19 ms·
Norway: Soldiers' location history found in data sold by Tamoco
- santamarias 6y agoA bit of context for non-Norwegians: The government owned media NRK bought location data from Tamoco worth approximately 3,400 USD. The NRK subsidiary NRKbeta has "connected the dots" from that data set. In this article they present how they could track down military personnel visiting restricted military sites in Norway, including the disputed radar installation in Vardø, close to the Russian border.
- Foxboron 6y agoA bit context on NRKbeta from their website. "NRKbeta is NRKs sandbox for technology and media. We write about media, the internet and new technology with a focus on you as the user, and what we at NRK do in this field. We call it a sandbox because we want to test things out, be curious and find out how things change. And bring you, the users, with us on this journey." https://nrkbeta.no/ https://nrkbeta.no/ EDIT: I also think it's important to contextualize this journalism with the current debate around the Norwegian contact tracing application. The application has been heavily criticized for the collection of GPS data for research usage and track behaviour when new guidelines are announced. They claim this data is going to be "anonymized", but alter clarified it would only be "pseudonomized". It is also unclear if the data collected is going to be deleted in December, when the app is set for deletion by the current regulation from Stortinget.
- SiempreViernes 6y agoIs december a realistic end date for the epidemic control it is supposed to provide? Herd immunity by vaccination at that point is extremely unlikely...
- Broken_Hippo 6y agoIf you are using it for data instead of control, well, that's months of data about how people move around with varying restrictions. It is enough to refine policies and note how different sorts of restrictions change people's behavior. For example, if no one really follows x mandate, well, you either drop the mandate, change it, or come in with some fairly heavy-duty force. Now, other uses might require more time. If you really need to see where the person has infected others and this is your tool, it might not be enough time. It is too early to tell, though, and I'm not sure how well phone inspections would go here in Norway nor how many people would download the app. It would make me more likely to leave my phone at home if, you know, I had much life outside of home.
- hhjinks 6y agoThey picked a dumb name. As a Norwegian, I was under the impression that they've actually got a beta version of some supposed new site functionality for the longest time.
- SiempreViernes 6y agoThis reminds me of this rumour about how someone used tinder to triangulate opponent units during an exercise and arty them to shit. Supposedly Finns outwitting Norwegians, but is a anon text so who knows: https://imgur.com/gallery/bySUH https://imgur.com/gallery/bySUH
- skocznymroczny 6y ago"Hot missile silos in your area are waiting for you"
- csiegert 6y agoReminds me of a story I heard: In a conflict, Russia sent SMS to the mothers of Ukrainian(?) soldiers, informing them of their son’s death (pretending to be the Ukrainian government/military). The mothers, distraught, called their son’s cellphone. The increased, clustered cellphone activity near the frontline gave away the unit positions. Shortly after, Russian bombs dropped.
- matt_the_bass 6y agoThis is sinister genius. Do you have a citation link? I’d love to read more.
- santamarias 6y agoperhaps useful to replace the wording "track down" with "identify"?
- belorn 6y agoIt is surprising that this is not illegal. It should be illegal under GDPR as sufficient anonymized data should not allow you to connect the dots to do anything like tracking military personnel. Transporting sensitive military information over the Norwegian border sounds also very illegal under Norwegian law. Back when Wikileaks released the Afghan War Diary, I wonder what would have happened if rather than a whistleblowers we would have people buying data collected from soldiers smartphones in order to reconstruct the material. It should be pretty easy to identify colaborators by which smartphone gets into contact with someones else smartphone thus reconstruct who is working with who.
- user5994461 6y agoGoogle translate: https://translate.google.com/translate?sl=auto&tl=en&u=https%3A%2F%2Fwww.nrk.no%2Fnorge%2Fxl%2Fnorske-offiserer-og-soldater-avslort-av-mobilen-1.14890424 https://translate.google.com/translate?sl=auto&tl=en&u=https... Original article is in Norwegian.
- deleted 6y ago[deleted]
- Grollicus 6y agoThis reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I suspect they didn't fix that as I've disabled appreaing on their heatmap but they still sold my location data when I forgot to disable my vpn during a run some time ago.
- mathieuh 6y agoYou can add privacy zones around locations so when people look at your activities your line just disappears inside the radius of your privacy zones. I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike
- egwor 6y agoThe fact that an area is made private is also a piece of information. I was thinking that you could use that to track down sensitive areas.
- muldvarp 6y agoUnless I'm missing something you can easily triangulate the center point of the private area.
- ashtonkem 6y agoThat’s effective on an individual level, but tricky to enforce at an organizational level. It’s not like it would be wise for the DoD to log into Strava and setup a privacy fence around every sensitive location.
- bluntfang 6y agoyou're essentially telling strava that the privacy area is very important to you (ie your home, work, etc) and they are probably selling that fact.
- daffy 6y agoIt would be interesting to know which ``apps'' were responsible for leaking the data.
- dylkil 6y agocheck the settings on your phone, the ones with location data access are selling it.
- daffy 6y agoAll of them? How do you know this?
- im3w1l 6y agoThe vast majority. You have to go out of your way to find apps that don't scoop up all the data they can. Why not? It's not like consumers penalize it.
- m1aw 6y agoYou don't but you could make the point that since they are not open source, you will never be sure about it. Even if GDPR should protect against it.
- dylkil 6y agoits makes them alot of money, they would be fools not to
- erikbye 6y ago"On average app publishers make $10,000 a month with Tamoco data monetization." https://www.tamoco.com/blog/best-app-revenue-calculator/ https://www.tamoco.com/blog/best-app-revenue-calculator/
- john_minsk 6y agoDon't allow soldiers to have mobile on restricted ground...
- ganzuul 6y agoThat is akin to not letting them have guns in modern warfare. Or a field shovel.
- sgt 6y agoNonsense. I agree, the soldiers should not be permitted to have cellphones in critical areas unless exception is given for some other reason. There are ways to communicate using encrypted communication bands used by police etc. They could be using small handheld devices for 2 way radio and basic messaging.
- svrtknst 6y agoNo, it's more like requiring them to use their issued equipment, over bringing their own guns.
- ganzuul 6y agoI did not say anything about using their own mobiles.
- willvarfar 6y ago
- TazeTSchnitzel 6y agoSomething similar has happened before: https://news.ycombinator.com/item?id=16249955 https://news.ycombinator.com/item?id=16249955
- JacobHonore 6y agoReminded me of this New York Times article where they got hold of location data from 12 million americans. I think NRK found some inspiration from that. https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html https://www.nytimes.com/interactive/2019/12/19/opinion/locat...
- dang 6y agoWe have nothing but respect for Norway, but HN is an English-language site, so articles here need to be in English. I'm sorry, but we have enough trouble getting this audience to read the articles as it is.
- santamarias 6y agopoint taken, thanks :)