{"id":18719,"date":"2026-09-13T08:15:29","date_gmt":"2026-09-13T15:15:29","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=18719"},"modified":"2026-09-13T08:15:29","modified_gmt":"2026-09-13T15:15:29","slug":"what-the-militarys-ad-tracking-problem-can-teach-you-about-your-phone","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/09\/13\/what-the-militarys-ad-tracking-problem-can-teach-you-about-your-phone\/","title":{"rendered":"What the Military\u2019s Ad Tracking Problem Can Teach You About Your Phone"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Some of this is diabolical. You can check apps for what data they share, rejecting those that share with third parties, use location&#8230; And I keep location off on my phone unless I need location for navigation, and it&#8217;s always connected through a VPN, and you can set apps to not run in the background, though I prefer to go into app information and stop apps manually as many you only use every once in a while. And even with stock Android there are a lot of settings to limit the tracking and delete the advertising ID, disable precise location where it&#8217;s spying on WiFi access points, Bluetooth and looking out for Bluetooth trackers&#8230; And often when leaving the house I turn off WiFi, have my phone in airplane mode especially when in my pocket, as I won&#8217;t get radiated and many businesses track those signals to follow where people are in their stores and probably getting tied into these digital price labels&#8230; And ditching the megacorps closed source systems for opensource operating systems give you more control to be degoogled, or severely limit what Google can see. A major thing is ditching Google&#8217;s apps for opensource ones like your dialer, SMS, keyboard, contacts&#8230; This really should be legislated and easier to manage, but then the government has purposely allowed this system to get around the 4th Amendment and purchase this information. And even if you control the phone, modern cars track you along with a massive network of ALPR cameras. And the new signal intelligence systems will track you even if you disable your car&#8217;s cellular connection by tracking identifiers broadcast by devices like your tire pressure sensors&#8230;, with the saving grace that all of this hasn&#8217;t been tied together yet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/what-the-militarys-ad-tracking-problem-can-teach-you-about-your-phone\" target=\"_blank\" rel=\"noopener\">https:\/\/reclaimthenet.org\/what-the-militarys-ad-tracking-problem-can-teach-you-about-your-phone<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_a6386ad8-8257-47d4-9aa5-0c862f4c1df2\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Your phone does not need your name to tell a stranger where you sleep and work.<\/h5>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/JysH7oq6qA1h.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">By Ken Macon<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of going to the trouble of hacking into a military system, a nation-state enemy of the US could buy useful intelligence from a commercial entity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.wyden.senate.gov\/news\/press-releases\/wyden-and-harrigan-call-for-investigation-into-dod-efforts-to-protect-us-servicemembers-from-commercial-location-data-threats\"><u>a statement Senator Ron Wyden (Oregon Democrat) and Representative Pat Harrigan (North Carolina Republican) released on September 4<\/u><\/a>, this is the gist of threat reports the US military has received.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same day, <a href=\"https:\/\/www.internazionale.it\/ultime-notizie-reuters\/2026\/09\/04\/exclusive-us-military-turns-off-ad-trackers-on-devices-amid-middle-east-targeting-reports\"><u>Reuters carried a statement from Harrigan<\/u><\/a>, who said US enemies \u201cshould not be able to pull out a credit card and buy information that helps them track American troops.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/unclassified_responses_to_sen_wyden_rfis_on_mobile_phone_use_in_centcom_aor.pdf\"><u>The CENTCOM response to Wyden<\/u><\/a> speaks of \u201cmultiple threat reports\u201d concerning adversary exploitation of commercial location data to \u201ctarget or surveil US personnel in theater.\u201d The response was provided on April 14, 2026. There is no mention of a specific successful attack, or a missile strike that resulted in casualties.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/wyden_harrigan_letter_on_dod_oig_location_data.pdf\"><u>Separate responses released by the two lawmakers<\/u><\/a> show that the Army, the Department of the Air Force, the Department of the Navy (including the Marine Corps), and US Special Operations Command all say they disable advertising identifiers on government-managed devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When joined to other observations \u2013 such as location, time of day or night, and other people whose devices are observed in the same location \u2013 <a href=\"https:\/\/media.defense.gov\/2020\/Aug\/04\/2002469874\/-1\/-1\/0\/CSI_LIMITING_LOCATION_DATA_EXPOSURE_FINAL.PDF\"><u>an advertising identifier can be used to build sensitive profiles<\/u><\/a>, even if the person\u2019s name is not known.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a device that is observed to spend nights near a particular residential address, and days near a military base, could be that of a member of the military. Travel abroad could indicate deployment. If several such devices are spotted moving together, it may indicate a unit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apple devices have an identifier that can be used for advertising purposes, <a href=\"https:\/\/support.apple.com\/en-us\/102420\"><u>Identifier for Advertisers (IDFA)<\/u><\/a>, while <a href=\"https:\/\/support.google.com\/googleplay\/android-developer\/answer\/6048248?hl=en\"><u>Google provides the Android advertising ID through Google Play services<\/u><\/a>. These are not hardware serial numbers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a device can be identified by a string of characters such as 38400000-8cf0-11bd-b23e-10b96e40000d. This is a fictional example, but real ones look similar.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/developer.android.com\/identity\/user-data-ids\"><u>Advertisers can recognize a returning device<\/u><\/a> and make decisions based on that, such as to not show the same ad over and over again (frequency capping). Then, they can attribute an installation of an app or a purchase to a particular advertising campaign, to see if the campaign is effective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ID can be used to target audiences and measure the reach of an ad campaign.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Advertising IDs themselves contain no name or location. Linking them to real identities takes other observations about what a person does on their phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One way to get more observations is to allow two apps to use the same advertising ID. This lets data brokers and advertisers join the dots between the two sets of observations, and build a more comprehensive profile.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, not every app has access to an advertising ID, nor does every app need it to function.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The data collected and sent to brokers and advertisers is pseudonymous, in the sense that the record is labeled with a unique identifier \u2013 but the data that accompanies this identifier may be linked to a real person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unlike hardware serial numbers, these IDs are not fixed and can be reset, or their access can be restricted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Apple devices, with the release of iOS 14.5, the company introduced <a href=\"https:\/\/developer.apple.com\/app-store\/user-privacy-and-data-use\/\"><u>App Tracking Transparency<\/u><\/a> \u2013 a feature that requires apps to ask for permission to use IDFA, and to track users for advertising across other companies\u2019 apps and websites.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a user denies this permission, the app will not be able to access IDFA, and Apple also forbids apps from using any other, alternative identifiers to bypass the rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose you download a free weather app, and, hoping to get the forecast for your area, you agree to give it access to your device\u2019s location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The app\u2019s developer can easily incorporate third-party software development kits (SDKs) \u2013 and they often do, since they spare them the trouble of developing each component of the app from scratch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SDKs can be used for advertising, analytics, attribution, mapping, crash reporting, or audience measurement \u2013 but not all of them are present in every app, and not all of them receive location data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, if an SDK does receive permission-based location and an available advertising ID, it can then combine that with a timestamp, coordinates, and device signals, <a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/e1budFngeg0R.pdf\">a US Federal Trade Commission (FTC) complaint details<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The case concerns X-Mode, a company succeeded by Outlogic, which <a href=\"https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/X-ModeSocialComplaint.pdf\"><u>the FTC alleges paid app developers to integrate its SDK<\/u><\/a> into their apps, and in this way ended up collecting data from over 300 apps, including games, fitness and religious apps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a user gave an app permission to know their location, the X-Mode SDK received that information, along with the device\u2019s operating-system information and time. The company combined it with data it had obtained from other brokers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result was that X-Mode was able to sell not only raw data, but also audience segments. The data was linked to the devices\u2019 mobile advertising IDs (MAIDs). In April 2024, <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/cases-proceedings\/2123038-x-mode-social-inc\"><u>the FTC finalized a settlement order prohibiting the company from sharing or selling sensitive location data<\/u><\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The auction route, or real-time bidding (RTB), involves an automated process where advertisers bid for a particular ad slot on a site or in an app within milliseconds. In order to decide how much to bid, they need to know what the ad opportunity is worth \u2013 and the bid request can include the identifier of the device, as well as its location, and other context.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FTC said that one company, Mobilewalla, <a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/1P9RLmnwQU0r.pdf\">collected and retained bid requests it received as a participant in the RTB process even where it lost the auction<\/a>. This was contrary to the terms of the exchanges it was working with. Mobilewalla estimated that from January 2018 to June 2020, some 60 percent of its consumer data came from RTB. The company also bought data from aggregators.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In January 2025, the FTC finalized an order that banned Mobilewalla from collecting and retaining RTB data for any purpose other than participating in an auction \u2013 and from selling sensitive location data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to SDKs, there are other intermediaries, such as data aggregators, that combine observations from many sources, and brokers, that package this data into files, audience lists, or search tools. And while the data may start with an app on a phone, <a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/pisrvyvRngAe.pdf\">the customer doesn\u2019t have to be an advertiser, but could also be an analyst \u2013 or the government<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The data arriving at a customer\u2019s end could be used to discern patterns in a person\u2019s life. In a fictional example, a device could be at a residence at night, at a workplace during weekdays, at a church on Sundays, and occasionally at a medical facility that deals with a specific condition. Home is particularly revealing because location can be combined with address records and other publicly available or commercial information to determine who lives there. That, in turn, can be used to build a profile of a person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the residence is an apartment building with many units, it could be harder to pinpoint whose phone it is. Or, the phone could be a shared one, or there could be visitors. Inference of identity can sometimes stop at determining that a person works in a particular building and sleeps in a particular house. But that information can be useful without knowing the person\u2019s legal name.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.nature.com\/articles\/srep01376\"><u>One study was published in 2013 by Yves-Alexandre de Montjoye and coauthors in Scientific Reports<\/u><\/a>. They analyzed 15 months of carrier data on 1.5 million users, and found that four randomly selected time-and-location observations were enough to uniquely identify 95 percent of the traces in that dataset.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the study was not about GPS data used in advertising today. It was about cell phone tower data with an hourly time resolution, and the ability to uniquely distinguish a trace in that particular dataset \u2013 which does not mean attaching a legal name to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A 2022 investigation documented police subscriptions to <a href=\"https:\/\/reclaimthenet.org\/how-data-brokers-tell-law-enforcement-everywhere-youve-been\/\">Fog Reveal<\/a> costing $6,000 to $9,000 a year, typically including 100 queries a month. But that\u2019s not a current price, and it\u2019s not the price of unrestricted public access to the data.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/o4PnMxDNRDmp.jpg\" alt=\"Aerial map interface showing redacted device tracking data, timestamps, and IP addresses over a residential street.\" style=\"aspect-ratio:1.2580645161290323;width:1170px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/outlogic.io\/privacy-policy\/\"><u>Outlogic\u2019s January 2026 privacy policy<\/u><\/a> still talks about precise location data and advertising IDs, and the company\u2019s business customers using this data for market research, urban planning, public health, security, and other purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Outlogic\u2019s policy, the company does not build audiences, or enable its customers to do so, based on sensitive health-related location data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Independent verification would require examining the company\u2019s suppliers, customers and onward transfers of data to assess enforcement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the US, the <a href=\"https:\/\/www.justice.gov\/nsd\/data-security\"><u>Justice Department\u2019s Data Security Program<\/u><\/a> came into effect in April 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The program restricts covered sensitive-data transactions with countries of concern and covered persons. Commercial location sales outside its scope remain possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/gEXvCcXcSN2h.pdf\"><u>The Army\u2019s July 8 memo<\/u><\/a> confirms that the advertising identifier is disabled in the Microsoft Intune managed-app environment and on government-furnished Windows desktop, Android and Apple hardware. <a href=\"https:\/\/www.internazionale.it\/ultime-notizie-reuters\/2026\/09\/04\/exclusive-us-military-turns-off-ad-trackers-on-devices-amid-middle-east-targeting-reports\"><u>The Army separately told Reuters<\/u><\/a> its Windows restriction predated 2021, and Apple and Android defaults were in place since at least February 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Navy\u2019s July 22, 2026 memo confirmed restrictions on government equipment and managed-app configurations. The Department of the Navy includes the Marine Corps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">US Special Operations Command (SOCOM) responded on July 28: the identifier had been blocked on managed Android and iOS devices, and recently disabled on Windows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to an August 18, 2026 Air Force department memo, iPhones and iPads are already subject to advertising-ID restrictions, but it doesn\u2019t state the date when it was adopted. The same document says that for Windows and Android devices, the restrictions were implemented between July 23 and July 27.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mobile device management (MDM) allows administrators to configure enrolled devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">App-only management is narrower in scope than whole-device management, covering the managed applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/intune\/device-configuration\/templates\/ref-device-restrictions-apple\"><u>Microsoft\u2019s documentation<\/u><\/a> for its Intune product reveals that the software contains separate controls that allow for disabling Apple\u2019s advertising identifier, and for limiting Apple\u2019s own personalized ads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The public memos leave details to establish: the exact deletion, reset or access-blocking method on each platform, and blanket coverage of contractor-owned devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wyden and Harrigan want to know if the military\u2019s controls are incomplete, or if other identifying information is being used instead, or if the data is being collected from personal devices of military personnel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those possibilities remain questions for the investigation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you log into a Google service, it identifies your account regardless of the advertising ID you are using.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you give an app permission to know your precise or background location, it can collect this data independently of the advertising ID. Websites, meanwhile, use cookies and local storage, while apps use internal identifiers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google recommends that developers use Firebase installation IDs or privately stored app IDs for measurement that is not related to advertising. Firebase IDs belong to one installation of an app and are used to deliver push messages and report crashes. Push tokens are used to route messages to app installations and can be connected to service records, but are not public and universal IDs for a device\u2019s hardware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IP addresses can give a rough idea of a user\u2019s location and the network they are using, and are often shared by multiple users. Google\u2019s location documentation also mentions places that users enter, activity and location data from the device if the app has been given permission to use it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Fingerprinting combines screen resolution, timezone, language, software and hardware capabilities, and rendering, and has variable accuracy. <a href=\"https:\/\/support.mozilla.org\/en-US\/kb\/firefox-protection-against-fingerprinting\"><u>Browsers restrict the signals<\/u><\/a> that are available to fingerprinting, while <a href=\"https:\/\/developer.apple.com\/app-store\/user-privacy-and-data-use\/\"><u>Apple prohibits fingerprinting<\/u><\/a> and requires permission for cross-company advertising tracking via substitute IDs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Server-to-server forwarding takes place after an app request or purchase reaches company systems, beyond the reach of a blocker on the phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google\u2019s server-side Tag Manager, meanwhile, runs outside of a browser and lets website operators control the forwarding of data to other Google services and third parties. Another use of server-side analytics is to measure and improve service performance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The 15-minute anti-tracking audit<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Open Settings &gt; Privacy &amp; Security &gt; Tracking on your iPhone. Turn off Allow Apps to Request to Track. Also, review the list of apps that already have this permission and revoke it where you don\u2019t want it.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/L4EH5GGVBiVS.jpg\" alt=\"An iPhone screen showing an App Tracking Transparency prompt asking to track activity with Ask App Not to Track and Allow.\" style=\"width:382px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Settings &gt; Privacy &amp; Security &gt; Location Services contains the location controls. Tap on each app to see the options, and choose Never to deny it, or While Using the App to allow it during the time the app is in use, or during the time a relevant feature is in use. Another option is to allow an app to access your location Always, which permits access even when you\u2019re not using it, in the background. The available options depend on the app.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/tC3AlFz932oi.jpg\" alt=\"iOS Location Services settings screen on an iPhone showing app permissions and location sharing options.\" style=\"aspect-ratio:0.48705921755249043;width:400px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Turn \u201cPrecise Location\u201d off if you don\u2019t want to share your exact location, but rather an approximate one. For example, a weather forecast app may only need to know your city, while a navigation app will need your precise location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Android, the path to these settings can vary depending on the version and the manufacturer of your phone. To delete the Advertising ID, you can follow Google\u2019s official instructions and go to Settings &gt; Privacy &gt; Ads &gt; Delete Advertising ID. If this option is not there, you can search for \u201cadvertising ID\u201d in your Settings app to find it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deleting the Advertising ID removes it: subsequent requests receive zeros. Resetting instead generates a new identifier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On some older Android versions, Google documents Privacy &gt; Advanced &gt; Ads &gt; Opt out of Ads Personalization; this older opt-out is not equivalent to deletion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Google Pixel phones, you can control location tracking by going to Settings &gt; Location &gt; App location permissions. Depending on the app, you can choose between \u201cDon\u2019t allow,\u201d \u201cAllow only while using the app,\u201d \u201cAsk every time,\u201d and \u201cAllow all the time.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Android 12 and later, you can also choose between \u201cPrecise\u201d and \u201cApproximate\u201d location. Switching off \u201cUse precise location\u201d will still allow apps to have access to your approximate location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are using an iPhone, go to Settings &gt; Apps &gt; Safari, and enable \u201cPrevent Cross-Site Tracking\u201d there. Firefox has Enhanced Tracking Protection enabled by default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The options to restrict third-party cookies in browsers are effective in reducing cross-site tracking.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tracker and content blockers, on the other hand, reduce the number of requests to known trackers. However, these tools may break the functionality of some websites, and you may have to make exceptions \u2013 it\u2019s a good idea to make these exceptions as narrow as possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Keep in mind that these browser-based protections do not extend to native apps.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first step to take with apps is to uninstall those you don\u2019t use, as removing their icons from the home screen is not enough. Once you uninstall an app, it will no longer be able to collect data from your device, but it may still be using and sharing data it has already collected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Next, review the account controls of various services you use to see if you can turn off personalized ads, location history, activity history, and disconnect services that don\u2019t need to be connected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Google, there are several controls that you need to visit separately: Timeline, Search Services History, and Web &amp; App Activity. Turning one off does not disable the others, or necessarily delete past data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Say, you\u2019re using an app that wants to phone home to its server, and that server is a known tracker. In this case, a DNS tracker blocking service on your phone will refuse to do a DNS lookup for that tracker\u2019s domain, effectively preventing the app from knowing the IP address of the tracker\u2019s server.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/XQDvXD6OgmD0.jpg\" alt=\"Diagram showing three steps of a device requesting an IP address from a DNS server to connect to a web server.\" style=\"aspect-ratio:1.6022944550669216;width:838px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Coverage across apps depends on the operating system and configuration. But even if the app can\u2019t reach that tracker, it can still make requests to unknown domains, or to an IP address directly (i.e., without a DNS lookup), or make a request to its own server, which then makes a request to the tracker. And some app functionality may break if it can\u2019t reach its intended destination.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/reclaimthenet.org\/recommended-tools\/vpn\">VPN (Virtual Private Network)<\/a> encrypts traffic that is routed through it, and hides the originating IP address from the service on the other end, showing them instead the IP of the VPN exit server. This reduces the amount of observation and tracking that your ISP or local network can perform, but shifts the trust to the VPN company, rather than removing the need to trust a network provider.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, a VPN cannot stop an app from sending your account identity, or your GPS-derived location, or any other data it collects through analytics, up the VPN tunnel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While some <a href=\"https:\/\/reclaimthenet.org\/data-brokers-deadly-consequences-and-the-wild-west-of-information-trade\/\">data brokers<\/a> allow users to opt-out of having their personal information sold, and in some cases deleted, this depends both on the law in their jurisdiction and the company\u2019s own procedures. Thus, it still pays off to try to limit the amount of data that is collected in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, even if a user succeeds in getting their information deleted from one data broker, that does not mean that all their data is gone from all brokers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The system, called DROP is available at privacy.ca.gov\/drop, and allows California residents to make a single request to have their data deleted from all the brokers registered with California\u2019s Privacy Protection Agency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first round of mandatory processing of these requests started on August 1, 2026, and the system works in 45-day cycles.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The agency explains that data brokers must continue deleting matching, non-exempt information collected after the initial request has been processed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The idea is to prevent the same broker from simply re-collecting and re-selling the deleted information, forcing the user to repeat the request over and over.<\/p>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/09\/sHUrVBAK5nCq.jpg\" alt=\"Table listing privacy actions like using a VPN or blocking cookies, what tracking they reduce, and other tracking routes.\" style=\"aspect-ratio:1.4132701421800948;width:1491px;height:auto\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">An organization can control the privacy settings of phones it issues, but it cannot assume the same authority over a service member\u2019s personal phone or a family member\u2019s phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phones are a primary way people stay in touch with family and loved ones, so practical security advice has to take that into account. And phones are not the only devices that can expose location \u2013 smartwatches and fitness trackers, tablets, and connected cars can all do it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In its April response, <a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/7DafbkZMk6mA.pdf\">CENTCOM said<\/a> personal phones were not banned within its area of responsibility, but geolocation restrictions applied under a December 2025 policy. That response does not establish the current rules everywhere personnel are deployed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NSA\u2019s April 2026 <a href=\"https:\/\/media.reclaimthenet.org\/documents\/2026\/09\/2eR6G8dHojuL.pdf\">guidance<\/a> also warns that photographs can reveal location either through metadata or by landmarks visible in the photo. Clear rules about sensitive locations and education about sharing need not become invasive monitoring of personnel or families.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">FTC cases show that location data can reveal visits to medical facilities, including those focused on reproductive health, places of worship, political gatherings, and protests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mere presence of a person\u2019s device near a particular venue provides a clue \u2013 though by no means a proof \u2013 of a medical condition, a visit to a reproductive health clinic, a religion, political affiliation, or participation in a protest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a hypothetical comparison, an advertising analyst working for a company that sells running shoes would be very interested in people who regularly appear near a store selling running gear. Meanwhile, an intelligence analyst is interested in phones that appear near military housing and a building where military operations are planned. The observation is the same, the purpose is different.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And even if the observation doesn\u2019t have a name, it can still be intelligence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is not to achieve digital invisibility but to reduce unnecessary digital trails, the number of companies that receive them, and make it harder to connect the dots.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some of this is diabolical. You can check apps for what data they share, rejecting those that share with third parties, use location&#8230; And I keep location off on my phone unless I need location for navigation, and it&#8217;s always connected through a VPN, and you can set apps to not run in the background, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-18719","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=18719"}],"version-history":[{"count":2,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18719\/revisions"}],"predecessor-version":[{"id":18721,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/18719\/revisions\/18721"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=18719"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=18719"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=18719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}