US troops can still be tracked by purchased location data, and Congress wants to know why

← Back to the feed

US troops can still be tracked by purchased location data, and Congress wants to know why

The Register · 3 hours ago

US lawmakers have asked the Defense Department's Inspector General to investigate why commercially available location data can still be used to track American military personnel, despite policies meant to stop it. Senator Ron Wyden and Representative Pat Harrigan raised concerns that troops' movements remain identifiable through data sold by brokers, even though several military branches have disabled advertising identifiers on government-issued phones. The issue matters because such data could allow adversaries to pinpoint where troops gather and potentially target those locations, a risk the Pentagon has reportedly known about since at least 2016.

In May, Wyden, Harrigan and twelve other members of Congress had urged the Defense Department to disable advertising identifiers, which are used by mobile apps and ad networks to track devices, on both government and personal devices brought onto military facilities or taken overseas. The Army, Air Force, Navy, Marine Corps and Special Operations Command have since confirmed they disable these identifiers on issued devices, yet reports suggest military location data is still being sold. The lawmakers suggest possible explanations, including that some branches only implemented the change in July, that disabling identifiers alone may no longer be enough, or that personal devices belonging to staff and contractors remain a source of leaks. A threat researcher at Infoblox noted that Google and Apple have not meaningfully reformed these advertising identifiers, which continue to serve as a key link enabling data brokers to compile bulk location data for sale.

  • Congress asks DoD Inspector General to probe ongoing military location data leaks.
  • Military branches disabled ad IDs on phones, but leaks persist.
  • Personal devices or ad-tech systems may still expose troop locations.

New here? Start with this

Data brokers routinely buy and sell location information gathered from smartphone apps, which often share a device's whereabouts with advertising networks in exchange for things like weather updates or games working properly. Privacy researchers and journalists have long warned that this data, though supposedly anonymised, can be pieced together to reveal sensitive patterns, including the movements of military personnel on and off base. The Pentagon has reportedly been aware since at least 2016 that such tracking could expose troop locations to hostile actors.

Senator Ron Wyden and Representative Pat Harrigan are the lawmakers pressing the Defense Department on this issue, having previously joined twelve colleagues in May to call for advertising identifiers, the codes apps use to track individual phones, to be switched off on military and personal devices. Several branches of the armed forces say they have since done this for government-issued phones, yet the practice of tracking service members through purchased data appears to have continued regardless.

The matter has now reached the Pentagon's Inspector General, the internal watchdog responsible for investigating problems within the Defense Department, who has been asked to examine why the safeguards have not worked as intended. The issue sits at the intersection of digital privacy and national security, since it concerns whether ordinary commercial data practices could inadvertently put military personnel at risk.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Advocates of a robust, urgent response argue that this is a serious and foreseeable failure of accountability, given that the Pentagon has reportedly known about the vulnerability since 2016 yet troop movements can still be traced through purchased data nearly a decade later. They see the call for an inspector-general investigation as reasonable and overdue, arguing that partial fixes such as disabling advertising identifiers on issued phones are plainly insufficient while personal devices and largely unreformed advertising ecosystems remain open channels for leaks. On this view, both the Defense Department and major technology platforms bear direct responsibility for closing a gap that could let adversaries pinpoint where service members gather, and continued exposure represents an unacceptable risk to safety that demands rapid, comprehensive action.

The case against

A more measured perspective holds that the military has already taken meaningful, good-faith steps, with five branches confirming they now disable advertising identifiers on government-issued devices, and that judging these efforts as failures may be premature given some changes only took effect in July. From this standpoint, fully closing the gap depends on structural reform of advertising identifier systems and data broker practices that lie largely outside the Pentagon's direct control, making Google, Apple and the broader ad-tech industry equally central to any lasting solution. Advocates of this view also point to genuine practical and privacy tradeoffs in restricting personal devices belonging to service members, staff and contractors, suggesting that a careful, phased approach focused on identifying precisely where leaks persist is more sensible than assuming negligence before the investigation has even begun.

Americas Government Politics World

Read the full article at the source →