Overseas Dangers and Released Geolocation Information
Accessing the positions of soldiers in combat could be as simple as purchasing the data from a legitimate entity. America’s global enemies have taken advantage of commercial geolocation data associated with US military personnel, as acknowledged by the Pentagon, utilizing it to target or monitor US forces in the Middle East. Nonetheless, officials point out that the Defense Department hasn’t acted swiftly to safeguard this information.
Senatorial Intervention
Senator Ron Wyden (D-OR), Representative Pat Harrigan (R-NC), and several other Congress members sent a letter to DoD CIO Kirsten Davies on Thursday, urging an overhaul of smartphone security measures within US military divisions. Among the contents of the letter is what lawmakers refer to as the initial public acknowledgment that commercial location data has been exploited to target or observe American troops in active combat areas. This information was relayed to Wyden’s office back in April. The delay in making this information public, Wyden’s team informed GadgetLad, was tied to “markings that restricted public release,” which Wyden allegedly contested, culminating in Thursday’s letter and the accompanying responses [PDF] from the DoD affirming that information acquired from commercial data brokers was used against troops.
Data Brokers and Geolocation Vulnerabilities
“USCENTCOM [US Central Command] has received several threat reports regarding adversaries’ misuse of commercial location data to target or monitor US personnel in the field,” the DoD’s April responses suggest. Regarding how data brokers obtained the information that enabled adversaries to pinpoint troop positions and movements, it was sourced from the same avenues as anyone else acquiring data from a commercial broker: Smartphone advertising profiles.
Smartphone Regulations and Disregard
According to the DoD responses included in Wyden’s letter, US military personnel are not only permitted to utilize personal devices within operational zones, but there is also no specific policy mandating that servicemembers deactivate geolocation features on their devices while in active combat areas. “USCENTCOM’s geolocation risk guidance instructs personnel to turn off geolocation functions when unnecessary; regularly check device and app privacy settings; and restrict public sharing of information,” the DoD stated last month, while concurrently admitting that such guidance doesn’t consistently disable geolocation on smartphones.
Advertising Profiles and Device Oversight
Furthermore, the DoD’s own issued smartphones also fail to deactivate advertising profiles. “The Personalized Advertising setting is turned off by group policy on the Mobile Device Management Server,” the DoD informed Wyden’s team. “However, Ad Targeting Information is not turned off and can be modified by users.” This response is not particularly clear-cut, and when we inquired with Wyden’s team about their thoughts on the reply, they concurred with our viewpoint that the Pentagon’s MDM stops the display of personal ads to users, but does not prevent the transfer of device advertising IDs or other related information.
MDM Solution Transition
The DoD indicated in the response that it is transitioning to a new MDM solution that enables the complete deactivation of location services on government-issued devices and is aiming for a completion date in early May, though it remains unclear if this process has been finalized. The Pentagon opted not to answer any of our inquiries, stating it would only address Wyden, not us. It is also uncertain how effective this MDM transition will be, as the DoD seems to be moving away from government-issued devices in favor of a more extensive BYOD approach in at least one branch. Based on a US Army press release from earlier this month, the branch aims to conclude the return of Army-managed work smartphones by the end of this month, as “the primary and preferred method for connectivity is the Bring Your Own Device, or BYOD, program.”
Background of Neglected Alerts
CENTCOM has allegedly reinforced its geolocation regulations in its operational areas; however, there is no indication of compliance among average soldiers, sailors, airmen, and Marines. How long have they been aware of this?! Failing to avert the exposure of sensitive location information of military resources could be excusable if it were a novel issue, but according to Wyden’s letter, it is not: The Pentagon has likely been aware of the problem for ten years. Per the letter, government contractors informed military leadership about the ease of locating smartphones owned by military personnel back in 2016.
Concerning Absence of Urgency
“DoD officials have not regarded this counterintelligence and force protection risk as an urgent crisis,” the letter contends, claiming that the Pentagon “has been aware of this threat for over a decade, yet has failed to initiate significant measures to safeguard our troops.” It’s not as if there haven’t been numerous instances of poor location data management jeopardizing military operations. Data from fitness tracking app Strava has been used to pinpoint the exercise paths of US military personnel running on base – and to disclose the location of French President Emmanuel Macron due to inadequate security measures by his bodyguards – while social media has also been flagged as a potential OPSEC catastrophe. Despite these numerous instances and briefings over the past ten years, the issue has persisted right up until the recent operations in Iran.
Goodness, They’re Purchasing Our Soldiers!
“That foreign adversaries can still acquire location data gathered from the smartphones of U.S. personnel stationed in military hotspots is a direct result of DoD leadership’s inability to prioritize this threat and enforce sensible cyber protections,” the letter states. Whether any actions will be taken in response remains uncertain.
Recap: Clandestine Devices and Dripping Secrets
Who would have imagined that safeguarding our troops from unwanted scrutiny could be as straightforward as instructing them to disable location services? Evidently, not the DoD. Let’s hope they rectify this situation before someone purchases our troops’ daily step counts and uses it to ignite world war three!