US Troops Are Still Being Tracked Through Commercial Location Data. Congress Is Losing Patience.
A bipartisan push in Congress to stop adversaries from tracking US military personnel via commercial location data has hit a wall, and now lawmakers want the Defense Department's own watchdog to explain what went wrong.
Senator Ron Wyden and Representative Pat Harrigan sent a formal request to the DoD Inspector General asking for an investigation into why troops can still apparently be followed through data originally harvested by mobile apps and advertising SDKs. This isn't a new problem. The DoD has known about it since at least 2016.
Back in May, Wyden, Harrigan, and a dozen other members of Congress laid out in uncomfortable detail how commercially available location data can be used to map where military personnel congregate, which is exactly the kind of intelligence a hostile state would love to have. The lawmakers pushed the Defense Department's CIO to respond by disabling advertising identifiers on government-issued phones and requiring the same on personal devices brought into DoD facilities or taken overseas.
Some progress was made. The Army, Air Force, Navy, Marine Corps, and Special Operations Command have all confirmed they now disable advertising IDs on government-issued devices. That's worth something. But it hasn't solved the problem, and location data tied to US troops keeps showing up in commercial databases.
The lawmakers have a few theories about why. Some branches only switched off advertising identifiers as recently as July, so the data pipeline may still be draining. Alternatively, disabling ad IDs may no longer be enough on its own, as the tracking ecosystem has grown sophisticated enough to route around that particular fix. The third, arguably most uncomfortable possibility, is that the leaking data is coming entirely from the personal phones of military personnel and contractors, which no government policy can touch without treading into very different territory.
Zach Edwards, staff threat researcher at Infoblox, told The Register that disabling mobile advertising IDs on military devices is a meaningful step, particularly for personnel in combat zones. 'This change will essentially ensure that military device location data isn't being included in bulk data sales being done by numerous vendors,' he said.
The core issue is what mobile advertising identifiers actually do. They act as join keys, linking datasets from different sources to build a coherent picture of where a specific device, and by extension a specific person, has been. Disable the ID and you reduce your footprint in the commercial data ecosystem. Keep it active and your movements can end up in a bulk sale to, as Edwards put it, 'literally anyone with a pulse and a credit card.'
There's a more pointed concern underneath all this. Edwards noted that Russian and Chinese ad tech companies participate in Western programmatic advertising auctions, partnering with publishers and apps to collect data. None of them, as far as he knows, have registered with any US state data broker registry. And under the laws of both countries, those firms can be compelled to hand data to the state with no appeal and no requirement to notify anyone.
'I think it's important to appreciate that these ad tech companies in Russia and China have also likely been getting MAID data from the programmatic ad tech auctions from members of the military,' Edwards said.
Google and Apple are not exactly covering themselves in glory here either. Both companies have faced sustained criticism for failing to meaningfully reform their mobile advertising ID systems, even as it became increasingly well documented that those identifiers are the primary mechanism data brokers use to stitch together location histories for bulk sale. The fix exists. The will to implement it, apparently, does not.