Dutch Defence bans Polarsteps travel app over data leak
Translated from Dutch and summarized by DistantNews. Read the original for the full story.
At a glance
- Dutch Defence has banned Polarsteps from military work phones after journalists reported that usersโ names, photos and GPS locations could be downloaded without permission.
- The reported exposure included dozens of military personnel on exercises in the Netherlands and abroad, with some addresses and workplaces allegedly easy to identify.
- Polarsteps disputes that a data leak occurred, while Defence said it may expand its list of prohibited apps.
Dutch military personnel may no longer use the travel app Polarsteps on their work phones. The decision followed reporting by investigative platform Follow the Money, which said large quantities of user data could be accessed without permission.
The exposed information reportedly included names, photographs and GPS locations. Some users could be followed almost in real time. Dozens of military personnel were among those identified while taking part in exercises in the Netherlands and abroad. Follow the Money wrote that it was often easy to determine their addresses, workplaces and schedules.
Defence said it would place Polarsteps on its deny-list immediately. The app can no longer be installed on work phones, and existing installations will be removed automatically. A Defence spokesperson said the list covers applications that users cannot install because they may create security risks, including by transmitting location data. Strava is also on the list, while Defence has not disclosed which other apps are banned.
The spokesperson expects the list to grow. The restrictions do not apply to private phones, although Defence can prohibit their use in certain locations or during particular exercises. โAt certain exercises, for example, you may not be allowed to carry a private phone.โ
Follow the Money reported that Polarsteps had known about the security risks for at least a year. The company rejects the description of the issue as a data leak, saying no passwords were exposed and that trip data never made public by users remained private.
At certain exercises, for example, you may not be allowed to carry a private phone.
Originally published by NRC Handelsblad in Dutch. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.