Addressing the recent attention focused on Strava and our global heatmap
blog.strava.com
blog.strava.com
I was later walking the dogs with my wife when she told me her mother was shocked that Strava was giving away the location of military bases. This was when I first became aware of Strava as a controversy.
So crazy how uninformed a populace can be. How is it Stravas fault that people use their software? If I logged onto Facebook and posted th location of a secret military base would it be Facebooks fault that I posted it?
Anyway, I have been an almost daily user of Strava for years- it's the best at what it does.
I'm not sure how to evaluate the risk here.
I'm sure the location of these bases are already known by other governments through various other means. But maybe they can gather some insight into the level of activity at a base, particularly if they monitor strava data over time.
OTOH, this info might be interesting to low-level adversaries (terrorists, ...) to find "weaker bases" which might be easier to attack.
Anybody informed can comment on the actual risks?
The big threat I see here is the names. Want to infiltrate a base? Get the name of someone who has access to the areas you want, find them on Facebook, get pictures of their family and children, learn about their habits, and <creativity>use that information</creativity> and now you've infiltrated the base.
Units shift bases all the time for various reason from simple rotation to specific operational needs.
This is a huge leak since it provides you a source for both collaborating intelligence you already have and gaining new intelligence.
Names of individual people might not be nearly as important especially for other nation states but through this data not only that the location is revealed but also the level of activity and through the personal information what is more valuable as far as intelligence goes who is deployed and here we aren’t talking about individuals but rather units.
This is huge, the level of activity in the base increases? Likely an influx of personnel which means that you’ve shifted your operational envelope to this area.
2 new support units and a SAR airwing we’re deployed to a base? Looks like some special operation is cooking.
Looks like a lot of army nerds are being deployed to this base might be setting up a SIGINT operation....
Heck the activity level alone is invaluable since it provide you with a signal which allows you to direct other sources of intelligence collection to a base that might otherwise would not have been noticed.
I can tell you that during specific operations when we would work out of hours or there would’ve be an increase in personnel an order would go out that would prohibit people from parking their car overnight and other controls would be set in place so no unusual activity that can be easily remotely picked up would be noticed.
On a non state actor level this as things like on the level of AQAP for example then the routines that can be gathered from the activity are more important, you know when people get up when they run and hitting a large group of soldiers on their morning run might be a juicy target.
Fortunately as a member of the elite RAF Regiment he was able to escape. That’s what they learn on the Five Miles Of Death.
That no human has to step in and check and maybe sometimes go, hmm, that's actually not a good idea to do that.
Computers are super-stupid, literal automatons being allowed to do whatever because Silicon Valley makes more money if it doesn't have to curate anything.
Normal humans expect computers to be a bit like humans. Have some common sense. Not have a god view. Forget stuff that happened 5 years ago, or at least be pretty hazy about it. Definitely not remember stuff from 20 years ago. Not, and this is totally crazy I know, record every voice search you've ever done in some creepy vault somewhere where it's used to sell you shit. Not be able to track you every movement from the time you leave your work, to when you go sleep with your bit-on-the-side, to where you go buy your drugs, to when you go back to your boyfriend.
We know they're not. Normal people don't, or at least haven't really thought the consequences through.
I find your view more disturbing and odd than your in-law's.
It actually is a feature. The problem is that not every feature is for everyone. When you are working in a security sensitive environment (or just like to have your privacy), you should be aware of risks and act accordingly.
> Normal humans expect computers to be a bit like humans.
This is about product design, not computer or software architecture.
The one lesson "normal humans" (whatever that means to you) should learn is that every bit of data can help to identify them.
Transferring this burden to the individual could very well lead, quickly, to no one wanting to take sensitive positions. Which would be a societal catastrophe of epic proportions.
A key part of her argument is normal people can't be expected to understand what the privacy risk is of running something like Strava. Particularly if the risk isn't so much to individual privacy but rather in aggregate.
What I find absurd here is the fact that people working in the military or other privacy sensitive fields would actually use a public social network to constantly publish updates on your activities and your precise location. I’m just a random guy that runs and bikes and still don’t let my activities public or only share some with friends. I still find it weird to blame Strava here for something that is so obvious. No matter what platform you use, be it you personal site, Facebook or others, you just don’t share certain things when you know you work in a certain environment.
* sees collected data *
Smartphone user: "How did they do this to me"
We get OpSec briefing shoved down our throats down so much that im putting this one on the DoD and the base's risk management policy.
Guys srsly wth
So if "secret" means "not listed on Wikipedia", I'm afraid only more arguments in favor of surveillance will come of this.
As far as I'm concerned, this is an industry norm, so my problem isn't so much with Strava, but the dangerous cultures that surround massive data collection operations.
Disclaimer: I work in adtech. Opinions are my own.
Not every enemy is a nation state with satellite capabilities. And not every satellite system can so extensively map e.g. patrol routes. This is a glaring opsec failure by the U.S. military.
https://www.military.com/defensetech/2012/03/15/insurgents-u...
We as technologists need to start taking some responsibility for our users privacy. Firstly, just because you can collect the data doesn't mean you should. There is this general idea that we should collect and store as much data as we can, just in case we can find a use for it. The problem is that firstly even if we claim to be only using/exposing 'anonymised' data, as this Strava situation shows, it is very hard to truly anonymise data. Secondly, the raw data is still stored somewhere and in the event of a data breach it doesn't matter what a users privacy setting was if you were still collecting and storing the data.
Strava just wouldn't exist if they didn't collect that data, it's the core of what they do - and I want Strava to exist, it's great!
There's a problem here, but maybe it's letting people use their own pocket, sensor-enabled supercomputers in secure locations?
Strava doesn't collect the data because it can, it's doing so because that's the service it provides. This isn't a case of installing some generic Messenger app and discovering that it also collects and sends to their servers the list of local wifi networks (for which there may be a valid technical reason but it would otherwise be surprising as it's removed from the main objective which is to send messages), it's more like installing a forum app and discovering that your post on the forums can be read by anyone else that accesses the same forum... I get that not all people have the same understanding of how an Internet forum works but that doesn't mean that it's always the website's fault here.
1) Does Strava present the user with privacy settings and properly explain what they do? (i.e. they don't have to dig in settings to even know that they exist)
2) Is data set to 'private' omitted from anonymized aggregate statistics like the heatmap?
If the answer to both is 'yes', then I don't understand what the fuss is about.
It’s pretty clear why in this case. The privacy settings are overcomplicated and misleading. It’s not intuitive at all that turning on “enhanced privacy” still includes you in route leaderboards and the heatmap, which you might not even know is a thing. This was bad design.
I think this news-event and some of the struggles Facebook has are highly similar (they're experiencing the pullback after years of inducing users to help them game their numbers).
What isn't obvious is if they are retaining the information or who they are sharing it with, etc. For my non-social uses there is no reason that the data really needs to leave my phone but it does anyway. We need much better consumer laws here and these things need to be made obvious and with explicit permission given by the user for each step.
In any case, I've found tech like this is more of a distraction and offers no real value. I'm a lot happier now that I've deleted strava, stopped using fitbit, removed my bike computer and gone back to basics. It feels like I can just go for a bike ride again without having to start recording and analyze all the feedback. It's like that feeling when you throw out all those kitchen gadgets you never used.
If so, then I completely blame them for this. If not, then this is clearly a user error.
"Sorry we have SO MANY users that it shows the location of, well, everything."
The military, CIA should have a clear policy to disable all location services, on all devices at all times.
If you're not supposed to be somewhere and you go for a run on Strava, it's pretty much your fault.
Doesn't look like they're actually public, though? https://www.strava.com/athletes/22230419
That is easy to change, but again there is the opt-int vs opt-out discussion.
If you purposely disengaged from this social part of the app and were trying to use it as a simple stopwatch and mileage logger then uploading data may seem weird. But that's not the clearly intended purpose of the app.
The app makes it pretty obvious and easy to control whether your profile is private or public, and if it's public, you can easily hide any activity. They've even got a "privacy screen" feature where you can set a geofence, and activities that start or end within the geofence are automatically made private.
(it's also very much in their interests not to have "delete Strava" as the first recommendation given to anyone starting a sensitive job)
You’re not supposed to be using a device which logs and beams your GPS coördinates when deployed. The fact that this is widespread means superiors failed to communicate and enforce some very basic rules.
I like privacy and think GDPR could clean up some of the mess online, but I don't even see that this tracking done by Strava is in any conflict with the law
That is BS. When you make anonymized data available publicly, you ABSOLUTELY bear a responsibility to making sure that your anonymized data is actually anonymous.
> However, we learned over the weekend that Strava members in the military, humanitarian workers and others living abroad may have shared their location in areas without other activity density and, in doing so, inadvertently increased awareness of sensitive locations.
Strava absolutely needs to be held to account for not filtering out anonymous data from regions that don't have other activity density. This should be a legal responsibility .(Currently I think the FTC can bring legal action for violating a privacy policy, but this is the only legal enforcement route?)
Strava also has a ethical responsibility to block data from sensitive area (such as military bases).
How are they supposed to know if they're displaying data for a secret base if the information to determine it actually is secret is, umm...secret?
I blame the joes -- they should know better than to share their location data because it's not a good idea for countless reasons. Back when I was deployed with the 82nd Airborne such a thing would be inconceivable.
This isn't about hiding secret bases, censoring a region from the data they release will obviously leave a blind spot. This is about not exposing the activity data of sensitive regions.