This isn't even "deanonymization" in the sense of "performing statistical inference to re-associate different pieces of data." It's "you ask the company to give you personally identifiable data, and it does so."
I couldn't think of any other good title. It's going from a heatmap to identifying individuals, who, if they didn't use an alias, are now identified. And of the 16 people faster than me on that circuit, 14 used full names.
Advanced Denanonymization through Strava
71–77 of 77 posts
Re: Advanced Denanonymization through Strava
#72> Here are some things Strava may reveal ... These are all things I want to share and use Strava to do that. (Well maybe not "When you are away from your house" but you could not turn on the live beacon if that's a concern.)
> maybe not "When you are away from your house" but you could not turn on the live beacon if that's a concern people have schedules, their commute timetables reveal them. If I start appearing on the logs as riding in in a different part of the world then I'm away for longer. That info is visible to anyone you are in the same "club" as, even if you have enhanced privacy enabled.
Re: Advanced Denanonymization through Strava
#73I find it hilarious that this guy outlines his cloak-and-dagger tactics to avoid people tracking down his bike via Strava, and then as an aside he mentions the time his bike actually got nicked was when a drug addict accessed it through an unlocked door. That never happened to Jason Bourne.
I was pretty unhappy about, I can tell you. And yes, I mentioned that fact to make clear that physical security comes first, and because I cherish the irony myself. In Bristol, most mountain bikers do cross the Bristol Suspension bridge on their way home, same for a lot of the roadies. There's been a fair few cases of people being followed back by some teenagers and then having their bike stolen that night, so rather…
Re: Advanced Denanonymization through Strava
#74Earlier quoted context omitted.
> maybe not "When you are away from your house" but you could not turn on the live beacon if that's a concern people have schedules, their commute timetables reveal them. If I start appearing on the logs as riding in in a different part of the world then I'm away for longer. That info is visible to anyone you are in the same "club" as, even if you have enhanced privacy enabled.
Don't join clubs with people you cant't trust. Post your rides with week delay or make them public when you are back home from your trip. It is called "enhanced" privacy mode for a reason and combined with other privacy settings it can give you very good results.
Re: Advanced Denanonymization through Strava
#75Earlier quoted context omitted.
I couldn't think of any other good title. It's going from a heatmap to identifying individuals, who, if they didn't use an alias, are now identified. And of the 16 people faster than me on that circuit, 14 used full names.
They posted their data as public so they could be found and identified anyway. Heatmap just speeds up the process by letting us know where to search.
Re: Advanced Denanonymization through Strava
#76Strava has even a toggle "Include my anonymized public activity data in Strava Metro and the Heatmaps" for controlling does location data from sport activities end up into heatmaps or not. Interesting, that in media this "news" has been mostly about Strava doing something it openly says it does. There hasn't been much critique about military not educating their personnel not to publish the exact locations of military…
It is not seen as a problem by the regular military. Kinda hard to hide tanks and artillery pieces and soldiers with iPads and C-130s flying into airfields from locals in countries where having a car is a luxury. Locals can get better information about the bases from people working on the bases, or from just watching them. There is basically nothing you can get from this heatmap that you couldn't get from really any…
Re: Advanced Denanonymization through Strava
#77Earlier quoted context omitted.
I think I haven't come to a conclusion about it, but I think it is more complicated than Strava just being opt-in. This op-ed makes the argument that it is difficult for users and even the companies offering services to fully understand the impact of their privacy choices: https://www.nytimes.com/2018/01/30/opinion/strava-privacy.ht... A sort of concrete scenario here would be the app asking the user before uploading…
There is a pretty accessible and obvious checkbox on every activity to make it private if you wish.
People make mistakes, do things by accident. If the conequences are this bad, we should question the standards which led us to them.