Live data from Hacker News

A low budget consumer hardware espionage implant (2018)

ha.cking.ch

11–20 of 99 posts

Re: A low budget consumer hardware espionage implant (2018)

#13
post #10
post #4

Using SMS as the control protocol seems like a bad idea. You are generating evidence with each command sent that may or may not be stored practically forever by the telcos.

Note that SMS is the protocol advertised to buyers but the unadvertised login credentials for the web portal let you manage the device without SMS

If I understand correctly you need atleast one sms to know the credentials to the web portal. that's probably enough to get caught if someone finds the device.

Re: A low budget consumer hardware espionage implant (2018)

#15
post #11

Is there some kind of device that can detect bugs like this? (I'm thinking of the "bug sweepers" I've seen in films)

The article covers that under the section "detection".

TL;DR: You can easily detect it while it communicates via GSM, and the device is also shielded quite badly, resulting in lots of easily detectable RF interference while it works.

All you need is a cheap RF detector. Having access to a full spectrum analyzer or a SDR will make this even easier.

All this gets much harder while the thing lies dormant, waiting for noise activation or commands. So the "quick bug sweeps" you see in the movies are more difficult.

Re: A low budget consumer hardware espionage implant (2018)

#16
post #4

Using SMS as the control protocol seems like a bad idea. You are generating evidence with each command sent that may or may not be stored practically forever by the telcos.

Wouldn't someone using this sort of thing also buy a cheap burner phone and throw-away sim card? They're easy to buy with cash and you don't need to register them or anything to use them. Supermarkets in the UK even sell sims with credit already loaded onto them.

Re: A low budget consumer hardware espionage implant (2018)

#17
post #13
post #10

Earlier quoted context omitted.

Note that SMS is the protocol advertised to buyers but the unadvertised login credentials for the web portal let you manage the device without SMS

If I understand correctly you need atleast one sms to know the credentials to the web portal. that's probably enough to get caught if someone finds the device.

If you can get an unidentifiable SIM for the tracker, you can also get one + a burner phone for yourself. And if someone is stupid enough to not do that or to turn on either device in an identifiable location, they're beyond help.

Re: A low budget consumer hardware espionage implant (2018)

#19
post #11

Is there some kind of device that can detect bugs like this? (I'm thinking of the "bug sweepers" I've seen in films)

The article covers that under the section "detection". TL;DR: You can easily detect it while it communicates via GSM, and the device is also shielded quite badly, resulting in lots of easily detectable RF interference while it works. All you need is a cheap RF detector. Having access to a full spectrum analyzer or a SDR will make this even easier. All this gets much harder while the thing lies dormant, waiting for no…

We used to have keychain lights that would start to blink whenever a nearby phone went off, I can imagine it could be set off by a device like this lol.
Post reply on HN