156 pointsby tencentshill8 hours ago21 comments
  • tencentshill8 hours ago
    It sounds like they disabled the "advertising ID" OS feature, but there are many other ways to fingerprint a device for advertising. Maybe this will lead to real privacy reform, now that the true risks are apparent. Not to mention ICE using the same data against civilians.
    • pnw5 hours ago
      Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones. Apple doesn't allow SDKs which attempt to bypass this, so the app would have to have a first party auth of some type.
      • gruez3 hours ago
        >Disabling "advertising ID" on iOS makes it extremely difficult to reliably fingerprint phones.

        You got this flipped. The whole point of "fingerprinting" is to build a stable identifier that works even if a explicit identifier (IMEI or advertising ID) isn't available. And yes, there are shady SDKs that do this without facing repercussions.

        https://www.buchodi.com/i-broke-applovins-mediation-cipher-p...

      • thrawa83873365 hours ago
        Dude, FAANG still manage to do it, day in day out.
        • jdm22125 hours ago
          IIRC they actually don't and it materially reduced Meta's profit when Apple rolled out the advertiser ID system.
          • throw0101d5 hours ago
            "Facebook says Apple iOS privacy change will result in $10 billion revenue hit this year" (2022):

            * https://www.cnbc.com/2022/02/02/facebook-says-apple-ios-priv...

            See also perhaps "It’s not Meta - its APPLE who have screwed us small advertisers":

            * https://www.reddit.com/r/FacebookAds/comments/1o85w2q/

            • DiggyJohnson3 hours ago
              Wow that number is line an order of magnitude or more than I expected it would be
            • kstrauser3 hours ago
              Won't someone please think of the poor advertisers? /s
          • elevation4 hours ago
            That may have been true initially but meta has enough information to heuristically observe unidentified users and compare their behaviors with known consumers. It only takes a few actions to uniquely identify a consumer with a high degree of confidence.
            • sroussey3 hours ago
              Yes, it was temporary and Meta revenue and profit at all time high (before data center buildout).
    • roosterIllusi0n3 hours ago
      Everything they do is a framework for consumer protection laws.
    • shevy-java6 hours ago
      [flagged]
      • monotomic6 hours ago
        [flagged]
        • 6 hours ago
          undefined
        • hnlmorg6 hours ago
          Just out of interest, what news sources do you follow?

          I ask because those claims are made by a very small few yet debunked by every independent investigation.

          • monotomic5 hours ago
            [flagged]
            • martyfunkhouser5 hours ago
              > All you losers hang out on HN and Reddit because its the only place you can flag and moderate away reality

              Minor correction, but you forgot Wikipedia. Why flag reality when you can rewrite it and police it with bots?

              Reverting change, references do not meet WP::59593 subparagraph 4.1

              • techteach003 hours ago
                Whatever you posted that is now dead I'm certain was true. These SWES are all imperialist servants. Here are 1 million upvotes
              • 5 hours ago
                undefined
            • hnlmorg5 hours ago
              And here lies the problem with having intelligent conversations with followers of popularist movements:

              I asked a straightforward question and you ramble on about something else entirely. If you actually cared about your country then you’d have answered honestly.

              So I won’t bother to engage with you further.

              • ryandrake5 hours ago
                Why worry about facts and evidence when you instead have "vibes from the real world."
                • 5 hours ago
                  undefined
              • 5 hours ago
                undefined
    • danparsonson6 hours ago
      [flagged]
      • tencentshill6 hours ago
        It now directly affects the troops and military, who they ostensibly do care about. Maybe the citizens can have a little privacy reform, as a trickle-down treat.
        • john_strinlai6 hours ago
          maybe trickle-down privacy will be more successful than trickle-down economics. one can hope.
        • bigyabai6 hours ago
          The US will still surveil the troops and citizens. All this does is reduce the commercial attack surface for adversaries, privacy be damned.
          • tencentshill4 hours ago
            The "buying from advertisers" strategy was a workaround, and has yet to be properly tested in court. Hopefully we'll get that loophole closed soon. They also use it heavily for recruitment to pinpoint the most desperate youth.
        • macintux6 hours ago
          Trump has demonstrated repeatedly, emphatically, and publicly that he does not care about the troops, or at least certainly not injured/captured/killed ones. Or minorities. Or non-citizens fighting for the country. Or citizens with non-citizen spouses/fiancees/parents.
        • jlarocco6 hours ago
          If they cared about the troops, they wouldn't send them on bullshit missions like whatever we're doing in Iran.
      • sublinear6 hours ago
        You insist on using broad brushstroke language like "masked goons". Nobody is going to listen to your lack of nuance on other topics either.
        • TheNastyPatty5 hours ago
          How much nuance is there really to explore in that topic if even longtime ICE agents are themselves decrying the current state of the agency, and rightfully blaming the current administration for opening the floodgates to any redneck who can read a job application

          https://www.the-independent.com/news/world/americas/us-polit...

          • 5 hours ago
            undefined
          • 5 hours ago
            undefined
        • juliushuijnk5 hours ago
          broad brushstroke guess; ICE
        • lovich4 hours ago
          I mean, they are masked, right?

          And they’ve been going around beating people and in a few cases killing them, like goons, right?

          Just because terms can and have been used hyperbolically doesn’t mean that the same term cannot accurately describe other situations.

      • copper-float5 hours ago
        [dead]
      • mannanj5 hours ago
        Note: much of the privacy work is done by Israeli intelligence firms. If you think that it's "our" government, you'll be disappointed.
  • ferguess_k5 hours ago
    Does it make sense to give the troops special phones instead of their own? I always find it weird that soldiers can take their own phones into the base.
    • metiscus4 hours ago
      Most of what goes on on most bases is as unsecret as it gets. The rooms where sensitive things happen have security measures in place and they keep you from bringing your phone in there. Usually a little locker is provided where you store your phone while you are inside the protected area. In some very sensitive places there may be additional active and passive measures but usually people with access to those areas police themselves.
      • MSFT_Edging2 hours ago
        Like a lot of data collection, the meta data gets you pretty far. The who's and where's can be hoovered up with tracking data buys and essentially get you a nice list of who has access to certain areas, which can be used for targeting individuals.
      • astrobe_3 hours ago
        Guess what people talk (and write) about after meetings.
        • AnimalMuppet3 hours ago
          If you talk and/or write about what happened in one of those places, you can face consequences from discipline up to prison.

          Yes, it happens. No, it better not happen much, and it's not supposed to happen at all.

      • lovich4 hours ago
        Unless your Matt Gaetz and co, in which case you just storm into the SCIF with a recording device and are allowed to get away with it.
    • pjc503 hours ago
      It allows fun things like locating aircraft carriers on Strava.

      I don't think the Iranians have direct targeting tech for individual mobiles for decapitation strikes yet, that's an Israeli capability.

    • apefulsin3 hours ago
      The base is where people live 24/7. You'd be banning them from having phones.
  • aleph_minus_onean hour ago
    Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?

    It should be obvious that the US military has good reasons why this would be the death for many military strategies. So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?

    • 2legit2quita minute ago
      > Why even allow any mobile phone for the US solider if it could cause any arbitrary problem for the US military if the location data, name, unit, rank, ... of the respective soldier was published and permanently updated on a publicly viewable website?

      By this logic, why keep anyone around after the SF86 hack[0]? Simple answer: Costs. It's a lot more expensive to lay off everyone with a security clearance (especially, if they're regular employees) and make a whole new batch of people go through the security background checks. We're probably talking billions - not to mention the issue with downtime of no one being around to do anything.

      > So, why doesn't the military than treat every soldier who has a mobile phone near to him where the above could cause military problems to be a saboteur (perhaps even with the accusation of being a spy of a hostile nation) who should be charged by a military tribunal?

      ...because they (they being the military, in general) have - relatively - planned for this in places that they physically control (and the threats levels demand it) by essentially making all buildings that need to be secure giant faraday cages.

      What that doesn't account for is people outside of the buildings[1], which is probably what they're hoping to address with this change. (Too little, too late, I think - as that data's already out there.)

      0 - https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

      1 - https://www.wired.com/story/phone-data-us-soldiers-spies-nuc...

    • obviouslynotme12 minutes ago
      There are MANY problems that are too politically or practically difficult to tackle for the US Military and personal cellphones aren't close to the top ten. It's far easier to force everyone to register their cells to be automatically blacklisted from data collection than it is to justify tens of thousands of NJPs and court martials every year, many of which will include officers and senior enlisted.

      The US Military doesn't win through stealth or secrets either. Their advantage from the beginning until now has always been funding and logistics. With the Internet, satellites, and now AI, OPSEC is a fool's errand outside of very specific operations anyhow.

  • cgannett4 hours ago
    Oh boy, what an easy way to see if the phone's user is military or not.
    • FuriouslyAdrift3 hours ago
      Exactly.

      The abscence of an indicator that is expected is itself an indicator.

  • 9cb14c1ec06 hours ago
    Just throwing this link out into the void:

    https://www.wired.com/story/how-pentagon-learned-targeted-ad...

    Wonder why it took the Pentagon so long to take the ads risk seriously.

  • silver92bullet4 hours ago
    This is probably a smart move. Especially finger printing is more and more intelligent. If foreign actors are using exercise tracking apps to track US Military personnel and positions. It seems reasonable that they would want to block something that is much lower effort for tracking.
  • sorenKaram3 hours ago
    Feels like this should have been done long ago. Like I would just assume that ad tracking (any kind of tracking) for military is always gonna be a bad idea.
  • iamnothere6 hours ago
    Wait until they realize that military spouses and children might also need this, and government employees, and sensitive contractors, etc. It’s almost as if “ad trackers” shouldn’t exist at all.

    The US government used to love this stuff when it was the only one who could abuse it. There might be a different outlook now that the tables have turned.

    • jonhohle6 hours ago
      It seems like stalking laws in most jurisdictions should already cover this. Is there any legal precedent that could help without the need for new laws?
      • iamnothere6 hours ago
        In a different legal environment this would be a good approach, but currently I don’t think the courts would accept this argument, as they are trying to push Congress to legislate rules on things like this (which Congress steadfastly refuses to do). Prior courts were more willing to “legislate from the bench” but current justices have expressed concern that Congress is abdicating its rulemaking responsibility.
        • manphone4 hours ago
          That’s a hilarious idea. Given the Supreme Court of today, afraid of legislating from the bench? Are you serious?
          • iamnothere4 hours ago
            Yes. The majority of their decisions seem to bear that out. While the current court isn’t run by strict constitutionalists, the direction of the court seems to be in favor of rolling back previous precedent that overstepped constitutional boundaries and restoring constitutional balances based on originalist interpretations. This doesn’t please anybody, of course, because both political “teams” have lost major fights in this process.

            Not that every decision bears this out, of course, and it’s also a slow process.

            IMO this restoration is a necessary step in restoring the operation of the constitution. As a country we need to decide if we’re going to actually follow it (including making use of the long-dead amendment process) or throw it out (amounting to a revolution). Selectively ignoring parts of it depending on who is in power, or based on whatever the bipartisan intelligence/defense agenda requires, is unworkable and needs to end ASAP.

          • kelnos3 hours ago
            Most of the contentious SCOTUS decisions these days are the opposite of that, where they defer to Congress or the executive.
          • DiggyJohnson3 hours ago
            Yes. Why do you disagree?
      • brookst5 hours ago
        I don’t think stalking laws cover it. Laws are largely about intent and I don’t think anyone could say that Google is planning to attack everyone.

        Law isn’t code. You can’t reduce stalking laws down to “it’s illegal to track people” and then extrapolate back up into ad tech. That’s what gets you “we should jail surgeons for cutting people with knives”. Context and intent matter.

      • john_strinlai6 hours ago
        i am not a lawyer, but to the best of my knowledge there are specific criteria for "stalking", one of which being that the stalking causes fear or distress.

        the average person (i.e. a "reasonable person" by legal definition, even if us tech folk don't consider it reasonable) is not particularly scared or distressed by targeted ads. some people even like them.

        a good lawyer might be able to make something out of it, but i'm not convinced that stalking laws are the right avenue.

        • LadyCailin3 hours ago
          Not to mention you “opted in” by the terms and conditions of the service, which would certainly argue that if you didn’t agree to the terms, you didn’t have to use their website.
      • ambicapter3 hours ago
        Laws won't help against foreign actors, which are, after all, the main adversaries of the military.
  • stevenalowe2 hours ago
    Why do deployed troops have cell phones at all? Seems like a huge security risk
  • exabrial6 hours ago
    Wow, it's like there should be a law that allows anyone to disable all data tracking about then, not just anonymize it.

    This is a large conversation about Consent, which is a concept Silicon Valley refuses to acknowledge.

    • GJim6 hours ago
      Ironically, the US Miliary appears to be supporting the GDPR.
    • lenerdenator6 hours ago
      To them, the consent is using the device/service/whatever.

      You see it in various bits of EULA and ToS all the time. "Continued use of <insert thing here> implies agreement with the license terms".

      Now, is that at all feasible when you need a smartphone to do things like pay for parking in cities or to read menus at restaurants? No. Do the people in SV who think this way also try to wedge their products and services in every single nook, cranny, and crevice of our lives as a way to increase their net worth? Yes. Is this indicative that these people have severe antisocial or sociopathic tendencies that we, as a society, need to handle? I'm not a psychologist.

      • john_strinlai5 hours ago
        >To them, the consent is using the device/service/whatever.

        exactly. the problem is the missing qualifying word.

        when consumers say consent, it's almost always referring to informed consent.

        when companies say consent, it's almost always referring to implied consent.

      • pona-a3 hours ago
        What's their excuse with Flock-like surveillance? Leaving the house is consent to their tracking. Let's be real: they don't value consent in any form.

        I wouldn't be surprised one of those big-tech product managers gets tried for not understanding sexual consent either.

      • cindyllm4 hours ago
        [dead]
    • throw849303846 hours ago
      [flagged]
  • quickthrowman7 hours ago
    Could probably get a lot of actionable military information about troop locations by running targeted ads for subprime auto loans and divorce lawyers and collecting location information, discarding any US locations.
    • ericmay5 hours ago
      Probably not anything more than you could find via publicly accessible information and then the movements you do care about (deploying to go fight in a war) you'd get via your satellites and so forth.

      It's unfortunate that predatory businesses exist (payday loans and furniture rental anyone - you could run ads for those in certain communities :o ) but it's a tough and demanding lifestyle that's a bit unstable since our military actually does things and there are a lot of predatory auto companies and banks out there praying on regular people (most of them from poorer, working class, and/or minority communities) who aren't as well educated as the rest of us on things like interest rates and loans and all of those things.

    • voakbasda7 hours ago
      You say that like it’s not already happening.
      • quickthrowman6 hours ago
        I have no doubt it’s already being used if it was the first thought that popped into my head.

        It’s less obvious than looking at Strava maps, but still low hanging fruit.

    • 9cb14c1ec06 hours ago
      Oh, this is an old trick the US has used for a long time:

      https://www.wired.com/story/how-pentagon-learned-targeted-ad...

  • nonameiguess6 hours ago
    These things need to include more details. What is the report that ads were used to target deployed troops? What is the device use policy as of today? FOBs and semi-permanent installations are not secret locations. They're extremely obvious, have marked fences, gates, and guards in uniform. They're on satellite and aerial photos, sometimes on maps, depending on how long they've been in place. During patrols and any other movements in which unit locations are meant to be secret, as of 15 years ago when I was still serving, phones or any other kind of personal electronic device were not allowed. Even in training exercises, as far back as 2009 that I experienced, and probably further back than that, SIGINT units used radio triangulation to find and kill you when you used a phone during an exercise, which resulted in both removal from the exercise and reprimand because you weren't supposed to have a phone with you in the first place. They also captured and publicly shamed shit like getting nudes from your girlfriend or even just exchanging text messages.

    If deployed personnel are sharing videos of their deployment activities to social media, how is that allowed? It can't be, right? They're violating some policy in doing that. Unit commanders have your social media accounts and monitor what you do there. Uniformed servicemembers have never had any expectation of privacy. UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice. All communications can and will be intercepted and read.

    • derektank5 hours ago
      >Unit commanders have your social media accounts and monitor what you do there.

      I’m prior Air Force, so never been deployed to a FOB, but I have never had a commander ask me for my social media accounts. I’m not sure how this is even possible. I couldn’t even tell you all my social media accounts if you define social media as a platform where people communicate directly with one another publicly (forums, marketplaces like Craigslist, etc.) You can correct me if I’m wrong, but I have never seen it happen and it seems like a pretty weak enforcement mechanism.

      > UCMJ doesn't have 4th amendment rights. Your room, housing, belongings, car, phone, can all be searched with impunity at any time, with or without notice.

      That’s a bit of an overstatement. For housing or computer systems owned by the military, yes, you have no expectation of privacy and they can be searched without probable cause. However, personal effects such as your phone or laptop do have protections against unauthorized searches. Commanders and military judges must have a reason for authorizing a search, that search must be narrowly tailored, and if the search does not meet these requirements the evidence can be suppressed during court martial proceedings. Good example would be US v. Nieto

      https://law.justia.com/cases/federal/appellate-courts/caaf/1...

      • nonameiguess2 hours ago
        That's entirely fair. It is an overstatement. What I meant was, when deployed or during an exercise, any radio communications you make, letters you write, television shows you watch, can be intercepted and read. It's not the case that 100% will be. Back in garrison, it depends on if you live in barracks or not. If you're off post, nobody is busting into your house in the middle of the night with no notice.

        As for social media, it's not that they universally ask for access, but they know what is happening. I was commissioned and we knew when Soldiers shit talked us on social media. I didn't care most of the time and didn't do anything about it other than give a few warnings here and there for really egregious shit, but we knew. We can get the contents of what you post from your existing friends.

    • samus6 hours ago
      The US military hasn't yet been in a military altercation with a peer adversary that can actually exploit that information. The war in Ukraine shows that these information leaks can have severe tactical consequences.
      • downrightmike5 hours ago
        China APTs are in our telecoms and no one is willing to fix that. China helps Russia, Russia helps Iran
  • 1vuio0pswjnm74 hours ago
    theguardian.com now requires a user-agent header

    Any string is acceptable, including zero characters

  • 7 hours ago
    undefined
  • mmooss3 hours ago
    If they can do it effectively, that would be impressive. There are so many ways phones and other devices are tracked. Do they prevent users from installing apps?

    For example, I was reading Apple's Platform Security guide, a technical, detailed manual: There are so many identifiers, before any applications are installed - really, before the OS is fully loaded - that it's hard to keep track of them, manage them, or even form a mental picture of what's going on. Apple in many ways requires you to send those identifiers to them in order to use the device.

    Apple is trying to protect consumers by operating the Root of Trust for the consumer devices, something consumers can't do effectively for themselves. And maybe Apple provides large customers with means to become their own root of trust; some of Apple's keys are embedded during manufacturing but other vendors allow large customers to substitute their own keys at that stage.

    Regardless, it makes Apple an incredibly valuable target for highly resourced attackers, like the kind targeting the US military: Gain the right authority at Apple and you can monitor and control Apple devices worldwide. I'm not sure how the US military protects themselves without highly managed, locked down, customized devices.

  • Havoc7 hours ago
    Could also you know just ban invasive tracking and adtech bullshit…
    • drnick13 hours ago
      This is basically impossible to do on a global scale. And even within a jurisdiction, there is a great risk of overregulation, see e.g. Europe.

      Disclaimer: I am a Linux and GrapheneOS user, running my own DNS with filtering for trackers, etc.

      • Havocan hour ago
        >This is basically impossible to do on a global scale.

        Is it though? Brussels effect and USB adoption tells me it is possible to affect global outcomes even in hard things like hardware if a heavyweight decides to put their finger on the scale

        • drnick133 minutes ago
          This precisely points to my overregulation point. The E.U. shouldn't be telling private companies how to design their products.
    • tamimio7 hours ago
      Absolutely not, rules for thee not for me!
  • slowmovintarget6 hours ago
    This is just happening now? Shouldn't this have been done for troop security a long time ago?
    • samus6 hours ago
      The US is currently not deploying troops against an adversary that can make use of that information.
      • nephihaha15 minutes ago
        China, Iran and Russia are probably all capable of it. Russians would love the blackmail potential.
      • slowmovintarget4 hours ago
        Why would they need to be deployed for an adversary to make use of that information? Sure it's more valuable on deployment, but wouldn't we also want to, you know, not give information on mobilization or lack thereof?
    • 6 hours ago
      undefined
  • shevy-java6 hours ago
    Google hates this trick.
    • a3w6 hours ago
      News article is about Microsoft Windows AdID?

      But Doubleclick might use it, no clue if it affects Google.

  • surcap5265 hours ago
    [dead]
  • colincowardly6 hours ago
    [dead]
  • JohnTHaller6 hours ago
    Hopefully they aren't forcing the military to install Trump's spyware White House app
    • 55556246 hours ago
      The rules for DoD phones are different than the rest of the Executive Branch. I don't know if it will eventually roll out to DoD phones; but, that was what we were told and we haven't seen it yet.