Live data from Hacker News

Advanced Denanonymization through Strava

steveloughran.blogspot.com

61–70 of 77 posts

Re: Advanced Denanonymization through Strava

#62
post #36

Earlier quoted context omitted.

It's easy to set privacy zones around home, work, or any other location. And you're not required to have any friends (followers). Activities can also be hidden from the public and made visible only to followers.

The author covered privacy zones and hidden activities. Neither are as secure as one would hope: privacy zones can be reverse-engineered fairly easily, and private activities can still be leaked.

Activities marked as "Private" Don't leak. But in "enhanced privacy" mode your activities can be seen via the segment leaderboards. In any declared privacy zone, you stay off those boards, irrespective of options, and (allegedly) heatmaps. So really, it's "slightly more advanced privacy"

Re: Advanced Denanonymization through Strava

#63

Strava is the first social network I want to be a part of. It promises to help me find activity partners that can help keep me motivated on the days where I'm finding it more difficult than usual to get on the pedals or put on the running shoes. Unlike most others, it might help me feel happier and healthier. I have to accept some loss of privacy for the sake of crawling out of a hole and having an automated system h…

I use Strava but I had no idea it's intended for meeting others. Can you give more details on this? I can't find much in the app.

find and join a running/cycling club in your area

Re: Advanced Denanonymization through Strava

#64
post #9
post #8

Earlier quoted context omitted.

Even the knowledge of exact guard patrol routes and possibly even timings inside a known military base can be extremely helpful information for someone planning an attack. Best part: you don't even have to place a scout in physical proximity as preparation and risk discovery. So this is less than ideal for military organizations.

You're totally right of course and I think it's pretty shocking that military personnel aren't aware they are broadcasting their location out to the web. Complete opsec failure.

They are, they just don't care. The State Dept will likely issue a ban on their facilities which personnel will adhere to. Other military installations like Special Forces bases or regular Army bases overseas probably will issue a memorandum ("Be Vigilant!"), but I predict they won't stop using the devices. State Department facilities are the only places that they try to hide from others. Not that people and equipment are operating out of them (because that's impossible), but that they are State Department facilities to begin with.

Re: Advanced Denanonymization through Strava

#65

Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not. Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military…

It is not seen as a problem by the regular military. Kinda hard to hide tanks and artillery pieces and soldiers with iPads and C-130s flying into airfields from locals in countries where having a car is a luxury. Locals can get better information about the bases from people working on the bases, or from just watching them. There is basically nothing you can get from this heatmap that you couldn't get from really any local living near the place. It's the other non-military facilities that would care about this.

Re: Advanced Denanonymization through Strava

#66
post #43
post #27

This is a total nothingburger. He hasn't found any security vulnerabilities; Strava is working exactly as documented. And you could do the same thing in Garmin Connect (probably other athletic social networks as well).

And Garmin Connect still doesn't seem to offer anything like privacy zones, it's all or nothing worth them. If anything, Strava is the beacon of privacy on the field of social fitness tracking. Garmin's only redeeming quality is that their failure to get Connect to really get off the ground in terms of social (segments and the like) that there is little incentive to ever set anything public there. In fact, I believe…

Garmin Connect added privacy zones in April 2017. They work exactly the same way as in Strava.

https://connect.garmin.com/modern/settings/privacySettings

I don't think Garmin Connect was really ever intended as a true Strava competitor. It's limited to just users of Garmin devices and intended to drive hardware sales through offering additional planning and analytics features.

Re: Advanced Denanonymization through Strava

#67

I think it's really a shame that Strava is taking so much heat. The heatmap was a really cool visualization and also useful to find out where people are running and biking, generally. And, it was created from tracks that people willing uploaded and made public, even if they didn't fully understand the privacy implications. But it's also frightening that this data, stored indefinitely, is effectively a mass surveillan…

>I was contacted by local law enforcement who had gotten my email address from Strava via an "official legal process" because I had ridden my bike in an area around the time a homicide occurred. If it makes you feel any better they probably filtered out all the "less likely to murder people" demographics, went though everything they could dig up on your and your friends/family looking for interesting things (e.g. tra…

What's interesting is that they thought to look at Strava to see who had ridden there during the time period of interest. You'd need to think "let's see who cycled", and come up with a way of querying strava, such as demanding the list of people who cycled there. If Strava gets checked, then except for the special case of a witness saying "I saw someone suspicious on a bike", they'd have already checked Waze, apple find friends, etc

Re: Advanced Denanonymization through Strava

#68
post #26

Earlier quoted context omitted.

You're way off. The reason this "news" is news is not because Strava has done anything naughty, it's because people that are tasked with the national security (and often some secrets) of their respective nations have committed such an easily avoidable op-sec failure.

So you didn't read the last two sentences of what I wrote :)

That was mostly what I was replying to, but yes I didn't really read it. I originally read the paragraph as meaning some of the media coverage you had seen/read tried to somehow find fault with Strava. I re-read it, and I see what you meant now. I read a bit too much into the quotes.

Re: Advanced Denanonymization through Strava

#69
post #45

Earlier quoted context omitted.

You might be able to, but even then it is more likely to be a person doing exercise on a device with the wrong time zone than it is to be someone on patrol. To reiterate: Strava isn't always on. These are activities people have actively chosen to log. The chance of it being someone out on patrol is... not high.

Having to actively log the data is interesting. I agree with your conclusion there. However, GPS is primarily a very high precision time signal, from which the current location is reconstructed. Basically, a properly designed software would do the proper time zone adjustment based on that, so the data should ideally be in local time everywhere without exception. Everything else would be a bug in my book.

OK, but that isn't how these devices work.

Source: I've used lots of them and it's a real pain in the ass.

Re: Advanced Denanonymization through Strava

#70

Earlier quoted context omitted.

The author covered privacy zones and hidden activities. Neither are as secure as one would hope: privacy zones can be reverse-engineered fairly easily, and private activities can still be leaked.

Activities marked as "Private" Don't leak. But in "enhanced privacy" mode your activities can be seen via the segment leaderboards. In any declared privacy zone, you stay off those boards, irrespective of options, and (allegedly) heatmaps. So really, it's "slightly more advanced privacy"

You can also opt-out of segment leaderboards. With some work you can lock out your account so only your friends can see your routes, photos and stuff. Everything is well explained on Strava support webpage in section called "Privacy Settings".
Post reply on HN