Live data from Hacker News

How a Hacker Proved Cops Used a Stingray to Find Him

politico.com

121–130 of 164 posts

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#121
post #85

I haven't worked with this stuff in a couple years (subpoena'd cell records), but given the date of this stuff, I didn't think cell phone towers could give a precise location. My understanding of them was they each had three sectors, so you could see in what general area they were in. With multiple towers, you might be able to get a more accurate reading, but it makes it sound like StingRay can actually see in real t…

A mobile telephone transmits an electromagnetic signal. Direction finding and triangulation for such signals have been known practices since the 19th and early 20th centuries. Remember that this base station impostor is mobile, and that there can be more than one.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#122
post #52

Earlier quoted context omitted.

Nit-picking a bit/kind of augmenting your train of thought. You can have non-interactive Diffie-Helman key exchange (via a PKI). As you say, the client would need to know prior to that the public key/have access to the certificate and that would require certainly revamping the DNS approach we now have (even if we did not use DNS, we would still have to deal with DNS requests).

That's literally the second option I describe. What is your point?

Your tone is unnecessarily harsh.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#124
post #2

Jesus. I wanted to keep reading that article but half way through my phone was hot enough it was burning my fingers and 20% of my battery had disappeared. What on earth is Politico doing.

I recommend FireFox Focus for mobile. It blocks JS and third party tracking by default. I wish they'd let you toggle between either of those options instead of both at once though.

Or normal FireFox with uBlock Origin if you want to maintain history, logins, etc.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#125
post #102

Earlier quoted context omitted.

The story didn't mention how they were able to get his IP address in the first place. That level of detail is important for this community!

He was filing fake tax returns. That probably exposed his IP in logs on government servers.

Should have used the USPS

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#126

The hacker was exposed because of poor OPSEC (due to tracking of his IP address). > Rigmaiden had received boxes and boxes of criminal discovery that would help him understand how the government planned to prosecute its case. In the penultimate box, he saw the word “stingray” in a set of notes. The authorities were exposed because of poor OPSEC as well. They weren't supposed to ever mention “stingray”.

It's difficult to never mention something so important, even if it's a local department rule. And once something like stingrays are well known to the public then it can be a fair inference that they are used in cases where that is the simplest explanation for how the police found or tracked a suspect. Poor OPSEC on the part of the police is basically a given in a society where we have public trials and due process (including discovery).

Whether the law allows or should allow the use of such devices, and whether with or without a warrant is up for debate, but it can't allow hiding their use, not in an open society with due process. It was always bound to be the case that some judge would think so, that some police note would leak this, that some police office would testify about it, that a Snowden would leak it, or that the public would figure it out anyways (especially when it comes to active devices).

So I wouldn't blame bad OPSEC on the part of the police here for anything. (Not that you are. Just saying.)

The defendant in the story, BTW, is not very sympathetic. In general, for test cases, one wants a sympathetic defendant. That's because judges are at least somewhat biased, typically. A judge has to imagine a much more sympathetic defendant and set of circumstances in order to convince themselves to continue with a line of argument that leads to the defendant being cleared on a technicality.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#128
post #59
post #6

The salient bit: Police found him by tracking his Internet Protocol (IP) address online first, and then taking it to Verizon Wireless, the Internet service provider connected with the account. Verizon provided records that showed that the AirCard associated with the IP address was transmitting through certain cell towers in certain parts of Santa Clara. Likely by using a stingray, the police found the exact block of…

Yes, this was the key fail. If he'd been careful enough not to leak his IP address, he would arguably have remained free. I was, for example, using VPN services and Tor well before 2008. And I've never been more than a gray-hat hobbyist sort of "hacker". Anyone seriously into criminal activity who didn't reliably hide their IP address was a fool, even then. My point isn't to dump on Rigmaiden. It's just that articles…

What anonymous methods would he have had of buying VPN access? Mailing cash? And if there wasn't stingray technology available, all the IP address could tell them was he was in the San Jose area, which the mail already told them.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#129

Earlier quoted context omitted.

What on earth? Isn't using a VPN the bare minimum when you're doing something potentially illegal?

Maybe he did. Unless he's careful in picking his VPN provider they probably have some level of cooperation with the FBI.

He didn't, but getting anonymous access to a VPN wasn't exactly the simplest thing then. And if you think they would be unable to find the precise location of the aircard, it's not really adding any protection.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#130

Something doesn’t seem to add up. First of all the story fails to mention that those devices do not only track the target, they track and record all phones in its range, which is a massive breach of privacy and the real issue with those devices. Furthermore, they allegedly already had his ip, so why bother with a stingray? They could simply tell his cell carrier to provide them with all his location data (as well as…

> Furthermore, they allegedly already had his ip, so why bother with a stingray? They could simply tell his cell carrier to provide them with all his location data Remember that getting subscriber data/metadata from ISPs requires a warrant, and that a single tower location could cover a 6-12 sq. km. area (plenty of space to hide in)

Can’t they use the towers to triangulate the exact position? So that area should be rather small. Furthermore, if they already had the IP of the offender, getting a search warrant should not be the problem at all. This tells me there is more to this story.
Post reply on HN