Live data from Hacker News

Americans’ Cellphones Targeted in Secret U.S. Spy Program

online.wsj.com

61–70 of 73 posts

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#61

> A Justice Department official would neither confirm nor deny the existence of such a program. The official said discussion of such matters would allow criminal suspects or foreign powers to determine U.S. surveillance capabilities. This is the go-to defense for surveillance secrecy. However, not discussing such matters allows criminal officials to abuse these powers without repercussion.

>The official said discussion of such matters would allow criminal suspects or foreign powers to determine U.S. surveillance capabilities.

Not to mention U.S. citizens!

I mean, if they want to use that argument, then they should actually limit their surveillance to "criminal suspects" and "foreign powers".

>This is the go-to defense for surveillance secrecy.

Indeed. And note how it used to be terrorism that provided the tidy justification for sweeping up large numbers of random U.S. citizens in these operations. Now, just plain ol' criminal suspects and foreign powers provide enough justification for domestic spying.

The goalposts are moving. We will all be accustomed to the surveillance state soon enough. Nothing to see here.

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#62

These are all still using GSM, which doesn't authenticate the network right? I really wish I could disable GSM on the iPhone like I could on my Android - none of the networks I regularly use have usable GSM networks. It's a waste of battery and a wide open security hole. Plain old classic GSM needs to die. Bring on the UMTS/LTE future.

There are a smattering of media reports saying that they can attack LTE (the new system or upgrade is called "Hailstorm").

They are pretty thin though:

http://arstechnica.com/tech-policy/2014/09/cities-scramble-t...

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#63

Isn't it time Google and Apple build some protections inside Android and iOS against this? Maybe do something like what these guys did, but I'm sure they can come up with even more comprehensive protections: http://www.wired.com/2014/09/cryptophone-firewall-identifies...

The application OS is basically irrelevant when talking about cell communications. They'd have to design their own boards to even have a chance at isolating the "baseband" processor - to say nothing of controlling its behavior, especially as carriers want to keep its workings secret for "security" Most phones (anything CDMA, or most everything LTE) use a Qualcomm SOC, with both the baseband and application processor…

being from San Diego, i can state that SAIC is right physically down the street from any number of qualcomm campus buildings. also note, that while i am not a conspiracy guy, the security community there has always been fairly tight, a lot of the top feeders know each other, and there are a lot of interworking groups, guilds, clubs, that would easily lend themselves to partnerships, cooperations, things like that. i am just saying not to rule it out.

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#64

Isn't it time Google and Apple build some protections inside Android and iOS against this? Maybe do something like what these guys did, but I'm sure they can come up with even more comprehensive protections: http://www.wired.com/2014/09/cryptophone-firewall-identifies...

If you have a Samsung s3 International version you can use this to identify when your GSM connection has no encryption https://github.com/darshakframework/darshak

Works on Intel xgold basebands by giving access to the event log

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#67
At a certain point, everyone will realize this has to stop. I've started to wonder though, if the way to beat the government at this is not to try and stop them, but to encrypt things in such a way that they can no longer use technology like this.

Personally, one thing I like about open source software, is I can host pretty much whatever I want, whenever I want. If this development path continues, I'd imagine that eventually, if there might be some entrepreneuring cell company[0] that would simply encrypt it all anonymously.

Obviously, this would mean a few changes to the way we do things. For example, maybe instead of triangulating your cellular position in an emergency, iOS and Android could create a 'distress' api that would allow for emergency services to access your location, and then alert you with the status. To be honest, it would end up working in a similar way as Emergency and Amber alerts on your device[1].

Realistically, it probably won't happen like this, but if privacy won't be given to us, we need to take it.

[0] http://www.artemis.com/ [1] http://support.apple.com/en-us/HT5795

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#68
post #6

There are also IMSI Catchers intercepting GSM all over the USA, for example this twitter feed reported one at SFO airport recently: https://twitter.com/cellhacking/status/524562944928264192 And all over Washington DC: https://twitter.com/esdamerica/status/512293117052334080

There are now a few Android apps in development to keep track of the towers your devices use day to day to hopefully detect rogue IMSI catchers.

This one is the most promising: http://signup.spideyapp.com/

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#69

Seems like you would get an excellent picture of everyone's location habits with a small number of flights per city per month. If this is legal, why can't they just subpoena carriers for the tower census data?

They could try, but they might not get it, and the carriers wouldn't like it - better to ask forgiveness than permission, right? I think it says this in the article.

Re: Americans’ Cellphones Targeted in Secret U.S. Spy Program

#70

At a certain point, everyone will realize this has to stop. I've started to wonder though, if the way to beat the government at this is not to try and stop them, but to encrypt things in such a way that they can no longer use technology like this. Personally, one thing I like about open source software, is I can host pretty much whatever I want, whenever I want. If this development path continues, I'd imagine that ev…

It's already fixed (I think) from UMTS upwards. In GSM (2G) the tower authenticated the handset but not vice versa. In UMTS+ the authentication is mutual. To impersonate a cell tower you would therefore need to be able to sign with the carriers signing keys.

One of the most interesting and unreported aspects of these Stingray boxes is how they handle the 2G/3G divergence here. In the USA there's also CDMA to think about and I don't know how that handles authentication, if at all. I suspect such IMSI catchers emulate a GSM base station and possibly jam 3G frequencies to try and force phones to downgrade. I don't think there's any way to tell phones to never use GSM even if it's the only option, but if there was, I suspect that'd "fix" things (except most people wouldn't know about or use them). Ultimately the only thing that can stop this is a phasing out of 2G entirely but that won't happen any time soon, and even once it's done, by that point law enforcement will have got used to the ability to just follow everyone around all the time and would insist that they MUST be able to use these devices otherwise chaos and anarchy would follow, so they'd probably mount a vigorous lobbying campaign to get the signing keys.

Post reply on HN