Live data from Hacker News

How a Hacker Proved Cops Used a Stingray to Find Him

politico.com

81–90 of 164 posts

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#82
post #81

Is there a physical device that can provide VPN-only wifi connection, so that a laptop or wifi-only ipad (say) which were to connect to it would not risk ever exposing its IP?

You can configure your router to route all traffic through a VPN. It's a standard setting in all routers.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#83

This guy wasn't really a hacker, just someone who knew a little bit about tech and figured out a flawed system. I think that sums him up as a scammer instead of a hacker.

This. He filed false tax returns with stolen identities, I fail to see any activities one would associate with a technical hack. I also have a hard time understanding why someone who is engaging in criminal acts has a reasonable expectation to privacy related to the commission of said crimes.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#84

This guy wasn't really a hacker, just someone who knew a little bit about tech and figured out a flawed system. I think that sums him up as a scammer instead of a hacker.

To be fair that is fundamentally what hacking is - noticing a flawed system an exploiting it. "Just scamming" would be convincing people that they need to use him to get tax refunds while he cashes it and takes a cut. Closer to fraud in many ways too really.

Really the term hacking could use more consistent sub-definitions per type. Social engineering is well established but there isn't even a uniform term for quickly conveying the nuance of say cracking DRM offline vs getting in a server.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#85
I haven't worked with this stuff in a couple years (subpoena'd cell records), but given the date of this stuff, I didn't think cell phone towers could give a precise location. My understanding of them was they each had three sectors, so you could see in what general area they were in. With multiple towers, you might be able to get a more accurate reading, but it makes it sound like StingRay can actually see in real time their position.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#86
post #52

Earlier quoted context omitted.

Nit-picking a bit/kind of augmenting your train of thought. You can have non-interactive Diffie-Helman key exchange (via a PKI). As you say, the client would need to know prior to that the public key/have access to the certificate and that would require certainly revamping the DNS approach we now have (even if we did not use DNS, we would still have to deal with DNS requests).

That's literally the second option I describe. What is your point?

What you guys are describing is starting to sound more and more like onion routing.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#87
post #85

I haven't worked with this stuff in a couple years (subpoena'd cell records), but given the date of this stuff, I didn't think cell phone towers could give a precise location. My understanding of them was they each had three sectors, so you could see in what general area they were in. With multiple towers, you might be able to get a more accurate reading, but it makes it sound like StingRay can actually see in real t…

[deleted]

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#88
post #19
post #18

Earlier quoted context omitted.

Lest anyone believe their positional privacy is at risk, even the Verizon routing prefix could have homed the cops onto which provider to drill down into. The take-away here, is that end-to-end protocols by neccessity as currently written send the src IP in the packet. If we'd designed IP to send the src IP as a payload, and had encrypted payload (TLS style) and then only had the destination IP in the outer packet, t…

If the source IP is encrypted, the recipient needs to decrypt it first in order to be able to send a response. To decrypt it, it needs to either have some shared secret with the sender, or the sender needs to use the recipient's private key. The parties cannot obtain the shared secret the usual way, the Diffie-Helman exchange. It cannot be performed, because it requires back-and-forth communication, which we are tryi…

> but it leads to all kinds of practical problems, figuring out which is probably best left as an exercise for the reader.

Any examples? I honestly don't see any problems here.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#89
post #59
post #6

The salient bit: Police found him by tracking his Internet Protocol (IP) address online first, and then taking it to Verizon Wireless, the Internet service provider connected with the account. Verizon provided records that showed that the AirCard associated with the IP address was transmitting through certain cell towers in certain parts of Santa Clara. Likely by using a stingray, the police found the exact block of…

Yes, this was the key fail. If he'd been careful enough not to leak his IP address, he would arguably have remained free. I was, for example, using VPN services and Tor well before 2008. And I've never been more than a gray-hat hobbyist sort of "hacker". Anyone seriously into criminal activity who didn't reliably hide their IP address was a fool, even then. My point isn't to dump on Rigmaiden. It's just that articles…

IMHO, it's less about privacy being impossible, and more about privacy being difficult and expensive.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#90
post #35
post #16

Earlier quoted context omitted.

Except that: 1) If you do it from home, the govt already knows where you live, or you can use proxies, or Tor, or a VPN. 2) If you don't do it from home, you are practically anonymous if you change your mac address and use someone else's wireless network, which are ubiquitous today in airports, restaurants, etc.

Another thing that is ubiquitous today in airports, restaurants etc. is CCTV.

It's technically infeasible to locate someone via CCTV unless you have an accurate location already, for precisely this reason - there's a massive surfeit of data to search through, and current facial-recognition software is incapable of the task.
Post reply on HN