How The Pentagon learned to use targeted ads to find its targets
wired.com
wired.com
I think you're referring to Facebook/Meta removing many detailed PII-specific targeting options, 1/2022.
I believe it's not direct targeting and there are limits to stop targeting like we're discussing.
Are you seriously telling me that government phones of national security employees allow for the installation of apps that track your location and/or these employees are allowed to bring personal cell phones into these buildings?
But this isn't the first time people are encountering this problem. Strava has given away plenty of US military bases: https://www.theguardian.com/world/2018/jan/28/fitness-tracki...
Russia has the same problem, VKontakte has given away plenty of secret Russian military bases and troop positions over the past few decades. I've never read of this on Weibo or WeChat, but my guess is they have the same problem, just English language open source accounts are keeping it more discrete for now.
The WashPost about a week ago had an article about how at a recent NTC rotation out at Fort Irwin the OPFOR was trying to figure out how an Apache had gotten past their air defenses, so they looked up commercial cell phone tracking data and were able to spot how a phone had gone across the desert at 120 mph and plug the hole in their air defenses.[1]
Adtech on the cell phone we all carry in our pocket is better at surveillance than the best tools a military has. And it's one of those things where not being part of the surveillance can make you stand out too. Think about a spy operating under a real cover, how long is their Facebook (or Weibo or VK or TikTok or whatever is appropriate for the person they are trying to be) account history? If you found someone claiming to be a 45 year old woman living in an American suburb and she had a Facebook account that was three months old, wouldn't you investigate further?
1: https://www.washingtonpost.com/national-security/2024/02/22/...
https://www.bbc.com/news/world-europe-66162502
Strava actually has extensive privacy controls that work well. Users can keep activities private by default and hide their tracks near sensitive locations. But of course if you don't use the privacy control and make everything public then obviously everyone can see exactly where you were.
https://www.theguardian.com/world/2018/jan/28/fitness-tracki...
Because soldiers will just go and take their phones anyway - they will want to keep in touch with their families.
The solution to this problem is to kill off the targeted ads market in its entirety. Maybe national security is the only way to actually make that go through.
When there is a military order - refusing is not an option. And you can check if people have smartphones with them without searching them - quite easy, how they do it in airplanes, emf meters. They are quite cheap.
Also you don't have to ban them everywhere. But everywhere critial, yes. A ordinary mobile phone is basically a spying device in terms of security. I would not ask who maybe has access, but who has not.
"The solution to this problem is to kill off the targeted ads market in its entirety. Maybe national security is the only way to actually make that go through."
So I am sorry, but national security won't help get us rid of targeted ads, you probably also missed the part, where national security of course happily uses that data for themself. So for them it is way easier to just ban smartphones in more areas, than disrupt the internet ad market.
The article I linked to in WP talked about how difficult the Ukrainian army is finding cellphone discipline, at the beginning of their third year of high intensity war (and a decade of low-intensity combat operations). Because even in a real shooting war zone this sort of stuff is hard to police.
So... still close enough?
If they drive nearby and leave it in the car, you can find them.
If they drive nearby and turn it off then, you can find them (improve it by bracketing by the average 9-5 workday, add correlation of world events to late-night anomalies - i.e. the Washington pizza index[1]).
If they leave their phone at home and switch it off, then you can still find them by that data.
If they leave their phone at home, switched on, then this also applies - you filter by public holidays.
The key is that the "phone policy" is effectively public information - so you don't have to guess, you can just go find out what it is to set your search parameters.
[1] https://www.washingtonpost.com/wp-srv/politics/special/clint...
Here's my proposal:
- Prohibit all Federal employees from bringing a personal cellular radio to work.
- Build many parking structures for DC Federal employees across the region.
- Assign each employee a particular parking structure, ideally selected at random.
- Ensure each parking structure is served by public transportation infrastructure, dedicated shuttles, and a USGOV-run black car service to bring people to their workplace, potentially via an extra obfuscating hop to a different parking structure.
In an ideal world, all Federal employees would behave indistinguishably. That's impractical, but we can do a lot better than the status quo.
"being really secret" doesn't work because the attempt to do so means you're doing a whole lot of stuff that no ordinary person does. That's a statistical anomaly - that's easy to find.
And again: all this information is public. It would be widely and well known that this is what is done, so what to look for would be well advertised. The locations of these buildings would then be well known. And since you've now added multiple intervening steps, nailing down who's going where is also easier - i.e. if someone drives into a known parking structure at time X, then you can draw a circle around that which is the mean transport time to get to any interesting federal buildings in the area before the work day starts. Map this across a few months and you'll pin down exactly which one they work at (I mean, you wouldn't bother if you were a foreign government though - a couple days worth of casual surveillance work would also grab every number plate and face you can see).
This is quite aside from the why of doing this: it would be a huge pain in the ass for the employees, who are not paid nearly enough to bother with it and become a hiring problem, for...what gain?
ICE in the US has been known to use this same data to track down and harm undocumented migrants.
Personally, I have a de-googled Pixel running GrapheneOS. It has a sandboxed version of Google Play, but without the elevated system privileges. I am not signed in to Google at any kind of global device level. I can still install and run most apps, but without the tracking.
https://www.penguinrandomhouse.com/books/706321/means-of-con...
What can AT&T/TMobile/etc... learn from my device as my carrier?
What can the apps I have installed decern from my device if I allow no access to anything settings?
How does this change if I use a vpn?
I have an idea of whats possible based on my career in tech, but I'd love a more solid answer. Happy to read any content answering the aforementioned.
Unfortunately that isn't a question you'll get an answer to. Anyone who actually knows and has access to sensitive sources and methods is under an obligation not to disclose them. Further nobody in the know wants to burn these sources - because it makes their job harder.
The general advice I can give is use an iPhone (turn on Lock Down mode if you believe you might be the target of well resourced attackers), use Google suite for your personal data (and turn on Advanced Protection), don't use commercially available VPNs (set up your own or just don't connect to wifi in untrusted places), and periodically delete third party apps you don't use (especially any that use location services).
You are more than welcome to try and secure your own stuff against nation state attackers. Or you can outsource that work to a company that has some of the best security minds in the world watching over your account 24/7.
There are some though "view Wi-Fi connections", "have full network access", "view network connections", "query all packages", "advertising ID permission", and so on, that give the app (and it's creator) a good view of what's going on in your phone. I tend to (by trial & error) block everything with NoRoot Firewall. Those who want to be naughty though cannot be stopped, as they send both useful and telemetry through the same connection/target IP.
For the latter:
One thing you can do is install a man in the middle and "sniff" what is being transferred by your phone (at least on wifi).
I use a tool called Proxyman, it allows me to install a self signed certificate on my phone and this allows the decryption of SSL traffic by Proxyman. From there its kinda like Wireshark (If you have used that).
It basically shows you all the data going in and out of the device.
So with the pieces set up you then start a new sniffing session and then open up an app on your phone and use it. This will show you all the data that is being transferred.
A lot of apps are transferring all sorts of data. For myself its become so burdensome that I am trying to find a way to automate this analysis for all my apps so I can build a personal "web" of what data has left what app and keep a record of it.
Not all data is horrendous, for example every app I have tested transfers some sort of data on analytics for QA and app quality improvements. Things like app crash reports or other things of that nature. Thats not so bad compared to other data.
You can also try decompiling an app and seeing what libraries are used. Using these two things for example I learned about the 7-Eleven app and its usage of Bluetooth beacons so they can track were you are going when you are in their store.
you're not wrong, but not going anywhere either.
Intelligence can be inferred at the carrier level even with paranoid privacy settings and all apps using HTTPS. CDNs in particular frequently serve content over regular HTTP, and there aren't too many reasons why you'd be communicating with Grindr's CDN. All of this is visible over the wire.
DNS requests betray a lot about you. VPNs are notoriously leaky when it comes to DNS as well. I'd expect that even with a VPN running you're not stopping anything, just changing the exfiltration route for some of your traffic.
Here how to delete it in Android and Apple: https://www.eff.org/pt-br/deeplinks/2022/05/how-disable-ad-i...
Does the ad auction tell the users current location? Does grindr let you run your own auction bidder on your own machine?
Tiktok was used to find and track/monitor Chinese dissident whereabouts a few years ago by the CCP in Hong Kong.
after that they all added targeting by weather (latest fine grained targeting under gdpr) and BT beacon tracking.
fun fact, google uses BT on your phone to mark of you entered a store after seeing an ad for it to get paid for the "conversion".
You can also target ads by geography and do a lat/long box over your target area and show a specific ad so you know how many unique users are in that area.
would you like to know more?
see also: https://www.jstor.org/stable/27862533
Baryshnikov & Ghrist, Target Enumeration Via Euler Characteristic Integrals (2009)
> We solve the problem of counting the total number of observable targets (e.g., persons, vehicles, landmarks) in a region using local counts performed by a network of sensors, each of which measures the number of targets nearby but neither their identities nor any positional information. We formulate and solve several such problems based on the types of sensors and mobility of the targets.
The one with the blue icon has a site at Windy.app. Their privacy policy is much more hand-wavy, with lines about how they “don’t sell” but “share” your personal information:
https://windyapp.co/CustomMenuItems/26/en
One of the techniques they list explicitly is to use the Meta pixel for targeted advertising. I’m not aware of any way to remove geo data from, for example, the Meta pixel and the auctions it sells into. It suggests to me that perhaps they’re thinking of your geo data as incidental to placing targeted advertising.
What a terrible take. People like apps, we should make apps private I stead of telling people not to use apps. FWIW, websites can gain access to your location too, so plenty of people will still be tracked.
Choose which apps use your Android phone's location
https://support.google.com/android/answer/6179507?hl=en
Control app tracking permissions on iPhone
https://support.apple.com/guide/iphone/control-app-tracking-...
Life360, like other apps that track location data, makes a significant portion of its annual revenue from selling this data -- about 20 percent in 2020.