Live data from Hacker News

Advanced Denanonymization through Strava

steveloughran.blogspot.com

11–20 of 77 posts

Re: Advanced Denanonymization through Strava

#11
post #10
post #8

Earlier quoted context omitted.

Even the knowledge of exact guard patrol routes and possibly even timings inside a known military base can be extremely helpful information for someone planning an attack. Best part: you don't even have to place a scout in physical proximity as preparation and risk discovery. So this is less than ideal for military organizations.

These are most most certainly not patrol routes, but routes taken by people in their off duty time or in mandatory fitness time.

Well, a route taken regularly at 3 am is almost certainly not someone taking an off duty stroll. I do not know if you can readily figure that out from the data available through Strava. But if you can, this is bad.

Re: Advanced Denanonymization through Strava

#12
Strava has trivial to use controls to shut down this type of data gathering. You simply define zones on the map as privacy zones and voila, any travel in those areas will simply not appear publicly, and will not be part of public heat maps or anything like that.

Of course, the original point of that is to avoid people knowing where you live to come steal your expensive bike. But it's useful for other reasons too.

Re: Advanced Denanonymization through Strava

#13
post #11
post #10

Earlier quoted context omitted.

These are most most certainly not patrol routes, but routes taken by people in their off duty time or in mandatory fitness time.

Well, a route taken regularly at 3 am is almost certainly not someone taking an off duty stroll. I do not know if you can readily figure that out from the data available through Strava. But if you can, this is bad.

How can you be so sure? Patrol shifts are normally rotated to prevent exactly that among other reasons, while someone having a regular non-patrol late shift (or early) and doing his exercise regularly at 3 am is also not unheard of.

Re: Advanced Denanonymization through Strava

#14
post #5

At this point Strava should pull all of its public data. All of these location based services are wide open to attack, correlating across pairs of them, scary.

At what point? There was no change in the last maybe 3~4 years. Heatmap wasn't kept that up to date, but that's about it. There are privacy settings you can set (and the app is nagging you to do so) to avoid these problems. If it is a problem.

Re: Advanced Denanonymization through Strava

#16
post #13
post #11

Earlier quoted context omitted.

Well, a route taken regularly at 3 am is almost certainly not someone taking an off duty stroll. I do not know if you can readily figure that out from the data available through Strava. But if you can, this is bad.

How can you be so sure? Patrol shifts are normally rotated to prevent exactly that among other reasons, while someone having a regular non-patrol late shift (or early) and doing his exercise regularly at 3 am is also not unheard of.

I did do some guard duty. The bases I was at were dead silent in the middle of the night.

Re: Advanced Denanonymization through Strava

#17
Interesting tips in this article for the paranoid. But it's way easier to do it old school: don't use a service that gobbles your data up, no matter how free it is.

It'd be great if there were better "really free"--noncentralized--alternatives built on open source. Maybe there are.

Re: Advanced Denanonymization through Strava

#19
I wonder what happened before the smart phone era. Didn't the armed personnel phone back to their loved one to let them know they were ok? I am sure they did it in a controlled environment. When you set up a base, should you not take into account the parameters responsible for your safety? For, example, register all the smart phones and impose strict rules for sharing data. Who ever get anything out, should get the shaft or get discharged from the service. And finally why would anyone upload their personal details to an unknown source? Are people so silly?
Post reply on HN