Live data from Hacker News

Advanced Denanonymization through Strava

steveloughran.blogspot.com

41–50 of 77 posts

Re: Advanced Denanonymization through Strava

#41
post #11
post #10

Earlier quoted context omitted.

These are most most certainly not patrol routes, but routes taken by people in their off duty time or in mandatory fitness time.

Well, a route taken regularly at 3 am is almost certainly not someone taking an off duty stroll. I do not know if you can readily figure that out from the data available through Strava. But if you can, this is bad.

You might be able to, but even then it is more likely to be a person doing exercise on a device with the wrong time zone than it is to be someone on patrol.

To reiterate: Strava isn't always on. These are activities people have actively chosen to log. The chance of it being someone out on patrol is... not high.

Re: Advanced Denanonymization through Strava

#42
post #36

Earlier quoted context omitted.

It's easy to set privacy zones around home, work, or any other location. And you're not required to have any friends (followers). Activities can also be hidden from the public and made visible only to followers.

The author covered privacy zones and hidden activities. Neither are as secure as one would hope: privacy zones can be reverse-engineered fairly easily, and private activities can still be leaked.

Ya, I've always been wary of privacy zones' effectiveness, to the extent that I simply just keep the feature off.

Re: Advanced Denanonymization through Strava

#43
post #27

This is a total nothingburger. He hasn't found any security vulnerabilities; Strava is working exactly as documented. And you could do the same thing in Garmin Connect (probably other athletic social networks as well).

And Garmin Connect still doesn't seem to offer anything like privacy zones, it's all or nothing worth them. If anything, Strava is the beacon of privacy on the field of social fitness tracking. Garmin's only redeeming quality is that their failure to get Connect to really get off the ground in terms of social (segments and the like) that there is little incentive to ever set anything public there.

In fact, I believe that their lack of gradual privacy controls was an important factor in the failure off Garmin's attempt to gobble up Strava's market (back when they introduced their own competitive segments with the Edge 1000, now they are happily cooperating).

Re: Advanced Denanonymization through Strava

#44
post #7

This is neither advanced nor denanonymization (sic). They basically pluck an interesting route from the hotmap (as per other people's recent discovery), pretend that they have also run/biked this route and Strava will show them names of others who run/biked the same way. That's clever, but that's not "advanced" by any means. It's also not a deanonymization as there's really no option in Strava for public _anonymous_…

I wonder why Uber/Lyft/Waze don't have a feature like this for ridesharing. Seems like it would be useful to find commuters going on the same commute each day.

Announced just the other week: https://www.waze.com/carpool/

Re: Advanced Denanonymization through Strava

#45
post #11

Earlier quoted context omitted.

Well, a route taken regularly at 3 am is almost certainly not someone taking an off duty stroll. I do not know if you can readily figure that out from the data available through Strava. But if you can, this is bad.

You might be able to, but even then it is more likely to be a person doing exercise on a device with the wrong time zone than it is to be someone on patrol. To reiterate: Strava isn't always on. These are activities people have actively chosen to log. The chance of it being someone out on patrol is... not high.

Having to actively log the data is interesting. I agree with your conclusion there.

However, GPS is primarily a very high precision time signal, from which the current location is reconstructed. Basically, a properly designed software would do the proper time zone adjustment based on that, so the data should ideally be in local time everywhere without exception. Everything else would be a bug in my book.

Re: Advanced Denanonymization through Strava

#46

Earlier quoted context omitted.

Individual privacy is the issue. Op sec is the military's problem.

I agree, but what I'm saying is that it's not at all "advanced deanonymization" skills that's a problem. It's the default standars way we share data is capable of undermining privacy, and even military op sec, quite easily, that needs to be changed.

Strava is opt-in, so I don't know what default standards you mean. You can track activities on other platforms that aren't designed to be social networks.

Re: Advanced Denanonymization through Strava

#47

Strava is the first social network I want to be a part of. It promises to help me find activity partners that can help keep me motivated on the days where I'm finding it more difficult than usual to get on the pedals or put on the running shoes. Unlike most others, it might help me feel happier and healthier. I have to accept some loss of privacy for the sake of crawling out of a hole and having an automated system h…

I use Strava but I had no idea it's intended for meeting others.

Can you give more details on this? I can't find much in the app.

Re: Advanced Denanonymization through Strava

#48

Earlier quoted context omitted.

I agree, but what I'm saying is that it's not at all "advanced deanonymization" skills that's a problem. It's the default standars way we share data is capable of undermining privacy, and even military op sec, quite easily, that needs to be changed.

Strava is opt-in, so I don't know what default standards you mean. You can track activities on other platforms that aren't designed to be social networks.

I think I haven't come to a conclusion about it, but I think it is more complicated than Strava just being opt-in.

This op-ed makes the argument that it is difficult for users and even the companies offering services to fully understand the impact of their privacy choices:

https://www.nytimes.com/2018/01/30/opinion/strava-privacy.ht...

A sort of concrete scenario here would be the app asking the user before uploading an activity and whether the user wants the activity and segments to be visible on the public parts of the service. Strava probably doesn't want to introduce that friction into their product, but maybe that is a better balance than having a setting allowing users to opt out.

Re: Advanced Denanonymization through Strava

#49

Earlier quoted context omitted.

Strava is opt-in, so I don't know what default standards you mean. You can track activities on other platforms that aren't designed to be social networks.

I think I haven't come to a conclusion about it, but I think it is more complicated than Strava just being opt-in. This op-ed makes the argument that it is difficult for users and even the companies offering services to fully understand the impact of their privacy choices: https://www.nytimes.com/2018/01/30/opinion/strava-privacy.ht... A sort of concrete scenario here would be the app asking the user before uploading…

There is a pretty accessible and obvious checkbox on every activity to make it private if you wish.

Re: Advanced Denanonymization through Strava

#50
post #44

Earlier quoted context omitted.

I wonder why Uber/Lyft/Waze don't have a feature like this for ridesharing. Seems like it would be useful to find commuters going on the same commute each day.

Announced just the other week: https://www.waze.com/carpool/

I think this is just a rebranding. Waze Rider (which is the same thing?) has been around for a good year now.
Post reply on HN