In short
Mike Yeagley explains how commercially purchased smartphone location data became usable for U.S. government intelligence and law-enforcement-style investigations, why it’s hard to target individuals with it, and the “Grindr problem” showing how app telemetry can expose sensitive government personnel. He also argues for engineered phone-level controls to stop telemetry from leaving devices, not just VPNs or toggles.
Guest backgrounds
Mike Yeagley is a privacy/location-data figure who helped introduce commercially sourced location data to the U.S. government around 2015, working from special-operations-style needs for understanding human movement in remote conflict zones. He later warned parts of government about risks.
Key claims
Bulk commercial location data can be bought in large volumes; it’s better for reverse-inference from locations than for finding specific people; oversight existed to avoid “targeting”; adversaries can exploit app telemetry; the solution is app/OS-level data minimization.
Notable examples
Lafarge cement factory in Syria linked to Fort Bragg/Southern Pines devices; Vegas shooting investigation starting from residences; Grindr telemetry involving users near national-security workplaces; CFIUS forcing Grindr repatriation; Pentagon/legislative response (NDAA 2027) to reduce app-layer data leakage.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOThe Evolution of Location Data
0:04 to 0:26
Explore the journey and implications of location data acquisition.
“It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block, or finally break down that long article you've had open for weeks.”
The Evolution of Location Data
1:23 to 3:06
Explore the journey and implications of location data acquisition.
“This week, I'm speaking to Mike Yeagley.”
Purchasing Location Data
3:06 to 6:40
Understand the practicalities of buying location data for government use.
“I'll let you enjoy the rest of the conversation.”
Use Cases of Location Data
6:40 to 11:21
Learn about specific instances where location data proved crucial.
“And, you know, once we got the economics down, and the data flows down and understood, we have that system up and running very quickly.”
The Grinder Problem Explained
11:21 to 14:00
Insight into the challenges and concerns regarding location data use.
“You know, the Vegas shooting in 2017, you know, that was an example where we had an individual we knew nothing about.”
Understanding Data Collection for Intelligence
14:00 to 17:06
Explore how data on population movements aids intelligence analysis, particularly related to terrorism.
“where we're trying to understand better population movements as opposed to a direct targeting application.”
Grindr's Data and National Security Risks
17:06 to 21:34
Investigate the implications of Grindr's data access on national security and potential risks.
“We're seeing a lot of data in one of our data sets that was originating from the application, the dating app, Grindr.”
Grindr's Data and National Security Risks
21:43 to 23:16
Investigate the implications of Grindr's data access on national security and potential risks.
“I've started thinking about clothes a little differently this year.”
Grindr's Data and National Security Risks
23:20 to 23:30
Investigate the implications of Grindr's data access on national security and potential risks.
“That's quince.com slash 404media for free shipping and 365 day returns.”
The Grindr Conversation and National Security
23:30 to 28:00
Delve into the conversations around Grindr's potential as a national security threat and the complexities of data privacy.
“I had some very uncomfortable conversations on the seventh floor of various government buildings with trying to explain to 50-plus-year-old white guys what Grindr is, and it's not just a dating app.”
Show all 13 chapters
Protecting Device Privacy in a Data-Driven World
28:00 to 29:59
Learn about the trade-offs of app permissions and mobile security developments.
“take steps to do so um how do you sort of protect your own device sort of privacy when it comes to sort of this data being collected by third-party apps installed on the phone yep so um so this is about the trade-off.”
Government Response and Commercial Data Use
30:00 to 34:15
Explore the government's awareness of location data issues and legislation efforts.
“and how it's resolving location when it doesn't have access to GPS.”
Consumer Power and App Responsibility
34:16 to 39:58
Understand the role of consumers and app developers in data privacy.
“And so we have some congressmen and women that sort of heard us out on this and have developed amendments to the NDAA.”
Transcript
Automatic transcript. May contain errors.0:01This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome, that's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50-page restoration block, or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it. Ready to make anything online make sense? There's no place like Chrome. Check responses set up required, compatibility and availability varies 18+. And so I just started looking into the data that they had access to, which just was odd to me. Of all of the dating apps that they could have purchased, they chose to purchase granted.
0:54404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. And they get early access to our interview series too. Gain access to that content at 404media.co. Also do remember to subscribe to our YouTube channel where you can watch all of our episodes, including this one. Subscribe at youtube.com slash at 404mediaco. This week, I'm speaking to Mike Yeagley. He is someone that you may have come across if you follow the worlds of privacy and location data, especially the stuff I cover, the stuff that Byron Tao covers as well, who was sort of the leading journalist on location data.
1:42Then I followed in his wake and did a bunch of stories. I spoke to Byron many, many episodes ago. You can go find that as well. But Mike comes up because he's one of these people that introduced location data to the government in the first place, way back in around 2015. I won't spoil everything we talk about, but what I will say is that I really like speaking to Mike because, frankly, he's kind of a complicated character. He's kind of hard to pin down. he doesn't fall into a neat pigeonhole. On one side, he was one of these people describing the immense intelligence benefit of commercially sourced location data to the government and to special forces and that sort of thing.
2:27And on the flip side, he's also trying to warn parts of the government about the threats that this data poses. So he's on both sides simultaneously. simultaneously. I imagine a lot of you may not agree with everything that Mike says, and you may sympathize with others, or some of you may take all of it on board as well. I think regardless of where you stand on this issue, this is a really, really interesting conversation about how we got to this point where you can just buy location data, right? Or rather the government is buying it, it is often using it without a warrant, or it has done that historically.
3:02We'll see how the recent Supreme Court ruling changes that. But with that, I'll let you enjoy the rest of the conversation.
3:11Mike, you have a long history with the government and location data. The location data industry and the advertising industry is a very, very interesting space. But I feel like only relatively recently did the government sort of clock on sort of the power here. And you played like a very, very important part in that transformation. how does this story start for you when it comes to location data and the government and that sort of thing so this goes to uh we did recently you know 10 years ago if we want to consider that recent but that's where the story starts for me and this was a project that's well documented uh not classified but originated at um in the special operations community they were looking for alternative methods of being able to understand human geography in very remote places.
4:04And it just was sort of a perfect combination of resources and requirements to be able to provide this new sort of foundational understanding of how humans move, even when we're talking about environments or marketplaces like Yemen, Syria, where it's not a huge, vibrant advertising market, but everybody there carries a smartphone. And that location data was indeed collected by the ad tech ecosystem, not monetized, not used, usually wound up on the cutting room floor, but again, available. And I came in and started buying it en masse. So when you say you started buying this data, I mean, what exactly does that look like in practice?
4:53I know a lot of people like to say that, well, anybody with a credit card or a checkbook can buy location data. I don't think that's strictly true. It really depends upon the context, really, although it can be quite easy. What did it look like practically for you at that time? So typically, these data providers are approached by advertisers, audience attribution companies. They've got a very specific use case. They want to target advertising to a certain demographic or a certain cohort. You can buy it with a credit card depending upon what you're buying. But I was buying about$400 ,000 worth of data per month, which is not something that you're going to slap on a credit card.
5:31Well, yeah, not on your personal credit card. Not on my personal. And so the suppliers, once they understood that this was not a usual buyer of their data, that I wasn't really trying to place an ad on any particular set of devices, that this was a straight data purchase, you know, that created this new sort of business model for them where we were moving bulk data from their cloud environment to my cloud environment, and then I would move it onward to other environments. But the companies were, it just was not something that they were used to. Somebody looking to buy bulk location data, ad IDs, and anything else that would be strung along with those observation events, metadata, user agent strings, and things like that.
6:28We weren't trying to advertise to people, but we needed to understand who these audiences were in these frontier markets for the humanitarian applications that we were building. So yeah, it evolved. And, you know, once we got the economics down, and the data flows down and understood, we have that system up and running very quickly. So give me some examples of what you were able to track in around that 2015 period. There's, I think these examples have been reported publicly before, but there was like some Syria stuff and then Putin's entourage as well. Is that the sort of stuff we're talking about at this particular point in time?
7:10Yeah. So think about it this way. When we needed to prove the efficacy or the value of the data, it would be one thing to say we've got all this location data and we're selling to a group of people who think of location data as something acquired through intercepts or stingrays, these types of technical means. And so demonstrating a use case that was relevant, that they would understand, brought us to this Lafarge cement factory in Syria, which clustered or emerged in my analysis because devices that had originated at Fort Bragg, North Carolina, and at residences in Southern Pines, North Carolina, were at this cement, this abandoned cement factory in Syria.
8:02And so when I sort of walked them through that analysis and showed, you know, and this is a home in Southern Pines, North Carolina. And this is the location at Fort Bragg. And obviously, they knew what the Lafarce Cement Factory represented, but that I was tracking right down to the operator's residence. That became a watershed moment for location data. And that's where I had to explain after being accused of hacking and witchcraft and remote viewing and all this other stuff. They called me, the guy called me a charlatan were his words. Well, because he thought that you had gathered this data through an intercept or something else.
8:44Like he couldn't believe that this was commercially available. Correct. Correct. That's, and that's understood, you know, but this is a, somebody who should know better, right? In my opinion. And so when I had to explain, you know, look guys, I didn't hack intercept engineer or steal this data. I bought it. And I bought it for a cost factor far below anything that you would have had to spend to collect the same amount of volume, you know, using using your technical methods and at zero risk because I did it sitting in the room you see me in right now. Right. So I don't have to put people downrange and at risk to go and do this.
9:28I don't have to fly drones or airborne platforms for hours while we're hoovering up mobile data. Now, there are different use cases. If you are actually trying to locate a specific device, i.e. locating the Bin Laden courier, if you've seen the movie Zero Dark Thirty, where they're driving around, they have a device in that vehicle that is looking to identify that specific device. That's a different use case. This is, I can collect in a large area and start micro-targeting based upon areas of interest. Who goes into these buildings? What do these buildings represent? What are the centers of gravity of the people that are spending time there?
10:16And how does this create new targeting or intelligence opportunities for us that otherwise would have required a lot of investment? Yeah, I think that's a really good point to highlight because it kind of clarifies something of a misconception about commercial location data, which is that even if you go look at the IRS, for example, they bought location data or access to it from one of the brokers, Ventel or one of those companies, Babel Street, whatever. and they were trying to use it i reported to identify specific individuals they were investigating i think for cryptocurrency tax reasons and they were unsuccessful in that because it actually is quite hard from this data to be like well i want to find this specific person i have all this data now i'm going to go look for it it's more fruitful the other way around where it's like i have a location like a cement factory for instance which is in syria and has a very sensitive operation going on there or an abortion clinic or the border which has also been done and you reverse engineer from the location then to the devices and ultimately the people it's rarely the other way around it seems yeah and in that use case particularly in the law enforcement use case where they are using they are trying to apply it to almost like a surveillance application where we're going to watch this uh location and anybody that comes in and out You really need to think about it from the perspective of I am I am opening up or I need more devices, more volume in order to develop investigative pathways.
11:53You know, the Vegas shooting in 2017, you know, that was an example where we had an individual we knew nothing about. He had two residences in Metro Vegas and trying to determine if there was any transnational terrorism links based upon his wife was Filipino. and was there any intersection between Stephen Paddock and foreign actors? You know, that was, we started with the homes, his two residences. We found a guy that cuts his grass, you know, eliminated him, a couple of UPS drivers, FedEx drivers. But, you know, this is not the kind of thing where you were going to zero in and monitor some ATM machines and try to piece together forensically a crime.
12:43it's not that it's not the use case for this kind of uh for this kind of application or for this kind of data i mean it's not exactly this but it is much closer to a reverse location uh warrant from google for example which was just ruled if i'm remembering correctly unconstitutional and of course that's going to be appealed as well but like that's when the authorities go to google and they're like we want all of the phones in this location at this time now of course the difference there is as a legal sort of court mandated mechanism and here you're obviously just buying the data and that's of course the key difference so that those initial use cases where you were trying to prove the value of this data that was you know to a part of the u.s government that was focused much more obviously on military and special operations and like that sort of thing eventually a few years later you're trying to warn i think of other parts of the u.s government about what you call the grinder problem?
13:40First of all, what other parts of government? So people have an idea if you're talking to law enforcement or more military or whatever, and then what is the grinder problem? So the users or the agencies that we were talking to, primarily sort of large-scale, large population-level intelligence applications where we're trying to understand better population movements as opposed to a direct targeting application. So, you know, think about an intelligence analyst who's trying to understand a building that we have interest in, but we don't know anything else about. This is kind of a way to sort of step away and observe that building without having to physically be there.
14:28The original, you know, design of this was for outside of the United States, focusing on the global war on terror at the time, ISIS at the time, and supporting those high-value targeting missions based upon the asymmetry of ISIS, where they would just sort of blend into the crowd and trying to figure out who's who was the challenge. Well, yeah, and they were everywhere, especially across Europe, obviously, as well, and obviously the Middle East and Syria as well, but Europe especially, it was a very scary time when in London and Paris, and we were having a lot of attacks at that time. So we were successful in working with partners to say, look, you have this cultural service center, and people who go there then go to another location in Europe, and the next time we see them, they're on the front lines.
15:31It's not probative of terrorism, but it's a clue, right? You should look into this. Yeah, if a guy goes from Europe to the Turkish border, then crosses the Turkish border via foot into Syria or something, that is interesting, probably. Yep, yep, absolutely. Once we sort of got into this, there's this perception that sort of the government just goes wild on this stuff and everybody's just, it's a free-for-all. There were, even before privacy and data rights was sort of a household term, there was a lot of oversight in what we could do, what we couldn't do, what constituted a U.S. person, which went well beyond their resident status or citizenship.
16:17If they dwelled in the United States for a week, it was considered a U.S. device. So a lot of oversight, a very, very top level, especially as we talk about all this AI and targeting events now. There was the most senior person at JSOC who saw my demo, saw my brief, saw the opportunity, and then made it very clear to everybody that we're not targeting anybody with this data. These are clues. This is for investigative purposes, analysis purpose. This is not a targeting. We are not going to launch kinetic action based upon these data sets. And so there was a lot of oversight and controls well before it became the topic that it is today.
17:05And so as this sort of moved on and the community began to understand and apply these things, I got a question from one of my users about Grindr. We're seeing a lot of data in one of our data sets that was originating from the application, the dating app, Grindr. And it was just more of a curiosity question. And there was logic to why we see a lot of Grindr because, you know, they are selling inventory really to anybody. It was like if they had inventory, they would sell it. So we were seeing a lot of these events in the United States originating through Grindr. And so I just, I wasn't familiar with the app.
17:45I just started looking into it a little bit and discovered that it's a dating app that is also had just been acquired by a private equity firm with ties to the CCP. and it's a dating app that doesn't really have the type of audience uh in china that it doesn't in in in the united states and so it just was odd to me that they would want to be involved with grinder and so i just started looking into the data that they had access to it's it's very similar to the TikTok problems because TikTok, you know, they have access to all of the telemetry on a device that went well beyond location data and a user and an ad ID.
18:30They owned that server-to-server data set from their users. And it just struck me as being odd. And sure enough, you would have Grindr users who clearly would work at a national security building Monday through Friday. So I had high confidence that these were people that worked in national security. And then you'd see them go into outbuildings that were also attributable to the U.S. government. So my confidence level increases that these are government people, users. And then I could see, I could visualize the date, right, which would last for about 22 minutes and would be on the side of the road at a road stop.
19:14I mean, it was just at a McDonald's, all sorts of places. Right. And by date, obviously, you don't mean the literal time and date, although that is there as well, obviously. But you mean, obviously, this data implies that this person who works in a national security context is meeting probably for a sexual encounter at a rest stop, whatever. And the concern here is that, well, it's almost worse than the Chinese one in a way because the Chinese first party argument is that, well, they could access data from TikTok if they have ownership structure over that. They could access data from Grindr if they have ownership structure over that.
19:49That's the concern. This is almost worse because you're clearly not the Chinese government. You have also got access basically to this data as well. And that is the Grindr problem. Yeah, I would say, look, if I can do it, we have to believe that a sophisticated adversary is doing it as well.
20:17If you listen to our show for more than a week, you know our beat is uncovering how your data is quietly harvested and exposed online. And if you're like us, working remotely, constantly on the move, and running your entire life off your laptop and phone, well, you're leaving a massive digital footprint. Every time you jump between networks, check emails on the go, or browse from a new location, your device is broadcasting your activity. Advertisers can track your activity, leading to targeted ads, price discrimination, and a sense of being monitored. It's the kind of systemic tracking we'd normally write a story about.
20:50That's why we recommend Surfshark. At its core, Surfshark VPN keeps your online activity private by hiding your IP address. It encrypts your connection, making your online activity much harder to track, so your research, your sources, and your personal data stay private no matter where you're working from. But Surfshark does far more than that. Surfshark blocks ads and trackers, which cuts down on price discrimination games that sites play based on what they know about you. It also includes Alert, which monitors your ID for data leaks and an email scam checker that protects against phishing attacks.
21:22And if you game, it helps defend against DDoS attacks and ISP throttling. Since you're always on the move, the best part is that one subscription secures unlimited devices so your entire household is covered. Go to surfshark.com slash 404media to get four extra months of Surfshark VPN with the reassurance of a 30-day money-back guarantee. Or just use code 404media at checkout. That's surfshark.com slash 404media. I've started thinking about clothes a little differently this year. Instead of asking, how much does it cost? I asked, how many times am I actually going to wear this? Because the shirt you wear twice isn't a bargain if it sits in your closet the rest of the year.
22:01That's why I've been buying more from Quince. Quince makes the kind of pieces that earn their keep. They're 100 % European linen shirts and pants have been my go-to this summer. And when it's really hot, I wear 100 % European linen shorts as well. They're lightweight, breathable, and look polished enough that I can wear them pretty much anywhere. To the beach, to dinner, to happy hour, to drinks, to walking around with my dog. And they start at just$34. Their tees are another surprise. They feel incredibly soft, fit really well, and they become the shirts I reach for on regular weekdays. Not just special occasions, although I wear them on the weekend as well.
22:38The reason Quinz can sell everything for 50 % to 80 % less than similar brands is because they work directly with ethical factories and cut out the middlemen. You're getting premium materials without paying for a premium logo. And Quinz goes way beyond clothing. They've got bedding, bath towels, cookware, furniture, and all kinds of home essentials. So it's become one of those sites I keep coming back to. I have quince towels, I have quince sheets, I have a quince duvet cover, I have a quince rug, I have a quince shirt, quince shoes, quince pants. So I can pretty much live my entire life at this point just using quince items, which is pretty crazy since I just learned about them within this last year.
23:14Make your summer wardrobe easier. Go to quince.com slash 404media for free shipping on your order and 365 day returns. Now available in Canada too. That's quince.com slash 404media for free shipping and 365 day returns. quince.com slash 404media.
23:41I had some very uncomfortable conversations on the seventh floor of various government buildings with trying to explain to 50-plus-year-old white guys what Grindr is, and it's not just a dating app. Once you told them what the app was, did they click that, oh, this is potentially a national security risk, not because obviously homosexual people oppose a risk or anything like that, but they realized that maybe this could be leveraged by an adversary in a bad way. Did they realize that? Yeah, that was... My example was, guys, this is not OKCubit. These are not, you know, this is not seeking romance and love and life partners.
24:20This is something different. At least in this context. Yeah. In this context. Yeah. Trying to, again, I'm telling you how I explained it to these guys that, you know, this is a different kind of dating app. And because it is a different kind of dating app, and because it is now owned by a company with ties to the CCP, we need to start, we need to understand that this is a different risk. there is a reason why they of all of the dating apps that they could have purchased they chose to purchase Grindr so I raised the flag the issue took me some time to get some audiences to understand and to focus on the issue and once we sort of crossed that chasm of okay this is different this was referred to CFIUS and CFIUS took action the Committee on Foreign investment for the U.S.
25:12and they are the ones that sort of review and arbitrate acquisitions of companies that are sensitive to the United States national security. This was probably their first, you know, examination of a dating app and their first action to force the repatriation of Grindr back to U.S. ownership. We see that happening a lot now with real estate and other sort of factories, etc. And so the Grindr problem, in my opinion, is still the current problem that we have today. Two million apps, most people have 70 plus apps on their phone. And when you install an app, you are giving that app privileged access to inspect and extract a variety of telemetry from your device that is far more probative about who you are and what your intent and context are than an ad ID and a GPS signal ever provided.
26:17And then, you know, you add in this new AI capability where you can drop in to a GPT a year's worth of telemetry. And when I say telemetry, I'm talking like the accelerometer, battery level, screen orientation, things that are not personally identifiable. And because they're not PII, the app does not require your consent. So you don't even know this is happening and there's nothing on your phone that can throttle that, throttle that extraction. And so when we think about sort of a threat surface of 2 million apps that some are owned by adversaries, people that work there, moving data from an app to an adversarial environment is not a hard thing to do.
27:08And privacy and privacy toggles and VPNs at this level, when an app is inspecting your device, there's nothing in the OS that prevents it from pulling that data and sending it to their server. Yeah, the one question I get, obviously, a ton when I report on location data is, how do I, as a reader or a listener, how do I specifically stop this tracking? And I'm an iOS user, so I can only really talk from that perspective. But my understanding is that when you do... I mean, I don't have location services on the vast, vast majority of the time at an OS level. And that would be the main thing. Of course, you then grant it on a per app basis.
27:50what you're saying is that there is other data that can be collected by these apps that isn't that doesn't fall under that sort of location permission i mean just briefly how do you if you take steps to do so um how do you sort of protect your own device sort of privacy when it comes to sort of this data being collected by third-party apps installed on the phone yep so um so this is about the trade-off. So there are some apps where I make that trade-off and I take that risk. When I open up Uber, I don't want to have to drop a pin because I probably have 2 % left in my battery. I want it to work.
28:31I want it to know where I am so it can come pick me up in the rain. Right. I do the opposite. It's a pain in the ass. I type it in every single time. Okay. So there you go. But it's a real pain. So I understand why you would. Yeah. But the sort of the new developments in mobile security or privacy, shifting away from these perimeter tools, VPNs and toggles into this notion of being able to inspect what an app is trying to extract from your phone and deprecating what is not essential for that app's functionality. So if it's trying to pull a bunch of telemetry fields that have nothing to do with app functionality, being able to, and this is, I get this question a lot too, from the operational community, how do I get out of commercial data?
29:17How do I do this? and the surface that we have to focus on first are the apps and minimizing the amount of telemetry that they're able to extract from your device. And that's going to require a rethink about the operating system and the hardware. And I will tell your listeners, because they'll figure this out that I'm on the board of advisors of a company called Unplugged. And the approach to this problem is being able to give the user control over what data leaves their device based upon what that app is. And when you start looking, you are able to see what an app is pulling and when it's pulling and how it's resolving location when it doesn't have access to GPS.
Read the full transcript
30:10Again, it makes me think that when Apple launched privacy and we had the adpocalypse in 2022 and Metastock tanked, the recovery based upon the telemetry and going deeper into the device and not just hanging their hat on stable identifiers like the ad ID and GPS, their ability to attribute behavior to resolve intent is far more detailed than it ever was. So it's almost like privacy gave the apps a gift. They had to figure out how do we replace the ad ID. Look at Meta. Meta stock is trading at 600 bucks now. Their business recovered without reliance on the ad ID. And if you look at what Meta is doing and any other app where they are resolving your location.
31:03Let's just focus on location. They're using everything from time zone to the ambient signals around you. Time zone changes to understand exactly where you are. And when you drop your telemetry for a week into JetGPT or Claude and say, tell me about this telemetry. It builds a profile and a pattern of life that at scale should concern every American, whether you're a case officer, special agent, special operator, I don't care. This is the next level of privacy. We've been sort of hand-waving privacy for years. and a VPN that mediates transport and privacy toggles are mostly just user preference.
31:59It's not an operating system gate. It's a user preference. Don't access my GPS. Most apps comply, but that's all it is. It's just indicating your preference. We need more engineered solutions that really attack this problem and give users control over their data once and for all. Yeah, yeah, if that makes sense. So you started warning the government about this and showing them this problem. And then in parallel, but obviously also related, you did have more and more agencies buying technology like this. Obviously, you mentioned your cases, and I covered a bunch of Customs and Border Protection, Immigration and Customs Enforcement, Secret Service as well.
32:42There was a lot of debate and argument around that because, of course, they were doing this without a warrant under the Fourth Amendment. That may now be in flux with this recent Supreme Court ruling. We haven't really seen the fallout from that yet. Frankly, it's going to take years probably to see that. But there was a lot of movement there. And then recently, there was some other news, which is that the Pentagon came out and it said that, yes, U.S. military personnel are being targeted using location data. This isn't quite related, but the Financial Times, I think, reported that commercial location data and SS7 stuff, which is the rooting backbone, right, was also used to monitor the location of senior U.S.
33:23officials during the Iran war. So there's all that sort of stuff. But back on the commercial data being used to target U.S. military personnel, what was your reaction to seeing that news? That, oh, the Pentagon found out or the Pentagon said it? Yeah, Senator Rodden Wyden from Oregon has been sort of in the lead on this for a long time. They brought this up. And so Senator Wyden, who's not even on armed services, wrote a letter to the CIO at the Department of Defense demanding an accountant. And in that letter, you can almost sense the tone, the exasperated tone. In 2016, a contractor blew the whistle on this.
34:08And what have we done in the last 10 years? And that's my reaction. I've kind of gotten a little desensitized by like, how many times do I have to say, yeah, I told you, we've been talking about this. We've known about this. How many different ways do I have to explain it until we get, you know, sort of national level policies to deal with this and deal with it in a way that's not hand-waving and creating more training and white papers and PowerPoint presentations describing ways that you can try to outthink and trick the, you know, ubiquitous technical surveillance or the platforms. but we need engineered solutions.
34:54And so we have some congressmen and women that sort of heard us out on this and have developed amendments to the NDAA. We came in late, the National Defense Authorization Act for 2027, in which instructs the Pentagon to explore and assess technologies that attack this commercial data problem from its origins at the app layer to examine methods and approaches to minimize this data, leaving a device and networking into this opaque cartel of data brokers and attribution companies that end up in the hands of adversaries, which, again, is not hard to do at all. And more of this legislation is just sort of trying to put the data back in the phone after it's left the phone.
35:58And we need to begin looking at how do we keep the data from leaving the phone in the first place? Because that's the problem. And that's been the problem. And we need to start thinking about, okay, how do we solve this? Because We're not going to out-tradecraft an$8 trillion duopoly of Apple and Google and 2 million apps, all of which have fraud detection algorithms that the minute you are doing something funky and weird, it deplatforms you or it outs you, it flags you as unique and anomalous. So we need to think about how do people that are in sensitive positions carry a phone into a war zone because a lot of our personnel have children.
36:45And if they're deployed for six months, they need to be able to reach back and do homework and do all of those kinds of things. So sending them out onto a deployment without a phone is not practical. They'll quit. I would quit. So how do we do this so that we are not giving an adversary an advantage for free? Yeah. And I mean, you touched on it there with Apple and Google. And the question is, which entity or player is the one with the most power here to make the biggest change to this problem? Now I'm sure the company that you're on the board on would love to say it was them. And then other providers would probably love that as well.
37:28You mentioned Apple and Google. Obviously, they are running the primary operating systems on this. You obviously then have the app developers as well, but they're probably going to do whatever the fuck they want. Which entity here is the one with the most power that can do the most change? Is it like ultimately Apple and Google who should do this? My answer to that question is the consumer. The consumer needs to decide, this is not proportionate. The amount of data that is being collected about me is not proportionate to a typical advertiser-consumer relationship. This is beyond that assumed relationship that has fences and gates.
38:08They are going far deeper into my existence. So the consumer needs to understand what they're up against. Google and Apple, they kind of depend upon their app ecosystem for a significant amount of revenue. So regulating them is difficult. And replacing them with Google or Apple apps triggers antitrust. So they're in kind of a bind. And Google is indeed an advertising business, especially because many people use Google apps. And so the answer to your question really is, it's the apps. If I were to be counseling somebody today who wasn't going to go into the market to buy a phone that was engineered for privacy, I would say, have an understanding of the apps that you're installing on your phone.
39:02just go to the app store and try to figure out, look and see where that app is manufactured. But again, you know, they can have employees there that are, you know, siphoning out data. But it really gets down to what apps do you need and controlling your appetite for convenience. Because convenience and lack of friction is how we got here in the first place and how surveillance sort of builds and layers upon itself. And if you are really concerned about sort of surveillance where you have no reason to be surveilled, you've got to take a look at your own sort of tech profile and minimize that footprint as best you can.
39:53But this is to really solve the problem, Joe. This is engineering. This is not having your name moved from data broker lists. Like, that's good. That's fine. Do it if it makes you feel better. But at the end of the day, we need to take back the flow of data and resolve it back to something that is more proportionate to what we get from these apps and these experiences. Yeah. Well, I think that's a really, really good way to pull it and a great place to leave it. Mike, thank you so much for joining us. I really, really enjoyed this conversation. Thank you so much. Thanks for having me. I appreciate it.
40:57is by leaving a five-star rating and review to the podcast. That stuff really, really does help us out. This has been 404 Media. We'll see you again next time.
From the publisher
Go to https://surfshark.com/404Media to get 4 extra months of Surfshark VPN, with the reassurance of a 30-day money-back guarantee, or just use code 404MEDIA at checkout. That's https://surfshark.com/404Media.
This week Joseph talks to Mike Yeagley. As you’ll hear, he is a very interesting guy. He introduced parts of the government to the whole idea of commercially sourced location data. He spent hundreds of thousands of dollars buying the data, and showing what could be done with it. It’s a fascinating conversation.
- How the Pentagon Learned to Use Targeted Ads to Find Its Targets—and Vladimir Putin: https://www.wired.com/story/how-pentagon-learned-targeted-ads-to-find-targets-and-vladimir-putin/
This is a production of 404 Media, a journalist-owned tech website. Learn more and subscribe at: htttps://404media.co
Listen to our weekly podcasts:
Apple Podcasts: https://podcasts.apple.com/us/podcast/the-404-media-podcast/id1703615331?ref=404media.co
Spotify: https://open.spotify.com/show/0F3oY47l2XgoBMaAmIaw29?ref=404media.co
Google Podcasts: https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5hY2FzdC5jb20vcHVibGljL3Nob3dzL3RoZS00MDQtbWVkaWEtcG9kY2FzdA?ref=404media.co
Become a paid subscriber for access to bonus content: https://404media.co/membership
Learn more about your ad choices. Visit megaphone.fm/adchoices
