Perspectives on the Glacier Privacy App
Tools, techniques, and procedures for personal security
Related Articles:
https://practivesecurity.substack.com/p/digital-privacy
https://practivesecurity.substack.com/p/managing-your-online-exposure
https://practivesecurity.substack.com/p/strategies-for-secure-messaging
https://practivesecurity.substack.com/p/vpn-explained
https://practivesecurity.substack.com/p/digital-health-101-what-you-should
https://practivesecurity.substack.com/p/the-internet-gold-rush
https://practivesecurity.substack.com/p/introducing-your-online-adversary
https://www.practivesecurity.com/s/Practive-101-Safe-Browsing.pdf
In this article we are taking a look at the topic of individual privacy online and reviewing the approach provided by the Glacier App, popularized by podcaster Shawn Ryan and one of the top apps being downloaded from the Apple App Store, to see how it stacks up against real-world privacy concerns and comparable solutions in the marketplace.
Bottom Line Up Front
Threats to our privacy are multifaceted and not only do we leak highly sensitive information about ourselves, but it is also intentionally harvested from our devices by the technology and service providers we use.
Those who collect our information and weaponize it against us also make up a wide spectrum of types, capabilities, and intent.
The Glacier App claims to be an “intelligence-grade” privacy protection solution, but has a very limited scope of features and capabilities.
The app seems to primarily focus on using VPN and DNS to limit exposure to network-based methods of violating our privacy.
At $14.99 / month, the app is priced over 2x comparable solutions and comes with fewer features than most competitors.
While device-based tools are an important part of protecting your privacy online, that is only part of the entire story and the Glacier App only provides a portion of the technical capabilities you need.
Ultimately how you use technology is the greatest threat to your privacy and so defending your privacy will be mostly up to your own behavior.
Practive Security does not see the value in the Glacier App as a viable alternative to existing solutions.
On Privacy
Privacy matters because you matter. Unfortunately, in the world in which we have monetized data, attention, and influence, our story is the prized commodity of the digital age. You may be surprised to know this, but the data we generate about ourselves through using digital devices and platforms has generated the vast majority of the wealth in Silicon Valley, which carries the US economy. The truly crazy part in all that is by using devices and online services we are giving ourselves freely over to those who turn our story into profits the world has never known.
Our personal data is like the raw material in a new gold rush. It is the real currency of the Internet. But it is also a unique commodity because it is prized by so many for different purposes and we who provide it can be manipulated to providing exactly what others want from us and they turn that around and sell it back to us in the form of products and services we use that generate even more data. We are both the producers and consumers with the technology providers filling a role as the ones who provide us the means to produce what we then consume. This has created an entire ecosystem where our privacy is under attack, even by those who we would consider to be on our side (nationally).
Online influencers, platform providers, politicians, cultural influencers, adversarial nation-states, predators, hackers, fraudsters…they all want bits of our data because they can weaponize it and use it against us both directly and indirectly. But the most savvy adversary will use what we expose to get us to expose more in service to their hidden agendas.
Privacy matters because the story you tell, intentionally and unintentionally, exposes vulnerabilities that can readily be weaponized and used to manipulate, extort, expose, and influence you to enrich others at your expense. Rather than protecting you from these threats, most of the providers of “free” online services, from apps to email to social platforms, are working against us. Some are even creating free apps and services with the explicit purpose of capturing a new set of data from an unreached demographic so they can sell that information via data exchanges. Those who buy our collected data can be criminal organizations, nation-states, or giants of Silicon Valley.
In recent years it was discovered that the Biden administration was partnering with tech companies and Internet service providers, in order to spy on the online habits of US citizens they considered political adversaries. Some of these citizens included those who were critical of the Biden administration’s policies, some were concerned citizens seeking provisions and training to withstand potential natural or political emergencies, and some were faith-based organizations or individuals who had been flagged for sharing information online that ran contrary to the cultural agenda of political forces. With that information, the Biden administration labeled citizens as a threat, monitored their online activity, and even sanctioned their access to resources and ability to move freely about the nation.
Privacy matters because you are viewed as a resource to harvest, one to manipulate, and one to control.
But managing our privacy is not something we can easily outsource. Managing our privacy requires awareness of the threat and diligence on our part to limit what we expose and how it can be weaponized against us. We can and should use tools to help us in this effort, but tools cannot take the place of the responsibility we have in protecting ourselves. Because even the greatest of all privacy tools can easily be compromised by our own actions. This is why practicing what we call “operational security” or simply protecting our privacy through our actions and choices, is a critical part of the whole story.
The collection or articles referenced at the top of this one represent my attempt to convey all that you need to know about the topic of online privacy, and they are packed with strategies, tips, and recommended tools that you can leverage to protect yourself. Much of this is also relayed in our book, Practive Security 101 which is available from Amazon.com.
Recently, a new tool was released that claims to be an “intelligence-grade” privacy guard. In this article we are going to look at the advertised capabilities of that solution and how it fits into the larger ecosystem of strategies and tools you can use to protect your privacy online.
Glacier Introduction
The Glacier Privacy App is advertised as providing “intelligence-grade device protection,” and “security that sets you free,” providing this protection through three key advertised features:
1. Device security: scanning the configurations of your device for weaknesses and signs of spying.
2. Communication security: using secure DNS and VPN to protect your device from the spying eyes of the Internet.
3. Anonymity: offering “burner” phone numbers to allow you to make calls or connections without attribution back to you as an individual.
The cost is surprisingly expensive for this class of protections. At $14.99 / month (without the burner phone numbers), Glacier competes directly with other device security products and privacy service providers, but at a much higher price point than others and with fewer features. Consider Proton VPN’s privacy protection service (which includes DNS) which ranges from $0-$12 / month, or BitDefender’s full-service device and privacy protection suite which costs about $7 / month and covers more than Glacier (minus the burner numbers).
In addition to these core features, marketing from Glacier focuses a lot on their US-based VPN network and their ad-blocker service (likely provided by their DNS security). These are services also provided by competitors like Proton and BitDefender and may not provide the value that they seem to (more on that later on).
Effectively this amounts to a bundled set of security features: privacy vulnerabilities on the device, secure network transmissions, ad blocking, and burner phone numbers.
But are the protections offered by Glacier enough? Is this a special and unique solution that is worth the added expense? Does Glacier stand out against the competition? That’s what I am going to assess by comparing their solution to my own “intelligence-grade” professional experience of over 25 years in combating nation-state espionage and military operations. I’m going to use competitive comparisons of products with similar features; namely Proton VPN and BitDefender.
Note: part of the Glacier marketing is that it was built by members of the intelligence community based on their experiences in special device protection contexts. It’s important to know that any specific knowledge those individuals gained in those contexts cannot be used in commoditized commercial applications or products unless that knowledge is available in the public domain. Intelligence community experience is helpful in that those with that background know what to focus on and prioritize, and they know what works and what doesn’t, but this has limitations in the commercial context.
Spying Eyes
Before we can assess if the service is sufficient in countering threats to our privacy, we need to understand the ways in which we are spied upon through our devices and who wants our private data.
Defining who our adversary is, is relatively straight forward: anyone who can use information about us that exposes a vulnerability they can exploit in order to force their will upon us and our expense and their enrichment. This can include:
Government actors (espionage, military, civil)
Technology providers
Advertisers
Predators
Hackers / criminals / fraudsters
Activists
Individual adversaries (competitors, jealous coworkers, former friends etc.)
Every bit of information shared by you can represent a bit of information that can be collected together among other sets of information in order to craft an action or series of actions against you. Those who weaponize your information may use it to:
Monitor your location, activity, communications, and relationships
Create a scenario of familiarity or trust that you will participate unto their ends
Claim to be someone you know or trust
Create scenarios for extortion or manipulation
Lure you into participation or exposure in order to influence you
Use your information to impersonate you to others or claim to be a trusted friend or representative of you—this can include using your information to gain access to people or resource that belong to you
Use your information to understand how to best target you (your device, services you use, software versions, location information and more)
The reality is what we expose, intentionally or otherwise, creates opportunity for others to find ways to attack us. How is our privacy compromised and our story told? Primarily through the communications our devices send, the information our apps generate and transmit, what we participate with online and how that is recorded, and of course what we post, send, click, share etc.
The moment our devices connect to a cellular or wifi network, they begin transmitting information about us. Those transmissions contain details that expose where we are, what our device is, what apps we are using, who we are, who we are communicating with, our account names, the Internet services we use, and more. As we use our devices, the story of our online activity (apps we use, websites we visit, people we communicate with, places from which we use our devices) adds details which expose the larger story and the patterns of our life. You would be stunned to learn all that can be derived about you simply by watching your device use via what it transmits.
Those transmissions are all visible to your network providers, and potentially any network peer (other devices on the same network), as well as any information sharing partnerships your providers hold with third parties (including other tech companies but also law enforcement and government agencies). Sometimes the networks that legitimately provide us connections to the Internet are compromised and an adversary has inserted devices or code that spies on all people who use that network. Sometimes rogue network gateways such as wifi routers are used by threat actors and intelligence agencies, which pose as legitimate Internet service providers and lure unsuspecting people to join those rogue networks. This is often the case at hotels, airports, and places that offer public wifi services.
Much of the data our devices transmit is protected with encryption that prevents third parties from being able to see the full details of what is sent and received, but it is often the case that enough information is intentionally leaked by apps and Internet services for the providers to gather many details that tell more about you than you realize. There are also ways for adversaries to setup rogue proxies that can decrypt our encrypted communications before relaying them to the real intended destination. In cyber security, we call that tactic a man-in-the-middle attack.
In the early 2000s, in what is referred to as the Comodo breach, the nation of Iran performed a man-in-the-middle attack that compromised the Internet connections of their entire population of citizens who were using common Internet services provided by Google and others. All network connections, emails, searches, website visits etc. send from individual computers and smartphones to Google were intercepted by the Iranian government and read without individual knowledge of the users transmitting them. In recent years both the nations of Russian and China have routed entire segments of global Internet traffic through their Internet infrastructure where it was exposed to spying by the Chinese government. But these attacks also happen at the small-scale as I recently reported in a threat brief about an individual who joined a rogue wifi network at a major US airport and had their device compromised almost instantly.
But the apps on our devices are also spying on us even when connected to legitimate networks. Our apps are always collecting information from our devices and also transmitting information about our use of the app to the app owner and their networks and their partners and affiliates. Depending on how the app communicates and what features it uses on our local device, a great deal of information may be exposed to third parties who can learn a lot about us.
Rogue apps are also a major problem, especially with the Android ecosystem. Adversaries know that if they can install an app onto our device, they can use it to collect information that can be used for their gain. Intelligence agencies all over the world use rogue apps to infiltrate militaries and governments, turning otherwise secure phones into mobile espionage platforms. But common criminals have also heavily weaponized Android app stores and regularly upload malicious apps that steal data or are used for extortion and ransom attacks. We have also reported cases of these in recent months.
Web browsers are a major problem to consider as well. Web browsers not only send information about us to websites and web services we access through them, but they also receive instructions from online services and can run commands or relay commands that can collect information we didn’t mean to transmit. Much of that spying happens through ads on websites that actually run code on our computer through our web browser. That code can be used to install trackers that monitor our Internet activities, or they can profile our devices and transmit that information back to whomever controls the ad. Weaponizing ad and content distribution networks so that malicious code appears on legitimate websites is a major problem. Browser plugins have made this even worse since they can, in real time, collect information and manipulate our online experience. Some browser plugin providers have partnerships with third parties
And of course the platform providers we use in the social spaces and for free Internet services make their money by aggressively harvesting information about us and creating apps that generate information that they can either use in their platforms for targeted advertising or influential content (think mind and behavior control) or sell to others to use. Platforms like Facebook, WhatsApp, TikTok, Google and more are notorious for this, but nearly every company in Silicon Valley today tries to use their platform in the larger economy of what is called data monetization. That roughly means collecting data about you that they can turn into money for them without your knowledge or awareness.
And the final place to consider as a source of leaking our story is of course we ourselves. What we do online, including what we transmit, post, share, like etc. is all telling a story about us that can be seen by whomever we share it with and potentially whomever they share it with. But we also have to consider that whomever receives the information we have transmitted, may be themselves compromised with spyware or malware or some other form of espionage so that our story can be collected by third parties who we don’t even know exist.
In all these ways, our personal privacy and security are in the hands of everyone else we interact with through the digital world. And that sharing can be used to affect all that we are: our heart, our mind, our body, our soul, and our property, because all that we share can be used to engage us in an intentional way for harm. How do we protect ourselves? Read on.

