Live data from Hacker News

A low budget consumer hardware espionage implant (2018)

ha.cking.ch

51–60 of 99 posts

Re: A low budget consumer hardware espionage implant (2018)

#53

Earlier quoted context omitted.

You can literally go into almost any corner shop in the UK and buy a SIM with no ID and cash. I do this regularly.

Are you regularly swapping SIMs? Are you keeping the same IMEI number?

If you're hacking around with phones or GSM boards for fun, on and off, it is cost effective to just grab one for a pound or so every time you want to do something as they sometimes come with a tiny bit of free data, or just a number to receive SMS on at least.

If you don't top up (with say a tenner) within some months the card deactivates and becomes useless, so it's a no-commitment way to access the GSM network.

Re: A low budget consumer hardware espionage implant (2018)

#54

Earlier quoted context omitted.

I can't imagine the UK doesn't have laws to prevent anonymous SIM card purchases, because of terrorism fears. Some duckduckgo-ing suggests it's possible, e.g. someone wrote just go to Tesco to get one and there are no ID checks (but this was written 6 years ago). In any case, just like teenagers buying booze, it's probably not that hard to pay someone off the street to buy one for you.

No ID is required to buy a pay as you go SIM card in the UK. Just walk into any supermarket or pretty much any corner shop and they will sell you a Sim for a quid at most. (You can also get them for free from the networks directly on their websites, but now they know the address the sim was sent too) Top up credit is the same, ask the counter staff for £x on network Y and once you have paid they will give you a print…

I thought I read you could buy "adult verification cards" by going to a newsstand and presenting ID that is potentially verified by the seller (if you appear underage) but not recorded. Like alcohol or tobacco purchases are in the US.

Re: A low budget consumer hardware espionage implant (2018)

#56
post #11

Is there some kind of device that can detect bugs like this? (I'm thinking of the "bug sweepers" I've seen in films)

I posted this on my Discord, one of our members is a security guy and pointed out that anyone concerned about things like this would be using a device called a NLJD, Non-Linear Junction Detector: https://reiusa.net/nljd/ , which can detect circuit boards: > The NLJD antenna head is a transceiver (transmitter and receiver) that radiates a digital spread spectrum signal to determine the presence of electronic component…

Exactly the kind of thing I was looking for! Although, I guess for a bug hidden within an electrical device (like that in the article), this approach wouldn't work?

I wonder how well these work against shielding? Might it be possible to build your own device like this?

Re: A low budget consumer hardware espionage implant (2018)

#57
post #12
post #11

Is there some kind of device that can detect bugs like this? (I'm thinking of the "bug sweepers" I've seen in films)

The article has a section on that very topic: https://ha.cking.ch/s8_data_line_locator/#detection

Thanks; I did actually read the article, but missed this section (and likely some others) as the page doesn't work well on mobile.

Re: A low budget consumer hardware espionage implant (2018)

#58
post #56

Earlier quoted context omitted.

I posted this on my Discord, one of our members is a security guy and pointed out that anyone concerned about things like this would be using a device called a NLJD, Non-Linear Junction Detector: https://reiusa.net/nljd/ , which can detect circuit boards: > The NLJD antenna head is a transceiver (transmitter and receiver) that radiates a digital spread spectrum signal to determine the presence of electronic component…

Exactly the kind of thing I was looking for! Although, I guess for a bug hidden within an electrical device (like that in the article), this approach wouldn't work? I wonder how well these work against shielding? Might it be possible to build your own device like this?

It would ‘work’ - but not be useful, because you’d already expect a circuit in that location.

Re: A low budget consumer hardware espionage implant (2018)

#60

An even easier one would be a modified keyboard. Anyone could fit an esp32 into a keyboard, swap it out, leave it lying around, sniff keystrokes, access with Bluetooth or WiFi, could have it only have the radio on for certain windows in time etc.

Even better use esp long range and have a receiver device outside maybe powered via solar… connected to cell network… this way no additional networks exposed internally…
Post reply on HN