Prerequisites
Tutorial 6: Wi-Fi positioning and geo-IP: locating by network data.
01
Every app that reads your location leaves a record someone else can buy
Advertising identifiers, the IDFA on iOS and the GAID on Android, are unique, resettable strings that apps use to link a user's behaviour across sessions and platforms. Location brokers collect those identifiers alongside GPS coordinates, timestamps and BSSID probe records, then resell the aggregated movement history. For investigators, that commercial data pipeline is both a source and a subject.
A single device moving through a city generates hundreds of location pings per day, each tagged to its advertising ID. Brokers aggregate these pings into trajectory files covering months or years. Publishers of mobile apps embed broker SDKs that silently transmit the device's advertising ID, timestamp and GPS coordinates to broker servers; the broker then sells access to that aggregated dataset to advertisers, data analytics firms, and -- in some jurisdictions -- directly to law enforcement or government contractors.
The same commercial pipeline that funds app monetisation has become a parallel surveillance infrastructure. Investigators who understand how it works can query it lawfully, interpret what it shows and -- crucially -- identify what it cannot prove.
In the field
In December 2019, the New York Times published "Twelve Million Phones, One Dataset, Zero Privacy," an investigation using a commercial location dataset containing over 50 billion pings from more than 12 million Americans. The reporting demonstrated that broker datasets marketed as anonymous could be used to trace individuals to named addresses, workplaces and sensitive locations.
- Trajectory analysis. Reporters filtered pings by time-of-day clustering to infer residential and workplace addresses, identifying named officials, law enforcement officers and intelligence personnel.
- De-anonymisation. Cross-referencing cluster centroids against public records confirmed identity, demonstrating the dataset's re-identification risk regardless of the absence of names in the raw data.
- Evidentiary standard. The team established the public benchmark for advertising-ID-based location journalism: independent corroboration, trajectory analysis rather than point attribution, and explicit confidence grading before publication.
New York Times · Twelve Million Phones, One Dataset, Zero Privacy · 19 December 2019
Learning outcomes
By the end of this tutorial you will be able to:
Explain the advertising ID pipeline and how broker datasets are structured
Query BSSID databases to corroborate device presence at a location
Use AppCensus to identify which broker SDKs are embedded in a target app
Apply the WiGLE confidence threshold before treating a BSSID result as verified
Distinguish lawful collection routes from surveillance-by-default practices
Grade advertising ID findings against the LST-001 confidence tiers
The rest of this tutorial is for Signal subscribers.
What remains: the decision framework, the tool configuration, the failure modes, and the evidentiary standard required to use the finding defensibly. Signal is €90 a year, or €9 a month. Students, €49 a year.
Join SignalA Signal subscription gives you:
- Full OSINT Reference Card library, 21 domains
- Methods, every tradecraft tutorial in full
- AI in OSINT, every prompt and field report
- Shadow Analysis, every forensic dossier


