Live data from Hacker News

Advanced Denanonymization through Strava

steveloughran.blogspot.com

21–30 of 77 posts

Re: Advanced Denanonymization through Strava

#21
post #7

This is neither advanced nor denanonymization (sic). They basically pluck an interesting route from the hotmap (as per other people's recent discovery), pretend that they have also run/biked this route and Strava will show them names of others who run/biked the same way. That's clever, but that's not "advanced" by any means. It's also not a deanonymization as there's really no option in Strava for public _anonymous_…

This is a good example to bring up when people talk about a digital bill of rights. It fundamentally shouldn't be so easy to undermine individual privacy and military op sec, but when you allow private data to be shared recklessly, you get that.

Re: Advanced Denanonymization through Strava

#22
Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not.

Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military bases in Internet's sport services. If that is even a problem in their perspective.

Re: Advanced Denanonymization through Strava

#23
post #7

This is neither advanced nor denanonymization (sic). They basically pluck an interesting route from the hotmap (as per other people's recent discovery), pretend that they have also run/biked this route and Strava will show them names of others who run/biked the same way. That's clever, but that's not "advanced" by any means. It's also not a deanonymization as there's really no option in Strava for public _anonymous_…

Unlike Facebook, Strava has no "real name" policy so you can be as anonymous as you want.

Re: Advanced Denanonymization through Strava

#24
post #4
post #3

This isn't even "deanonymization" in the sense of "performing statistical inference to re-associate different pieces of data." It's "you ask the company to give you personally identifiable data, and it does so."

Strava is a public-by-default social networking website that happens to focus on athletics. Given that, it's no surprise some users happen to work in the military (they're also on Facebook). It seems like the various militaries need to do a better job of informing and enforcing social media policy, including auditing websites like Strava. You could also argue that Strava should be private by default, but I don't thin…

Users can configure Strava so that activities are private by default.

Re: Advanced Denanonymization through Strava

#26

Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not. Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military…

You're way off. The reason this "news" is news is not because Strava has done anything naughty, it's because people that are tasked with the national security (and often some secrets) of their respective nations have committed such an easily avoidable op-sec failure.

Re: Advanced Denanonymization through Strava

#28
post #26

Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not. Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military…

You're way off. The reason this "news" is news is not because Strava has done anything naughty, it's because people that are tasked with the national security (and often some secrets) of their respective nations have committed such an easily avoidable op-sec failure.

So you didn't read the last two sentences of what I wrote :)

Re: Advanced Denanonymization through Strava

#29
> Here are some things Strava may reveal ...

These are all things I want to share and use Strava to do that. (Well maybe not "When you are away from your house" but you could not turn on the live beacon if that's a concern.)

Re: Advanced Denanonymization through Strava

#30
post #7

This is neither advanced nor denanonymization (sic). They basically pluck an interesting route from the hotmap (as per other people's recent discovery), pretend that they have also run/biked this route and Strava will show them names of others who run/biked the same way. That's clever, but that's not "advanced" by any means. It's also not a deanonymization as there's really no option in Strava for public _anonymous_…

This is a good example to bring up when people talk about a digital bill of rights. It fundamentally shouldn't be so easy to undermine individual privacy and military op sec, but when you allow private data to be shared recklessly, you get that.

Individual privacy is the issue.

Op sec is the military's problem.

Post reply on HN