The 404 Media Podcast

This Man Bought Phone Location Data from Around the World

42 min
Jul 27, 2026about 1 month ago
Listen to Episode
Summary

Mike Yeagley, a government contractor who introduced commercial location data to U.S. special operations in 2015, discusses how he bought bulk location data to track targets in Syria and beyond, then later warned the government about the "Grindr problem"—the national security risk of adversaries accessing sensitive telemetry through apps owned by foreign entities. The episode explores how commercial location data became a surveillance tool, its current use by law enforcement without warrants, and why engineering solutions at the OS level are needed to prevent data extraction.

Insights
  • Commercial location data is more valuable for reverse-engineering from locations to people than for tracking specific individuals forward—making it ideal for surveillance of sensitive sites rather than targeted person-tracking
  • Modern apps collect far more exploitable telemetry (accelerometer, battery level, screen orientation) than just GPS and ad IDs, and this data isn't classified as PII so users never consent to its extraction
  • The real privacy threat has shifted from location data alone to the combination of device telemetry + AI analysis, where a year of sensor data fed into GPT can build detailed behavioral profiles
  • Apple and Google's privacy improvements (like iOS App Tracking Transparency) paradoxically forced apps to go deeper into device telemetry, making surveillance more sophisticated rather than less
  • Solving this requires engineering controls at the OS/hardware layer to prevent data leaving devices, not just user toggles or VPN tools, which are merely preference indicators rather than system gates
Trends
Shift from location-based surveillance to multi-sensor telemetry surveillance as primary tracking methodForeign adversaries acquiring U.S. dating apps and social platforms to access government employee behavioral dataLaw enforcement agencies purchasing commercial location data to conduct warrantless surveillance, now facing legal challengesAI-enabled behavioral profiling using non-PII device telemetry to build detailed patterns of life at scaleCongressional and Pentagon recognition of commercial data as national security vulnerability requiring legislative solutionsPrivacy regulations (like iOS ATT) inadvertently incentivizing deeper, less transparent data collection methodsEmergence of privacy-focused phone manufacturers and OS-level data control solutions as market responseIncreased focus on app-layer data extraction as the critical vulnerability point in mobile securityGrowing tension between military/government personnel needing phones for operational connectivity and data security risksData broker ecosystem consolidation and opaque attribution companies becoming de facto intelligence infrastructure
Topics
Commercial Location Data SurveillanceGovernment Warrantless Data PurchasesForeign Adversary Access to U.S. AppsDevice Telemetry and Behavioral ProfilingFourth Amendment and Location Data WarrantsNational Security Risks of Dating AppsCFIUS Foreign Investment ReviewMobile OS Privacy ArchitectureData Broker Industry StructureAI-Enabled Pattern of Life AnalysisSpecial Operations Intelligence MethodsApp-Layer Data Extraction ControlsPentagon Commercial Data VulnerabilityPrivacy vs. Operational Convenience Trade-offsLegislation and NDAA Amendments on Data Control
Companies
Grindr
Dating app acquired by private equity firm with CCP ties; became case study for foreign adversary access to U.S. gove...
Meta
Recovered advertising business post-iOS privacy changes by shifting from ad ID reliance to deeper device telemetry co...
Apple
iOS operating system provider; implemented App Tracking Transparency that inadvertently pushed apps toward deeper, le...
Google
Android OS provider and advertising business; controls app ecosystem but faces regulatory constraints on privacy enfo...
Ventel
Location data broker that sold access to government agencies including IRS for surveillance purposes
Babel Street
Data broker providing location data and analytics to government law enforcement agencies
TikTok
Foreign-owned app with access to comprehensive device telemetry; cited as parallel national security concern to Grind...
Unplugged
Privacy-focused company developing OS-level controls to give users visibility and control over app data extraction
People
Mike Yeagley
Introduced commercial location data to U.S. military in 2015; warned government about foreign adversary risks through...
Byron Tao
Leading journalist covering location data and commercial surveillance; predecessor to host on this beat
Ron Wyden
Led investigation into Pentagon's use of commercial location data to track military personnel; demanded DOD accountin...
Quotes
"I didn't hack, intercept, engineer or steal this data. I bought it and I bought it for a cost factor far below anything that you would have had to spend to collect the same amount of volume using your technical methods and at zero risk because I did it sitting in the room you see me in right now."
Mike Yeagley~15 minutes
"If I can do it, we have to believe that a sophisticated adversary is doing it as well."
Mike Yeagley~35 minutes
"We need to begin looking at how do we keep the data from leaving the phone in the first place? Because that's the problem. And that's been the problem."
Mike Yeagley~55 minutes
"Privacy toggles and VPNs at this level, when an app is inspecting your device, there's nothing in the OS that prevents it from pulling that data and sending it to their server."
Mike Yeagley~42 minutes
"The consumer needs to decide. The amount of data that is being collected about me is not proportionate to a typical advertiser-consumer relationship."
Mike Yeagley~62 minutes
Full Transcript
The Wired Newsroom is known for award-winning reporting on how technology shapes our world. On Wired's Uncanny Valley, we take that curiosity even further. Each week, journalists from Wired break down the biggest stories in tech while speaking directly with the people building, challenging, and reshaping the future. Is the AI boom sustainable? How do you protect your privacy in an age of constant surveillance? Uncanny Valley tackles the questions driving today's tech debates and lighting up your group chats. Listen to new episodes every Thursday, wherever you get your podcasts. town the company and needs your support. To subscribe, go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. And they get early access to our interview series too. Gain access to that content at 404media.co. Also do remember to subscribe to our YouTube channel where you can watch all of our episodes, including this one. Subscribe at youtube.com slash at 404mediaco. This week, I'm speaking to Mike Yeagley. He is someone that you may have come across if you follow the worlds of privacy and location data, especially the stuff I cover, the stuff that Byron Tao covers as well, who was sort of the leading journalist on location data. I followed in his wake into the bunch of stories. I spoke to Byron many, many episodes ago. You can go find that as well. But Mike comes up because he's one of these people that introduced location data to the government in the first place, way back in around 2015. I won't spoil everything we talk about, but what I will say is that I really like speaking to Mike because, frankly, he's kind of a complicated character. He's kind of hard to pin down. He doesn't fall into a neat pigeonhole. On one side, he was one of these people describing the immense intelligence benefit of commercially sourced location data to the government and to special forces and that sort of thing. And then on the flip side, he's also trying to warn parts of the government about the threat that this data poses. So he's on both sides simultaneously. I imagine a lot of you may not agree with everything that Mike says, and you may sympathize with others, or some of you may take all of it on board as well. I think regardless of where you stand on this issue, this is a really, really interesting conversation about how we got to this point where you can just buy location data, right? Or rather the government is buying it, it is often using it without a warrant, or it has done that historically. We'll see how the recent Supreme Court ruling changes that. But with that, I'll let you enjoy the rest of the conversation. Mike, you have a long history with the government and location data. The location data industry and the advertising industry is a very, very interesting space. But I feel like only relatively recently did the government sort of clock on sort of the power here. And you played like a very, very important part in that transformation. How does this story start for you when it comes to location data and the government and that sort of thing? So this goes to recently, you know, 10 years ago, if we want to consider that recent. But that's where the story starts for me. And this was a project that's well documented, not classified, but originated in the special operations community. They were looking for alternative methods of being able to understand human geography in very remote places. And it just was sort of a perfect combination of resources and requirements to be able to provide this new sort of foundational understanding of how humans move, even when we're talking about environments or marketplaces like Yemen, Syria, where it's not a huge, vibrant advertising market, but everybody there carries a smartphone. and that location data was indeed collected by the ad tech ecosystem, not monetized, not used, usually wound up on the cutting room floor, but again, available. And I came in and started buying it en masse. So when you say you started buying this data, I mean, what exactly does that look like in practice? I know a lot of people like to say that, well, anybody with a credit card or a checkbook can buy location data. I don't think that's strictly true. It really depends upon the context, really, although it can be quite easy. What did it look like practically for you at that time? So typically, these data providers are approached by advertisers, audience attribution companies. They've got a very specific use case. They want to target advertising to a certain demographic or a certain cohort. You can buy it with a credit card depending upon what you're buying. But I was buying about $400,000 worth of data per month, which is not something that you're going to slap on a credit card. Well, yeah, not on your personal credit card. Not on my personal. And so the suppliers, once they understood that this was not a usual buyer of their data, that I wasn't really trying to place an ad on any particular set of devices, that this was a straight data purchase, you know, created this new sort of business model for them where we were moving bulk data from their cloud environment to my cloud environment. and then I would move it onward to other environments. But the companies were, it just was not something that they were used to. Somebody looking to buy bulk location data, ad IDs, and anything else that would be strung along with those observation events, metadata, user agent strings and things like that. We weren't trying to advertise to people, but we needed to understand who these audiences were in these frontier markets for the humanitarian applications that we were building. So yeah, it evolved. And once we got the economics down and the data flows down and understood, we had that system up and running very quickly. So give me some examples of what you were able to track in around that 2015 period. I think these examples have been reported publicly before, but there was like some Syria stuff and then Putin's entourage as well. Is that the sort of stuff we're talking about at this particular point in time? Yeah, so think about it this way. When we needed to prove the efficacy or the value of the data, it would be one thing to say we've got all this location data and we're selling to a group of people who think of location data as something acquired through intercepts or stingrays, these types of technical means. And so demonstrating a use case that was relevant that they would understand brought us to this Lafarge cement factory in Syria, which clustered or emerged in my analysis because devices that had originated at Fort Bragg, North Carolina, and at residences in Southern Pines, North Carolina, were at this cement, this abandoned cement factory in Syria. And so when I sort of walked them through that analysis and showed, you know, and this is a home in Southern Pines, North Carolina, and this is the location at Fort Bragg, you know, and obviously they knew what the Lafarce Cement Factory represented, but that I was tracking right down to the operator's residence, that became a watershed moment for location data. And that's where I had to explain after being accused of hacking and witchcraft and remote viewing and all this other stuff. They called me, the guy called me a charlatan were his words. Well, because he thought that you had gathered this data through an intercept or something else. Like he couldn't believe that this was commercially available. Correct. Correct. And that's understood, you know, but this is somebody who should know better, right? In my opinion. And so when I had to explain, you know, look, guys, I didn't hack Intercept Engineer or steal this data. I bought it and I bought it for a cost factor far below anything that you would have had to spend to collect the same amount of volume, you know, using using your technical methods and at zero risk because I did it sitting in the room you see me in right now. Right. So I don't have to put people downrange and at risk to go and do this. I don't have to fly drones or airborne platforms for hours while we're hoovering up mobile data. Now, there are different use cases. If you are actually trying to locate a specific device, i.e. locating the Bin Laden courier, if you've seen the movie Zero Dark Thirty, where they're driving around, they have a device in that vehicle that is looking to identify that specific device. That's a different use case. This is I can collect in a large area and start micro targeting based upon areas of interest. Who goes into these buildings What do these buildings represent What are the centers of gravity of the people that are spending time there And how does this create new targeting or intelligence opportunities for us that otherwise would have required a lot of investment? Yeah, I think that's a really good point to highlight because it kind of clarifies something of a misconception about commercial location data, which is that even if you go look at the IRS, for example, they bought location data or access to it from one of the brokers, Ventel, or one of those companies, Babel Street, whatever. And they were trying to use it, I reported, to identify specific individuals they were investigating, I think, for cryptocurrency tax reasons. And they were unsuccessful in that, because it actually is quite hard from this data to be like, well, I want to find this specific person, I have all this data, now I'm going to go look for it. It's more fruitful the other way around, where it's like, I have a location, like a cement factory, for instance, which is in Syria and has a very sensitive operation going on there, or an abortion clinic, or the border, which has also been done. And you reverse engineer from the location, then to the devices and ultimately the people. It's rarely the other way around, it seems. Yeah. And in that use case, particularly in the law enforcement use case, where they are using, they are trying to apply it to almost like a surveillance application, where we're going to watch this location and anybody that comes in and out, you really need to think about it from the perspective of, I am opening up, right? I need more devices, more volume in order to develop investigative pathways. You know, the Vegas shooting in 2017, You know, that was an example where we had an individual where we knew nothing about. He had two residences in Metro Vegas and trying to determine if there was any transnational terrorism links based upon his wife was Filipino. And was there any intersection between Steven Paddock and foreign actors? You know, that was we started with the homes, his two residences. We found a guy that cuts his grass, you know, eliminated him, a couple of UPS drivers, FedEx drivers. But, you know, this is not the kind of thing where you are going to zero in and monitor some ATM machines and try to piece together forensically a crime. It's not that it's not the use case for this kind of for this kind of application or for this kind of data. I mean, it's not exactly this, but it is much closer to a reverse location warrant from Google, for example, which was just ruled, if I'm remembering correctly, unconstitutional. And of course, that's going to be appealed as well. But like, that's when the authorities go to Google and they're like, we want all of the phones in this location at this time. Now, of course, the difference there is as a legal sort of court mandated mechanism. And here, you're obviously just buying the data. And that's, of course, the key difference. So those initial use cases where you were trying to prove the value of this data, that was to a part of the US government that was focused much more obviously on military and special operations and that sort of thing. Eventually, a few years later, you're trying to warn, I think, of other parts of the US government about what you call the grinder problem. First of all, what other parts of government? So people have an idea if you're talking to law enforcement or more military or whatever, and then what is the grinder problem? So the users or the agencies that we were talking to, primarily sort of large-scale, large population-level intelligence applications where we're trying to understand better population movements as opposed to a direct targeting application. So, you know, think about an intelligence analyst who's trying to understand a building that we have interest in, but we don't know anything else about. This is kind of a way to sort of step away and observe that building without having to physically be there. The original, you know, design of this was for outside of the United States, focusing on the global war on terror at the time, ISIS at the time, and supporting those high-value targeting missions based upon the asymmetry of ISIS, where they would just sort of blend into the crowd and trying to figure out who's who was the challenge. Well, yeah, and they were everywhere, especially across Europe, obviously, as well, and obviously the Middle East and Syria as well, But Europe, especially, it was a very scary time when in London and Paris and, you know, we were having a lot of attacks at that time. So there was, we were successful in working with partners to say, look, you have this, you know, cultural service center and people who go there then go to a, you know, another location in Europe. And the next time we see them, they're, you know, they're on the front lines. It's not probative of terrorism, but it's a clue, right? You should look into this. Yeah, if a guy goes from Europe to the Turkish border, then crosses the Turkish border via foot into Syria or something, that is interesting, probably. Yep, yep, absolutely. Once we sort of got into this, there's this perception that sort of the government just goes wild on this stuff and everybody's just, it's a free-for-all. There were, even before privacy and data rights was sort of a household term, there was a lot of oversight in what we could do, what we couldn't do, what constituted a U.S. person, which went well beyond their resident status or citizenship. citizenship. If they dwelled in the United States for a week, it was considered a US device. So a lot of oversight, a very, very top level, especially as we talk about all this AI and targeting events now, there was the most senior person at JSOC who saw my demo, saw my brief, saw the opportunity, and then made it very clear to everybody that we're not targeting anybody with this data. These are clues. This is for investigative purposes, analysis purpose. This is not a targeting. We are not going to launch kinetic action based upon these data sets. And so there was a lot of oversight and controls well before it became the topic that it is today. And so as this sort of moved on and the community began to understand and apply these things, I got a question from one of my users about Grindr. We're seeing a lot of data in one of our data sets that was originating from the application, the dating app, Grindr. And it was just more of a curiosity question. And there was logic to why we see a lot of Grindr because they are selling inventory really to anybody. It was like if they had inventory, they would sell it. So we were seeing a lot of these events in the United States originating through Grindr. And so I just, I wasn't familiar with the app. I just started looking into it a little bit and discovered that it's a dating app that is also had just been acquired by a private equity firm with ties to the CCP. And it's a dating app that doesn't really have the type of audience in China that it does in the United States. And so it just was odd to me that they would want to be involved with Grindr. And so I just started looking into the data that they had access to. It's very similar to the TikTok problems because TikTok, you know, they have access to all of the telemetry on a device. This went well beyond location data and a user and an ad ID. They owned that server-to-server data set from their users. And it just struck me as being odd. And sure enough, you would have Grindr users who clearly would work at a national security building Monday through Friday. So I had high confidence that these were people that worked in national security. And then you'd see them go into outbuildings that were also attributable to the U.S. government. So my confidence level increases that these are government people, users. And then I could see, I could visualize the date, right? Which would last for about 22 minutes and would be on the side of the road at a road stop. I mean, it was just at a McDonald's, all sorts of places. Right. And by date, obviously, you don't mean the literal time and date, although that is there as well, obviously. But you mean, obviously, this data implies that this person who works in a national security context is meeting probably for a sexual encounter at a rest stop, whatever. And the concern here is that, well, it's almost worse than the Chinese one in a way because the Chinese first party argument is that, well, they could access data from TikTok if they have ownership structure over that. They could access data from Grindr if they have ownership structure over that. That's the concern. this is almost worse because you're clearly not the Chinese government. You have also got access basically to this data as well. And that is a grind. Yeah, I would say, look, if I can do it, we have to believe that a sophisticated adversary is doing it as well. if you listen to our show for more than a week you know our beat is uncovering how your data is quietly harvested and exposed online and if you're like us working remotely constantly on the move and running your entire life off your laptop and phone well you leaving a massive digital footprint Every time you jump between networks check emails on the go or browse from a new location your device is broadcasting your activity Advertisers can track your activity leading to targeted ads, price discrimination, and a sense of being monitored. It's the kind of systemic tracking we'd normally write a story about. That's why we recommend Surfshark. At its core, Surfshark VPN keeps your online activity private by hiding your IP address. It encrypts your connection, making your online activity much harder to track. So your research, your sources, and your personal data stay private no matter where you're working from. But Surfshark does far more than that. Surfshark blocks ads and trackers, which cuts down on price discrimination games that sites play based on what they know about you. It also includes Alert, which monitors your ID for data leaks and an email scam checker that protects against phishing attacks. And if you game, it helps defend against DDoS attacks and ISP throttling. Since you're always on the move, the best part is that one subscription secures unlimited devices so your entire household is covered. Go to surfshark.com slash 404media to get four extra months of Surfshark VPN with the reassurance of a 30-day money-back guarantee or just use code 404media at checkout. That's surfshark.com slash 404media. I've started thinking about clothes a little differently this year. Instead of asking how much does it cost, I asked how many times am I actually going to wear this? because the shirt you wear twice isn't a bargain if it sits in your closet the rest of the year. That's why I've been buying more from Quince. Quince makes the kind of pieces that earn their keep. They're 100% European linen shirts and pants have been my go-to this summer. And when it's really hot, I wear 100% European linen shorts as well. They're lightweight, breathable, and look polished enough that I can wear them pretty much anywhere. To the beach, to dinner, to happy hour, to drinks, to walking around with my dog. And they start at just $34. Their tees are another surprise. They feel incredibly soft, fit really well, and they become the shirts I reach for on regular weekdays, not just special occasions, although I wear them on the weekend as well. The reason Quinz can sell everything for 50% to 80% less than similar brands is because they work directly with ethical factories and cut out the middlemen. You're getting premium materials without paying for a premium logo. And Quinz goes way beyond clothing. They've got bedding, bath towels, cookware, furniture, and all kinds of home essentials. So it's become one of those sites I keep coming back to. I have Quince towels. I have Quince sheets. I have a Quince duvet cover. I have a Quince rug. I have a Quince shirt, Quince shoes, Quince pants. So I can pretty much live my entire life at this point just using Quince items, which is pretty crazy since I just learned about them within this last year. Make your summer wardrobe easier. Go to quince.com slash 404media for free shipping on your order and 365 day returns. now available in Canada too. That's quince.com slash 404media for free shipping and 365 day returns. quince.com slash 404media. I had some very uncomfortable conversations on the seventh floor of various government buildings with trying to explain to 50 plus year old white guys what grinder is and it's not just a dating app once you told them what the app was did they click that oh this is potentially a national security risk not because obviously homosexual people oppose a risk or anything like that but they realized that maybe this could be leveraged by an adversary in a bad way like did they realize that yeah that was my example was guys this is not okay cuban these are not you know this is not seeking romance and love and life partners this is something different. At least in this context. Yeah. In this context. Yeah. Trying to, again, I'm telling you how I explained it to these guys that, you know, this is a different kind of dating app. And because it is a different kind of dating app, and because it is now owned by a company with ties to the CCP, we need to start, we need to understand that this is a different risk. There is a reason why they, of all of the dating apps that they could have purchased, they chose to purchase Grindr. So I raised the flag of the issue, took me some time to get some audiences to understand and to focus on the issue. And once we sort of crossed that chasm of, okay, this is different, this was referred to CFIUS. And CFIUS took action, the Committee on Foreign Investment for the U.S., and they are the ones that sort of review and arbitrate acquisitions of companies that are sensitive to the United States national security. This was probably their first examination of a dating app and their first action to force the repatriation of Grindr back to US ownership. We see that happening a lot now with real estate and other factories, etc. And so the grinder problem, in my opinion, is still the current problem that we have today. Two million apps. Most people have 70 plus apps on their phone. And when you install an app, you are giving that app privileged access to inspect and extract a variety of telemetry from your device that is far more probative about who you are and what your intent and context are than an ad ID and a GPS signal ever provided. And then, you know, you add in this new AI capability where you can drop in to a GPT a year's worth of telemetry. And when I say telemetry, I'm talking like the accelerometer, battery level, screen orientation, things that are not personally identifiable. And because they're not PII, the app does not require your consent. So you don't even know this is happening and there's nothing on your phone that can throttle that, throttle that extraction. And so when we think about sort of a threat surface of 2 million apps that some are owned by adversaries, people that work there, moving data from an app to an adversarial environment is not a hard thing to do. And, you know, privacy and privacy toggles and VPNs at this level, when an app is inspecting your device, there's nothing in the OS that prevents it from pulling that data and sending it to their server. Yeah, the one question I get obviously a ton when I report on location data is how do I as a reader or a listener, how do I specifically stop this tracking? And I'm a iOS user, so I can only really talk from that perspective. But my understanding is that when you do, I mean, I don't have location services on the vast, vast majority of the time at an OS level. And that would be the main thing. Of course, you then grant it on a per app basis. What you're saying is that there is other data that can be collected by these apps that doesn't fall under that sort of location permission. I mean, just briefly, how do you, if you take steps to do so, how do you sort of protect your own device privacy when it comes to sort of this data being collected by third party apps installed on the phone? Yep. So this is about the trade-off. So there are some apps where I make that trade-off and I take that risk. When I open up Uber, I don't want to have to drop a pin because I probably have 2% left in my battery. I want it to work. I want it to know where I am so it can come pick me up in the rain. Right. I do the opposite. It's a pain in the ass. I type it in every single time. Okay. So there you go. But it's a real pain. So I understand why you would. Yeah. Yeah. But the new developments in mobile security or privacy shifting away from these perimeter tools, VPNs and toggles into this notion of being able to inspect what an app is trying to extract from your phone and deprecating what is not essential for that app's functionality. So if it's trying to pull a bunch of telemetry fields that have nothing to do with app functionality, being able to, and this is, I get this question a lot too, from the operational community? How do I get out of commercial data? How do I do this? And the surface that we have to focus on first are the apps and minimizing the amount of telemetry that they're able to extract from your device. And that's going to require a rethink about the operating system and the hardware. And I will tell your listeners because they'll figure this out that I'm on the board of advisors of a company called Unplugged. And the approach to this problem is being able to give the user control over what data leaves their device based upon what that app is. And when you start looking, you are able to see what an app is pulling and when it's pulling and how it's resolving location when it doesn't have access to GPS. Again, it makes me think that when Apple launched privacy and we had the adpocalypse in 2022 and Metastock tanked, the recovery based upon the telemetry and going deeper into the device and not just hanging their hat on stable identifiers like the ad ID and GPS, their ability to attribute behavior, to resolve intent is far more detailed than it ever was. So it's almost like privacy gave the apps a gift. They had to figure out how do we replace the ad ID. Look at Meta. Meta stock is trading at 600 bucks now. Their business recovered without reliance on the ad ID And if you look at what Meta is doing and any other app where they are resolving your location let's just focus on location. They're using everything from time zone to the ambient signals around you. Time zone changes to understand exactly where you are. And when you drop your telemetry for a week into JetGPT or Claude and say, tell me about this telemetry, it builds a profile and a pattern of life that at scale should concern every American, whether you're a case officer, special agent, special operator. I don't care. This is the next level of privacy. We've been sort of hand-waving privacy for years. And a VPN that mediates transport and privacy toggles are mostly just user preference. It's not an operating system gate. It's a user preference. Don't access my GPS. Most apps comply, but that's all it is. It's just indicating your preference. We need more engineered solutions that really attack this problem and give users control over their data once and for all. Yeah, yeah, that makes sense. So you started warning the government about this and showing them this problem. And then in parallel, but obviously also related, you did have more and more agencies buying technology like this. Obviously, you mentioned your cases, and I covered a bunch of Customs and Border Protection, Immigration and Customs Enforcement, Secret Service as well. There was a lot of debate and argument around that because, of course, they were doing this without a warrant under the Fourth Amendment. That may now be in flux with this recent Supreme Court ruling. We haven't really seen the fallout from that yet. Frankly, it's going to take years probably to see that. But there was a lot of movement there. And then recently, there was some other news, which is that the Pentagon came out and it said that, yes, U.S. military personnel are being targeted using location data. This isn't quite related, but the Financial Times, I think, reported that commercial location data and SS7 stuff, which is the rooting backbone, right, was also used to monitor the location of senior U.S. officials during the Iran war. So there's all that sort of stuff. But back on the commercial data being used to target U.S. military personnel, what was your reaction to seeing that news? Oh, the Pentagon found out or the Pentagon said it. Yeah, Senator Rodden Wyden from Oregon has been sort of in the lead on this for a long time. They brought this up. And so Senator Wyden, who's not even on armed services, wrote a letter to the CIO at the Department of Defense demanding an accounting. And in that letter, you could almost sense the tone, the exasperated tone. In 2016, a contractor blew the whistle on this. And what have we done in the last 10 years? And that's my reaction. I've kind of gotten a little desensitized by like, how many times do I have to say, yeah, I told you, we've been talking about this, we've known about this. How many different ways do I have to explain it until we get sort of national level policies to deal with this and deal with it in a way that's not hand-waving and creating more training and white papers and PowerPoint presentations describing ways that you can try to outthink and trick the ubiquitous technical surveillance or the platforms, but we need engineered solutions. And so we have some congressmen and women that sort of heard us out on this and have developed amendments to the NDAA. We came in late, the National Defense Authorization Act for 2027, in which instructs the Pentagon to explore and assess technologies that attack this commercial data problem from its origins at the app layer to examine methods and approaches to minimize this data, leaving a device and networking into this opaque cartel of data brokers and And attribution companies that end up in the hands of adversaries, which, again, is not hard to do at all. And more of this legislation is just sort of trying to put the data back in the phone after it's left the phone. And we need to begin looking at how do we keep the data from leaving the phone in the first place? Because that's the problem. And that's been the problem. And that's, we need to start thinking about, okay, how do we solve this? Because we're not going to out-tradecraft an $8 trillion duopoly of Apple and Google and 2 million apps, all of which have, you know, fraud detection algorithms that the minute you are doing something funky and weird, it deplatforms you or, you know, it outs you, it flags you as unique and anomalous. So we need to think about how do people that are in sensitive positions carry a phone into a war zone? Because a lot of our personnel have children. And if they're deployed for six months, they need to be able to reach back and do homework and do all of those kinds of things. So sending them out onto a deployment without a phone is not practical. They'll quit. I would quit. So how do we do this so that we are not giving an adversary an advantage for free? Yeah. And I mean, you touched on it there with Apple and Google. And the question is, which entity or player is the one with the most power here to make the biggest change to this problem? Now, I'm sure the company that you're on the board on would love to say it was them and And then other providers would probably love that as well. You mentioned Apple and Google. Obviously, they are running the primary operating systems on this. You obviously then have the app developers as well, but they're probably going to do whatever the fuck they want. Which entity here is the one with the most power that can do the most change? Is it like ultimately Apple and Google who should do this? My answer to that question is the consumer. The consumer needs to decide. This is not proportionally. The amount of data that is being collected about me is not proportionate to a typical advertiser-consumer relationship. This is beyond that assumed relationship that has fences and gates. They are going far deeper into my existence. So consumer needs to understand what they're up against. Google and Apple, they kind of depend upon their app ecosystem for a significant amount of revenue. So regulating them is difficult. And replacing them with Google or Apple apps triggers antitrust. So they're in kind of a bind. And Google is indeed an advertising business, especially because many people use Google apps. And so the answer to your question really is, it's the apps. If I were to be counseling somebody today who wasn't going to go into the market to buy a phone that was engineered for privacy, I would say, have an understanding of the apps that you're installing on your phone. just go to the app store and try to figure out, look and see where that app is manufactured. But again, you know, they can have employees there that are, you know, siphoning out data. But it really gets down to what apps do you need and controlling your appetite for convenience. Because convenience and lack of friction is how we got here in the first place and how surveillance sort of builds and layers upon itself. And if you are really concerned about sort of surveillance where you have no reason to be surveilled, you've got to take a look at your own sort of tech profile and minimize that footprint as best you can. But this is to really solve the problem, Joe. This is engineering. This is not having your name moved from data broker lists. Like, that's good. That's fine. Do it if it makes you feel better. But at the end of the day, we need to take back the flow of data and resolve it back to something that is more proportionate to what we get from these apps and these experiences. Yeah. Well, I think that's a really, really good way to pull it and a great place to leave it. Mike, thank you so much for joining us. I really, really enjoyed this conversation. Thank you so much. Thanks for having me. I appreciate it. As a reminder, 404 Media is journalist founded and supported by subscribers. If you do wish to subscribe to 404 Media and directly support our work, please go to 404media.co. You'll get unlimited access to our articles and an ad-free version of this podcast. You'll also get to listen to the subscribers only section where we talk about a bonus story each week. This podcast is produced by Alyssa Midcalf. another way to support us is by leaving a five-star rating and review for the podcast that stuff really really does help us out this has been for a full media we'll see you again next time