The U.S. military has disabled advertising tracking tools in government-issued phones, computers and other devices, officials recently told Congress. The different military branches confirmed they had done so, some only this summer, following reporting that commercially available data taken from these devices and sold freely by data brokers, was being used by Iran and other adversaries to track and in some cases target American bases and personnel. The confirmation came from a letter shared by Sen. Ron Wyden (D-Ore.) and Rep. Pat Harrigan (R-NC). The letter calls on the Department of Defense Office of the Inspector General to review department security guidelines. Wyden and others revealed in a similar letter in May that foreign groups were using commercially available location data to target U.S. troops. “The sale of location data, particularly that of U.S. government personnel, poses a serious threat to national security,” Wyden wrote. According to Wyden and Harrigon’s letter, the Army, Navy, Air Force, Marine Corps and Special Operations Command all confirmed they have disabled mobile advertising IDs on government-issued devices. However, that has only been recent for some service branches; the Air Force admitted in its letter to the members of Congress that it only directed disabling ad trackers in July. Mobile advertising IDs, also known as MAIDs , are unique identifying numbers that go with specific devices. They are a key part of the data collected by mobile apps and can track location, common routes and habits, something that can be exploited by adversarial groups. Disabling those MAIDs is “a very simple and straightforward way that you can close a loophole,” according to Eva Galperin, Director of Cybersecurity for the Electronic Frontier Foundation. MAIDs aren’t the only way devices can be tracked, but are a major one. “Minimizing the attack surface is always good, even if