Live data from Hacker News

Norway: Soldiers' location history found in data sold by Tamoco

nrk.no

11–20 of 78 posts

Re: Norway: Soldiers' location history found in data sold by Tamoco

#11
post #3

Earlier quoted context omitted.

A bit context on NRKbeta from their website. "NRKbeta is NRKs sandbox for technology and media. We write about media, the internet and new technology with a focus on you as the user, and what we at NRK do in this field. We call it a sandbox because we want to test things out, be curious and find out how things change. And bring you, the users, with us on this journey." https://nrkbeta.no/ EDIT: I also think it's impo…

Is december a realistic end date for the epidemic control it is supposed to provide? Herd immunity by vaccination at that point is extremely unlikely...

If you are using it for data instead of control, well, that's months of data about how people move around with varying restrictions. It is enough to refine policies and note how different sorts of restrictions change people's behavior. For example, if no one really follows x mandate, well, you either drop the mandate, change it, or come in with some fairly heavy-duty force.

Now, other uses might require more time. If you really need to see where the person has infected others and this is your tool, it might not be enough time. It is too early to tell, though, and I'm not sure how well phone inspections would go here in Norway nor how many people would download the app. It would make me more likely to leave my phone at home if, you know, I had much life outside of home.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#13
post #9

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

You can add privacy zones around locations so when people look at your activities your line just disappears inside the radius of your privacy zones. I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike

The fact that an area is made private is also a piece of information. I was thinking that you could use that to track down sensitive areas.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#14

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

Not only could you see bases because of activity around an otherwise empty area. You could almost pinpoint the exact shape of the bases perimeter because soldiers would prefer to jog along the inside of the perimeter. Smartphones and location based apps and services are a security nightmare.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#15
post #9

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

You can add privacy zones around locations so when people look at your activities your line just disappears inside the radius of your privacy zones. I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike

That’s effective on an individual level, but tricky to enforce at an organizational level. It’s not like it would be wise for the DoD to log into Strava and setup a privacy fence around every sensitive location.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#16

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

Seems to me the scandal is that US military bases allowed people in protected areas to upload GPS traces of their activities, more so than strava showing these along with millions of other traces in their activity maps...

Re: Norway: Soldiers' location history found in data sold by Tamoco

#17
post #13
post #9

Earlier quoted context omitted.

You can add privacy zones around locations so when people look at your activities your line just disappears inside the radius of your privacy zones. I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike

The fact that an area is made private is also a piece of information. I was thinking that you could use that to track down sensitive areas.

Unless I'm missing something you can easily triangulate the center point of the private area.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#18
post #16

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

Seems to me the scandal is that US military bases allowed people in protected areas to upload GPS traces of their activities, more so than strava showing these along with millions of other traces in their activity maps...

Well, yes, but also that Strava takes this hands-off approach like they're not responsible for the data they collate

Re: Norway: Soldiers' location history found in data sold by Tamoco

#19
post #9

This reminds me of an experiment I'd like someone to run on Strava. They had this big scandal some time ago where People identified US military bases simply by having a lot of activity in an otherwise empty area. Now they've added some mojo to prevent this but still sell location data. So how about running the same attack but instead of using the browser and their own website just use the bought location data. I susp…

You can add privacy zones around locations so when people look at your activities your line just disappears inside the radius of your privacy zones. I have ones around my home and where I work. No idea if that affects whatever data they sell (I doubt it, since you can still the full activity yourself even with a privacy zone), but stops people finding where you live/work and nicking your bike

you're essentially telling strava that the privacy area is very important to you (ie your home, work, etc) and they are probably selling that fact.

Re: Norway: Soldiers' location history found in data sold by Tamoco

#20

A bit of context for non-Norwegians: The government owned media NRK bought location data from Tamoco worth approximately 3,400 USD. The NRK subsidiary NRKbeta has "connected the dots" from that data set. In this article they present how they could track down military personnel visiting restricted military sites in Norway, including the disputed radar installation in Vardø, close to the Russian border.

This reminds me of this rumour about how someone used tinder to triangulate opponent units during an exercise and arty them to shit. Supposedly Finns outwitting Norwegians, but is a anon text so who knows: https://imgur.com/gallery/bySUH

"Hot missile silos in your area are waiting for you"
Post reply on HN