Senator Ron Wyden (D-OR) and Representative Pat Harrigan (R-NC) have called on the Defense Department Inspector General to investigate why policies meant to stop the flow of location data from US military personnel have not fully succeeded. In a letter sent Friday, the lawmakers said that while all branches of the military have now disabled advertising IDs on government-issued devices, ongoing reports indicate that location data pinpointing troops' movements remains available for purchase.
In May, Wyden, Harrigan, and a bipartisan group of 12 other members of Congress warned that commercially purchased location data—often captured by mobile apps and advertising SDKs—can be used to identify where US military personnel gather and to target those locations. The DoD has been aware of the threat since at least 2016.
According to the letter, the Army, Air Force, Navy, Marine Corps, and Special Operations Command have all confirmed they now disable advertising identifiers on government-issued devices. "We commend these service branches for implementing this cybersecurity defensive best practice on government devices," the lawmakers wrote. "However, recent reports regarding the continued availability of commercial location data originating from DoD facilities raise troubling questions."
The letter speculates about three possible explanations for the policy's failure: some parts of the DoD may have only turned off their advertising identifiers as recently as July; disabling ad identifiers may no longer be sufficient to limit location data availability; or the location data is coming entirely from personal devices of DoD personnel and contractors.
Zach Edwards, staff threat researcher at Infoblox, told The Register that disabling advertising IDs is a positive step that will make service members and their families safer. He noted that mobile advertising identifiers (MAIDs) serve as join keys for tracking people across datasets. "This change will essentially ensure that military device location data isn't being included in bulk data sales being done by numerous vendors," Edwards said. He added that while states like California, Vermont, Texas, and Oregon have data broker registries, he is unaware of any Russian or Chinese ad tech vendors who have registered, and those companies partner with Western publishers and mobile apps to collect data anyway.