A travel app is stirring concerns among the military community due to purported invasions of privacy and security concerns.
Polarsteps, located in The Netherlands, is facing questions after an investigation found that numerous military personnel from the United States, United Kingdom, the Netherlands and other nations could be tracked down and have their personal information compromised through the app. The app was started in 2015 and today has more than 22 million users.
FTM, which stands for “Follow the Money,” is a Dutch platform for independent investigative journalism. They spent months investigating Polarsteps and found loopholes that allowed user identities, locations, pictures, and friends and family connections that could saved and potentially misused by a third party.”
“Even when they didn’t use their real names, FTM was able to identify them using data from the app and track them to military bases and missions—and back home,” the FTM investigation found. “With some military personnel sharing their GPS location for months on end, FTM was able to identify other locations they frequently visited: for example, a service member with children who regularly stops at a primary school in his village.”
Military.com reached out to Polarsteps for reaction to the FTM Investigation, asking about the company’s security protocols that could potentially leave service members and others at risk.
“Follow the Money recently published an investigation into Polarsteps. Despite their claim that this is a data leak, we would like to emphasize that this is incorrect,” a Polarsteps spokesperson told Military.com. “FTM only had access to public trip data and to the best of our knowledge, there has been no data breach.
“We care deeply about user privacy, and privacy is a key part of our app’s design. All user trips and profiles are set to ‘private/followers only’ by default, never public.”
How Popular is Polarsteps?
Many of Polarsteps’ 22-plus million users and counting are abroad.
The app lets users plan their travels, add where they stayed, and add photos and videos. Experts describe it as “Vacation Instagram.”
On the backend, Polarsteps connects devices like phones and laptops to an Application Programming Interface, or API. It’s a gateway to the Polarsteps server where content that the app retrieves and displays to the user is stored.
By analyzing data posted on Polarsteps, FTM tracked more than 30 military personnel from the United States, the United Kingdom, France, and Belgium, and was able to trace their likely home address in many cases.
FTM was also able to download sensitive information, including names, places of residence, details of the people they follow, as well as pictures and GPS data.
Broad Tracking Concerns, Mitigation
Experts warn this level of compromised security poses severe risks, including stalking, identity theft and potential blackmail.
“I found it quite surprising that the company would allow all that data to be easily accessible to anyone who simply downloads their API,” Sam Allen, CEO of Iterable, a San Francisco-based customer engagement platform, told Military.com. “To me, this story exemplifies the importance of reviewing terms and conditions for any app you download.
“Consumers should also regularly audit the tracking settings on their mobile devices. Personally, I allow very little tracking.”
On its website, Polarsteps also addressed the FTM investigation.
For its part, FTM said after it presented its findings with Polarsteps, the company implemented a series of measures—including how users now have to approve new followers unless they opt out in their phone settings.
Allen told Military.com that user security starts with the way an app is designed. For Iterable, user information is unavailable for export.
“The good news about our platform is that everything that we do is inside the customer data environment,” Allen said. “So, we don’t export the data. We don’t sell the data. It’s all at the behest of that brand that we work with.
“You agree with their terms of service and if you get a text message, and if you want to opt out of that text message, you can. We honor all of that.”
Read the full article here
