Live data from Hacker News

Cellphone Spy Tools Have Flooded Local Police Departments

citylab.com

21–30 of 98 posts

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#21
post #6

Earlier quoted context omitted.

I don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.

No production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?

I remember seeing "lawful intercept" being mentioned somewhere in the GSM standards, and it seemed they were certainly not opposed to it...

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#22
post #6

Earlier quoted context omitted.

I don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.

No production basestation ever used the "no encryption" mode. No handset should ever accept using it, just as no browser will accept to using the NULL cipher. So what is the justification 25 years on?

Perhaps many phones don't, hence the many complaints that "phones stopped working" when the surveillance vehicle was nearby.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#23

'Cellebrite "Pro Series" purchases all appear to include the firm’s Cloud Analyzer tool, which extracts “private-user cloud data” by "utilizing login information extracted from the mobile device.' Chilling that is can be done without a warrant e.g. arrested protesters or to citizens crossing the US border.

Does this mean that as long as you use different strong passwords for everything (via say, 1Password), and do NOT use a fingerprint unlock, Cloud Analyzer wouldn't work? Or is it extracting login info in some other manner that would still function?

Presumably it'd require passwords or cookies to be downloaded from people's phones to work. With those credentials they could login to FB / Twitter / GMail etc and snoop about, downloading whatever data they can find there too.

I doubt they could do that passively. It would probably require them physically taking your (unlocked) phone and imaging it. (Which I suspect is becoming standard practice when they arrest people, if they can get away with it.)

If thats the case then 1Password would only keep your credentials safe while you aren't actually logged in to the services in question on your phone.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#24
So what is the move if you are caught with your pants down, and a LEO is requesting access to your actual phone? Does a factory restore wipe all data, or is in necessary to wipe, fill up with bunk data, wipe again?

I don't know about everyone else but my phone is has data including me talking about controversial opinions, intimate photos, and various other data that I would not want anyone else to have.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#25
post #6
post #5

Earlier quoted context omitted.

"It should be noted that, while cell phones do use encryption for content, the encryption can be turned off easily by a cell-site simulator itself, and there’s no notification that encryption is no longer operating." The incompetence of telecom companies / chipmakers knows no bounds. Of course, it could be by design.

I don't think this is malice. This is more likely an artifact of a history where encryption was not initially part of the protocol, and seamless fall back had to be supported.

GSM crypto was designed to not be strong (in the late 80s).

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#26

So what is the move if you are caught with your pants down, and a LEO is requesting access to your actual phone? Does a factory restore wipe all data, or is in necessary to wipe, fill up with bunk data, wipe again? I don't know about everyone else but my phone is has data including me talking about controversial opinions, intimate photos, and various other data that I would not want anyone else to have.

In the US, unless we are talking about a border search, LEO will still need a warrant to search your phone. I'm unsure if this is what you meant by "pants down" tho :)

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#27
post #9

I've lived in Fort Worth, TX for about a year. I was already aware of the existence of these devices. I had no clue that my local PD was spending such an insane amount of money on surveillance. It's also worth mentioning that our population is only 792K. I've lived in Texas most of life and in general I think the people here are great. However, Texans do have a tendency to blindly support anything the Military and Po…

> It's also worth mentioning that our population is only 792K.

Most of the homeland security money funding surveillance is likely tied to DFW being along a major drug distribution corridor coming up from Mexico, and has nothing to do with the local population.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#28
post #19
post #9

I've lived in Fort Worth, TX for about a year. I was already aware of the existence of these devices. I had no clue that my local PD was spending such an insane amount of money on surveillance. It's also worth mentioning that our population is only 792K. I've lived in Texas most of life and in general I think the people here are great. However, Texans do have a tendency to blindly support anything the Military and Po…

Are we powerless to stop it? Should we bother?

There are options between stop it and do nothing. I would assume cellphone companies can easily give access to any conversation from their internal network so that's probably a more cost effective solution at all levels. The question becomes, why do police feel the need for other tools?

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#29
post #11

Huh. Is there a good, open, secure encryption messaging system you can get on Android?

Signal by Open Whisper Systems is far and away the most popular right now.

Note that with cell phone spoofing, someone could impersonate you to OWS. All your contacts would get messages stating that your key ('secret numbers,' I think is the term they use) has changed, and all messages would then go to the imposter.

Re: Cellphone Spy Tools Have Flooded Local Police Departments

#30
post #11

Huh. Is there a good, open, secure encryption messaging system you can get on Android?

Android is your first problem there.

I'm inclined to say there's no reliably secure mobile platform, though idlewords (Maciej Ceglowski) and tptacek (Thomas Ptacek) are presently recommending iPhone or iPad.

(I'm writing this on an Android device I fear, dread, and detest.)

Post reply on HN