Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 11 submissions in the queue.
posted by hubie on Thursday July 30, @07:19PM   Printer-friendly

Apps targeted at US troops contain Chinese and Russian code:

A recent examination of hundreds of mobile apps marketed toward US military personnel found more than one in eight contained software built by companies in China , Russia , or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work, and deploy.

According to researchers at Purdue University, the US Military Academy at West Point, and Florida International University , one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that US regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.

The largely unregulated advertising industry that tracks Americans online treats civilians and service members mostly the same—unless there is profit in telling them apart —despite evidence that exposure can reveal troop deployments, unit movements, and the routines of personnel within intelligence facilities and hardened shelters where nuclear weapons are believed to be stored.

WIRED investigations have previously shown location data harvested from ordinary apps tracing US service members to their homes, their children's schools, and off-base establishments where troops are prohibited from being seen. Experts have warned the same data could aid foreign spies in identifying personnel with access to sensitive sites , map when a facility is least guarded, or surface other compromising details.

The stakes are no longer hypothetical. In April, US Central Command acknowledged in a letter to Senator Ron Wyden that it had received multiple threat reports of adversaries exploiting commercial location data to target or surveil American personnel in the Middle East, where US forces remain locked in a standoff with the Iranian military over the Strait of Hormuz. Lawmakers called it the first official confirmation that troops in an active war zone were being hunted through the data-broker economy—a threat the Pentagon's own contractors and researchers had warned about for nearly a decade.

The new study takes a first look at one piece of that exposure: what actually sits inside the apps built and marketed specifically for the military.

[...] The most common SDKs came from Google and Facebook, the two companies that dominate US digital advertising. But 76 turned up in all, including code traced back to China, Russia, Israel, India, Germany, and others. Roughly 7 percent of the apps carried third-party code from a nation considered adversarial by the Pentagon.

[...] Participants reported being more comfortable with data collection when an app was branded for military use.

Meanwhile, nearly two-thirds said they had received little or no institutional guidance on personal app use. Of those who had received some, nearly three-quarters called it inadequate.

The Pentagon declined to comment.

Asked to weigh potential mitigations, participants ranked in-phone warnings—alerts when foreign or unknown third-party code is present in an installed app—as both the most effective and the most likely for them to support.

A federal law restricting data brokers from buying or selling data on military-affiliated personnel, independent audits of app privacy disclosures, and stricter bans on foreign code in military-marketed apps drew nearly identical support.


Original Submission

This discussion was created by hubie (1068) for logged-in users only. Log in and try again!
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 4, Insightful) by FunkyLich on Thursday July 30, @09:09PM (5 children)

    by FunkyLich (4689) on Thursday July 30, @09:09PM (#1449834)

    ... not funny anymore, rather starting to be annoying all this paranoia/propaganda of "look, there are commies and enemies of America everywhere". In case these "OMG enemies!" peoplr didn't notice, there is an entire World out there with people that are *not* americans and they too happen to be educated and smart and able to produce and make things, including applications for mobile devices for various purposes. And more often than not, their interests and goals are for their own benefit and prosperity rather than the benefit and prosperity of the USA. They all learned the modern capitalism techniques to gain an advantage from the USA all these last 7+ decades after WW2, including foul play with those in theory claimed to be allies (hello Greenland).

    • (Score: 2) by ikanreed on Thursday July 30, @09:26PM

      by ikanreed (3164) on Thursday July 30, @09:26PM (#1449835) Journal

      If you have the technical know-how to realize what this means (importing an npm package maintained by someone in China), your opinion is irrelevant to the panic they want to sell

    • (Score: 4, Insightful) by JoeMerchant on Thursday July 30, @10:53PM (2 children)

      by JoeMerchant (3937) on Thursday July 30, @10:53PM (#1449841) Journal

      Generally speaking, we should be less concerned about commie spies than we should about general commercial exploitation - because if you look back in US history, exploitation of the masses by the moneyed few is a long standing tradition with far more direct impact on "Life, Liberty and the Pursuit of Happiness" than commie enemies of America ever had.

      Regarding:

      > off-base establishments where troops are prohibited from being seen

      I would expect that members of the Armed Services, sworn to serve their country, put their very lives in harm's way, should be required to install an official military app full of propaganda, secure delivery of sensitive messages, and real-time tracking data available to your CO, their CO, etc. all the way up to the Resolute Desk. Further, their personal phones should be switched off, stowed, and only permitted to be switched on while on leave, their duty phone should be maintained and cared for better than their firearms, and on their person at all times 24-7-365 until their discharge from the reserves. But I understand that our current leadership has other priorities than secure and reliable communication with the troops: https://www.bbc.com/news/articles/cn0nlx18rz0o [bbc.com]

      --
      🌻🌻🌻🌻✌️ [google.com]
      • (Score: 1, Interesting) by Anonymous Coward on Friday July 31, @09:57AM

        by Anonymous Coward on Friday July 31, @09:57AM (#1449857)

        Yeah I think the real problem is bad OPSEC. AFAIK these apps seem to be US based not Chinese: https://www.bellingcat.com/news/2021/05/28/us-soldiers-expose-nuclear-weapons-secrets-via-flashcard-apps/ [bellingcat.com]

        However, the flashcards studied by soldiers tasked with guarding these devices reveal not just the bases, but even identify the exact shelters with “hot” vaults that likely contain nuclear weapons.

        They also detail intricate security details and protocols such as the positions of cameras, the frequency of patrols around the vaults, secret duress words that signal when a guard is being threatened and the unique identifiers that a restricted area badge needs to have.

        https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29/ [reuters.com]

        Admiral Brad Cooper, in a previously unreported letter, said Iran was benefiting from being able to see the success or failure of its strikes in near real-time by searching news reports or online posts by journalists referencing "reactions, photos, and footage from the cellphones of our troops."
        "The direct, unavoidable cost of this open-source intelligence could be measured ​in the lives of American service members and civilian residents in targeted Gulf countries," Cooper, head of U.S. Central Command, wrote in his July 28 letter, a copy of which was obtained by Reuters.

      • (Score: 2) by mcgrew on Sunday August 02, @03:20PM

        by mcgrew (701) <publish@mcgrewbooks.com> on Sunday August 02, @03:20PM (#1450091) Homepage Journal

        Generally speaking, we should be less concerned about commie spies than we should about general commercial exploitation - because if you look back in US history, exploitation of the masses by the moneyed few is a long standing tradition with far more direct impact on "Life, Liberty and the Pursuit of Happiness" than commie enemies of America ever had.

        Indeed. All three of America's great depressions were caused by that, as well as far worse things, like slavery, genocide... and right now, communism is the least of our problems with a Nazi in the White House (who has torn a third of it down).

        --
        The Stupid-Ass Voter Evisceration act: SAVE Trump and his family from prison
    • (Score: 2) by mcgrew on Sunday August 02, @03:13PM

      by mcgrew (701) <publish@mcgrewbooks.com> on Sunday August 02, @03:13PM (#1450090) Homepage Journal

      This isn't like Trump and his clownish minions calling everyone who isn't a die-hard Nazi a Communist. This is apps aimed at US Military personnel with Russian and Chinese language remarks in the code and is indeed a real security problem.

      If I was Pete Hogshead (drunken Secretary of Defense) I'd order that all cell phones stay in your car when you're on duty. Of course since I'm not and he used a civilian phone app to transmit top secrets without realizing that the Editor in Chief of The Atlantic was in the chat, well... there's a decidedly incredible lack of competence in the administration.

      Maybe after the Commander in Chief is impeached, convicted, and removed by the new congress next year we can get a competent DefSec, but considering Jadey will be prez, well...

      --
      The Stupid-Ass Voter Evisceration act: SAVE Trump and his family from prison
(1)