Live data from Hacker News

Cellphone Spy Tools Have Flooded Local Police Departments

citylab.com

11–20 of 98 posts

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#12
'Cellebrite "Pro Series" purchases all appear to include the firm’s Cloud Analyzer tool, which extracts “private-user cloud data” by "utilizing login information extracted from the mobile device.'

Chilling that is can be done without a warrant e.g. arrested protesters or to citizens crossing the US border.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#14

I have no idea how this works. Can someone explain the site simulators? When the site simulators intercept the traffic, they can see all the data. If it's encrypted, can they still read it or decrypt it somehow?

Site simulators aren't very new technology. Police departments have had these devices for so long that they were even mentioned in The Wire (2002) with the exact brand name (StingRay).

Handsets will always connect to the basestation with the strongest signal, there is no authentication involved. They then "exploit" (it's really by design) a feature of GSM where you can simply tell the handset not to use any encryption, and since the interface between baseband chip and application processor (the ARM that runs your Android or iOS) is more akin to a cold war curtain than actual information exchange, your device won't ever notify you. Even if they enable the old A55 encryption, that can be cracked in realtime nowadays.

One popular use is to mount them on a drone, wait for it to detect a particular IMSI and then bomb the general area. That is the reality of the so called "precision strikes" in Afghanistan or Iraq.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#16
post #6
post #5

Earlier quoted context omitted.

"It should be noted that, while cell phones do use encryption for content, the encryption can be turned off easily by a cell-site simulator itself, and there’s no notification that encryption is no longer operating." The incompetence of telecom companies / chipmakers knows no bounds. Of course, it could be by design.

I don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.

No production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#17

'Cellebrite "Pro Series" purchases all appear to include the firm’s Cloud Analyzer tool, which extracts “private-user cloud data” by "utilizing login information extracted from the mobile device.' Chilling that is can be done without a warrant e.g. arrested protesters or to citizens crossing the US border.

Does this mean that as long as you use different strong passwords for everything (via say, 1Password), and do NOT use a fingerprint unlock, Cloud Analyzer wouldn't work?

Or is it extracting login info in some other manner that would still function?

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#19
post #9

I've lived in Fort Worth, TX for about a year. I was already aware of the existence of these devices. I had no clue that my local PD was spending such an insane amount of money on surveillance. It's also worth mentioning that our population is only 792K. I've lived in Texas most of life and in general I think the people here are great. However, Texans do have a tendency to blindly support anything the Military and Po…

Are we powerless to stop it? Should we bother?
Post reply on HN