4 ms·
I don't see why this is Strava's problem, to be honest. The military, CIA should have a clear policy to disable all location services, on all devices at all ti
by avitzurel 9y ago
I don't see why this is Strava's problem, to be honest.
The military, CIA should have a clear policy to disable all location services, on all devices at all times.
If you're not supposed to be somewhere and you go for a run on Strava, it's pretty much your fault.
- anfilt 9y agoIt's probably easier to scape goat the company for some people than think about the root cause.
- dawhizkid 9y agoI am not an active Strava user but from what I've read the company engaged in some dark UX patterns that made it really confusing (unclear if purposefully confusing) to understand what you were sharing. The most egregious sound like the privacy setting on native mobile are more limited than on web , which is a problem considering how many users probably ever only use the app on mobile.
- anfedorov 9y agoI'm a quasi-active user and never realized my updates were public beyond the people who followed me. It has absolutely no UI indicating it the way, e.g. Facebook does, and does not show me any activity of people whom I do not follow. Doesn't look like they're actually public, though? https://www.strava.com/athletes/22230419 https://www.strava.com/athletes/22230419
- TallGuyShort 9y agoUpdates are effectively public because once they're collected by a third-party and / or shared with anyone, it's now out of your control. But my understanding (in which I'm not certain) is that the controversy is the heatmap feature, and that your name wouldn't show up in this proof-of-concept attack unless you had opted into that specific feature.
- anfedorov 9y agoI get what the controversy is about, but I don't get how this is OK from Strava's PoV — none of my runs are "public" in the sense that I think of it — they're not on the website that's my "profile" and they're not visible to people who are not following me in the app...
- jcdavis 9y agoI'm assuming you're looking from another browser, in which case if you are logged out you cannot. However I, a random logged in strava user, can see at least some of your activities (Last Sept 3) That is easy to change, but again there is the opt-int vs opt-out discussion.
- rypskar 9y agoHave you looked at the segment records on your workout? I guess most of the people you get listed compared to you are not in your circle of followers
- bytecodes 9y agoI use it, and it's really clear you're sharing your location, speed, and heartrate data with Strava and other users. There is a Facebook-like newsfeed that shows where your friends have been working out. You can see who else runs your routes and how fast they are. Sharing this data is really the purpose of the app. If you purposely disengaged from this social part of the app and were trying to use it as a simple stopwatch and mileage logger then uploading data may seem weird. But that's not the clearly intended purpose of the app.
- dawhizkid 9y agoYes, but you probably don't represent the average Strava user. Clearly there are many who are sharing publicly who don't realize it for some reason. Design, IMO, is part of the reason.
- TallGuyShort 9y agoStrava overtly markets itself as a social network. It doesn't open with, "use me - I'm an app to help you track your workout plan", it opens with, "use me - I'll share your workouts with your friends." The sharing of data is the primary feature and it's right there in the title of their website. If you use the app and think sharing is an anti-pattern, I'm concerned about your presence near nuclear weapons for reasons other than privacy.
- drtillberg 9y agoBut the jogging routes were shared beyond any circle of "friends." It got shared with potential adversaries. Clear privacy fail by Strava.
- FridgeSeal 9y agoAs a frequent user of Strava I disagree. The app makes it pretty obvious and easy to control whether your profile is private or public, and if it's public, you can easily hide any activity. They've even got a "privacy screen" feature where you can set a geofence, and activities that start or end within the geofence are automatically made private.
- notahacker 9y agoAnd in some respects, it's far more practical for a company to adopt commonsense policies of not sharing locations publicly by default in war zones than for everyone active in that area to audit all their staff's smartphones; possibly the military have the resources and responsibility to do this but aid agencies don't. (it's also very much in their interests not to have "delete Strava" as the first recommendation given to anyone starting a sensitive job)
- JumpCrisscross 9y ago> the company engaged in some dark UX patterns You’re not supposed to be using a device which logs and beams your GPS coördinates when deployed. The fact that this is widespread means superiors failed to communicate and enforce some very basic rules.
- redbeard0x0a 9y agoThis also reveals dead-zones where people aren't feeding Strava data. So it is possible to look for the lack of data as well. (Remember the possible CIA site, it has a line around the border, but nothing inside it, because no electronics allowed inside...)