
Loading summary
Mike Yeagley
This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block. Or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it, ready to make anything online make sense. There's no place like Chrome. Check responses set up, required compatibility and availability. Veris18 and so I just started looking into the data that they had access to, which just was odd to me. Of all of the dating apps that they could have purchased, they chose to purchase Grindr.
Host (Possibly Joe)
Hello and welcome to the 404 Media podcast where we bring you unparalleled access to hidden rules, both online and IRL. 404 Media is a journalist found the company and news your support. To subscribe, go to 404 Media Co as well as bonus content every single week. Subscribers also get access to additional episodes where we respond to their best comments and they get early access to our interview series too. Gain access to that content@404 media co. Also do remember to subscribe to our YouTube channel where you can watch all of our episodes, including this one. Subscribe@YouTube.com 404Media Co this week I'm speaking to Mike Yeagley. He is someone that you may have come across if you follow the worlds of privacy and location data, especially the stuff I cover, the stuff that Byron Tao covers as well, who was sort of the leading journalist on location data, and I followed in his wake and did a bunch of stories. I spoke to Byron many, many episodes ago. You can go find that as well. But Mike comes up because he's one of these people that introduced location data to the government in the first place way back in around 2015. I won't spoil everything we talk about, but what I will say is that I really like speaking to Mike because frankly, he's kind of a complicated character. He's kind of hard to pin down. He doesn't fall into a neat pigeonhole. On one side, he was one of these people describing the immense intelligence benefit of commercially sourced location data to the government and to special forces and that sort of thing. And on the flip side, he's also trying to warn parts of the government about the threat that this data poses. So he's on both sides simultaneously. I imagine a lot of you may not agree with everything that Mike says, and you may sympathise with others, or some of you may take take all of it on board as well. I think regardless of where you stand on this issue, this is a really, really interesting conversation about how we got to this point where you can just buy location data, right? Or rather the government is buying it. It is often using it without a warrant, or it has done that historically. We'll see how the recent Supreme Court ruling changes that. But with that, I'll let you enjoy the rest of the conversation. Mike, you have a long history with the government and location data. The location data industry and the advertising industry is a very, very interesting space, but I feel like only relatively recently did the government sort of clock on to sort of the power here, and you played like a very, very important part in that transformation. How does this story start for you when it comes to location data and the government and that sort of thing?
Mike Yeagley
So this goes to recently, you know, 10 years ago, if we want to consider that recent. But. But that's where the story starts for me. And this was a project that's well documented, not classified, but originated at. In the special operations community. They were looking for alternative methods of being able to understand human geography in very remote places. And it just was sort of a perfect combination of resources and requirements to be able to provide this new sort of foundational understanding of how humans move. Even when we're talking about environments or marketplaces like Yemen, Syria, where it's not a huge, vibrant advertising market, but everybody there carries a smartphone. And that location data was indeed collected by the ad tech ecosystem, not monetized, not used, usually wound up on the cutting room floor, but again, available. And I came in and started buying it in mass.
Host (Possibly Joe)
So when you say you started buying this data, I mean, what exactly does that look like in practice? I know a lot of people like to say that, well, anybody with a credit card or a checkbook can buy location data. I don't think that's strictly true. It really depends upon the context, really. Although it can be quite easy. What did it look like practically for you at that time?
Mike Yeagley
So typically, these data providers are approached by advertisers, audience attribution companies. They've got a very specific use case. They want to target advertising to a certain demographic or a certain cohort. You can buy it with a credit card, depending upon what you're buying. But I was buying about $400,000 worth of data per month, which is not something that you're going to slap on a credit card. But.
Host (Possibly Joe)
Well, yeah, not on your. Not on your personal credit card.
Mike Yeagley
Not on my personal credit. And so the, the suppliers, once they Understood that this was not a usual buyer of their data, that I wasn't really trying to place an ad on any particular set of devices, that this was a straight data purchase, you know, that created this new sort of business model for them where we were moving bulk data from their cloud environment to my cloud environment, and then I would move it, move it onward to other environments. But the companies were. It just was not. Not something that they were used to. Somebody looking to buy bulk location data, AD IDs, and anything else that would be strung along with those observation events, metadata, user agent strings, and things like that. We weren't trying to advertise to people, but we needed to understand who these audiences were in these frontier markets for the humanitarian applications that we were building. So, yeah, it evolved. And once we got the economics down and the data flows down and understood, we had that system up and running very quickly.
Host (Possibly Joe)
So give me some examples of what you were able to track in around that 2015 period. I think these examples have been reported publicly before, but there was some serious stuff. And then Putin's entourage as well. Is that the sort of stuff we're talking about at this particular point in time?
Mike Yeagley
Yeah. So think about it this way. When we needed to prove the efficacy or the value of the data, it would be one thing to say we've got all this location data and we're selling to a group of people who think of location data as something acquired through intercepts or stingrays, you know, these types of technical means. And so demonstrating a use case that was relevant that they would understand, brought us to this Lafarge cement factory in Syria, which clustered or emerged in my analysis, because devices that had originated at Fort Bragg, North Carolina, and at residences in Southern Pines, North Carolina, were at this cement. This abandoned cement factory in Syria. And so when I sort of walked them through that analysis and showed, you know, and this is a home in Southern Pines, North Carolina, and. And this is the location at Fort Bragg, you know, and obviously they knew what. What the Lafar cement factory represented, but that I was tracking right down to the operator's residence. That became a watershed moment for location data. And that's where I had to explain, after being accused of hacking and witchcraft and remote viewing and all this other stuff, they called me. The guy called me a charlatan. Were his. His words.
Host (Possibly Joe)
Well, because he thought that you had gathered this data through an intercept or something else. Like he couldn't believe that this was commercially available.
Mike Yeagley
Correct, correct. That. That's. And that's understood, you know, but this is a somebody who should know better. Right. In my opinion. And so when I had to explain, you know, look guys, I didn't hack, intercept, engineer or steal this data, I bought it. And I bought it for a cost factor far below anything that you would have had to spend to collect the same amount of volume, you know, using, using your technical methods and at zero risk because I did it sitting in the room you see me in right now.
Sponsor/Advertisement Voice
Right.
Mike Yeagley
So I don't have to put people downrange and at risk to go and do this. I don't have to fly drones or airborne platforms for hours while we're, you know, hoovering up mobile data. Now there's, there are different use cases if you are actually trying to locate a specific device, I. E. Locating the bin Laden courier. If you've seen the movie Zero Dark Thirty where they're driving around, they have a device in that vehicle that is looking to identify that specific device. That's a different use case. This is, I can collect in a large area and start micro targeting based upon areas of interest. Who goes into these buildings? What, you know, what do these buildings represent? What are the centers of gravity of the people that are spending time there? And how does this, how does this create new targeting or intelligence opportunities for us that otherwise would have required a lot of investment?
Host (Possibly Joe)
Yeah, I think that's a really good point to highlight because it kind of clarifies something of a misconception about commercial location data, which is that even if you go look at the IRS for example, they bought location data or access to it from one of the brokers, Vent out or one of those companies, Babel street, whatever, and they were trying to use it. I reported to identify specific individuals they were investigating, I think for cryptocurrency tax reasons. And they were unsuccessful in that because it actually is quite hard from this data to be like, well I want to find this specific person, I have all this data now I'm going to go look for it. It's more fruitful the other way round where it's like I have a location like a cement factory for instance, which is in Syria and has a very sensitive operation going on there, or an abortion clin or the border, which has also been done and you reverse engineer from the location then to the devices and ultimately the people. It's rarely the other way around it seems.
Mike Yeagley
Yeah. And in that use case, particularly in the law enforcement use case where they are using, they are trying to apply it to almost like a surveillance application where we're going to watch this location and anybody that comes in and out, you really need to think about it from the perspective of I am opening up, right? I need more devices, more volume in order to develop investigative pathways. The Vegas shooting in 2017, that was an example where we had an individual where we knew nothing about. He had two residences in metro Vegas and trying to determine if there was any transnational terrorism links based upon his wife was Filipino and was there any intersection between Stephen Paddock and foreign actors? You know, that was. We started with the homes, his two residences. We found the guy that cuts his grass, you know, eliminated him, couple UPS drivers, FedEx drivers. But you know, this is not the kind of thing where you are going to zero in and monitor some ATM machines and try to piece together forensically a crime. It's not that. It's not the use case for this kind of, for this kind of application or for this kind of data.
Host (Possibly Joe)
I mean, it's not exactly this, but it is much closer to a reverse location warrant from Google, for example, which was just ruled, if I'm remembering correctly, unconstitutional. And of course that's going to be appealed as well. But like, that's when the authorities go to Google and they're like, want all of the phones in this location at this time. Now, of course the difference there is as a legal sort of court mandated mechanism, and here you're obviously just buying the data and that's of course the key difference. So those initial use cases where you were trying to prove the value of this data, that was to a part of the US Government that was focused much more obviously on military and special operations and that sort of thing. Eventually, a few years later, you were trying to warn, I think, of other parts of the US Government about what you call the grinder problem. First of all, what other parts of government? So people have an idea if you're talking to law enforcement or more military or whatever, and then what is the grinder problem?
Mike Yeagley
So the users or the agencies that we were talking to primarily sort of large scale, large population level intelligence applications where, you know, we're, we're trying to understand better population movements as opposed to a direct targeting application. So, you know, think about an intelligence analyst who's trying to understand a building that we have interest in, but we don't know anything else about. This is kind of a way to sort of step away and, and observe that building without having to physically be there. The original, you know, design of this was for outside of the United States, focusing on the, the global war on terror at the time ISIS at the time and supporting those high value targeting missions based upon the asymmetry of ISIS where, you know, we didn't. They would just sort of blend into the, into the crowd and trying to figure out who's. Who was. Was the challenge.
Host (Possibly Joe)
Well, yeah, and they were everywhere, especially across Europe obviously as well. And obviously the Middle east and Syria as well. But Europe especially, it was a very scary time when in London and Paris and you know, we were having a lot of attacks at that time.
Sponsor/Advertisement Voice
Yeah.
Mike Yeagley
So there was, we were, we were successful in working with partners to say, look, you have this, you know, cultural service center and people who go there then go to a, you know, another location in Europe and the next time we see them, they're, you know, they are on the front lines. It's not probative of terrorism, but it's a clue. Right. You should, you should look into this.
Host (Possibly Joe)
Yeah. If a guy goes from Europe to the Turkish border, then crosses the Turkish border, Firefox into Syria or something. That is interesting, probably.
Mike Yeagley
Yep, yep, absolutely. Once we sort of got into this, there's this perception that sort of the government just goes wild on this stuff and everybody's just, it's a free for all. There were, even before privacy and data rights was sort of a household term, there was a lot of oversight in what we could do, what we couldn't do. What constituted a. A US Person, which went well beyond their resident status or citizenship. If they dwelled in the United States for a week, it was considered a US Device. So a lot of oversight, a very, very top level, especially as we talk about all this AI and targeting events. Now there was the most senior person at JSOC who saw my demo, saw my brief, saw the opportunity, and then made it very clear to everybody that we're not targeting anybody with this data. These are clues. This is for investigative purposes, analysis purpose. This is not a targeting. We are not going to launch kinetic action based upon these data sets. And so there was a lot of oversight and controls well before it became the topic that it is today. And so as this sort of moved on and the community began to understand and apply these things, I got a question from one of my users about Grindr. We were seeing a lot of data in one of our data sets that was originating from the application, the dating app Grindr. And it was just more of a curiosity question. And there was logic to why we see a lot of Grindr. Because, you know, they are selling inventory really to anybody. It was like if they had inventory, they Would they would sell it. So we were seeing a lot of these events in the United States originating through Grindr. And so I just, I wasn't familiar with the app. I just started looking into it a little bit and, and discovered that it's a dating app that is also had just been acquired by a private equity firm with ties to the ccp. And it's a dating app that doesn't really have the type of audience in China that it doesn't in. In. In the United States. And so it just was odd to me that they would want to be involved with Grindr. And so I just started looking into the data that they had access to. It's. It's very similar to the TikTok problem because TikTok, you know, they have access to all of the telemetry on a device. This went well beyond location data and user and an AD id. They owned that server to server data set from their users. And it just was just struck me as being odd. And sure enough, you would have Grindr users who clearly would work at a national security building Monday through Friday. So I had high confidence that these were people that worked in national security. And then you'd see them go into outbuildings that were also attributable to the US Government. So my confidence level increases that these are government people users. And then I could, I could see, I could visualize the date, right. Which would last for about 22 minutes and would be, you know, on the side of the road at a road stop. I mean, it was just at a McDonald's, all sorts of places.
Host (Possibly Joe)
Right. And by date, obviously you don't mean the literal time and date, although that is there as well, obviously. But you mean, obviously this data implies that this person who works in a national security context is meeting probably for a sexual encounter at a rest stop, whatever. And the concern here is that, well, it's almost worse than the Chinese one in a way, because the Chinese first party argument is that, well, they could access data from TikTok if they have ownership structure over that. They could access data from Grindr if they have ownership structure over that. That's the concern. This is almost worse because you're clearly not the Chinese government. You have also got access basically to this data as well. And that is a Grinder problem.
Mike Yeagley
Yeah, I would say, look, if I can do it, we have to believe that a sophisticated adversary is doing it as well.
Sponsor/Advertisement Voice
If you listen to our show for more than a week, you know, our beat is uncovering how your data is quietly harvested and exposed online. And if you're like us, working remotely, constantly on the move, and running your entire life off your laptop and phone, well, you're leaving a massive digital footprint. Every time you jump between networks, check emails on the go, or browse from a new location, your device is broadcasting your activity. Advertisers can track your activity, leading to targeted ads, price discrimination and a sense of being monitored. It's the kind of systemic tracking we'd normally write a story about. That's why we recommend surfshark. At its core, surfshark VPN keeps your online activity private. By hiding your IP address, it encrypts your connection, making your online activity much harder to track. So your research, your sources and your personal data stay private no matter where you're working from. But surfshark does far more than that. Surfshark blocks ads and trackers, which cuts down on price discrimination games that sites play based on what they know about you. It also includes Alert, which monitors your ID for data leaks, and an email scam checker that protects against phishing attacks. And if you game, it helps defend against DDoS attacks and ISP throttling since you're always on the move. The best part is that one subscription secures unlimited devices, so your entire household is covered. Go to surfshark.com 404media to get four extra months of Surfshark VPN with the reassurance of a 30 day money back guarantee. Or just use code 404media at checkout that surfshark.com 404media I've started thinking about clothes a little differently this year. Instead of asking how much does it cost? I ask how many times am I actually going to wear this? Because the shirt you wear twice isn't a bargain if it sits in your closet the rest of the year. That's why I've been buying more from Quint. Quint's makes the kind of pieces that earn their keep. Their 100% European linen shirts and pants have been my go to this summer, and when it's really hot, I wear 100% European linen shorts as well. They're lightweight, breathable, and look polished enough that I can wear them pretty much anywhere. To the beach, to dinner, to happy hour, to drinks, to walking around with my dog. And they start at just $34. Their tees are another surprise. They feel incredibly soft, fit really well, and they become the shirts I reach for on regular weekdays, not just special occasions. Although I wear them on the weekend as well. The reason Quince can sell everything for 50 to 80% less than similar brands is because they work directly with ethical factories and cut out the middlemen. You're getting premium materials without paying for a premium logo. And Quince goes way beyond clothing. They've got bedding, bath towels, cookware, furniture, and all kinds of home essentials. So it's become one of those sites I keep coming back to. I have Quince towels, I have Quinn's sheets, I have a Quince duvet cover, I have a Quint's rug, I have a Quinn shirt, Quince shoes, Quint's pants. So I can pretty much like live my entire life at this point just using Quint's items, which is pretty crazy since I just learned about them within this last year. Make your summer wardrobe easier. Go to quints.com 404Media for free shipping on your order and 365 day returns. Now available in Canada too. That's Q U-N-E.com 404Media for free shipping and 365 day returns. Quince.com 404Media.
Mike Yeagley
I had some very uncomfortable conversations on the seventh floor of various government buildings with trying to explain, you know, to 50 plus year old white guys what Grindr is. And it's not just a dating app.
Host (Possibly Joe)
Once you told them what the app was, did they click that, oh, this is potentially a national security risk. Not because obviously homosexual people oppose a risk or anything like that, but they realize that maybe this could be leveraged by an adversary in a bad way. Like, did they realize that?
Mike Yeagley
Yeah, that was my example was, guys, this is not OkCupid. These are not. This is not seeking romance and love and life partners.
Host (Possibly Joe)
This is something different, at least in this context. Yeah, in this context.
Mike Yeagley
Yeah. Trying to. Again, I'm telling you how I explained it to these guys that, you know, this is, this is a different kind of dating app.
Host (Possibly Joe)
And.
Mike Yeagley
And because it is a different kind of dating app and because it is now owned by a company with ties to the ccp, we need to start, we need to understand that this is a different risk. There is a reason why they, of all of the dating apps that they could have purchased, they chose to purchase Grindr. So I raised the flag. The issue took me some time to get some audiences to understand and to focus on the issue. And once we sort of crossed that chasm of, okay, this is different, this was referred to cfius and CFIUS took action, the Committee on Foreign Investment for the US and they are the ones that sort of review and arbitrate acquisitions of companies that are sensitive to, to the United States national security. This is probably their first, you know, examination of a dating app and their first action to force the repatriation of Grindr back to US ownership. We see that, we see that happening a lot now with real estate and other sort of factories, etc. And so the Grinder problem, in my opinion is still the current problem that we have today. 2 million apps, most people have 70 plus apps on their phone. And when you install an app, you are giving that app privileged access to inspect and extract a variety of telemetry from your device that is far more probative about who you are and what you're intent and context are than an ad ID and a GPS signal ever provided. And then, you know, you add in this new AI capability where you can drop in to a GPT, a year's worth of telemetry. And when I say telemetry, I'm talking like the accelerometer, battery level, screen orientation, things that are not personally identifiable. And because they're not pii, the app does not require your consent. You don't even know this is happening. And there's nothing on your phone that can throttle that extraction. When we think about a threat surface of 2 million apps that some are owned by adversaries, people that work there, moving data from an app to an adversarial environment is not a hard thing to do. And you know, privacy and privacy toggles and VPNs. At this level, when an app is inspecting your device, there's nothing in the OS that prevents it from pulling that data and sending it to their server.
Host (Possibly Joe)
Yeah. The one question I get obviously a ton when I report on location data is how do I as a reader or a listener, how do I specifically stop this tracking? And I'm a iOS user, so I can only really talk from that perspective. But my understanding is that when you do, I mean, I don't have location services on the vast, vast majority of the time at an OS level. And that would be the main thing, of course, you then grant it on a per app basis. What you're saying is that there is other data that can be collected by these apps that doesn't fall under that sort of location permission. I mean, just briefly, how do you, if you take steps to do so, how do you sort of protect your own device sort of privacy when it comes to sort of this data being collected by third party apps installed on the phone?
Mike Yeagley
Yep. So this is about the trade off. So there are some apps where you know, I make that trade off and I take that risk. When I open up Uber, I don't want to have to drop a pin because I probably have 2% left of my battery. I want it to work. I want it to know where I am so it can come pick me up in the rain. Right.
Host (Possibly Joe)
I do the opposite. It's a pain in the ass. I type it in every single time. Okay, all right.
Mike Yeagley
So there you go.
Host (Possibly Joe)
But it's a real pain. So I understand why you would. Yeah, yeah, yeah.
Mike Yeagley
But the sort of the new developments in mobile security or privacy, shifting away from These perimeter tools, VPNs and toggles into this notion of, of being able to inspect what an app is trying to extract from your phone and deprecating what is not essential to that app's functionality. So if it's trying to pull a bunch of telemetry fields that have nothing to do with app functionality, being able to. And this is, I get this question a lot too, from the operational community. How do I get out of commercial data? How do I do this? And the surface that we have to focus on first are the apps and minimizing the amount of telemetry that they're able to extract from your device. And that is, that's getting. That's going to require a rethink about the operating system and the hardware. And I will tell your listeners, because they'll figure this out, that I'm on the board of advisors of a company called Unplugged and the approach to this problem is being able to give the user control over what data leaves their device based upon what that app is. When you start looking and you are able to see what an app is pulling and when it's pulling and how it's resolving location when it doesn't have access to gps. Again, it makes me think that when privacy when Apple launched Privacy and we had the ad Apocalypse in 2022 and Meta Stock tanked, the recovery based upon the telemetry and going deeper into the device and not just hanging their hat on stable identifiers like the AD ID and gps. Their ability to attribute behavior to resolve intent is far more detailed than it ever was. So it's almost like privacy gave the apps a gift. They had to figure out how do we replace the ad id. Look at Meta Meta stocks trading at 600 bucks now they their business recovered without, without reliance on the AD id. And if you look at what meta is doing and any other app where they are resolving your location. Let's just focus on Location. They're using everything from time zone to the ambient signals around you. Time zone changes to understand exactly where you are and when. You drop your, your telemetry for a week into ChatGPT or Claude and say tell me about this telemetry, it just, it builds a profile and a pattern of life that at scale should concern every American. Whether you're a case officer, special agent, special operator, I don't care. This is the next level of privacy. We've been sort of hand waving privacy for years and a VPN that you know, that mediates transport and privacy. Toggles are mostly just user in user preference. There isn't, it's not an operating system gate, it's a user preference. You know, don't access my gps. Most apps comply, but that's all it is, it's just indicating your preference. We need more engineered solutions that really attack this problem and give users control over their data once and for all.
Host (Possibly Joe)
Yeah, yeah, that makes sense. So you started warning the government about this and showing them this problem and then in parallel, but obviously also related, you did have more and more agencies buying technology like this. Obviously you mentioned your cases and I covered a bunch of Customs and Border Protection, Immigration and Customs Enforcement, Secret Service as well. There was a lot of debate and argument around that because of course they were doing this without a warrant under the fourth Amendment. That may now be in flux with this recent Supreme Court ruling. We haven't really seen the fallout from that yet, frankly. It's going to take years probably to see that. But there was a lot of movement there. And then recently there were some other news which is that the Pentagon came out and it said that yes, US military personnel are being targeted using location data. This isn't quite related, but the Financial Times I think reported that commercial location data and SS7 stuff, which is the routing backbone, was also used to monitor location of senior US officials during the Iran war. So there's all that sort of stuff. But back on the commercial data being used to target US military personnel, what was your reaction to seeing that news that oh, the Pentagon found out or the Pentagon said it?
Mike Yeagley
Yeah. Senator Rod Wyden from Oregon has been sort of in the lead on this for a long time. They brought this up. And so Senator Wyden, who's not even on armed services, wrote a letter to the CIO at the Department of Defense demanding an accounting. And in that letter you could almost sense the tone, the exasperated tone. In 2016, a contractor blew the whistle on this and what have we done in the last 10 years. And that's my reaction. I've kind of gotten a little desensitized by like how many times do I have to say, yeah, I told you, we've been talking about this, we've known about this. How many different ways do I have to explain it? Until we be, until we get, you know, sort of national level policies to, to deal with this and deal with it in a way that's not hand waving and creating more training and white papers and PowerPoint presentations describing ways that you can try to outthink and trip the, you know, ubiquitous technical surveillance or the platforms. But we need to, we need engineered solutions. And so we have some, we have some, some, some congressmen and women that sort of heard, heard us out on this and have developed amendments to the ndaa. We came in late the National Defense Authorization act for 2027 in which instructs the Pentagon to explore and assess technologies that attack this commercial data problem from its origins at the app layer to examine methods and approaches to minimize this data, leaving a device and networking into this opaque cartel of data brokers and attribution companies that end up in the hands of adversaries, which again is not hard to do at all. And, and more of this legislation is just sort of trying to put the, put the data back in the phone after it's, after it's left the phone. And we need to begin looking at how do we keep the data from leaving the phone in the first place? Because that's the problem and that's been the problem. And that's, we need to start thinking about, okay, how do we solve this? Because we're not going to out tradecraft. An $8 trillion duopoly of Apple and Google and 2 million apps, all of which have, you know, fraud detection algorithms that the minute you are doing something funky and weird, it deplatforms you or, you know, it, it outs you, it flags you as, as unique and anomalous. So we need to think about how do people that are in sensitive positions carry a phone into a war zone? Because a lot of our personnel have children and if they're deployed for six months, they need to be able to reach back and do homework and do all of those kinds of things. So sending them out into the, onto a deployment without a phone is not a solution, not practical. They'll quit. I would quit. So how do we do this so that we are not giving an adversary an advantage for free?
Host (Possibly Joe)
Yeah, and I mean, you touched on it there with Apple and Google. And the question is which entity or player is the one with the most power here to make the biggest change to this problem. Now, I'm sure the company that you're on the board on would love to say was them, and then other providers would probably love that as well. You mentioned Apple and Google. Obviously they are running the primary operating systems on this. You obviously then have the app developers as well. But they're probably going to do whatever the fuck they want, right? Which entity here is the one with the most power that can do the most change? Is it ultimately Apple and Google who should do this?
Mike Yeagley
My answer to that question is the consumer, right? The consumer needs to decide this is not proportionate the amount of data that is being collected about me is not proportionate to, you know, to a typical advertiser consumer relationship. This is, this is beyond that assumed relationship that has fences and gates. They are going far deeper into my existence. So consumer needs to, needs to understand what they're up against. You know, Google and Apple, they kind of depend upon their app ecosystem for significant amount of revenue. So, so regulating them is difficult and replacing them with Google or Apple apps triggers antitrust. So they're in kind of a bind. And Google is indeed an advertising business, especially because many people use Google apps. And so the answer to your question really is it's the apps. If I were to be counseling somebody today who wasn't going to go into the market to buy a phone that was, you know, engineered for privacy, I would say have an understanding of the apps that you're installing on your phone. Just go to the App Store and try to figure out, look and see where that app is manufactured. But again, you know, they can have employees there that are, you know, siphoning out data. But it really gets down to what apps do you need and controlling your appetite for convenience, because convenience and lack of friction is how we got here in the first place and how surveillance sort of builds and layers upon itself. And if you are really concerned about sort of surveillance where you have no reason to be surveilled, you've gotta, you gotta take, you gotta take a look at your own sort of tech profile and minimize that footprint as best you can. But this is to really solve the problem, Joe. This is engineering. This is not having your name moved from data broker list. Like, that's good, that's fine, do it if it makes you feel better. But at the end of the day, we need to take back the, the flow of data and resolve it back to something that is more proportionate to what we get from these apps and these experiences.
Host (Possibly Joe)
Yeah, well I think that's a really good way to pull it and a great place to leave it. Mike, thank you so much for joining us. I really really enjoyed this conversation. Thank you so much.
Mike Yeagley
Thanks for having me. I appreciate it.
Host (Possibly Joe)
As a reminder, 404 Media is German seamless, founded and supported by subscribers. If you do wish to subscribe to 404 Media and directly support our work, please go to 404 Media co. You'll get unlimited access to our articles and an ad free version of this podcast. You also get to listen to the Subscribers only section where we talk about a bonus story each week. This podcast is produced by Alyssa Midcalf. Another way to support us is by leaving a five star rating and review to the the podcast. That stuff really, really does help us out. This has been 404 Media. We'll see you again next.
Episode: This Man Bought Phone Location Data from Around the World
Date: July 27, 2026
Host: 404 Media (likely Joseph)
Guest: Mike Yeagley, pioneer in government use of commercially-sourced location data
This episode dives deep into the under-explored world of commercial phone location data—how it's bought, how governments use it, and the immense risks and challenges this presents for privacy, security, and civil liberties. In conversation with Mike Yeagley, one of the first to introduce mass-purchased commercial location datasets to the U.S. government and military, the discussion ranges from the intelligence gold rush on cell phone data, through the “Grindr problem” and foreign ownership, to the prospects for reform and meaningful privacy controls.
[03:39 – 06:52]
Yeagley’s Story Begins (~2015):
● Special operations community sought alternative methods to understand “human geography” in remote areas (Yemen, Syria), leveraging the omnipresence of smartphones.
● Ad tech companies collected location data even in countries with small ad markets; this unused data was cheap and accessible.
Buying in Bulk:
“I came in and started buying it in mass.” (03:39 – 04:46)
Yeagley describes the novelty of not wanting to advertise, but just buying bulk location data (AD IDs, user agent strings, metadata), creating a new business model for suppliers.
[06:52 – 12:49]
Demonstrating Value to Government:
Example: Linking devices traveling from residences in North Carolina to an abandoned Lafarge cement factory in Syria.
"I was tracking right down to the operator's residence. That became a watershed moment for location data." — Yeagley (07:10)
Officials initially accused Yeagley of “hacking,” unable to believe such intelligence was commercially acquired.
“The guy called me a charlatan... I didn’t hack, intercept, engineer or steal this data, I bought it.” — Yeagley (08:47)
Reverse Engineering, Not Individual Targeting:
“It’s more fruitful the other way round... you reverse engineer from the location to the devices and ultimately the people.” — Host (10:27)
Usage in High-Profile Cases:
[13:48 – 20:18]
Oversight and Internal Warnings:
The “Grindr Problem”:
Yeagley noticed a lot of US location data originated from the dating app Grindr, recently acquired by a company with Chinese ties.
Risks:
“If I can do it, we have to believe that a sophisticated adversary is doing it as well.” — Yeagley (20:00)
CFIUS Action:
Depth of Telemetry Extracted:
Apps can extract far more than location—accelerometer, battery, screen orientation, etc.—often without user knowledge or real consent, since those data aren't classified as personally identifiable information (PII).
“When you install an app, you are giving that app privileged access... far more probative about who you are... than an ad ID and a GPS signal ever provided... there’s nothing on your phone that can throttle that extraction.” — Yeagley (24:33 – 27:26)
[27:26 – 32:20]
Personal Privacy Trade-Offs:
Most users blindly accept risks for convenience (e.g., allowing Uber access to location).
iOS/Android privacy toggles only limit so much—apps collect telemetry that skirts permission dialogs.
“The perimeter tools, VPNs and toggles... they're mostly just user preference, it’s not an OS gate.” — Yeagley (29:59)
Need for Engineered Solutions:
Genuine user-level control over what data gets extracted—examining the app layer, limiting telemetry that leaves the device.
Yeagley mentions involvement (as advisor) with Unplugged, a firm building such protections.
“We need more engineered solutions that really attack this problem and give users control over their data once and for all.” — Yeagley (29:59 – 32:20)
[32:20 – 40:00]
Pentagon, Congress, and Real-World Threats:
Who Bears Responsibility?
App developers aggressively collect data; Apple and Google depend on these ecosystems but are caught in regulatory binds.
Ultimately, says Yeagley, the consumer must drive demand for change, but the solution must be engineered, not just regulatory.
“This is engineering. This is not having your name moved from data broker list... we need to take back the, the flow of data and resolve it back to something that is more proportionate...” — Yeagley (39:00)
“I was tracking right down to the operator's residence. That became a watershed moment for location data.”
— Mike Yeagley, [07:10]
"I didn’t hack, intercept, engineer or steal this data, I bought it. And I bought it for a cost factor far below anything you would have had to spend to collect... using your technical methods and at zero risk because I did it sitting in the room you see me in right now."
— Mike Yeagley, [08:47]
“If I can do it, we have to believe that a sophisticated adversary is doing it as well.”
— Mike Yeagley, [20:00]
"When you install an app, you are giving that app privileged access to inspect and extract a variety of telemetry from your device that is far more probative about who you are and what your intent and context are than an ad ID and a GPS signal ever provided."
— Mike Yeagley, [24:33]
“We need engineered solutions... we need to start thinking about, okay, how do we solve this? Because we're not going to out tradecraft an $8 trillion duopoly of Apple and Google and 2 million apps.”
— Mike Yeagley, [36:10]
“This is engineering. This is not having your name moved from data broker list... we need to take back the flow of data and resolve it back to something that is more proportionate...”
— Mike Yeagley, [39:00]
Through candid discussion with a key figure at the center of government-commercial data entanglement, this episode exposes how easy, cheap, and impactful mass location data has been for intelligence gathering—and why oversight, regulatory efforts, and current privacy features are not enough. The “Grindr” case exemplifies the persistent vulnerabilities, while Yeagley’s warnings highlight both the power of these datasets and the urgent need for technical solutions that give users real control over their data.
For listeners:
Final word:
“We need to take back the flow of data... to something that is more proportionate to what we get from these apps and these experiences.” — Mike Yeagley [39:00]