Investigation | Using easily accessible advertising data, Le Monde was able to pinpoint the identities, home addresses and daily routines of several dozen people working for sensitive official entities.

The identities of French spies are among the Republic’s most closely-guarded secrets. Revealing them is even a criminal offense. Yet, with just a little technical know-how, one can track down the home addresses of certain agents, and thereby discover their identities, daily routines and even those of their loved ones, all of which represent risks to their safety and that of their families and their agencies.

The blame lies with the advertising industry, an insatiable and unregulated sector with no regard for transparency, which extracts billions of personal data points from people’s smartphones every day. This data, which can be used to track people’s movements particularly precisely, down to a few meters, is then resold. Evading such tracking, except for users with flawless digital hygiene, is nearly impossible.

Staff members working for all of France’s most sensitive institutions are affected: intelligence officers, personnel responsible for protecting the country’s top officials, high-ranking police officers, members of the elite National Gendarmerie Intervention Group (GIGN) unit, military personnel stationed at critical nuclear weapons bases, defense company executives, prison staff, and even nuclear power plant staff.

      • General_Effort@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        6 hours ago

        It’s a myth that the GDPR is a useful tool in such cases. You know the expression “protected by copyright”? That’s how lawyers protect data.

        The GDPR grants people rights over data concerning them, similar to how copyright grants rights over data. That means 2 things.

        1. It’s rarely obvious that some data processing is illegal. It’s not obvious if it happens without consent. But even so, you often don’t need explicit consent to use someone’s data. EG when we write about French president Macron, then that is Macron’s data under the GDPR. Of course, you don’t need his consent to discuss or report on politics, and so you usually don’t need his consent to discuss his person.

        2. Enforcement is difficult and expensive. Think about the problems the copyright industry has. Surveillance tools like Content ID can at least rely on knowing what exactly they are looking for. Besides, much of the world has similar laws supported by influential industries. Little chance to do that for GDPR.

        Basically, using GDPR to protect actual secrets is like using copyright for the purpose.

  • ILoveUnions@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    4
    ·
    edit-2
    1 day ago

    The fact that the french don’t even have basic countermeasures to prevent this is as hilarious as it is depressing . It wouldn’t even be hard.

    • verdi@feddit.org
      link
      fedilink
      English
      arrow-up
      21
      ·
      1 day ago

      The US secret service agents were being tracked with Strava… Everyone is getting fucked by the unregulated collection and use of personal data. Shit, some idiots even voluntarily give it away.

      • partofthevoice@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        22 hours ago

        Some idiots voluntarily give it away? Brother… we as a society moved the public common areas for discourse, entertainment, finance, and research onto a digital landscape. That landscape, in particular, is set up like as though every Roman in the fora had an invisible personal Sherlock Holmes set up to automatically dissect their footprints, fingerprints, the direction and timeliness of their stair, … and then to record it in a virtually limitless ledger where it can later be aggregated and analyzed for behavioral patterns. We aren’t giving it away anymore than the Roman commoners would have been by merely walking around town. This is a very aggressive data harvesting situation.

    • Goodlucksil@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      24
      arrow-down
      3
      ·
      edit-2
      1 day ago

      GrapheneOS, one of the few countermeasures they could have, recently was banned left to avoid being broken in France.

      Edit: Rewording