10 ms·
Cellphone Spy Tools Have Flooded Local Police Departments
- analogmemory 10y agoI have no idea how this works. Can someone explain the site simulators? When the site simulators intercept the traffic, they can see all the data. If it's encrypted, can they still read it or decrypt it somehow?
- dsp1234 10y agohttps://www.eff.org/sls/tech/cell-site-simulators/faq#faq-How-does-it-work https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-Ho...?
- lend000 10y ago"It should be noted that, while cell phones do use encryption for content, the encryption can be turned off easily by a cell-site simulator itself, and there’s no notification that encryption is no longer operating." The incompetence of telecom companies / chipmakers knows no bounds. Of course, it could be by design.
- Kalium 10y agoI don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.
- revelation 10y agoNo production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?
- userbinator 10y agoI remember seeing "lawful intercept" being mentioned somewhere in the GSM standards, and it seemed they were certainly not opposed to it...
- deleted 10y ago[deleted]
- tastythrowaway2 10y agothey don't have the option to oppose (in the US, at least): https://en.m.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.m.wikipedia.org/wiki/Communications_Assistance_fo...
- ptaipale 10y agoAnd the same has been true in practically all countries, democratic or not, developed or not, ever.
- ams6110 10y agoPerhaps many phones don't, hence the many complaints that "phones stopped working" when the surveillance vehicle was nearby.
- funnyfacts365 10y agoThey stop working maybe because the stingray is only collecting identifiers instead if conducting a true MITM attack and forwarding any calls por SMS's. In any case, I suspect they could only do a MITM to outgoing traffic, so any incoming traffic/data would not be delivered, like the phone is out of service/no network.
- throwawayish 10y agoGSM crypto was designed to not be strong (in the late 80s).
- deleted 10y ago[deleted]
- justinjlynn 10y agoIt is absolutely by design. The GSM standard recommends that, if encryption is disabled, the user be notified. This feature is called the "chiphering indicator". However, practically none of the available handsets do so.
- justinjlynn 10y agooops, "ciphering" ... also, even if the handset supports ciphering indication the SIM can disable it. Oh, and you're not permitted to reconfigure that part of the SIM either.
- analogmemory 10y agoDoes it affect the data connection, like a SSL connection to my bank? Can it see that data stream as well?
- revelation 10y agoSite simulators aren't very new technology. Police departments have had these devices for so long that they were even mentioned in The Wire (2002) with the exact brand name (StingRay). Handsets will always connect to the basestation with the strongest signal, there is no authentication involved. They then "exploit" (it's really by design) a feature of GSM where you can simply tell the handset not to use any encryption, and since the interface between baseband chip and application processor (the ARM that runs your Android or iOS) is more akin to a cold war curtain than actual information exchange, your device won't ever notify you. Even if they enable the old A55 encryption, that can be cracked in realtime nowadays. One popular use is to mount them on a drone, wait for it to detect a particular IMSI and then bomb the general area. That is the reality of the so called "precision strikes" in Afghanistan or Iraq.
- iak8god 10y ago> One popular use is to mount them on a drone, wait for it to detect a particular IMSI and then bomb the general area. That is the reality of the so called "precision strikes" in Afghanistan or Iraq. Holy crap. Do you have a good source for that? I've somehow never heard this before.
- zkms 10y agoAFAICT the codename for the SIM-card-finding operation on drones is "GILGAMESH", here's a few things about it: See https://theintercept.com/2014/02/10/the-nsas-secret-role/ https://theintercept.com/2014/02/10/the-nsas-secret-role/ and https://theintercept.com/surveillance-catalogue/gilgamesh/ https://theintercept.com/surveillance-catalogue/gilgamesh/
- arca_vorago 10y ago“Criminals tend to try and make tracking their data more difficult, so this kind of mass collection of telephony data will more easily find our political activists, our civil society leaders, and just regular people,” he says. “If the courts—if the public—knew how powerful these tools were, they would move to restrict their use.” The mass surveillance system is about control, not security, and I think time and time again that is being proven. On the constitutional post-warrant data anlysis tools I have these issues: 1) This is local law enforcement wising up and playing a similar game to the big three letters. 2) I have concerns about the privacy protections for those associated with suspects, and see ripe abuse potential for guilt by association or even "using data from a warrant to get the data on the person you really want but can't get the warrant" type of situations. 3) I have concerns with the level of data sharing between the LEA's, and the post shared protections of said data. 4) I have concerns with private companies providing these services because private companies often have sub-par data security practices, and often have strange third-party data selling loopholes so they often end up "scrubbing" data and selling it, but most of us know it's not that hard these days to "unscrub" that kind of data. All of this is assuming we are just talking about constitutional methods too. What I find even more insidious and dangerous is the unconstitutional tools like imsicatchers and others being used for parallel construction. Bottom line is this: the LEA's and LEO's need to remember that they swear an oath: "I, [name], do solemnly swear (or affirm) that I will support and defend the Constitution of the United States against all enemies, foreign and domestic; that I will bear true faith and allegiance to the same;" The problem as I see it, is that I tracked down the law that punishes congress for a few specific violations of oath of office (5 U.S. Code § 7311), but I have yet to find any law for punishing people in the executive branch for violation of oath of office. If anyone knows of such, please let me know. IANAL, so perhaps 5 U.S. Code § 7311 could apply to the executive and I just misunderstand it.
- deleted 10y ago[deleted]
- sh-run 10y agoI've lived in Fort Worth, TX for about a year. I was already aware of the existence of these devices. I had no clue that my local PD was spending such an insane amount of money on surveillance. It's also worth mentioning that our population is only 792K. I've lived in Texas most of life and in general I think the people here are great. However, Texans do have a tendency to blindly support anything the Military and Police want to do, while at the same time complaining about big government. I guess I'd better start bringing this up in my circles. I don't think many people are fully aware of what's going on.
- jjawssd 10y agoAre we powerless to stop it? Should we bother?
- Retric 10y agoThere are options between stop it and do nothing. I would assume cellphone companies can easily give access to any conversation from their internal network so that's probably a more cost effective solution at all levels. The question becomes, why do police feel the need for other tools?
- barake 10y agoCellphone companies is one more layer in their trust circle. It's easier to just bypass them and collect the data yourself. Warrants only really became a requirement in 2015. And police were misleading judges on Stingray usage to hide the tech. https://arstechnica.com/tech-policy/2016/03/appeals-court-no-stingrays-without-a-warrant-explanation-to-judge/ https://arstechnica.com/tech-policy/2016/03/appeals-court-no...
- upofadown 10y agoCasual ad hoc surveillance can be very useful for law enforcement. It can save a tremendous amount of time and money keeping track of where people are and where they are planning to be. The fact that the information gained is not admissible in court is not important. From the article: >“You guys picking up any information? Where they're going, possibly?" Law enforcement has become somewhat dependent on this sort of access and would not be able to do their job as effectively without it. Hence the desperation shown by the use of things like Stingrays where the network is actively attacked in what is arguably a straight up illegal way.
- M_Grey 10y agoHuh. Is there a good, open, secure encryption messaging system you can get on Android?
- simplyluke 10y agoSignal by Open Whisper Systems is far and away the most popular right now.
- M_Grey 10y agoThanks, I appreciate that.
- wtbob 10y agoNote that with cell phone spoofing, someone could impersonate you to OWS. All your contacts would get messages stating that your key ('secret numbers,' I think is the term they use) has changed, and all messages would then go to the imposter.
- wapz 10y agoDo you have any info on how cell phone spoofing works? Is the IMEI number used by signal to verify you?
- hughw 10y agoIsn't WhatsApp more popular? I understood it to be more popular and accessible while still using the Signal protocol.
- SturgeonsLaw 10y agoMore popular, but also closed source and owned by Facebook (make of that what you will)
- stevehawk 10y agowho has publicly stated that they're mining the metadata, and does not by default notify you when one end's keys change (say if the phone were compromised).
- jakelarkin 10y ago'Cellebrite "Pro Series" purchases all appear to include the firm’s Cloud Analyzer tool, which extracts “private-user cloud data” by "utilizing login information extracted from the mobile device.' Chilling that is can be done without a warrant e.g. arrested protesters or to citizens crossing the US border.
- shostack 10y agoDoes this mean that as long as you use different strong passwords for everything (via say, 1Password), and do NOT use a fingerprint unlock, Cloud Analyzer wouldn't work? Or is it extracting login info in some other manner that would still function?
- josephg 10y agoPresumably it'd require passwords or cookies to be downloaded from people's phones to work. With those credentials they could login to FB / Twitter / GMail etc and snoop about, downloading whatever data they can find there too. I doubt they could do that passively. It would probably require them physically taking your (unlocked) phone and imaging it. (Which I suspect is becoming standard practice when they arrest people, if they can get away with it.) If thats the case then 1Password would only keep your credentials safe while you aren't actually logged in to the services in question on your phone.
- nawtacawp 10y agoI would venture to say that a search warrant for a device, would not cover the contents stored in the cloud. While the cellebrite does have this feature I would presume a separate warrant would be required to obtain the cloud data, which is located in another physical location.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- troncheadle 10y agoSo what is the move if you are caught with your pants down, and a LEO is requesting access to your actual phone? Does a factory restore wipe all data, or is in necessary to wipe, fill up with bunk data, wipe again? I don't know about everyone else but my phone is has data including me talking about controversial opinions, intimate photos, and various other data that I would not want anyone else to have.
- mhays 10y agoIn the US, unless we are talking about a border search, LEO will still need a warrant to search your phone. I'm unsure if this is what you meant by "pants down" tho :)
- Tangurena2 10y agoIn the US, use passwords to protect your phone. Passwords have been held by courts to be testimony and thus protected by the 5th Amendment. Patterns, swipes, facial recognition and fingerprints have been held by courts to be the equivalent of "keys" and you can be required to turn them over upon being ordered by a lawful authority (such as a police officer demanding them). Passwords require a court order and if you have a competent attorney, they can argue that revealing the password would result in self-incrimination (and this can spend a lot of time in court before anything happens).
- freedrock87 10y agohttps://arstechnica.com/tech-policy/2017/02/justice-naps-man-jailed-16-months-for-refusing-to-reveal-passwords/ https://arstechnica.com/tech-policy/2017/02/justice-naps-man...
- Too 10y agoUse full drive encryption.
- nawtacawp 10y agoFirst, it would vary by phone -- but if LEO is requesting your phone and do not have a warrant (yet), they could still seize the phone citing exigent circumstances. The exigent circumstances being that if they left the phone in the custody of the subject, then they will likely delete the contents or at least could delete the contents. Once the phone is in LEO possession then they can take the time to apply for a warrant to search the device. So -- if you get to the point of LEO requesting your phone and you have data on your phone, then it is too late.
- a3n 10y agoSo if the Washington D.C. police, or anyone who can afford it, are tracking protesters, or merely tracking, near the White House, they may inadvertently intercept calls from all those insecure, non-presidentially locked phones carried by top White House aides, and by the President?
- JustSomeNobody 10y agoDo the cell site simulators spoof existing towers? How hard would it be to write an app to detect when you connect to another tower and shut the phone down. Unless Google and Apple don't let you programmatically shut down the phone.
- 2_listerine_pls 10y agoStingray's inner workings are supposedly not disclosed but it is said to mimic a nearby cell tower. I bet the device just echoes & amplifies the signal to trick your phone to connect. If that's how it works, then If you know what each tower relative strength from that given position must be and you note a new surge in strength, that will tell you. You could also use triangulation with cooperating devices.
- notatoad 10y agoNote that cell providers will install perfectly legitimate temporary towers to handle increased demand, so simply looking for a surge in signal strength over "normal" levels doesn't necessarily indicate surveillance.
- multidelo 10y agohttps://cellularprivacy.github.io/Android-IMSI-Catcher-Detector/ https://cellularprivacy.github.io/Android-IMSI-Catcher-Detec...
- spyder 10y agoSnoopsnitch: https://play.google.com/store/apps/details?id=de.srlabs.snoopsnitch https://play.google.com/store/apps/details?id=de.srlabs.snoo... ( requires a rooted device with Qualcomm chipset) Cell Spy Catcher: https://play.google.com/store/apps/details?id=com.skibapps.cellspycatcher&hl=en https://play.google.com/store/apps/details?id=com.skibapps.c... https://play.google.com/store/apps/details?id=kz.galan.antispy https://play.google.com/store/apps/details?id=kz.galan.antis...
- dandare 10y agoI think the only thing that can prevent the US from spiraling into a dictatorship is a successful Netflix show about US spiraling into a dictatorship. Maybe it is too late for that too.
- al2o3cr 10y agoHoly passive voice, Batman. Surely a better title would have been "Local Police Departments Buying Loads of Cellphone Spy Tools", since it's not like the damn things are mysteriously appearing unbidden...
- DyslexicAtheist 10y agohackingteam breach has shown that law enforcement are among the biggest customers of HackingTeam. They supply not just the tools but also a subscription (to the constantly changing) payloads to breach a target. Kind of a poor man's TAO for the "neighborhood" police-unit. These tools make planting evidence just as easy so it is a massive change in the amount of trust put into individuals working in LE. This is even more scary when you think of how little the average cop knows about the tech they use from some questionable outside private vendor. https://media.ccc.de/v/30C3_-_5439_-_en_-_saal_1_-_201312292105_-_to_protect_and_infect_-_claudio_guarnieri_-_morgan_marquis-boire https://media.ccc.de/v/30C3_-_5439_-_en_-_saal_1_-_201312292... https://www.technologyreview.com/s/543991/the-growth-industry-helping-governments-hack-terrorists-criminals-and-political/ https://www.technologyreview.com/s/543991/the-growth-industr...
- lfender6445 10y agoWould wifi calling help in a situations like these?
- ParadoxOryx 10y agoYes, your calls would be traveling over an encrypted tunnel to the carrier instead of the (simulated) cell tower, thus preventing the Stingray/site-simulator from carrying and listening in on your call. However, it would not stop someone from listening to the call at any point over the rest of the path since the call itself is not encrypted, only the transport between the carrier and your phone.
- Jill_the_Pill 10y agoAnalyzing this sort of data is why the NYPD is suddenly hiring 100 statisticians? https://www.linkedin.com/jobs/view/245927769 https://www.linkedin.com/jobs/view/245927769 http://www.nypdrecruit.com/statistician-level-1/ http://www.nypdrecruit.com/statistician-level-1/
- Jill_the_Pill 10y agoAnalyzing this sort of data is why the NYPD is suddenly hiring 100 statisticians? https://www.linkedin.com/jobs/view/245927769 https://www.linkedin.com/jobs/view/245927769 http://www.nypdrecruit.com/statistician-level-1/ http://www.nypdrecruit.com/statistician-level-1/
- theonespy 10y agoI think it's not just the Govt and Police who involves in spying on people's data. Multiple spy apps i.e. TheOneSpy, PhoneSherif, FlxiSpy, and much more are readily available in the online market to spy on anyone's data through his/her smartphone. In my point of view first, we should ban these data and privacy breach apps in our state then move on the other Governmental monitorings and protect our privacies.