Congress presses Pentagon on troop tracking via data brokers

Congress presses Pentagon on troop tracking via data brokers

US Senator Ron Wyden (D-OR) and Rep. Pat Harrigan (R-NC) asked the Defense Department Inspector General on Friday to investigate why Pentagon policies meant to stop adversaries tracking troops through commercially purchased location data have only partly worked. In May, Wyden, Harrigan and a bipartisan group of 12 other members of Congress had released details showing how location data captured by mobile apps and advertising SDKs can reveal where US military personnel gather, letting that data be used to target those locations; the two lawmakers say the Pentagon has known about the threat since at least 2016. Following that May report, the lawmakers pushed Defense Department CIO Kirsten A. Davies to disable advertising identifiers on DoD smartphones and to require the same on any personal device brought onto DoD facilities or taken overseas. Several service branches, including the Army, Air Force, Navy, Marine Corps and Special Operations Command, have since confirmed they now turn off advertising IDs on government-issued devices. But Wyden and Harrigan say ongoing reports show commercial location data tied to DoD facilities is still available, and their letter to the Inspector General offers three possible explanations: some parts of the DoD may have only disabled the identifiers as recently as July, disabling the identifiers alone may no longer be enough to stop the data from surfacing, or the remaining data may be coming entirely from the personal devices of DoD personnel and contractors. Zach Edwards, a staff threat researcher at Infoblox, told The Register that disabling the identifiers is a genuine improvement because mobile advertising IDs (MAIDs) work as join keys that let different datasets be linked together, so switching them off keeps military device data out of bulk sales by data brokers and stops it from being broadcast to every ad system bidding in programmatic ad auctions. Edwards criticized Google and Apple for not reforming their advertising IDs more broadly, given how well documented their role in enabling bulk location-data sales already is. He also noted that while states such as California, Vermont, Texas and Oregon maintain data broker registries, he is not aware of any Russian or Chinese ad tech vendors registered in them, even though he believes such companies likely still obtain MAID data through programmatic ad auctions involving military personnel, data those companies would be obligated to share with their home governments without any right of appeal or external notice for the person tracked.

Key facts

  • Wyden and Harrigan asked the DoD Inspector General on Friday to investigate why purchased location data can still track US troops.
  • In May, the same two lawmakers plus 12 others in Congress detailed how mobile apps and advertising SDKs expose troop locations; the DoD has reportedly known of the threat since at least 2016.
  • The Army, Air Force, Navy, Marine Corps and Special Operations Command have confirmed they now disable advertising IDs on government-issued devices.
  • Despite that, the lawmakers cite ongoing reports of commercial location data still tied to DoD facilities, and offer three possible causes, including that some branches may have acted only as recently as July.
  • Infoblox researcher Zach Edwards says he knows of no Russian or Chinese ad tech vendors registered in US state data-broker registries, though he suspects they still obtain military-linked MAID data through ad auctions.

Why it matters

A known tracking risk to deployed troops, one the Pentagon has reportedly been aware of since 2016, has still not been closed even after the fix lawmakers demanded was largely put in place. That gap is now the subject of a formal request for an Inspector General investigation rather than a quietly resolved technical issue.

Who it affects

US military personnel and their families, particularly those in combat zones, whose movements can be inferred from location data harvested by ordinary phone apps and advertising SDKs. It also touches Google and Apple, whose mobile advertising ID systems are the mechanism Edwards blames for feeding data brokers, and any foreign ad tech firm, including Russian or Chinese vendors, that could obtain the same data through ad auctions.

How to use it

For anyone weighing device policy on sensitive sites, the concrete step already adopted by the Army, Air Force, Navy, Marine Corps and Special Operations Command is disabling advertising identifiers on issued devices; the open question this letter raises is whether that step needs to extend to personal devices brought onto military facilities or overseas, since the lawmakers flag personal devices as one possible remaining leak.

How solid is it

The account rests on a letter from two sitting members of Congress to the DoD Inspector General, on a documented history stretching back to a May report signed by 14 lawmakers, and on on-the-record comment from a named threat researcher at Infoblox; The Register's report quotes both the letter and Edwards directly.

Risks and caveats

The three explanations Wyden and Harrigan offer for why the leak persists are their own speculation, not confirmed findings. The article does not name the specific apps or advertising SDKs involved, give any count of affected personnel or facilities, or say whether the Inspector General has agreed to open the investigation. Google and Apple's response, if any, to Edwards's criticism is not reported, and no specific Russian or Chinese ad tech vendor is identified by name.

“We commend these service branches for implementing this cybersecurity defensive best practice on government devices. However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”

— Wyden and Harrigan, in their letter to the DoD Inspector General