Norway: Soldiers' location history found in data sold by Tamoco
nrk.no
nrk.no
I'm sorry, but we have enough trouble getting this audience to read the articles as it is.
The NRK subsidiary NRKbeta has "connected the dots" from that data set. In this article they present how they could track down military personnel visiting restricted military sites in Norway, including the disputed radar installation in Vardø, close to the Russian border.
"NRKbeta is NRKs sandbox for technology and media. We write about media, the internet and new technology with a focus on you as the user, and what we at NRK do in this field. We call it a sandbox because we want to test things out, be curious and find out how things change. And bring you, the users, with us on this journey."
EDIT:
I also think it's important to contextualize this journalism with the current debate around the Norwegian contact tracing application.
The application has been heavily criticized for the collection of GPS data for research usage and track behaviour when new guidelines are announced. They claim this data is going to be "anonymized", but alter clarified it would only be "pseudonomized".
It is also unclear if the data collected is going to be deleted in December, when the app is set for deletion by the current regulation from Stortinget.
Now, other uses might require more time. If you really need to see where the person has infected others and this is your tool, it might not be enough time. It is too early to tell, though, and I'm not sure how well phone inspections would go here in Norway nor how many people would download the app. It would make me more likely to leave my phone at home if, you know, I had much life outside of home.
They might not wear them out on patrol or manoeuvres, but back at their tents/barracks, I would assume some if not all have their personal phones. You only need a couple to track them.
I also read once Strave/Fitbit type trackers was rife at army bases and used to work out patrol routes.
Back when Wikileaks released the Afghan War Diary, I wonder what would have happened if rather than a whistleblowers we would have people buying data collected from soldiers smartphones in order to reconstruct the material. It should be pretty easy to identify colaborators by which smartphone gets into contact with someones else smartphone thus reconstruct who is working with who.
Now they've added some mojo to prevent this but still sell location data.
So how about running the same attack but instead of using the browser and their own website just use the bought location data.
I suspect they didn't fix that as I've disabled appreaing on their heatmap but they still sold my location data when I forgot to disable my vpn during a run some time ago.
I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike
Presumably you could filter by average speed and only get people with expensive bikes too.
If you find that > 3 of folks in that clique are close together and somewhere else, probably having a group event, many of them may not be in their "privacy area".
Anything that collects your location data is a shtshow when it comes to operational security. Even having one friend with poor GNSS hygiene can expose an entire network of relationships.
I can see the smartest countries providing a standard webservice: you-private-company-using-geolocation will have to query a certain area, and get back a shape that you must blur or otherwise suppress. Access to the service should be heavily logged / throttled to avoid mass-scanning, and obviously “customers” will be vetted and forced to sign onerous NDAs. You don’t like the service constraints? Tough shit, here is a law that says use it or be fucked.
What's the punishment for having GPS tracking devices on a military base?
Bet they all love their free USB drives sent from a friend they forgot they had, too.
Hope they're epoxying the USB connections on their Win95 nuclear submarines.
There were also armchair people wondering about other tracks in various places in the world.
https://www.bellingcat.com/resources/how-tos/2018/01/29/stra...
Strava publish a "heat map" that shows aggregated activity of all their users. It's useful for finding common running/biking routes in areas you don't know well. That's how the military bases were found.
https://www.strava.com/heatmap#7.00/-120.90000/38.36000/hot/...
EDIT: I forgot that Strava do sell heatmap data to government transportation departments and such so I fixed the comment.
Original article is in Norwegian.
Even if GDPR should protect against it.
A lot of British intelligence during WW2 was gleamed not from the contents of the messages they intercepted, but rather from tracking who was where and communicating with whom.
And if you stop soldiers from using mobile phones on restricted ground, you are just going to have lots of tracks stopping abruptly at the gates and secure facilities identifiable by their lack of emissions.
Patterns.
There have been great examples of correctly identifying the crews of nuclear submarines by their predictable periods of time offline.
In any case, the attack here was to identify personnel based on known locations, not finding new locations in the first place. Big bases can't be hidden anyway, the best you can do is conceal what happens indoor in them so it seems silly to let foreign intelligence track personnel movement inside a base...
https://www.nytimes.com/interactive/2019/12/19/opinion/locat...