Skip to main content
HonestMOS
InvestigationsCongress made VA disability claims free to file. An entire industry charges veterans anyway — and nobody can stop them.
Field Manual · Signal

Digital OPSEC (The Skill Nobody Teaches)

The annual OPSEC CBT taught you to click Next until the certificate printed. Meanwhile your phone, your watch, your apps, and your mom's Facebook are broadcasting a pattern-of-life file on you that a foreign intelligence service would have needed a surveillance team to build twenty years ago. This is the practical version — grounded in AR 530-1, Operations Security and NSA's public mobile-device guidance, minus the death-by-PowerPoint.

01Why This Is a Soldier Skill Now

In January 2018, a 20-year-old analyst looking at Strava's public global heat map noticed something: bright little loops of GPS exercise data in the middle of otherwise-dark stretches of Syria, Afghanistan, and Africa. Troops had jogged the perimeters of their own bases with fitness trackers on, and the app had helpfully published the pattern to the entire internet. Runs traced outposts that weren't supposed to be publicly known. It was one of the loudest OPSEC failures of the smartphone era, and nobody involved did anything but exercise.

That's the shape of modern OPSEC failure. It's rarely a spy and rarely a leak. It's a thousand people making individually reasonable choices — I'll log my run, I'll post the homecoming date, I'll use the free Wi-Fi — that aggregate into a picture. Doctrine calls the pieces critical information: your unit's capabilities, activities, limitations, and intentions. Nobody gives those away on purpose. They give them away in metadata.

The Pentagon's response to the heat map was an August 2018 policy restricting geolocation features on devices and apps in operational areas. That policy protects operational locations. Nobody issued a policy for you — your accounts, your money, your family, your pattern of life at home station. That part is a personal soldier skill, and this page is the class.

02Your Phone Is a Sensor Platform

Your phone carries a GPS receiver, two cameras, several microphones, and radios that announce themselves to every network and beacon in range. Treat it like what it is: a sensor platform you volunteered to carry. The good news is that most of the leakage is configuration, not fate.

The NSA publishes genuinely readable public guidance on this (search "NSA Mobile Device Best Practices"). The load-bearing items:

  • Location permissions: audit every app. "While using" at most; "Never" for anything that doesn't obviously need it. Your flashlight app does not need your grid.
  • Bluetooth and Wi-Fi off when not in use. Both constantly advertise your device to its surroundings, and auto-join will happily connect you to a hostile network with a familiar name.
  • Reboot the phone regularly. It disrupts a real class of non-persistent exploits. Cheapest security control you'll ever run.
  • Reset your advertising ID and turn off ad personalization. Commercial location-data brokers have sold datasets that included devices moving around military installations — you don't have to be interesting to be in the dataset.
  • Strip photo metadata. Photos embed GPS coordinates by default. A barracks-room selfie can carry an eight-digit grid in its EXIF data.

03Fitness Trackers Told On Everybody

The Strava map wasn't a Strava problem; it was a defaults problem. Fitness devices and apps are built to share — public activity feeds, segment leaderboards, route maps — and every default leans social. Your watch is a flight recorder for your body, and by default it files its reports in public.

  • Set every fitness app's activity visibility to private, and kill route/heat-map sharing outright. A PR nobody can see still counts.
  • Your recurring routes are your pattern of life: same gate, same loop, same time. That's true at home station, not just downrange.
  • In designated operational areas, the 2018 DoD policy makes it simple: geolocation features off. Not private — off. Ask what your theater's rules are before you bring the watch at all.

04Social Media: Where OPSEC Goes to Die

AR 530-1 makes individual soldiers responsible for protecting critical information — and social media is where that responsibility goes to die, one harmless-looking post at a time. The classic kills: deployment dates, locations, unit movements, homecoming timelines, and geotagged photos on the installation. Each one feels like family news. In aggregate they're an intelligence product, assembled for free.

  • No dates, no places, no counts. "Leaving soon" beats "wheels up Tuesday out of Pope, 300 of us."
  • Turn off geotagging, and post travel photos after you've left, not while you're there.
  • Audit old posts. Your public profile going back years is a biography a targeter doesn't have to write.
  • Assume the friendly stranger who DMs about your job is working. Romance and recruitment approaches against service members over social media are a documented, ongoing thing — vanity is the vulnerability.

05Wi-Fi You Don’t Own

Military life is lived on other people's networks: the passenger terminal, the USO, the hotel during PCS, the morale Wi-Fi on the pad, the café outside the gate at your OCONUS base. The rule for all of them is the same: a network you don't control is a network you should assume is monitored. Whoever runs it — and anyone else on it with modest skills — can see where your traffic goes, and can interfere with anything unencrypted.

Ranked defenses: use your own cellular data when you can. Keep the sensitive sessions — banking, DTS, anything with a password you care about — off shared Wi-Fi entirely when practical. And when you're going to live on networks you don't control for months at a time, which is exactly what OCONUS orders, deployment, and heavy TDY mean, encrypt your traffic yourself with a paid VPN instead of trusting every network to be honest.

06What a VPN Is — and Isn’t

A VPN does exactly one job: it encrypts everything between your device and a server you chose, so the local network — hotel, terminal, morale pad, foreign ISP — sees only noise. Two honest consequences follow. Your traffic on hostile Wi-Fi stops being readable. And because your traffic exits from the server's location, a US server gives you a US IP address overseas — which is why your banking app stops flagging you and your streaming library comes back.

What a VPN does not do: it doesn't make you anonymous, it doesn't secure a phone full of over-permissioned apps, it doesn't fix a reused password, and it can't un-post your homecoming date. It closes the untrusted-network hole — sections 02, 04, and 07 are still on you.

07Passwords, MFA, and the Reuse Problem

Password reuse is how one leaked shopping account becomes your email, then your bank, then your identity. The fix is boring and total: a password manager generating a unique password per account, and multi-factor authentication turned on everywhere it exists. Prefer an authenticator app or hardware key over SMS codes where you get the choice — phone numbers can be hijacked.

Do it before the deployment or the PCS, while you still have good internet and free evenings. And treat unexpected texts about packages, pay problems, and "suspicious activity" as hostile until proven otherwise — service members are a named, targeted demographic for exactly that scam traffic.

08The Family Brief

You can run this whole page perfectly and be undone by one proud parent. Families post the deployment countdowns, the "he can't tell me where he is but it's hot" updates, the homecoming dates with the flag emoji. None of it is malicious. All of it is collection.

So give your people the brief the unit never gives them: no dates, no locations, no unit movements, no countdown clocks, and homecoming photos wait until everyone's home. Explain the why — the aggregation problem, not "because I said so" — and they'll hold the line better than half your formation.

Digital OPSEC isn't paranoia. It's noise discipline for the century you're actually serving in.

Grounded In
  • AR 530-1, Operations Security — individual responsibility for critical information
  • DoD policy memorandum, August 2018 — geolocation-capable devices and applications in operational areas
  • NSA, Mobile Device Best Practices (public guidance)
  • The Strava global heat map disclosures, January 2018 (widely reported)