{"id":11258,"date":"2022-11-16T10:00:38","date_gmt":"2022-11-16T13:00:38","guid":{"rendered":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=11258"},"modified":"2022-11-16T10:00:38","modified_gmt":"2022-11-16T13:00:38","slug":"control-y-regulaciones-una-aplicacion-oficial-del-ejercito-de-los-ee-uu-tenia-codigo-ruso-y-pudo-haber-recopilado-datos-de-usuarios-militares","status":"publish","type":"post","link":"https:\/\/www.fie.undef.edu.ar\/ceptm\/?p=11258","title":{"rendered":"Control y regulaciones: una aplicaci\u00f3n oficial del ej\u00e9rcito de los EE. UU. ten\u00eda c\u00f3digo ruso, y pudo haber recopilado datos de usuarios militares"},"content":{"rendered":"<p>El Ej\u00e9rcito de los EE. UU. confirm\u00f3 que se cre\u00f3 una aplicaci\u00f3n aprobada oficialmente utilizando el c\u00f3digo de una empresa de tecnolog\u00eda con ra\u00edces rusas que proporciona herramientas populares para que los desarrolladores env\u00eden notificaciones personalizadas a sus usuarios. La app funcion\u00f3 para las tropas en el Centro Nacional de Entrenamiento en Fort Irwin, California, un punto de referencia cr\u00edtico para el despliegue de unidades para probar su destreza en el campo de batalla antes de partir al extranjero. La aplicaci\u00f3n dej\u00f3 de usarse en 2019.<\/p>\n<hr \/>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The U.S. Army confirmed that an officially approved app was built using code from a tech company with Russian roots that provides popular tools for developers to send customized notifications to their users.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">At least 1,000 people downloaded the app, which delivered updates for troops at the National Training Center on Fort Irwin, California, a critical waypoint for deploying units to test their battlefield prowess before heading overseas. The app fell out of use in 2019 due to routine personnel changeover, and likely wouldn\u2019t have been approved today due to more stringent IT protocols in recent years, according to an Army official and a service spokesperson. The confirmation comes after a\u00a0<a href=\"https:\/\/www.reuters.com\/technology\/exclusive-russian-software-disguised-american-finds-its-way-into-us-army-cdc-2022-11-14\/\" target=\"_blank\" rel=\"noopener\">Reuters investigation<\/a>\u00a0spotlighted the situation.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">Some of the app\u2019s code came from a company known as Pushwoosh, which reportedly went to significant lengths to present itself as a U.S.-based entity, according to Reuters. Those efforts included fake LinkedIn profiles, phony addresses and more. The company\u2019s founder, Max Konev, told the news organization that he was \u201cproud to be Russian\u201d in a September statement.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The U.S. considers Russia a top-tier threat to national security, alongside China. Officials in Washington have repeatedly\u00a0<a href=\"https:\/\/www.c4isrnet.com\/cyber\/2022\/10\/05\/us-says-hackers-attacked-defense-organization-stole-sensitive-info\/\" target=\"_blank\" rel=\"noopener\">warned of Moscow\u2019s hacking chops<\/a>\u00a0and its ability to wage influence campaigns abroad, and cybersecurity experts told Reuters that Russia\u2019s intelligence services may be able to compel companies like Pushwoosh to turn over their data, regardless of where it\u2019s stored.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">According to legal experts interviewed by Reuters, the company was able to circumvent industry regulations and government contracting rules against doing business with Russian companies. Such restrictions have tightened since Russia\u2019s renewed invasion of Ukraine that began in February, and a growing number of companies have come under formal sanctions as well.<\/p>\n<figure id=\"attachment_11260\" aria-describedby=\"caption-attachment-11260\" style=\"width: 1440px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" class=\"size-full wp-image-11260\" src=\"https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/VAZCQCJ5F5EOPEFAXE6WTMWI5M.jpg\" alt=\"\" width=\"1440\" height=\"810\" srcset=\"https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/VAZCQCJ5F5EOPEFAXE6WTMWI5M.jpg 1440w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/VAZCQCJ5F5EOPEFAXE6WTMWI5M-300x169.jpg 300w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/VAZCQCJ5F5EOPEFAXE6WTMWI5M-1024x576.jpg 1024w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/VAZCQCJ5F5EOPEFAXE6WTMWI5M-768x432.jpg 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/><figcaption id=\"caption-attachment-11260\" class=\"wp-caption-text\">Screenshots of the National Training Center app from its Apple App Store listing. (Screenshot\/App Aware)<\/figcaption><\/figure>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">Pushwoosh is one of many software development companies that offer third-party coding solutions to other developers who are seeking off-the-shelf features to fold into their projects. According to the\u00a0<a href=\"https:\/\/help.pushwoosh.com\/hc\/en-us\/articles\/360015945252-What-user-data-does-Pushwoosh-collect\" target=\"_blank\" rel=\"noopener\">company website<\/a>, Pushwoosh customizes its targeted notifications by collecting and storing a bevy of user data on its servers in Germany.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The Russian-owned entity gathers location data, device data and other potentially identifying information collected from apps that use its notifications code and pools it on its servers. A\u00a0<a href=\"https:\/\/blog.pushwoosh.com\/blog\/choose-customer-engagement-platform\/\" target=\"_blank\" rel=\"noopener\">company blog post\u00a0<\/a>reveals it retains that data \u201ceternally,\u201d no matter how long it has been since a user has opened the app, unless a user turns off notifications or deletes the app.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The National Training Center application, published by the service\u2019s\u00a0<a href=\"https:\/\/www.armytimes.com\/news\/your-army\/2015\/11\/04\/tradoc-launches-app-store-up-to-150-apps-available-in-january\/\" target=\"_blank\" rel=\"noopener\">TRADOC Mobile app portal<\/a>\u00a0and listed in both the Apple and Google app stores, \u201cwas developed in 2016\u2033 using \u201ca free version of Pushwoosh,\u201d confirmed Army spokesperson Bryce Dubee in an emailed statement to Army Times and C4ISRNET.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">It\u2019s not clear what user data was collected from the NTC app and stored by Pushwoosh, and it\u2019s not certain whether Russian intelligence services have obtained it or can access it. But even seemingly innocuous apps can feed targeting efforts: A\u00a0<a href=\"https:\/\/www.vice.com\/en\/article\/jgqm5x\/us-military-location-data-xmode-locate-x\" target=\"_blank\" rel=\"noopener\">2020 VICE Motherboard investigation<\/a>\u00a0revealed U.S. Special Operations Command had been purchasing anonymized location data for several apps popular in the Muslim world, presumably to unmask and target individuals associated with terrorist groups.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">Russia has historically denied accusations of cyber aggression and espionage. Pushwoosh founder Konev told Reuters his company \u201chas no connection with the Russian government of any kind.\u201d<\/p>\n<p class=\"heading__StyledHeading-sc-123v3ct-0 iKlOni a-heading2\"><strong>Why did an Army app use Pushwoosh code?<\/strong><\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">An individual assigned to NTC, a major training center, created the application and submitted it for Army approval and publishing, according to Dubee. It was then approved.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">According to the app\u2019s description in the Apple store, which was archived by\u00a0<a href=\"https:\/\/appadvice.com\/app\/national-training-center\/1094252341\" target=\"_blank\" rel=\"noopener\">App Aware\u2019s API scraper<\/a>, the NTC app advertised providing \u201cthe latest Fort Irwin news, information and social media updates\u201d to users. It also included \u201cquick-click buttons for calling post facilities, a community calendar and a map to popular establishments and much more.\u201d<\/p>\n<figure id=\"attachment_11261\" aria-describedby=\"caption-attachment-11261\" style=\"width: 1440px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" class=\"size-full wp-image-11261\" src=\"https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU.jpg\" alt=\"\" width=\"1440\" height=\"1440\" srcset=\"https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU.jpg 1440w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU-300x300.jpg 300w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU-1024x1024.jpg 1024w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU-150x150.jpg 150w, https:\/\/www.fie.undef.edu.ar\/ceptm\/wp-content\/uploads\/2022\/11\/7UZLC4D7KZGP7DN4FRND7FXMVU-768x768.jpg 768w\" sizes=\"(max-width: 1440px) 100vw, 1440px\" \/><figcaption id=\"caption-attachment-11261\" class=\"wp-caption-text\">The National Training Center application\u2019s logo from the Apple App Store. (Screenshot\/App Aware)<\/figcaption><\/figure>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">It\u2019s not clear whether the map feature required users to opt into sharing their location with the app \u2014 and potentially with Pushwoosh. Regardless, the app saw fairly wide use; an archived listing for the app on\u00a0<a href=\"https:\/\/apkcombo.com\/national-training-center\/mil.army.ntc\/\" target=\"_blank\" rel=\"noopener\">Google Play store scraper APK Combo<\/a>\u00a0said more than 1,000 Android users downloaded it. Army Times and C4ISRNET could not confirm how many Apple devices had installed the app before it was removed from the App Store.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The NTC app fell out of use in 2019, an Army official said, after changes in personnel. But the potential risks went undetected for years after the NTC app was abandoned, the official added, until a \u201croutine scan\u201d of Army apps in March \u201cdetermined the NTC app was not in compliance, not in use, and not able to be updated.\u201d<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">Today, the app wouldn\u2019t be approved at all \u201cbecause regulations and guidance have become more stringent since 2016 [when it was developed],\u201d and the Army \u201cmoved to have the app taken offline completely while conducting a routine review of authorized apps,\u201d Dubee confirmed.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">\u201cRegulations do not authorize the use of free software when paid software is available, and consequently, the PM Army Mobile team would have immediately disallowed\/disapproved the use of free software,\u201d Dubee explained.<\/p>\n<p class=\"Paragraph-sc-1tqpf5s-0 kEzXdV body-paragraph body-paragraph\">The spokesperson did not answer\u00a0<a href=\"https:\/\/www.armytimes.com\/\" target=\"_blank\" rel=\"noopener\">questions from Army Times and C4ISRNET<\/a>\u00a0seeking more information on what data the app collected and whether the service was aware of the company\u2019s origins when it shut down the NTC app in March.<\/p>\n<p><strong>Fuente:<\/strong> <a href=\"https:\/\/www.c4isrnet.com\/cyber\/2022\/11\/15\/official-us-army-app-had-russian-code-may-have-harvested-user-data\/\" target=\"_blank\" rel=\"noopener\"><em>https:\/\/www.c4isrnet.com<\/em><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>El Ej\u00e9rcito de los EE. UU. confirm\u00f3 que se cre\u00f3 una aplicaci\u00f3n aprobada oficialmente utilizando el c\u00f3digo de una empresa de tecnolog\u00eda con ra\u00edces rusas&hellip; <\/p>\n","protected":false},"author":1,"featured_media":11259,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[37,23],"tags":[],"_links":{"self":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11258"}],"collection":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11258"}],"version-history":[{"count":1,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11258\/revisions"}],"predecessor-version":[{"id":11262,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/posts\/11258\/revisions\/11262"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=\/wp\/v2\/media\/11259"}],"wp:attachment":[{"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fie.undef.edu.ar\/ceptm\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}