Live data from Hacker News

How The Pentagon learned to use targeted ads to find its targets

wired.com

51–60 of 139 posts

Re: How The Pentagon learned to use targeted ads to find its targets

#51
post #24

So, what's the best weather app to use that's not going to sell my location?

The Windy privacy policy seems decent. https://account.windy.com/agreements/windy-privacy-policy

+1 for Windy! Note that there are two apps named Windy, one with a red icon and one with a blue icon. The one you linked to has a red icon and lists its developer as Windyty, SE.

The one with the blue icon has a site at Windy.app. Their privacy policy is much more hand-wavy, with lines about how they “don’t sell” but “share” your personal information:

https://windyapp.co/CustomMenuItems/26/en

One of the techniques they list explicitly is to use the Meta pixel for targeted advertising. I’m not aware of any way to remove geo data from, for example, the Meta pixel and the auctions it sells into. It suggests to me that perhaps they’re thinking of your geo data as incidental to placing targeted advertising.

Re: How The Pentagon learned to use targeted ads to find its targets

#53
post #33

Earlier quoted context omitted.

When we had to go into SCIFs, generally phones went into lockers. At some locations, phones stayed in cars. But that doesn't make it any harder to figure out. But this isn't the first time people are encountering this problem. Strava has given away plenty of US military bases: https://www.theguardian.com/world/2018/jan/28/fitness-tracki... Russia has the same problem, VKontakte has given away plenty of secret Russian…

When I was in the military cell phones were extremely new, but I honestly don't see why most commands don't say "leave phones and other electronics at home when coming to base" and then you just tell anyone who needs to contact you to call the command quarterdeck or whatever. Examples you just gave are good reasons to do this, much like how in the 90's during Desert Storm several people figured out (post-hoc, but sti…

> When I was in the military cell phones were extremely new, but I honestly don't see why most commands don't say "leave phones and other electronics at home when coming to base" and then you just tell anyone who needs to contact you to call the command quarterdeck or whatever.

Because soldiers will just go and take their phones anyway - they will want to keep in touch with their families.

The solution to this problem is to kill off the targeted ads market in its entirety. Maybe national security is the only way to actually make that go through.

Re: How The Pentagon learned to use targeted ads to find its targets

#54

Android lets you delete the advertising id that's mentioned in the article, as well as reset it. Does anybody who is in Adtech know what that does in terms of identifiability on brokers? Am I now "anon at location x,y", or am I "anon4321 at location x,y”?

Never underestimate the power of metadata. An expired ID that patterns quite similar to a new ID is quite easy to identify.

it looks like you stay with "no id". There is just an option "get a new advertising id"

Here how to delete it in Android and Apple: https://www.eff.org/pt-br/deeplinks/2022/05/how-disable-ad-i...

Re: How The Pentagon learned to use targeted ads to find its targets

#56

Android lets you delete the advertising id that's mentioned in the article, as well as reset it. Does anybody who is in Adtech know what that does in terms of identifiability on brokers? Am I now "anon at location x,y", or am I "anon4321 at location x,y”?

here how to delete it: https://www.eff.org/pt-br/deeplinks/2022/05/how-disable-ad-i...

Re: How The Pentagon learned to use targeted ads to find its targets

#58

One thing I've always been curious about, and have never been able to find a solid answer too, is what data is available to the various companies whose software I have on my phone? What can AT&T/TMobile/etc... learn from my device as my carrier? What can the apps I have installed decern from my device if I allow no access to anything settings? How does this change if I use a vpn? I have an idea of whats possible base…

I don't know of any carrier hypervisory capability, but there has been a lot of discussion about OnePlus phones and the data they exfiltrate. There's a bunch of vendor bloatware even on my factory-reset phones so it's not out of the question that a carrier-locked phone might have snuck something else in there.

Intelligence can be inferred at the carrier level even with paranoid privacy settings and all apps using HTTPS. CDNs in particular frequently serve content over regular HTTP, and there aren't too many reasons why you'd be communicating with Grindr's CDN. All of this is visible over the wire.

DNS requests betray a lot about you. VPNs are notoriously leaky when it comes to DNS as well. I'd expect that even with a VPN running you're not stopping anything, just changing the exfiltration route for some of your traffic.

Re: How The Pentagon learned to use targeted ads to find its targets

#59

One thing I've always been curious about, and have never been able to find a solid answer too, is what data is available to the various companies whose software I have on my phone? What can AT&T/TMobile/etc... learn from my device as my carrier? What can the apps I have installed decern from my device if I allow no access to anything settings? How does this change if I use a vpn? I have an idea of whats possible base…

Chances are yes. On Android, you can control 'some' of the permissions - the basic ones (contacts, calendar, location, etc.)

There are some though "view Wi-Fi connections", "have full network access", "view network connections", "query all packages", "advertising ID permission", and so on, that give the app (and it's creator) a good view of what's going on in your phone. I tend to (by trial & error) block everything with NoRoot Firewall. Those who want to be naughty though cannot be stopped, as they send both useful and telemetry through the same connection/target IP.

Post reply on HN