{"id":31196,"date":"2018-01-30T21:31:50","date_gmt":"2018-01-31T05:31:50","guid":{"rendered":"http:\/\/www.politicsplus.org\/blog\/?p=31196"},"modified":"2018-01-30T21:38:12","modified_gmt":"2018-01-31T05:38:12","slug":"security-breach-from-fitness-trackers","status":"publish","type":"post","link":"https:\/\/www.politicsplus.org\/blog\/2018\/01\/30\/security-breach-from-fitness-trackers\/","title":{"rendered":"Security Breach from Fitness Trackers"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.washingtonpost.com\/world\/the-us-military-reviews-its-rules-as-new-details-of-us-soldiers-and-bases-emerge\/2018\/01\/29\/6310d518-050f-11e8-aa61-f3391373867e_story.html\" target=\"_blank\" rel=\"noopener\">So this happened<\/a>. And the boss told me I should go for it as an article.<\/p>\n<p>I don&#8217;t use a fitness tracker, and this is why. Not that I am nefarious enough to have imagined the scope of something like this; I&#8217;m not. (And I also don&#8217;t do any fitness activities worth tracking.) People who do use fitness trackers, however, want to have convenient access to the information from them. And putting information on the internet is certainly one way to provide unfettered access.<\/p>\n<p>The only problem with this is that one aspect of the information provided by these trackers is GPS. And GPS means that the trackers are tracking exactly where on the globe the users are at any given moment (and previous moments as well.)<\/p>\n<p>Let&#8217;s look at Strava as an example &#8211; a pretty good example, since Strava is the one the Washington Post found out about and has done a couple of stories on. It&#8217;s also handy for us at PP, since Strava is the one Nameless featured in a <a href=\"https:\/\/www.7thstep.org\/blog\/2016\/02\/26\/friday-fun-an-artist-who-paints-with-his-bike\/\" target=\"_blank\" rel=\"noopener\">Friday Fun, almost two years ago now<\/a>, because a Canadian biker was using it as an art creating device.<\/p>\n<p>At the time, we all thought this was cool, and then probably forgot about it. The art in question is featured on the Strava home page of the artist, and doesn&#8217;t provide any information that can&#8217;t publicly be obtained almost anywhere. But there is more to Strava than personal home pages and art.<\/p>\n<blockquote><p><em>An interactive map posted on the Internet that shows the whereabouts of people who use<img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-20208\" src=\"https:\/\/www.7thstep.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-300x297.png\" alt=\"\" width=\"300\" height=\"297\" srcset=\"https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-300x297.png 300w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-150x150.png 150w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-96x96.png 96w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-24x24.png 24w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-36x36.png 36w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-48x48.png 48w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper-64x64.png 64w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_25_Grasshopper.png 760w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/> fitness devices such as Fitbit <span style=\"color: #3366ff;\"><strong>also reveals highly sensitive information about the locations and activities of soldiers at U.S. military bases<\/strong><\/span>, in what appears to be a major security oversight&#8230;.<\/em><\/p>\n<p><em>Most parts of the United States and Europe, where millions of people use some type of fitness tracker, show up on the map as blazes of light because there is so much activity.<\/em><\/p>\n<p><em>In war zones and deserts in countries such as Iraq and Syria, the &#8230; map becomes almost entirely dark &#8211; except for scattered pinpricks of activity. Zooming in on those areas <span style=\"color: #3366ff;\"><strong>brings into focus &#8230; unknown and sensitive sites<\/strong> <\/span>&#8211; presumably because American soldiers and other personnel are using fitness trackers as they move around.<\/em><\/p><\/blockquote>\n<p>The name of this map is the Global Heat Map, and it was posted online in November 2017, but it was only this week that a 20-year-old Australian student (of international security and the Middle East) looked closely at it, specifically searching for military.<\/p>\n<p>Few occupations are as obsessed with the employees being physically fit as is the military. It&#8217;s not surprising that a lot of soldiers have fitness trackers. In fact, in 2013, the Pentagon gave 2,500 of them out &#8220;as part of a pilot program to battle obesity.&#8221;<\/p>\n<p>I don&#8217;t suppose that there was such a thing as a Global Heat Map in 2013. However, there has been a GPS feature in fitness trackers since &#8211; well, I assume since they were invented. And it all this time. it apparently did not occur to soldiers, it did not occur to the Pentagon, it did not occur to anyone involved in the manufacture and\/or coding of fitness trackers that if there were a map, it might just reveal information that impacted someone&#8217;s national security.<\/p>\n<p>I am only seeing this in the Washington Post, and I would say that&#8217;s probably a good thing (why give spies ideas if they didn&#8217;t already have them?), but it has been all over the Internet, particularly people in the security community, on Twitter and others.<\/p>\n<blockquote><p><em>On one of the Strava sites, it is possible to click on a frequently used jogging route and at what times. One Strava user demonstrated how to use the map and Google to <span style=\"color: #3366ff;\"><strong>identify by name a U.S.Army Major and his running route at a base in Afghanistan<\/strong><\/span>.<\/em><\/p>\n<p><em>On a separate Internet site, it is possible to establish the names and home towns of individuals who have signed up for a social sharing network on which runners post their routes and speeds.<\/em><\/p><\/blockquote>\n<p>I&#8217;m not showing any cuts from the Global Heat Map here (although the Post did &#8211; I guess they figured it was already out, so why sit on them). Instead, I&#8217;ll show a couple of &#8220;paintings&#8221; from Nameless&#8217;s article. Please realize I am not trying to pick on Strava.<img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-20210\" src=\"https:\/\/www.7thstep.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_19_Queen-Victoria-300x279.jpg\" alt=\"\" width=\"300\" height=\"279\" srcset=\"https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_19_Queen-Victoria-300x279.jpg 300w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_19_Queen-Victoria-768x713.jpg 768w, https:\/\/www.politicsplus.org\/blog\/wp-content\/uploads\/2016\/02\/GPS_19_Queen-Victoria.jpg 800w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<blockquote><p><em>Privacy experts noted that <span style=\"color: #3366ff;\"><strong>Strava is far from alone<\/strong><\/span> in collecting and using location data and that such granular information about the movements of individuals could reveal <span style=\"color: #3366ff;\"><strong>where they live, work, shop, and socialize<\/strong><\/span>.<\/em><\/p><\/blockquote>\n<p>I might point out that cell phones also have GPS technology, and many people leave theirs on all the time except when charging &#8230; so maybe the Pentagon should look into that, if they aren&#8217;t already. <a href=\"https:\/\/www.washingtonpost.com\/world\/a-map-showing-the-users-of-fitness-devices-lets-the-world-see-where-us-soldiers-are-and-what-they-are-doing\/2018\/01\/28\/86915662-0441-11e8-aa61-f3391373867e_story.html\" target=\"_blank\" rel=\"noopener\">They have announced a huge policy review on privacy and privacy settings<\/a>, so they probably are.<\/p>\n<blockquote><p><em>Privacy experts have longed warned that tech companies often make <span style=\"color: #3366ff;\"><strong>personal information &#8211; including contact lists, social media posts, and location data &#8211; available by default<\/strong><\/span>. That means users who do not routinely read privacy notices and tweak settings can be surprised by how much information is collected by private companies, as well as how that data ultimately is used.<\/em><\/p><\/blockquote>\n<p>And Americans in all walks of life have long routinely ignored these warnings.<\/p>\n<p>The Post has a lot more on this. In fact, I haven&#8217;t done much more than scratch the surface. But one thing not mentioned did occur to me.<\/p>\n<p><strong><span style=\"color: #008080;\">Can you imagine the howls from Republicans that we would hearing now and up to forever had this map been posted and this information come out on Obama&#8217;s watch? <\/span><\/strong>(Not that they won&#8217;t try to find a way to make it Obama&#8217;s fault somehow, of course.)<\/p>\n<p>Cross posted to Care2 <a href=\"http:\/\/www.care2.com\/news\/member\/101612212\/4087836\" target=\"_blank\" rel=\"noopener\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; So this happened. And the boss told me I should go for it as an article. I don&#8217;t use a fitness tracker, and this is why. Not that I am nefarious enough to have imagined the scope of something like this; I&#8217;m not. (And I also don&#8217;t do any fitness activities worth tracking.) People <a href='https:\/\/www.politicsplus.org\/blog\/2018\/01\/30\/security-breach-from-fitness-trackers\/' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":8,"featured_media":20204,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-31196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-politics","category-5-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"_links":{"self":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts\/31196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/comments?post=31196"}],"version-history":[{"count":0,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts\/31196\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/media\/20204"}],"wp:attachment":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/media?parent=31196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/categories?post=31196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/tags?post=31196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}