Their only means of communication with superiors was a bog-standard cell phone with a US-number SIM-card.
Forget the tracking implications: orders were texted, often via SMS.
“Yeah, getting all those Foo widgets to that secret storage place was a real pain, I know! It was bunker X9, I think.. that’s the worst, am I right?"
These tools also go a long way toward operational readiness / fitness. They incentivize these things and are used for a reason. There are trade-offs with all these things, not to mention the practical issues of blocking them.
I would expect, however, that identifying this as a huge security problem is relatively easy. "HEY DO NOT UPLOAD YOUR RUN WHILE DEPLOYED OR YOU MAY GET MORTARED" is likely a better option here, just below "MAKE SURE YOU WEAR YOUR NEON BELT" on every sign.
I take the whole lesson here to be: information can leak in unexpected ways. So solving this particular issue does nothing to help the larger problem. I'd imagine there are countless similar side channel leaks that already exist... and then even more that don't exist yet but will retroactively exist with a future phone or app update. The fox is in henhouse.
It's stupid easy to leave an Apple Watch or FitBit on your wrist walking around a secure location (as evidence suggests). Big signs required to avoid these kinds of risks.
The signage required just to get people to leave their bloody phones outside a room is incredible - and they still err. Social Network training is already provided as well to avoid these kinds of social engineering risks, and yet... well, just search LinkedIn I'd imagine.
Communication with family and friends would be my first thought. Many historical accounts put a lot of emphasise on the mail delivery and what the news from home was. It must be/have been a significant problem dealing with the mail when you had a lot of troops in the field.
In some ways this is similar however the immediacy of the data in an active conflict is more troubling.
[0] https://www.amazon.com/Lens-Infantryman-Memoir-Photographs-H...
Because there are only so few people who have factually so much power, I urge every hacker, everybody who understands the digital world, to act in the best faith of everybody. This technological revolution is too important to serve only a few.
Luckily, many hackers do the right thing and don't do everything they could to maximize their immediate benefit. I sincerely hope for humanity, for the people of poor countries, for people suffering from corrupted governments, for people who weren't as fortunate as we were, that we provide them with the technology they need. But we must not maintain control over it to have control over them. Free and just software and hardware must prevail.
If you look at GPS watches like Garmin tactix Bravo. It has a feature set, where some of the features, really only makes sense in a military/hunting setting. Although I wonder what kind of animal you are hunting if you start your hunting trip by doing a HALO parachute jump.
Garmin is not the only one making those kind of GPS watches either. I believe that Suunto has similar watches as well.
Obviously the soldiers should not be uploading their GPS tracks to Strava. But banning your non special forces soldiers from buying the same "civilian" watches that your special forces soldiers use. Sounds like a morale killer.
Want to transfer files between computers? Can't use a thumb drive! You need to burn a disk (for real).
This got a lot of attention a couple years ago:
https://www.blackhat.com/us-14/briefings.html#badusb-on-acce...
This kind of problem is endemic to small cheap devices, too – for example:
Around here a lot of places don't allow USB drives, but .. I think that's mostly a "Do Not Steal Our Data" policy.
Not, my real question is: Does that make sense? People talk about USB HID things, but .. I would expect that most keyboards and mice these days are using USB. So if you find a way to block USB drives for mass storage aka "Do Not Steal Data" uses, are you still open for all the "I type in exploits because I'm not really a USB drive, I can be a keyboard too" things?
Say you're in a "secure" place, where I'm not allowed to do stuff. You probably have keyboard/mouse connected via USB, right?
I can easily unplug them and insert my own, if you don't glue them in place. I did that in a number of internet cafes in the past.
Correct. If you're doing it right, you've blocked all unused ports, and you've glued in all used ports. Ideally having testing that the devices you're plugging in aren't already compromised first.
USB device fails and needs replacing? One place I worked disposed of the whole unit and bought a new computer to replace it, rather than dealing with glue removal. It's difficult to distinguish between legit and illegit tampering, so better to have no signs of tampering.
>I can easily unplug them and insert my own [keyboard/mouse]
Can you see where the problem lies? For you to be able to insert your own kb/mouse, you'd need to bring it from home in the first place. And while it might work if you're at an Internet cafe which isn't super strictly controlled, in an office with more stringent security requirements and checks you'd at least raise some eyebrows.
My subthread started as a reply to "Want to transfer files between computers? Can't use a thumb drive" and I wondered if that on its own - disallowing data transfers by say blocking USB mass storage device drivers or something - is useful or enough, when anything I can connect via USB can _act_ as a keyboard for example.
At no point did I talk about bringing an actual keyboard or mouse anywhere.
Not to mention lower level exploits that exist for USB.
Alternatively, have the driver require that keyboards verify themselves with a digital signature from a trusted source.
Flash drives are a huge security vulnerability. With more secure workstations you can't plug in any USB peripherals, because they're such big risk.
Write only media is a lot safer, despite the waste it causes.
[0] https://hackaday.com/2016/06/30/transcend-wifi-sd-card-is-a-...