Live data from Hacker News

How to Block Stingray Devices

oaklandmofo.com

31–40 of 58 posts

Re: How to Block Stingray Devices

#31
post #8

Earlier quoted context omitted.

I do not know the specifics of the Stingray, but I can tell you more similair "lawfull interception" devices exist. These devices "talk" with your Baseband; the radio in your phone that runs it's own OS. Many of these can do DMA to with the memory of your "phone" / ordinary soc. Theoretically, a exploited baseband could allow the lawfull interception device to read and write to your internal storage and more. I have…

I can't speak for Google devices but per Apple's iOS security whitepaper (page 41) [1]: "To protect the device from vulnerabilities in network processor firmware, network interfaces including Wi-Fi and baseband have limited access to application processor memory. When USB or SDIO is used to interface with the network processor, the network processor can’t initiate Direct Memory Access (DMA) transactions to the applic…

PS4 PCI-E accesses were protected with an IO MMU too, but they managed to screw it up. So that doesn't necessarily mean that it's safe.

Re: How to Block Stingray Devices

#32
post #30
post #6

Earlier quoted context omitted.

Okay, thanks for the explanation. Meanwhile, setting my Samsung Galaxy S9 to no-2G gives me a warning message that cannot be dismissed: "This setting turns off 2G service. If 2G service is off, some app..." (the remainder can't be viewed).

> (the remainder can't be viewed). Sounds like terrific UI design

Also like their QA team is slacking, if they have one.

Re: How to Block Stingray Devices

#33
post #30

Earlier quoted context omitted.

> (the remainder can't be viewed). Sounds like terrific UI design

Also like their QA team is slacking, if they have one.

> if they have one

I believe they have a single QA person who is paid minimum wage and whose desk is in a broom closet somewhere, judging from my own experiences...

Re: How to Block Stingray Devices

#35

Earlier quoted context omitted.

Also like their QA team is slacking, if they have one.

> if they have one I believe they have a single QA person who is paid minimum wage and whose desk is in a broom closet somewhere, judging from my own experiences...

Sadly just because you have a QA department doesn't mean much. Your investment is only as good as the people you invest in (at least in this case). "Oh I sit around all day using a phone?"

Re: How to Block Stingray Devices

#36

Earlier quoted context omitted.

I can't speak for Google devices but per Apple's iOS security whitepaper (page 41) [1]: "To protect the device from vulnerabilities in network processor firmware, network interfaces including Wi-Fi and baseband have limited access to application processor memory. When USB or SDIO is used to interface with the network processor, the network processor can’t initiate Direct Memory Access (DMA) transactions to the applic…

PS4 PCI-E accesses were protected with an IO MMU too, but they managed to screw it up. So that doesn't necessarily mean that it's safe.

It does mean that SDIO or USB-only access is safe.

Of course, it's not 100% safe, but the lack of DMA moves the control over safety from the modem firmware to the application processor.

Re: How to Block Stingray Devices

#37

On modern phones Stingray devices are just one of the many tools that can be used to gain access to private communications and data. Any app requiring access permissions to everything is a potential vulnerability that can be exploited by 3rd parties (not to mention closed blobs etc); in this context smartphones are all things considered much more vulnerable than old 2G ones. Not being a target of interest for the pol…

What exactly are the practical consequences of being spied on by GMAF, compared to law enforcement?

You'll see a targeted advertisement, in place of an untargeted one?

The problem with being spied upon by law enforcement is that it's not you who decides whether or not you're an interesting person. They do.

Re: How to Block Stingray Devices

#38
post #15

When sincerely concerned about stingray devices it might be a better idea to either invest in a professional detection appliance or to install applications such as AIMSICD. ( foss/free) If you only deny 2g connectivity; it provides no certainty against being stung and you won't know if you are a target. https://github.com/CellularPrivacy/Android-IMSI-Catcher-Dete...

I have struggled to come up with a way of asking this neutrally, and I believe in a right to privacy and think "nothing to hide, nothing to fear" is nonsense, but seriously... wtf are people doing that they are "sincerely concerned about stingray devices"?

Re: How to Block Stingray Devices

#39
post #36

Earlier quoted context omitted.

PS4 PCI-E accesses were protected with an IO MMU too, but they managed to screw it up. So that doesn't necessarily mean that it's safe.

It does mean that SDIO or USB-only access is safe. Of course, it's not 100% safe, but the lack of DMA moves the control over safety from the modem firmware to the application processor.

You'd be surprised how unsafe those are too, even though they aren't RDMA protocols. USB and SDIO stacks aren't really designed with malicious input in mind; it's like the 90s all over again if you think of those as the network protocols they are.

Re: How to Block Stingray Devices

#40
post #15

When sincerely concerned about stingray devices it might be a better idea to either invest in a professional detection appliance or to install applications such as AIMSICD. ( foss/free) If you only deny 2g connectivity; it provides no certainty against being stung and you won't know if you are a target. https://github.com/CellularPrivacy/Android-IMSI-Catcher-Dete...

I have struggled to come up with a way of asking this neutrally, and I believe in a right to privacy and think "nothing to hide, nothing to fear" is nonsense, but seriously... wtf are people doing that they are "sincerely concerned about stingray devices"?

The article mentions attending protests as one such "suspicious" activity.
Post reply on HN