Digital Force Protection FAQ
Fast answers on defending personnel and operations against ubiquitous technical surveillance. For OPSEC fundamentals, see OPSEC, UTS, and Digital Force Protection FAQ. For the full long-form treatment, see Ubiquitous Technical Surveillance Will Get You Killed on the Streets.
What is Digital Force Protection?
Digital Force Protection (DFP) is force protection extended into the digital, electronic, and signature domain. It protects personnel and operations from the exposure created by their electromagnetic, cyber, and commercial-data footprint by measuring and managing the aggregate signature an adversary could fuse from device emissions, location data, social media, and other observables.
DFP operates on the same Sense-Make Sense-Act continuum as the rest of the Empyrean platform: sense the emissions environment, fuse observations into identities and patterns, and apply policy or alert when something deviates from the expected signature envelope.
How does commercial location data threaten military personnel?
Commercial location data collected through advertising auctions (real-time bidding) and embedded software development kits reveals where personnel sleep, work, train, congregate, travel, and deploy. When device identifiers and coordinates are fused with public records, imagery, social media, vehicle data, or access records, pseudonymous movement histories become named patterns of life and targeting intelligence.
In April 2026, U.S. Central Command confirmed to Congress that it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater. The data was not obtained through a device compromise. It was part of the commercial surveillance ecosystem through which movement histories are routinely collected, packaged, and sold.
What is a mobile advertising identifier (MAID)?
A MAID is a unique device-level string (IDFA on iOS, Google Advertising ID on Android) that the advertising ecosystem uses to track behavior across applications. In a UTS context it functions as a persistent selector that links a device to coordinates, timestamps, and behavioral data sold through real-time bidding auctions and data brokers.
The identifier is pseudonymous in the sense that the string itself is not your name. It is not pseudonymous in any meaningful operational sense, because an industry of identity-resolution services will accept a MAID and return names, email addresses, and physical addresses for a fee. Even without the resolution service, a device that sleeps at one address every night and works inside a fenced installation has self-identified in the aggregate.
What is real-time bidding and why does it matter for DFP?
Real-time bidding (RTB) is the programmatic auction process through which digital advertising inventory is sold in milliseconds. Each bid request broadcasts device identifiers, GPS coordinates, timestamps, device model, operating system, and application context to hundreds of potential buyers. Only one buyer wins the auction, but every participant keeps the data. Anyone who can present themselves as a plausible ad buyer receives a firehose of location data about billions of devices per day, whether they ever purchase a single advertisement.
What is co-traveler analysis?
Co-traveler analysis identifies entities whose movements repeatedly correlate in space and time with a target of interest. It bins observations in space and time, measures overlaps, applies thresholds for distance, duration, and recurrence, and discounts likely coincidences such as airports or traffic corridors.
Defensively, co-traveler analysis answers two questions: Which unknown devices are shadowing a protected person or asset, and which of our own devices are correlating in ways they should not? The technique also runs inward: the Tehran operation that located Khamenei worked his co-travelers (bodyguards and drivers) rather than tracking the principal directly.
How does pattern-of-life analysis work?
Pattern of life reduces a person or entity's movement into a probabilistic model of their schedule. It answers where they will be, with whom, and when. The model improves monotonically with the length of the observation window, which is why indefinite data retention is the load-bearing element of the threat.
The most exploitable pattern is not the sensitive one (operations are irregular by construction) but the boring one: the gym, the school, the church, the commute. These mundane routines are what place a person in a known location at a known time, and they live entirely outside the classified portion of anyone's life.
What is the difference between OPSEC and signature management?
OPSEC is a five-step analytical process (identify critical information, analyze threats, analyze vulnerabilities, assess risk, apply countermeasures) focused on denying critical information to an adversary. It is codified in DoDD 5205.02E and JP 3-13.3.
Signature management is the broader discipline of measuring and shaping all observable indicators (physical, electromagnetic, cyber, commercial-data) so a force is harder to classify, locate, target, or predict. The objective is not silence but controlled ambiguity. OPSEC is best understood as a subordinate process within signature management, alongside emissions control, cover, deception, and digital force protection.
Can going dark make you more visible?
Yes. In a sufficiently instrumented environment, an expected signal disappearing is itself an observable. Three failure modes exist:
- Silence: An expected signal disappears in a repeated or operationally significant pattern.
- Substitution: One identifier disappears and another begins reproducing its behavior (same routes, timing, associates).
- Convergence: Otherwise ordinary devices abandon normal patterns and begin moving together near sensitive locations.
The objective is not zero emission. It is a signature consistent with the mission, stable across time, compatible with the surrounding environment, and difficult for the adversary to interpret correctly.
What is a Telemetry Bill of Materials (TBOM)?
A TBOM is a structured disclosure listing every permission, identifier, embedded SDK, network destination, and data-sharing relationship within an application or device. It is the telemetry equivalent of a Software Bill of Materials (SBOM) and is proposed as a procurement and risk-management requirement for organizations subject to UTS.
A TBOM should identify every requested permission and sensor, every persistent or resettable identifier, every embedded advertising/analytics SDK, every network destination and subprocessor, retention and deletion behavior, whether data is sold or shared, and whether foreign personnel or infrastructure can access it. No advertising SDK belongs in a mission application unless somebody can articulate a mission requirement worth the exposure.
How does UTS affect EABO and Stand-In Forces?
Expeditionary Advanced Base Operations (EABO) and Stand-In Forces (SIF) depend on mobile, distributed, low-signature units operating inside contested littorals, often embedded in host-nation cellular networks and civilian populations. Commercial networks, civilian devices, constrained island geography, and long pre-collection windows can expose the personnel, logistics, sensors, and behavioral patterns that sustain those formations.
The theater's defining characteristic is dispersion, and dispersion is the posture that co-traveler analysis and device-census analytics are best at defeating. A dispersed force often believes it is concealed but has never measured what it emits. That gap between believed and actual signature is where the first day of a war gets decided.
What is a device census and why does it matter?
A device census is a fused inventory of all electromagnetic emitters (cellular, Wi-Fi, Bluetooth, satellite, vehicle, industrial, embedded) within a defined volume of space, correlated across radio types and over time. It answers what is authorized, what is expected but unmanaged, what is environmental background, what cannot be accounted for, and what appears only during specific activities.
No single sensor produces a complete census. Carrier visibility, network telemetry, passive RF observation, MDM inventory, access-control records, and physical surveys each reveal different portions. Reconciling them into a unified picture is the first step of any DFP deployment, and the detected emitter count is always higher than the badge count.
What is Salt Typhoon and why does it matter for DFP?
Salt Typhoon is a cyber espionage campaign attributed to contractors working for China's Ministry of State Security. It achieved persistent access to Western telecommunications backbone infrastructure, including lawful-intercept systems, across over 200 organizations in more than 80 countries. It accessed metadata and geolocation for millions of devices, most in the Washington, D.C. metropolitan area.
Salt Typhoon demonstrates that UTS threats extend below the device layer into carrier infrastructure itself. There is no advertising ID to disable and no app to delete when the adversary has compromised the network underneath every individual mitigation. This is why signature management must be an institutional program with a technical measurement capability, not a personal responsibility.
What can individuals do to reduce UTS exposure?
Remove unnecessary advertising identifiers (delete, not just reset). Restrict location permissions to the minimum necessary. Delete stored location histories. Lock down fitness and social profiles. Minimize connected devices around sensitive activity. Keep devices supported and updated. Treat household accounts, wearables, vehicles, and photographs as part of the exposure surface. Understand that resetting one identifier closes one column in a table with six columns.
What should small teams do about UTS?
Use centrally managed devices with MDM enforcement. Enforce risk-tiered geolocation policies. Issue dedicated mission devices rather than casual burners. Measure group-level correlations during exercises. Include support personnel, vendors, transportation, and households in the operational security boundary. A team's signature is the aggregate of its members, and identity can propagate outward through the co-traveler graph from whichever node is easiest to resolve.
What should institutions do about UTS?
Establish an accountable signature-management program with a recurring battle rhythm. Maintain a governed emitter inventory and environmental baseline. Require a Telemetry Bill of Materials from vendors. Run lawful signature red-team assessments at the organizational level. Manage commercial-data exposure through broker deletions and contract restrictions. Measure whether an adversary can resolve the force, not merely whether devices are compliant.
How does Empyrean Defense approach Digital Force Protection?
Empyrean's DFP capability sees your own signature the way a fused adversary would: a device census across radio types, correlated over time into tracks with identity resolution, fused with external feeds (commercial ALPR, wardriving databases, imagery, open-source footprint). It runs co-travel detection, anomaly detection over approaches, cell-site simulator and GNSS interference detection, and is edge-deployable and air-gap capable. See Digital Force Protection.