Advanced Denanonymization through Strava
61–70 of 77 posts
Re: Advanced Denanonymization through Strava
#62Earlier quoted context omitted.
It's easy to set privacy zones around home, work, or any other location. And you're not required to have any friends (followers). Activities can also be hidden from the public and made visible only to followers.
The author covered privacy zones and hidden activities. Neither are as secure as one would hope: privacy zones can be reverse-engineered fairly easily, and private activities can still be leaked.
Re: Advanced Denanonymization through Strava
#63Strava is the first social network I want to be a part of. It promises to help me find activity partners that can help keep me motivated on the days where I'm finding it more difficult than usual to get on the pedals or put on the running shoes. Unlike most others, it might help me feel happier and healthier. I have to accept some loss of privacy for the sake of crawling out of a hole and having an automated system h…
I use Strava but I had no idea it's intended for meeting others. Can you give more details on this? I can't find much in the app.
Re: Advanced Denanonymization through Strava
#64Earlier quoted context omitted.
Even the knowledge of exact guard patrol routes and possibly even timings inside a known military base can be extremely helpful information for someone planning an attack. Best part: you don't even have to place a scout in physical proximity as preparation and risk discovery. So this is less than ideal for military organizations.
You're totally right of course and I think it's pretty shocking that military personnel aren't aware they are broadcasting their location out to the web. Complete opsec failure.
Re: Advanced Denanonymization through Strava
#65Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not. Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military…
Re: Advanced Denanonymization through Strava
#66This is a total nothingburger. He hasn't found any security vulnerabilities; Strava is working exactly as documented. And you could do the same thing in Garmin Connect (probably other athletic social networks as well).
And Garmin Connect still doesn't seem to offer anything like privacy zones, it's all or nothing worth them. If anything, Strava is the beacon of privacy on the field of social fitness tracking. Garmin's only redeeming quality is that their failure to get Connect to really get off the ground in terms of social (segments and the like) that there is little incentive to ever set anything public there. In fact, I believe…
https://connect.garmin.com/modern/settings/privacySettings
I don't think Garmin Connect was really ever intended as a true Strava competitor. It's limited to just users of Garmin devices and intended to drive hardware sales through offering additional planning and analytics features.
Re: Advanced Denanonymization through Strava
#67I think it's really a shame that Strava is taking so much heat. The heatmap was a really cool visualization and also useful to find out where people are running and biking, generally. And, it was created from tracks that people willing uploaded and made public, even if they didn't fully understand the privacy implications. But it's also frightening that this data, stored indefinitely, is effectively a mass surveillan…
>I was contacted by local law enforcement who had gotten my email address from Strava via an "official legal process" because I had ridden my bike in an area around the time a homicide occurred. If it makes you feel any better they probably filtered out all the "less likely to murder people" demographics, went though everything they could dig up on your and your friends/family looking for interesting things (e.g. tra…
Re: Advanced Denanonymization through Strava
#68Earlier quoted context omitted.
You're way off. The reason this "news" is news is not because Strava has done anything naughty, it's because people that are tasked with the national security (and often some secrets) of their respective nations have committed such an easily avoidable op-sec failure.
So you didn't read the last two sentences of what I wrote :)
Re: Advanced Denanonymization through Strava
#69Earlier quoted context omitted.
You might be able to, but even then it is more likely to be a person doing exercise on a device with the wrong time zone than it is to be someone on patrol. To reiterate: Strava isn't always on. These are activities people have actively chosen to log. The chance of it being someone out on patrol is... not high.
Having to actively log the data is interesting. I agree with your conclusion there. However, GPS is primarily a very high precision time signal, from which the current location is reconstructed. Basically, a properly designed software would do the proper time zone adjustment based on that, so the data should ideally be in local time everywhere without exception. Everything else would be a bug in my book.
Source: I've used lots of them and it's a real pain in the ass.
Re: Advanced Denanonymization through Strava
#70Earlier quoted context omitted.
The author covered privacy zones and hidden activities. Neither are as secure as one would hope: privacy zones can be reverse-engineered fairly easily, and private activities can still be leaked.
Activities marked as "Private" Don't leak. But in "enhanced privacy" mode your activities can be seen via the segment leaderboards. In any declared privacy zone, you stay off those boards, irrespective of options, and (allegedly) heatmaps. So really, it's "slightly more advanced privacy"