The US military’s initiative to safeguard troops from adversarial tracking via purchased location data has proven less effective than intended, prompting lawmakers to demand an explanation.
On Friday, Senator Ron Wyden (D-OR) and Representative Pat Harrigan (R-NC) requested that the Defense Department Inspector General investigate the partial measures that have failed to fully prevent the tracking and targeting of military personnel through location data.
In May, Wyden, Harrigan, and a bipartisan coalition of twelve other congressional members exposed how commercially acquired location data—often harvested through mobile applications and advertising software development kits—can identify the gathering points of US military personnel and target them. They highlighted that the Defense Department has been aware of this vulnerability since at least 2016.
These lawmakers urged Defense Department CIO Kirsten A. Davies to implement risk mitigation strategies, such as disabling advertising identifiers on DoD-issued smartphones and establishing a policy to turn off advertising identifiers on all personal devices brought into DoD facilities or deployed overseas.
Since then, various military branches have restricted advertising identifiers on government-issued devices. Per the letter, “several DoD components—the Army, Air Force, Navy and Marine Corps, and Special Operations Command—confirm that they now disable advertising IDs on government-issued devices to protect their personnel from such threats.”
However, this has not entirely eliminated the availability of location data associated with US military personnel. Referencing ongoing reports, Wyden and Harrigan seek to understand why location data pinpointing troop movements remains accessible.
“We commend these service branches for implementing this cybersecurity defensive best practice on government devices,” they stated in their letter [PDF] to the DoD IG. “However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions.”
The lawmakers hypothesize several reasons for the shortfall in DoD policies. They suggest that some DoD components only disabled their advertising identifiers as recently as July. Additionally, they posit that disabling ad identifiers may no longer be sufficient to restrict the availability of location data. A third possibility is that the data originates entirely from the personal devices of DoD personnel and contractors.
Zach Edwards, staff threat researcher at Infoblox, told The Register in an email that it is reassuring to hear all military branches have disabled advertising IDs on their phones, as this will better protect military members and their families, particularly those deployed in combat zones overseas.
“This change will essentially ensure that military device location data is excluded from the bulk data sales conducted by numerous vendors,” he stated. “It is deeply regrettable that Google and Apple have not effectively reformed their mobile advertising IDs, especially after it has been well documented that these identifiers are the primary data point used by brokers to aggregate people’s mobile phone location data for bulk sales.”
Edwards explained that mobile advertising identifiers (MAIDs) function as join keys for tracking individuals, capable of linking disparate datasets.
“Consequently, one primary benefit is that military data will no longer be available for sale through data brokers, who sell to virtually anyone,” Edwards noted. “However, the other, slightly less obvious benefit is that this MAID was also being broadcast to all advertising systems participating in the auctions.”
Edwards pointed out that while states such as California, Vermont, Texas, and Oregon maintain data broker registries, he is unaware of any Russian or Chinese ad tech vendors that have registered. He noted, however, that these companies partner with Western publishers and mobile applications to collect data regardless.
“It is crucial to recognize that these ad tech companies in Russia and China have likely also been receiving MAID data from the programmatic ad tech auctions involving military members,” Edwards stated. “Furthermore, companies in those nations have an obligation to share this data with the state, without any ability to appeal or provide external notice.” ®
Also Read
- NYT Connections: Sports Edition Hints and Solutions for September 6, Puzzle #713
- Editorial Board Stages Mass Resignation at Elsevier’s Games and Economic Behavior Following Editor-in-Chief’s Dismissal
- Earth’s Natural Cavity May Reveal Dark Matter Signals
- Orbitals Review: Vintage Anime Inspirations and Couch Co-op Action on Switch 2


