Live data from Hacker News

Feds: There are hostile stingrays in DC, but we don’t know how to find them

arstechnica.com

61–70 of 101 posts

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#61
post #28

Layman question: one can limit their exposure with encrypted VoIP communications (e.g. FaceTime) and chats (iMessage, Signal), correct? That being said, the intercepter would still know: - phone being connected (IMEI) - location of the phone - which servers were requested, but not the encrypted content (yet) - how much data was transmitted, "call time" So if two phones were talking with each other over FaceTime conne…

The metadata is most of the story. Certainly, if the stingray lets arbitrary protocols through, you can secure the contents of your communications, including any metadata tunneled through (e.g., if you're using VPN), but not the metadata on the outside of the tunnel. Depending on the VoIP protocol, you may not get any protection for metadata unless you're using a VPN.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#62

Most will probably be owned by law enforcement. Many will be operating without the benefit of a warrant. So what do you do when you find one? You won't make many friends if you interfere with an ongoing investigation particularly if you raise questions about the legality of the operation at the same time. Things were much the same back in the old days. If a telephone employee would find listening devices on the lines…

That reminds me of some photos my dad took years ago of a line technician on a crane truck fiddling with some equipment on a utility pole at the edge of our front yard for about thirty minutes. He thinks the guy was testing for some illegal cable descrambler on the line although I suppose it could have been anything since this happened in the DC Metro area :)

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#63

I think this is good news. I think the kinds of politicians that are typically over-friendly with the police are also the kind that want a strong military. The use of "law enforcement" technology like stingrays by hostile intelligence agencies, might create a useful tension in them that could help convince them to harden domestic communications against law enforcement spying.

except that if/when politicians get cozy, either willingly or not, with the hostile intelligence agencies then they would likely want all the benefits of that cozy relationship to continue indefinitely

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#64
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

I think there is a perfect storm of savant security nerds with piss-pour communications skills and telcos over-indexing on mba/finance leadership. The security nerds make blustery comments that “anyone with motivation and a couple g’s worth of gear can target ANYONE.” There are a bunch or problems with this argument. Gnuradio is not easy. You need to be in radio proximity to your target. Targeting someone requires so…

Naive question: how does net neutrality entrench companies? To me it seems the opposite, the more you can pay the better service your company can offer which directly benefits larger entrenched companies, no?

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#65

> IMSI-Catchers also allow adversaries to intercept your conversations, text messages, and data. Police can use them to determine your location or to find out who is in a given geographic area at what time. [1] Does turning one's phone off not disable pinging cell towers? [1] https://cellularprivacy.github.io/Android-IMSI-Catcher-Detec...

Many modern phones don't turn off all the way, and continue to ping towers.

I can't find any official documentation, but several Android phones I've owned over the years have powered themselves on when switched off and receiving a phone call.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#66

> IMSI-Catchers also allow adversaries to intercept your conversations, text messages, and data. Police can use them to determine your location or to find out who is in a given geographic area at what time. [1] Does turning one's phone off not disable pinging cell towers? [1] https://cellularprivacy.github.io/Android-IMSI-Catcher-Detec...

Wrong. This is an exaggeration at best and just plain wrong for most US LTE users. LTE is very hard to fully MiTM. You can still catch / observe through IMSI, but the phone won't deal with your rogue tower. If you can downgrade someone to 3G you can more easily observe voice and or texts. Data is actually harder to MiTM, even on 3G. That said, it is not feasible to down grade any modern US LTE devices as far as I know.

Turning your phone off usually does prevent tower pings, but some phones have been known to be sneaky.

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#68

I work in wireless telecom: Really doubtful "we don't know how to find them". The FCC's enforcement bureau has a set of vans equipped to find unauthorized transmitters. IMSI catchers must transmit and remain on the air. It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours. The only other explanation I…

"It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours."

Even more so in 2018 where an IMSI catcher is only relevant/useful if you downgrade the target to 2G operation, which requires some kind of additional interference/jamming.

Unless they are using "stingray" as some kind of generic term for "device you use to intercept mobile phones" and there are now 3G/LTE "stingrays".

This would all be so simple to deal with if phones just displayed an "unlocked" or "downgraded" warning when operating in 2G or unencrypted mode ...

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#69
post #68

I work in wireless telecom: Really doubtful "we don't know how to find them". The FCC's enforcement bureau has a set of vans equipped to find unauthorized transmitters. IMSI catchers must transmit and remain on the air. It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours. The only other explanation I…

"It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours." Even more so in 2018 where an IMSI catcher is only relevant/useful if you downgrade the target to 2G operation, which requires some kind of additional interference/jamming. Unless they are using "stingray" as some kind of generic term for "device…

IMSI catchers exist for at least 3gpp release 12, which is one type of LTE.

https://www.unwiredinsight.com/2014/highlights-of-3gpp-relea...

https://www.google.ca/search?q=3gpp+release+12+imsi+catcher&...

Re: Feds: There are hostile stingrays in DC, but we don’t know how to find them

#70
post #53

Can someone please explain to me why this cell security problem seems to be completely ignored? If encryption algorithms are broken, they're phased out and untrusted. But if 2g is insecure, there's not a single peep from networks or phone manufactures or Google or Apple about phasing out 2g. There isn't even an option to disable it. Why don't towers have a sort of encryption certificate verifying they're legit? Why d…

"I can think of so many ways to solve this problem. But it's super hard to find any information if how this all works."

LTE and 3G solve the problem of authentication and encryption with the tower - the problem is that an attacker can, through interference or other means, force your handset to downgrade to 2G operation.

There is a very, very simple solution to this: display an icon/error when you downgrade to 2G and an even bigger icon when your 2G connection has no encryption (which is a valid option for a 2G connection).

This would be trivially simple but for reasons that are difficult to understand, phone OS and SIM providers do not do this.

"But it's super hard to find any information if how this all works."

I would recommend viewing/listening to the CCC (Congress) talks on GSM subjects that have been given over the last ten years. The osmocom "baseband-devel" is also a good mailing list to read the archives of ...

Post reply on HN