3 Comments

Great article. I have a question though. The data that was used to track users at the capitol appears to primarily be from the Parler hack initiated by "Donk", where he grabbed posts of users, and farmed the EXIF data from their posts. But, I also heard but cannot confirm, that this occurred at the same time Maetz (?) the CEO at the time turned over the data to the FBI. So not sure on if that was a government request, or Donk was the one that published the data, and that is how we ended up with the activity (in one form) of Parler users at the capitol. So I guess I am wondering how much of the anonymous tracking animations we see of the Capitol insurrection are from government inquires or the Donk hack?

I work as a security guy at a manufacturing firm (I use that term loosely) and since we are global we both NA and EU privacy policies to contend with. The EU policies are arguably tougher, and it is easier for people to opt out, also, EU users can anonymize their user ID. Since I am that guy that can see every mouse click, web url visited, email (if legally asked to do so) etc. etc. having an anonymized ID is nice perk for the end user . . . but, as an administrator if HR gets involved, we can always tie that ID to the actual user ID. I guess my point being, I think the corporate entities you are discussing are more in the retail and social media arena? Here in the glamorous manufacturing sector we are striving to take user privacy pretty seriously, albeit it is driven by legal developments and requirements.

Expand full comment

Thanks, Mason! Our understanding was that the NYT data came from a different broker with more "active" geolocation data pulled from more apps than just the Parler EXIF data (which is a brilliant OSINT move in its own right). We likely wouldn't see as many datapoints just relying on EXIF data alone, which suggests this was a massive dataset that pulled from multiple pooled sources.

Retail is definitely a major industry for location-based data, as location-based marketing seems to thrive in the form of targeted advertising. I don't have many insights on the manufacturing industry's use of geolocation data except for maybe IoT-style process monitoring or tracking, etc.

Expand full comment

IIoT (Industrial Internet of Everything) would tie into the geolocation stuff, but for us, I would think it is primarily supply chain, i.e. finished goods, but something I fret over to some degree.

Thanks for the insight, makes this data-set for the events on Jan 6th all the more intriguing.

Expand full comment