8 ms·
https://twitter.com/kevinkiklee/status/957629856518459392 https://twitter.com/kevinkiklee/status/957629856518459392 I just created an overlay of Google Maps an
by iser 9y ago
https://twitter.com/kevinkiklee/status/957629856518459392 https://twitter.com/kevinkiklee/status/957629856518459392
I just created an overlay of Google Maps and Strava Heatmap of the forward operating base I was at in Afghanistan. The heatmap clearly shows the layout of the base.
That base has been in operation for at least 6-8 years, and it is well-developed. The up-to-date satellite imagery of the area is not available on Google Maps for a good reason, and Strava just released it.
I imagine that this heatmap has been thoroughly scraped already.
* I was deployed to Afghanistan from 2011-2012.
edit: initially mis-typed '2011-2102' =D
edit2: A well-established military base, even in a combat zone, has access to wifi and cellphone network.
We are constantly training physically, and we like to keep track of ourselves. We were early adopters of fitness trackers, and I used a couple of them myself also.
- givinguflac 9y agoThat’s one hell of a deployment duration! :)
- iser 9y ago=D
- maxerickson 9y agoSo what other internet services have deployed soldiers sent sensitive location data to? Does each internet service need to proactively hire someone with clearance and coordinate hiding of sensitive information with the US military?
- iser 9y agoWe were on a separate network from the secured military network, but we had complete and free access to the internet when I was there 6 years ago. Even in the most remote combat operating posts, we had access to wifi. Not sure if this can be solved from the civilian side. There is just too much information being transmitted out of a combat zone, and I think it has to be controlled from the source. Certain sites need to be just blocked in combat zones. Rather, we need to only have a list of allowed sites. I know how much it sucks in a combat zone, and I know how much that internet connection makes someone feel like they are still part of the civilization. However, some data just should not be transmitted out of it, and it needs to be heavily controlled.
- znfi 9y agoIn this particular case I'm not sure that blocking internet access at the base will solve much since the data is stored on the device, and it's enough to bring the device to a location with internet access? Basically people go home or whatever and plug in their Garmin and then it'll just upload the last 6 months of data, and there is the same issue.
- pbhjpbhj 9y agoWhy do deployed soldiers need personal fitness trackers (or what did you mean by a Garmin). Surely anything with a GPS or other wireless network abilities is an affront to opsec I'd imagine?
- znfi 9y agoWell, the data does not just appear on strava all by itself. I made an assumption that a non-neglible fraction of the data uploaded was from Garmins/fitness trackers or similar devices (like watch for tracking your running etc). I guess people could also be using their smartphone app, which I am less familiar with. If I'm misunderstanding what the source of the data is I apologize.
- Johnny555 9y ago"need" or "want"? I'm sure they don't "need" them any more than anyone else, but I'm also sure they "want" them for the same reason as everyone else that wants them -- for fitness tracking.
- chrisseaton 9y ago> Why do deployed soldiers need personal fitness trackers To track their personal fitness while deployed?
- notatoad 9y agotracking fitness and tracking location aren't the same thing.
- tenaciousDaniel 9y agoExactly. I'm all for constructive criticisms to make technology better, but these services (like Strava) are reaching millions of people. We're only talking about this military base issue because we became aware of it. How many other externalities are waiting out there for us to find? We really can't expect tech companies to proactively account for all of them; that's literally impossible. In this case, the sensitive data being uploaded is entirely the fault of the user. I'm actually shocked that soldiers would track a run around a military base. It takes about 10 seconds of thought to realize how bad of an idea that is.
- nickvbreda 9y ago100% behind your point. You are so much putting yourself and others in danger with using internet connected devices. Why don't you only use VPN secured services to text. Fitness tracking is like a luxury problem that puts alot of people at risk.
- fossuser 9y agoCould you get in trouble for posting this given rules around security clearances?
- fjsolwmv 9y agoSince the military don't care about soldiers constantly broadcasting their locations, why would anyone HN post matter?
- iser 9y agoEverything shown in the Afghanistan heatmap is a military base. The locations of these bases are not secrets, and the locals already know the layout thoroughly. What I am concerned about is that Strava released this data in such an easily accessible format, and also, whether they even had an internal conversation about managing sensitive material.
- pc86 9y ago> whether they even had an internal conversation about managing sensitive material Probably not, because that's not their job. A service like Strava should not have confidential or sensitive material uploaded to it (obviously), but it's not on Strava to make sure the data it has is not confidential or sensitive.
- notatoad 9y ago>Strava just released it. Strava didn't release it. It's not strava's job to stop you from uploading sensitive information. Strava does not have a security clearance. Military personell released it to strava. Surely the military already has rules about not uploading GPS tracks of their bases to random websites?
- smallnamespace 9y agoSurely the issue is not that Strava decided to release sensitive information, or the military decided to release sensitive information, but that neither actor realized that they were in aggregate revealing sensitive information ahead of time. If one guy runs around a base using Strava, that's not an issue. If a few hundred do, then it lights up on the map. But realizing that is a potential issue ahead of time and then proactively addressing it is the challenge.
- mxfh 9y agoWhat would be the bigger security risk? Uploads of ambivalent track data or the existence of a dataset of geofenced high importance areas shared with private companies?
- deleted 9y ago[deleted]
- carbocation 9y agoI'm surprised that using a GPS tracking tool is permitted in forward operating bases. I guess I would think that if one guy runs around the base with Strava, it actually is an issue.
- Humdeee 9y agoI imagine many of these soldier's higher ups are unaware that such networked 'workout by GPS' services exist to provide insight beyond a personal means. If so, I wonder why soldiers were permitted to run with GPS watches or phones. Many professional endurance based athletes also do not track using GPS for similar reasons. Openly sharing training programs is an advantage to opposition and their coaches. Especially with Strava, where people are searchable by name like facebook.
- kpU8efre7r 9y agoWhat was the base called?
- jahmed 9y agoAlso easily spotted are military outposts littered across North Africa.
- cafard 9y agoNot to be flippant, but is there anyone with an interest in the base--hostile or just curious--who doesn't already know where it is?