U.S. military members' personal data being sold by online brokers
axios.com
axios.com
Who needs to do a driveby shooting if you could drop a homemade bomb from a McDonalds bathroom 20 miles away using some jailbroken drone? Violence isn't the only issue either -- Imagine what will happen when courts catch up to the internet age. Get ready for the normalization of digging through decades of comment history to character assassinate people on a whim. This is getting really bad. I don't think society at large is ready for the coming nightmare.
--
We need immediate privacy reforms to:
1. Fine companies for requiring unneeded personal data. Fine companies for collecting addresses and numbers when they don't need them. Address + number specifically should be dumped when no longer needed.
2. Fully regulate+audit data-based industries to confirm that anonymized user profiles are truly anonymous.
3. Raise the legal bar allowing usage of personal data to harm an individual. Lawyers and employers shouldn't be able to find+splice your Youtube comment history to try and character assassinate you outside of some felony-tier criminal case.
It should cost enough to retain personal data that, unless that's your primary business and you're very good at it, it doesn't make financial sense.
Famously, this system works well after it would be useful.
It's a legal requirement for drones above 250g to broadcast not only their position but also the position of the operator and their identification number.
And the FCC is pretty damn ruthless about finding and triangulating signals that don't comply with their rules.
Drones and IUDs may be less traceable than guns and offer even less risk to the user. Currently if you're going to use a gun, you basically have to be suicidal or care zero about the consequences.
But that also brings up a good point -- people worry about addresses being available because someone might be able to use a gun and kill them as well. Or hell, just their fists.
Doxxing is dangerous, is this not the case in Europe as well?
Gotta watch out for those intra-uterine devices - they can take out a city block. ;)
s/IUD/IED/r
The rest of the world doesn't really have the same concern or context, because the rest of the world doesn't have the same issues or political/media environment.
Also read in many places buying illegally is easy. How true is that?
If you buy a gun from someone on a classifieds site or friend/family, in most states you don't have to get a background check to transfer ownership of the firearm. This is typically the "loophole" that people refer to when they want Universal Background Checks.
I'm not sure what you mean by buying illegally - whether you mean to someone prohibited from owning firearms (like a felon or something), or buying "illegal" guns... Either way there are usually stiff penalties for owning restricted devices. For example if I were to 3D print an auto-sear for an AR-15 (making it full-auto), that's a ticket to a 10 year sentence in federal prison. Assuming I don't have the permission slip from the ATF. As for prohibited persons buying a firearm, I'm not sure what the penalties are, but at the least it'd be a violation of their release?
Or unless you have a felony, which would make up a much larger share of illegall firearm purchases than teenagers.
Or unless, of course, you're a criminal who is forbidden from legally buying a gun.
"not technically an assault rifle" doesn't matter in the slightest, no one's impressed by this constant pedantry... yes, yes, it's an ArmaLite 15 and isn't technically an assault rifle because it's only semi-automatic. This changes absolutely nothing, mass shooters are essentially cosplaying during mass shootings with this thing because it looks like an assault rifle and it's easily accessible.
the proliferation of modern small arms is one of the worst things to happen in human history
In Europe, all you need to kill your enemy and his family is two guys and a baseball bat or a knife. In America, you atleast need a gun since odds are they have a gun at home.
Source: get me out of here
I assume you understand the question re: Schengen.
There are plenty of ways to contribute to discussion without making remarks that are emotionally charged and inflammatory.
Annals of revealed preferences.
At what point do you look inward for someone to blame for your circumstances?
You can renounce a citizenship. They added an exit-fee recently. Plus if you've been living in the US working for a US company you've been paying taxes, no?
Or else you're under the table and not paying taxes, in which case this is all moot.
2. The US does not collect, if you don't want to come back to the US it doesn't matter.
First world children accidentally having US citizenship from their parents youthful indiscretions aren't so happy this decade with their inability to use normal financial services in their own country.
There's the possibility that the US gets sidelined in global finance but otherwise there's no reason to assume it won't continue with its current momentum instead of recently developed progressions somehow being steady state.
Going to the US as some kind of fun few year adventure is really no longer something someone should contemplate without first consulting non existent neutral international financial/immigration/legal council. If you aren't sure of a very specific goal/desire consider if somewhere else might work well enough instead.
Worst case you can always go back to whatever country you're a citizen on, go on welfare and start over from scratch.
They should be. As should you.
Imagine Iranian agents using these address books to track down naval officers in San Diego from across the border in Tijuana. Having a global address book lowers the barrier for hunting people down and hurting them. This is already happening to off-duty Russian officers mowing the lawn at home.
https://nypost.com/2023/08/29/russian-lieutenant-colonel-mow...
Edit: not the person making the claim, nor am I particularly vested in this story or its validity. But it took me all of 5 seconds to find.
Long range autonomous drones clearly are able to take out large scale infrastructure like pipelines, ships etc, the soft underbelly of the western world. And against the poor and proxy war forces of the world, the law is useless. We will miss the covid delivery crisis very soon.
And yes the US has the biggest navy, but against current drifting Kajak sized anti-ship submarine drones it and civil shipping is actually quite vulnerable.
And to make such a device smart enough to sleep until it identifies sounds and ship pictures, it needs no military industrial complex magic. A smartphone will do..
Driveby shootings are super easy. Drone bombing someone is way harder. Especially from 20 miles away. I don't see how Ukraine would change that.
Getting away with driveby shooting requires about the same amount of faff as getting away with a drone murder. (Because in both cases unless you biff it spectacularly the police is not going to catch you red-handed. They are going to find you based on who wanted the person gone.)
The barriers for police have also gotten lower over the time. The thing where a lot of criminals get caught is dragnet surveillance - just subpoena Google, Apple and the operators of cellphone towers for a list of everyone who was in the proximity of where a crime happened, and they have no choice but to deliver the data you yourself collected to the police.
This is also getting worse because it's just a matter of time until states with abortion bans subpoena Google, Microsoft and Apple for which persons that are regularly in that state have visited known abortion providers in another state in a timeframe consistent with an abortion visit, or who have searched about abortions on the Internet.
It's gotten a lot harder to drive off into the sunset when there are massive CCTV networks.
Drone physically distances the operator from the crime.
> The logic was simple, Pharmacist says: Exploding drones cost roughly $400 to make, while a conventional projectile can cost nearly 10 times as much. Even if it requires multiple drones to take out a tank — and sometimes it does — it is still worth it.
> But first they had to modify commercial drones with hardware and software to suit the battlefield, enabling them to penetrate deeper behind enemy lines without being detected or jammed. A breakthrough came through the clever use of several drones in unison.
https://www.pbs.org/newshour/world/how-ukraine-soldiers-use-...
Cell phone w/ 5G and a time investment from a software engineer could make the range limitless. The point is, it's entirely possible to remotely drone strike using shit from amazon if one were so inclined.
do you have an infinite battery technology? no one's crossing international borders with diy assassin drones unless it's like a mile across the canadian or mexican border — much easier to just shoot someone
You're assuming they intend to fly the drone across an ocean or something to hit a target. We don't fly predator drones across the ocean either, they are transported somewhere via other means, and then deployed to the area needed in a way they have the range to actually hit their target.
Leaving something on a building rooftop and flying back home to later operate it is not an impossible idea. Use your imagination, there are many ways. Fedex is a thing too.
again, just easier to shoot someone... we don't need to make up imaginary drone violence, there's not much reason for it outside of a warzone
All meaningless if you don't fly and use only cash, and a fake ID
> again, just easier to shoot someone... we don't need to make up imaginary drone violence, there's not much reason for it outside of a warzone
I didn't think it was easier than shooting someone. All of this stems from me saying it's only a matter of time until a psycho mounts a gun onto a drone and flies it over a crowd. We have a mass shooting once a week. Tech is easier and more accessible and only continues to be easier and more available. If soldiers are taking off the shelf drones and using them to easily kill people on the cheap, it's only a matter of time until instead of a box of ammo and trench coat, someone throws on a dji vr headset and flies a drone with either a gun on it or a bomb.
It's not imaginary
> Just a few months ago, a head of state was attacked with off-the-shelf consumer drones — an apparent first. It happened in broad daylight on August 4 in Venezuela. According to police, the drones exploded and missed their target
https://www.defenseone.com/feature/against-the-drones/
> Armed men allegedly identified as members of the Jalisco New Generation Cartel (CJNG) attacked the community of Pinolapa, in the municipality of Tepalcatepec, in the state of Michoacán, with drones loaded with explosives.
> residents of the area indicated that the drones were loaded with C4 explosives and fragmentation grenades
https://smallwarsjournal.com/jrnl/art/mexican-cartel-tactica...
https://www.politico.eu/article/future-warfare-400-army-stri...
It's illogical to think it won't happen at some point
The implication that their data is more important or something just seems like a ploy to get more eyeballs on the research.
The holy Grail of documents is the DD-214, which has every single piece of sensitive personal information a civilian has, all in one place, and we are REQUIRED to keep it indefinitely, to present it under a large number of circumstances. It's a complete identity package; full name, signature, photo, work history, residence history, dates, personal description, mother's maiden name, date of birth, location of birth, name of birth hospital and doctor. Then there's security clearance paperwork, which may be even worse, extensive un-redacted medical records, etc.
All of these documents are viewed hundreds of times by hundreds of people during a military career, scanned, photocopied, emailed, printed, all without any sort of authorization or even knowledge by the service member. It's legitimately scary. And then after you're out, all of this information is managed by the VA by people who have nearly unrestricted access to it, and in my case along with thousands of others, put on a thumb drive and taken home and sold to a broker. It's a life ruiner.
- https://en.wikipedia.org/wiki/Standard_Form_86
The OPM data breach (2015) affected service members, civilian government employees, and other civilians
- https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
Hostile foreign powers are a problem, but so are hostile domestic extremists along with a large population of the mentally ill who over the last century have gone from being abused to being ignored, which means that while most of the mentally ill are harmless, nobody is keeping an eye on the ones who aren't. Not even after they get repeatedly reported to authorities by concerned family members (Robert Card, Ethan Crumbley, Orlando Harris, etc).
If I had to guess at a motivation, it's jockeying for reasons for congress to care about data privacy issues.
I am sure some enterprising person is going to purchase all the data on members of congress and release it at some point.
So? Their data IS more important from a national security perspective, as the study suggests. If you handle nukes, your personal information would probably be more valuable than the data of someone flipping burgers at McD.
If this framing - 'the data brokerage industry is in itself a threat to national security' - forces congress to better regulate the industry, I think it is a win even if the regulations will only target military folks. It's a foot-in-the-door and objectively a good thing for the US national security.
"Policymakers should consider the following steps:
Congress should pass a comprehensive U.S. privacy law, with strong controls on the data brokerage ecosystem. The most effective step to prevent harms from data brokerage for all Americans would be a strong, comprehensive privacy law."
"Everyone's car is getting stolen these days" ... "Yeah, isn't that crazy? What are ya gonna do?"
"Your car is getting stolen right now" ... "Wait, what!?!?"
I think people really just write off the scale and scope of data privacy in this country as "yeah, sounds bad, but since it's happening to everyone there's nothing I can do about it"
Most of the previous research on data brokers and national security focuses on data about all U.S. persons, rather than focusing on servicemembers as we do in this report. Research in both categories is described here.
Also, I think of note is that Military personnel are unique in that they are banned from using tiktok, at least right now, as of recently. This research, combined with earlier and future research might be able to determine what kind of effect this ban has on data collection/data brokers.
I also think it is unique in that the US government is the employer of military personnel, so if they take any action related to protecting their employee data from brokers or from selling, maybe this can be a model for all US citizens, or at least for other employers.
I clicked through because I wanted to see whether the data was health info or OPM breach data.
Between VA employees leaving laptops full of PII laying around and that big OPM leak several years ago, I apparently have no private life.
It should not be the only information required to authenticate people.
The problem is that the entire Department of Defense is still very much a paper-oriented organization, and they got rid of service numbers in the 1970s, leaving the SSN as the only meaningful unique identifier. As a result it gets put on every piece of paperwork associated with a service member. Their own recordkeeping practices have the consequence that if you get almost any paperwork regarding a soldier, it has enough information to gain access to other personal information.
This is an important requirement for quickly checking on a person or their orders or their training status, but at the sacrifice of personal information security for you. It gets even worse going to the VA, which I can say from personal experience, will happily allow just about anyone to have whatever information they want about you. I got a happy surprise letter from them stating that my DD-214, a super identity document, containing information found on a birth certificate, a social security card, a driver's license, plus so much more, had been put on a thumb drive by a third party contractor, along with thousands of other service members info, and sold to a dark web information broker. So, the problem is just that it's to the military's benefit to not protect you.
This is not true, it's propaganda promoted by rich people who want to get rid of social security. It could be eliminated for political reasons, but spreading this idea that it's going to "run out of money" only makes that more likely. The government cannot run out of its own money. It can cause inflation, but continuing to pay social security benefits is not going to suddenly cause massive inflation. The only way social security could end is if politicians and voters decide they don't want it anymore.
Exactly: “social security is going to be gone by the time you would get it” is a line peddled almost entirely by political activists looking to build support for eliminating social security, and it has been such a line for the entire life span of people who are now old enough to receive SS old age retirement benefits.
Social security is a massive portion of federal spending, indefinitely printing money to fund it is not sustainable and will cause significant inflation
You are right that they will continue printing money regardless, and at this point it's too late for a 20% reduction to fix anything. Might as well just take the checks while you can and make the most of it, not much else you can do. But that doesn't mean its sustainable or will last forever.
“US Inflation Rate is at 3.70%, compared to 3.67% last month and 8.20% last year. This is higher than the long term average of 3.28%.”
I would hardly call something that’s only slightly above average (and less than half of what it was a year ago) as “rising rapidly“.
Is it “tacitly understanding” when you've been bathed your whole life in active propaganda promoting an idea? Because, on this, if you are in any cohort from Gen X, or maybe the trailing edge of thr Boomers, on, you have been.
Inflation will make them worthless, but we'll get our checks :)
Cranking the money printer just drives up nominal social security benefits to compensate (for current retires) or more (because easy money drives higher wages).
https://m.youtube.com/watch?v=Erp8IAUouus&pp=ygUYY2dwIGdyZXk...
(This a trick question, not a rabbit hole you actually want to go down, because no matter what you suggest, I'll happily poke a thousand holes in it.)
https://en.wikipedia.org/wiki/United_States_Office_of_Person...
But yeah, compared to that, sadly, this acquisition of much less detailed information about 30,000 service members seems moot.
It did take a few years in the mid-2010s for the forms to catch up and replace the SSN field with the DOD ID number. In 2021, I think I was supposed to get new ID tags (dog tags) that would have my DOD ID number instead of my SSN.
/s
What outcome did we expect?
There are some aspects of my work history that no one knows about and I would definitely not share them with a 3rd party just so I can board a plane 3 minutes before everyone else.
1. Servicemembers hold security clearances and thus access to critical things.
2. Leaked PII is a national security threat. This report, I'd argue, is good 'marketing' for the very real need for privacy protections nationwide. The U.S. military is, despite its best efforts, still an admired and respected institution.
As for your second point, big shrug. All the data is already out there and isn't going away anytime soon. Best case is to protect future data from being leaked, but the US isn't going to outlaw data brokers anytime soon and holding companies with poor computer security practices to account is very recent.
The solution is simple: if you want to do business with or in the United States, you must respect its citizens' rights. There's plenty of other comparable regulatory frameworks; food safety, weapons, etc.
I'm not. If there was, their data wouldn't be lumped in with everyone else when it's leaked/hacked from all these large different organizations.
> WRT your second point, 'all the data is out there' is an awful argument.
It's a fact. You won't be able to remove that stuff now that it's out. IT's somewhat an instance of the Streisand effect. Numerous people have it torrented and downloaded locally.
> The solution is simple: if you want to do business with or in the United States, you must respect its citizens' rights.
That's not any kind of solution, especially when much of the issue is internal.
You're giving the World's Largest And Most Ineffective Bureaucracy far too much agency.
> You won't be able to remove that stuff now that it's out
Who said it needs to be removed in order to secure these servicemembers' identities?
> That's not any kind of solution
It's the only solution that will work; to treat it as a constiutional mandate. It's one of the only ways to enforce widespread change when it comes to individual rights. Source: history.
Not really sure what you're saying here.
I'll just reiterate my point. If there were any real measures in place to protect the data of specific individuals, their data wouldn't be winding up in hacked databases all over the web.
> Who said it needs to be removed in order to secure these servicemembers' identities?
That's what your previous comment seemed to imply. If that wasn't your point, what was your point?
> It's the only solution that will work; to treat it as a constiutional mandate.
Orrrr you could just have a privacy act like California, Europe and numerous other reasonable states have. It has nothing to do with the constitution or foreign trading in particular.
That's pretty clear, friendo. I can't do you thinking for you, but there's plenty of ways to mitigate risk and protect identities beyond deletion of the data.
> Orrrr you could just have a privacy act like California
We agree on this, except it should be at the federal level because privacy is a natural human right that should be enshrined in our most influential and powerful laws.
Sigh. No need for your condescension. You're making poor points and defending them even worse. I'm asking you to be clearer and support your arguments.
The problem isn't with me, but your lack of clear communication.
So far, based on your replies and refusal to clarify and elaborate, the only reasonable conclusion is you don't really know what you're talking about.
My mistake, I should have known better from your first reply.
You are ignoring huge parts of reality to be able to say those 2 points above.
There is nothing in place to stop people collecting and selling data of any American personnel, and a large market that thrives on it. At the moment sensitive US people, cops, special ops people, judges, whoever, they are just as susceptible to having their data sold as joe schmo.
Then this OMB started leaking fingerprints of TS contractors. They caught the Chinese contractor.
No telling if damage was done.
Seems he was going to submit a docket of info collected on congress people which was supposed to nudge actions towards regulating data broker collections and online privacy.
Welcome to a cyberpunk novel I could not get through when I was in college, but now it's real.
Everybody's data is being sold by online brokers. Welcome to the 21 century.
Sure, some of those users don't actually have clearance at all, but many actually do, and work at firms all doing contracting for the federal government. Call me crazy, but giving out a list of people with clearance to the highest levels of secrets, usually doing tech work, is a bad idea. Even if a tiny fraction of them has anything that can be used as leverage to flip them, they all have targets on their backs and it kinda blows my mind that they all run around proudly plastering such things on their profiles and in public groups. It seems that's the last thing they would all be doing, as to not draw any attention from "the enemy"
"TS/SCI cleared IT Professionals" - https://www.linkedin.com/groups/3967699/
I'm also not job seeking, just using it as a rolodex in case I ever need it later. Maybe I'll need to lay out the details if I ever do use it for job seeking.
if you were a foreign power wanting to gather data on defence programmers, for blackmail, corruption, surveillance etc, why wouldn't you do this?
There are 140 stars on the CIA memorial wall total, which includes plenty of wars and combat zones.
There's no serious threat to almost all people who have a security clearance. Quds Force is not scraping LinkedIn for the names of these people.
You've listed a whole bunch of questions but the things you've proposed - the threat, its reality, the notion it actually affects someone, etc are entirely of your own making. The onus is on you to provide any evidence of them and there just doesn't seem to be any.
I'm saying it's for sure an attack vector. How could it not be?
Empirically, it doesn't appear to be and hasn't been ever? Again, what makes you think otherwise?
The key phrase in my original statement is _in extreme cases_ - I'm not saying such a thing is common or even likely, I'm saying when you have a bunch of tech contractors with TS access all over the place advertising to the world that they have such access, there's no way other places haven't used that info in an attempt to intimidate someone, bribe, or force, one of those contractors into helping them get into a system or get information out. If a contractor was able to yank and leak the Prism documents with the same access, working for the same firm as some of the people in the group I linked to, then it's a massive risk that these people are being looked into and attempts are being made to flip them somehow. Might not be by killing people, but who's to say for sure.