Live data from Hacker News

How The Pentagon learned to use targeted ads to find its targets

wired.com

81–90 of 139 posts

Re: How The Pentagon learned to use targeted ads to find its targets

#81
post #77
post #64

Reminds me of the guy who pranked his roommate with Facebook ads targeted to an audience of one: https://ghostinfluence.com/the-ultimate-retaliation-pranking...

I did this once too and it worked. The targeting is much less specific than it was years ago though.

Useful to gives dates. Swichkow's prank ad mentioned above was back in 2014.

I think you're referring to Facebook/Meta removing many detailed PII-specific targeting options, 1/2022.

Re: How The Pentagon learned to use targeted ads to find its targets

#82
post #33

Earlier quoted context omitted.

When we had to go into SCIFs, generally phones went into lockers. At some locations, phones stayed in cars. But that doesn't make it any harder to figure out. But this isn't the first time people are encountering this problem. Strava has given away plenty of US military bases: https://www.theguardian.com/world/2018/jan/28/fitness-tracki... Russia has the same problem, VKontakte has given away plenty of secret Russian…

When I was in the military cell phones were extremely new, but I honestly don't see why most commands don't say "leave phones and other electronics at home when coming to base" and then you just tell anyone who needs to contact you to call the command quarterdeck or whatever. Examples you just gave are good reasons to do this, much like how in the 90's during Desert Storm several people figured out (post-hoc, but sti…

I think your instinct is well founded but at odds with the massive tech industry pushing the other way. This is the classic imbalance between offense and defense: for something like a building’s location, the defender has to do the right thing every time. You put out that order and most people follow it but over time someone’s going to make a mistake - they’ll forget their LTE AppleWatch counts as a phone, their spouse or kid will leave their phone in the car and Facebook will helpfully share that location belongs to people who like military pages, their cell provider helpfully links their vehicle’s integrated cellular device with the other devices on the account when selling data, etc. It feels like the solution might need to start with a significant data protection law making some of that data collection impossible and all of it requiring notification so someone could at least have the chance to know where they’d be breaking policy.

Re: How The Pentagon learned to use targeted ads to find its targets

#83
post #24

So, what's the best weather app to use that's not going to sell my location?

Why you need an app for the weather, what's wrong with websites?

Mine gives me notifications before unpleasant weather events. A website can’t send me an alert saying that it’s about to start raining in 20 minutes.

Re: How The Pentagon learned to use targeted ads to find its targets

#84
post #54

Earlier quoted context omitted.

Never underestimate the power of metadata. An expired ID that patterns quite similar to a new ID is quite easy to identify.

it looks like you stay with "no id". There is just an option "get a new advertising id" Here how to delete it in Android and Apple: https://www.eff.org/pt-br/deeplinks/2022/05/how-disable-ad-i...

If you have Android 12+, well that's another reason for me to replace my fairly old phone.

Re: How The Pentagon learned to use targeted ads to find its targets

#85
post #17

I don't understand how targeted ads on Grindr can be used to get peoples locations. Does the ad auction tell the users current location? Does grindr let you run your own auction bidder on your own machine?

SnapChat does the same thing, we (not me technically, I am just a developer that worked with our ad team) set up Geofences around events to serve ads and we could continue to target those users for continuous remarketing as soon as they stepped foot into and out of a location of our choosing. In our case it was mostly a concert and car race. We knew -a lot- more than we probably should have. You could push filters, a…

It feels so creepy, thanks for the insight.

Re: How The Pentagon learned to use targeted ads to find its targets

#86

Apropos to nothing... Choose which apps use your Android phone's location https://support.google.com/android/answer/6179507?hl=en Control app tracking permissions on iPhone https://support.apple.com/guide/iphone/control-app-tracking-...

I found that OnePlus android allows you to toggle mobile data and WiFi data per app, by the way. Pixel and Samsung only allow that for mobile. Semi related.

I was very pleased to discover that option in LineageOS a few years ago.

Re: How The Pentagon learned to use targeted ads to find its targets

#87
post #64

Reminds me of the guy who pranked his roommate with Facebook ads targeted to an audience of one: https://ghostinfluence.com/the-ultimate-retaliation-pranking...

I did this to land some larger B2B clients, sadly facebook doesn't support this detailed targeting anymore.

Re: How The Pentagon learned to use targeted ads to find its targets

#88

One thing I've always been curious about, and have never been able to find a solid answer too, is what data is available to the various companies whose software I have on my phone? What can AT&T/TMobile/etc... learn from my device as my carrier? What can the apps I have installed decern from my device if I allow no access to anything settings? How does this change if I use a vpn? I have an idea of whats possible base…

I am not sure if this is exactly what you are asking. Are you looking for aggregated data on yourself or methods to discover what is being transferred?

For the latter:

One thing you can do is install a man in the middle and "sniff" what is being transferred by your phone (at least on wifi).

I use a tool called Proxyman, it allows me to install a self signed certificate on my phone and this allows the decryption of SSL traffic by Proxyman. From there its kinda like Wireshark (If you have used that).

It basically shows you all the data going in and out of the device.

So with the pieces set up you then start a new sniffing session and then open up an app on your phone and use it. This will show you all the data that is being transferred.

A lot of apps are transferring all sorts of data. For myself its become so burdensome that I am trying to find a way to automate this analysis for all my apps so I can build a personal "web" of what data has left what app and keep a record of it.

Not all data is horrendous, for example every app I have tested transfers some sort of data on analytics for QA and app quality improvements. Things like app crash reports or other things of that nature. Thats not so bad compared to other data.

You can also try decompiling an app and seeing what libraries are used. Using these two things for example I learned about the 7-Eleven app and its usage of Bluetooth beacons so they can track were you are going when you are in their store.

Re: How The Pentagon learned to use targeted ads to find its targets

#89
post #33

Earlier quoted context omitted.

When I was in the military cell phones were extremely new, but I honestly don't see why most commands don't say "leave phones and other electronics at home when coming to base" and then you just tell anyone who needs to contact you to call the command quarterdeck or whatever. Examples you just gave are good reasons to do this, much like how in the 90's during Desert Storm several people figured out (post-hoc, but sti…

Because the 18 year old who really misses his girlfriend needs to have his phone on him? The operator's wife back at Bragg (excuse me, Fort Liberty now) wants to know that he's safe, to use the example from the original article about watching phones go from North Carolina to Syria and back. The article I linked to in WP talked about how difficult the Ukrainian army is finding cellphone discipline, at the beginning of…

The Ukrainian situation is especially interesting because to my mind it is the first cellphone war. We've gone from cellphones being used as passive electronic switches (as in, detonation systems for roadside bombs) to it being the control interface for innovative weaponry and tactics such as drones against infantry. I dont know that irregular or inexperienced troops will ever give up this level of capability, and I'm not sure that wealthier militaries have figured out how to mutate consumer cellphones into equally powerful portable tools without essentially dumbing them down back to tetra radios.

Re: How The Pentagon learned to use targeted ads to find its targets

#90
This is why you don't let the weather app access your location. In fact, weather apps are one of the main offenders here.

ICE in the US has been known to use this same data to track down and harm undocumented migrants.

Personally, I have a de-googled Pixel running GrapheneOS. It has a sandboxed version of Google Play, but without the elevated system privileges. I am not signed in to Google at any kind of global device level. I can still install and run most apps, but without the tracking.

Post reply on HN