Recent Inspection Over one-eighth of the hundreds of mobile applications sold to U.S. military personnel have been identified to contain software developed by Chinese, Russian, and other foreign entities. This raises significant concerns about potential data collection by hostile governments, which could disclose sensitive information regarding the whereabouts of service members, including their homes, workplaces, and deployment locations.
Research led by scholars from Purdue University, West Point, and Florida International University highlights that one widely-used app among military personnel for assessing living conditions at bases includes code from Huawei. This Chinese telecommunications firm was identified as a national security risk by U.S. regulators back in 2020. Furthermore, two other apps were developed by Russian companies and integrated with the Russian advertising platform Yandex.
The largely unregulated digital advertising sector treats both civilians and military members similarly, with little differentiation unless specified. Despite evidence suggesting that disclosures from these apps could potentially reveal troop movements, deployments, and everyday activities of personnel in high-security areas believed to house intelligence operations and nuclear arsenals.
A prior investigation by WIRED uncovered that common apps are capable of tracking U.S. service members to their residences, children’s schools, and off-base locations where military activity is restricted. Experts caution that this data can assist foreign spies in identifying personnel with access to sensitive areas, determining when a facility is most vulnerable, and uncovering other critical details.
This concern has rapidly escalated from theoretical scenarios to real threats. In April, U.S. Central Command confirmed in a letter to Senator Ron Wyden that multiple threat reports have indicated adversaries leveraging commercial location data to monitor U.S. military personnel in the Middle East. This area remains a hotspot, with U.S. forces engaged in a longstanding standoff with Iranian forces over the Strait of Hormuz. Lawmakers have described this as the first official acknowledgment that soldiers in active combat zones are being tracked through the data broker economy. The Pentagon’s contractors and researchers have been sounding the alarm about this threat for nearly a decade.
A new study delves into this significant revelation for the first time, examining the actual content within apps designed and marketed specifically for military use.
Joshua Shinkle, a postdoctoral fellow at Purdue University and the lead author of the study, stated, “We are grateful for the opportunity to bring greater attention to these issues. We hope this research aids military personnel, developers, and platforms in making informed privacy decisions and fosters ongoing discussions with developers, platforms, and policymakers to address these gaps.”
The research investigated over 220 military-specific apps, ranging from uniform guidelines and preparation for promotion exams to banking and dating apps, sourced from the Google Play Store and military-related subreddits. Alarmingly, nearly two-thirds (64%) were found to incorporate third-party code, known as SDKs, which are pre-built software components typically used for analytics and advertising. These SDKs track user behavior, including location data, and may share this information with external companies.
The study revealed that 40% of the apps gathered or shared more data than they disclosed in their listings on Google and Apple stores.
The predominant SDKs originated from Google and Facebook, the leading players in U.S. digital advertising. However, the study identified a total of 76 different SDKs, including ones traced back to countries like China, Russia, Israel, India, Germany, and others. Approximately 7% of the apps contained third-party code from nations regarded as hostile by the Department of Defense.
Twelve of these applications utilized HMS Core, a software kit from Huawei that claims to track users’ locations, serve advertisements, and store multimedia files. Some of these apps were developed for state National Guard organizations.
While researchers noted that no data was currently sent to Huawei’s servers, remote updates to the SDK can be executed at any time. Code that appears inert today may evolve into spyware tomorrow. In a striking example cited in the study, Huawei code was embedded as a dependency for a commercial notification tool without the app developer’s knowledge.
Source: www.wired.com


