I haven't worked with this stuff in a couple years (subpoena'd cell records), but given the date of this stuff, I didn't think cell phone towers could give a precise location. My understanding of them was they each had three sectors, so you could see in what general area they were in. With multiple towers, you might be able to get a more accurate reading, but it makes it sound like StingRay can actually see in real t…
How a Hacker Proved Cops Used a Stingray to Find Him
121–130 of 164 posts
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#122Earlier quoted context omitted.
Nit-picking a bit/kind of augmenting your train of thought. You can have non-interactive Diffie-Helman key exchange (via a PKI). As you say, the client would need to know prior to that the public key/have access to the certificate and that would require certainly revamping the DNS approach we now have (even if we did not use DNS, we would still have to deal with DNS requests).
That's literally the second option I describe. What is your point?
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#123How can he call himself a hacker when he doesn't know how to hide his ip?
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#124Jesus. I wanted to keep reading that article but half way through my phone was hot enough it was burning my fingers and 20% of my battery had disappeared. What on earth is Politico doing.
I recommend FireFox Focus for mobile. It blocks JS and third party tracking by default. I wish they'd let you toggle between either of those options instead of both at once though.
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#125Earlier quoted context omitted.
The story didn't mention how they were able to get his IP address in the first place. That level of detail is important for this community!
He was filing fake tax returns. That probably exposed his IP in logs on government servers.
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#126The hacker was exposed because of poor OPSEC (due to tracking of his IP address). > Rigmaiden had received boxes and boxes of criminal discovery that would help him understand how the government planned to prosecute its case. In the penultimate box, he saw the word “stingray” in a set of notes. The authorities were exposed because of poor OPSEC as well. They weren't supposed to ever mention “stingray”.
Whether the law allows or should allow the use of such devices, and whether with or without a warrant is up for debate, but it can't allow hiding their use, not in an open society with due process. It was always bound to be the case that some judge would think so, that some police note would leak this, that some police office would testify about it, that a Snowden would leak it, or that the public would figure it out anyways (especially when it comes to active devices).
So I wouldn't blame bad OPSEC on the part of the police here for anything. (Not that you are. Just saying.)
The defendant in the story, BTW, is not very sympathetic. In general, for test cases, one wants a sympathetic defendant. That's because judges are at least somewhat biased, typically. A judge has to imagine a much more sympathetic defendant and set of circumstances in order to convince themselves to continue with a line of argument that leads to the defendant being cleared on a technicality.
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#127How can he call himself a hacker when he doesn't know how to hide his ip?
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#128The salient bit: Police found him by tracking his Internet Protocol (IP) address online first, and then taking it to Verizon Wireless, the Internet service provider connected with the account. Verizon provided records that showed that the AirCard associated with the IP address was transmitting through certain cell towers in certain parts of Santa Clara. Likely by using a stingray, the police found the exact block of…
Yes, this was the key fail. If he'd been careful enough not to leak his IP address, he would arguably have remained free. I was, for example, using VPN services and Tor well before 2008. And I've never been more than a gray-hat hobbyist sort of "hacker". Anyone seriously into criminal activity who didn't reliably hide their IP address was a fool, even then. My point isn't to dump on Rigmaiden. It's just that articles…
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#129Earlier quoted context omitted.
What on earth? Isn't using a VPN the bare minimum when you're doing something potentially illegal?
Maybe he did. Unless he's careful in picking his VPN provider they probably have some level of cooperation with the FBI.
Re: How a Hacker Proved Cops Used a Stingray to Find Him
#130Something doesn’t seem to add up. First of all the story fails to mention that those devices do not only track the target, they track and record all phones in its range, which is a massive breach of privacy and the real issue with those devices. Furthermore, they allegedly already had his ip, so why bother with a stingray? They could simply tell his cell carrier to provide them with all his location data (as well as…
> Furthermore, they allegedly already had his ip, so why bother with a stingray? They could simply tell his cell carrier to provide them with all his location data Remember that getting subscriber data/metadata from ISPs requires a warrant, and that a single tower location could cover a 6-12 sq. km. area (plenty of space to hide in)