit.
These things need to include more details. What is the report that ads were used to target deployed troops? What is the device use policy as of today? FOBs and semi-permanent installations are not secret locations. They're extremely obvious, have marked fences, gates, and guards in uniform. They're on satellite and aerial photos, sometimes on maps, depending on how long they've been in place. During patrols and any other movements in which unit locations are meant to be secret, as of 15 years ago when I was still serving, phones or any other kind of personal electronic device were not allowed. Even in training exercises, as far back as 2009 that I experienced, and probably further back than that, SIGINT units used radio triangulation to find and kill you when you used a phone during an exercise, which resulted in both removal from the exercise and reprimand because you weren't supposed to have a phone with you in the first place. They also captured and publicly shamed shit like getting nudes from your girlfriend or even just exchanging text messages.
If deployed personnel are sharing videos of their deployment activities to social media, how is that allowed? It can't be, right? They're violating some policy in doing that. Unit commanders have your social media accounts and monitor what you do there. Uniformed servicemembers have never had any expectation of privacy. UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice. All communications can and will be intercepted and read.
>Unit commanders have your social media accounts and monitor what you do there.
I’m prior Air Force, so never been deployed to a FOB, but I have never had a commander ask me for my social media accounts. I’m not sure how this is even possible. I couldn’t even tell you all my social media accounts if you define social media as a platform where people communicate directly with one another publicly (forums, marketplaces like Craigslist, etc.) You can correct me if I’m wrong, but I have never seen it happen and it seems like a pretty weak enforcement mechanism.
> UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice.
That’s a bit of an overstatement. For housing or computer systems owned by the military, yes, you have no expectation of privacy and they can be searched without probable cause. However, personal effects such as your phone or laptop do have protections against unauthorized searches. Commanders and military judges must have a reason for authorizing a search, that search must be narrowly tailored, and if the search does not meet these requirements the evidence can be suppressed during court martial proceedings. Good example would be US v. Nieto
https://law.justia.com/cases/federal/appellate-courts/caaf/1...
That's entirely fair. It is an overstatement. What I meant was, when deployed or during an exercise, any radio communications you make, letters you write, television shows you watch, can be intercepted and read. It's not the case that 100% will be. Back in garrison, it depends on if you live in barracks or not. If you're off post, nobody is busting into your house in the middle of the night with no notice.
As for social media, it's not that they universally ask for access, but they know what is happening. I was commissioned and we knew when Soldiers shit talked us on social media. I didn't care most of the time and didn't do anything about it other than give a few warnings here and there for really egregious shit, but we knew. We can get the contents of what you post from your existing friends.
The US military hasn't yet been in a military altercation with a peer adversary that can actually exploit that information. The war in Ukraine shows that these information leaks can have severe tactical consequences.
China APTs are in our telecoms and no one is willing to fix that. China helps Russia, Russia helps Iran
theguardian.com now requires a user-agent header
Any string is acceptable, including zero characters
If they can do it effectively, that would be impressive. There are so many ways phones and other devices are tracked. Do they prevent users from installing apps?
For example, I was reading Apple's Platform Security guide, a technical, detailed manual: There are so many identifiers, before any applications are installed - really, before the OS is fully loaded - that it's hard to keep track of them, manage them, or even form a mental picture of what's going on. Apple in many ways requires you to send those identifiers to them in order to use the device.
Apple is trying to protect consumers by operating the Root of Trust for the consumer devices, something consumers can't do effectively for themselves. And maybe Apple provides large customers with means to become their own root of trust; some of Apple's keys are embedded during manufacturing but other vendors allow large customers to substitute their own keys at that stage.
Regardless, it makes Apple an incredibly valuable target for highly resourced attackers, like the kind targeting the US military: Gain the right authority at Apple and you can monitor and control Apple devices worldwide. I'm not sure how the US military protects themselves without highly managed, locked down, customized devices.
Could also you know just ban invasive tracking and adtech bullshit…
This is basically impossible to do on a global scale. And even within a jurisdiction, there is a great risk of overregulation, see e.g. Europe.
Disclaimer: I am a Linux and GrapheneOS user, running my own DNS with filtering for trackers, etc.
>This is basically impossible to do on a global scale.
Is it though? Brussels effect and USB adoption tells me it is possible to affect global outcomes even in hard things like hardware if a heavyweight decides to put their finger on the scale
This precisely points to my overregulation point. The E.U. shouldn't be telling private companies how to design their products.
Absolutely not, rules for thee not for me!
This is just happening now? Shouldn't this have been done for troop security a long time ago?
The US is currently not deploying troops against an adversary that can make use of that information.
China, Iran and Russia are probably all capable of it. Russians would love the blackmail potential.
Why would they need to be deployed for an adversary to make use of that information? Sure it's more valuable on deployment, but wouldn't we also want to, you know, not give information on mobilization or lack thereof?
Google hates this trick.
News article is about Microsoft Windows AdID?
But Doubleclick might use it, no clue if it affects Google.
Hopefully they aren't forcing the military to install Trump's spyware White House app
The rules for DoD phones are different than the rest of the Executive Branch. I don't know if it will eventually roll out to DoD phones; but, that was what we were told and we haven't seen it yet.