Live data from Hacker News

How a Hacker Proved Cops Used a Stingray to Find Him

politico.com

71–80 of 164 posts

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#72

Earlier quoted context omitted.

How would you return errors if the destination is known to be unreachable?

Or how would you troubleshoot which hop was the source of a routing problem without including a source IP to send a message back to. These kinds of discussions seem utterly divorced from the reality of networking to me.

Oh. we talked about that. You could include the origin-AS and each AS along the path would change it in flight, was one idea.

Which also didn't fly for obvious reasons. src,dst pair as part of a tuple was just simpler.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#74
post #37

Earlier quoted context omitted.

* Secure handshaking requires interactivity, unless you share secrets with your actual partner (no, your CA trust store isn't enough) in advance. So your first packet would leak it. * To return ICMP error messages ("destination unreachable"), otherwise you'd have long timeouts. * Ratelimiting outside the server (e.g. DDOS protection). Many ISPs do actually filter source IPs. (Of course you can't on the backbone, any…

+RPF requires it to help prevent spoofing (BCP 38)

In our thought-experiment world where each address has a public key that can be used to encrypt the payload data destined for it, the public key of the source can also be used to sign the data, ensuring the sender address isn't spoofed.

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#75
post #2

Jesus. I wanted to keep reading that article but half way through my phone was hot enough it was burning my fingers and 20% of my battery had disappeared. What on earth is Politico doing.

It's quite the thing. I profiled it with and without ads, and it looks like the ads are the culprit. There are two of them just sitting there using CPU time the entire time the page is open. (I had two Facebook ads that had animated text being typed. They continued to use 100% of the CPU even when the animation was complete.) There should really be some sort of CPU/power budget enforced by one's phone on a per page b…

It's always the adverts that screw up a site. Maybe it's mining crypto currency too?

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#76
post #38

Stingrays were being used as early as the 1990s by federal law enforcement. They were used to help locate Kevin Mitnick in North Carolina. Edit - I recall reading that years ago in Tsutomu Shimomura's book 'Takedown' (published in 1996). Outside of this, I have no other reference. It's a good read BTW. https://www.amazon.com/Takedown-Pursuit-Capture-Americas-Com...

Your assertion re early 1990s is backed up here: https://www.wired.com/2014/03/stingray/

"Use of stingray technology goes back at least 20 years [ <= 1994]. In a 2009 Utah case, an FBI agent described using a cell site emulator more than 300 times over a decade.... "

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#77
post #25
post #20

Earlier quoted context omitted.

You must not be looking for work, or for that matter have a job. My phone is indispensable for the kind of work that I do, I literally couldn't do my job without it.

Ha, funny you should mention that. I am in fact looking for a job. Luckily the one interview I've had since losing the phone was on-site. If I need to participate in on-call rotation or similar, I expect the employer to issue a phone. For a remote job, I will obviously get one myself -- but then strictly for job-related activities. (by the way, if anyone is looking for an experienced infrastructure engineer/"DevOps"…

Interesting calculus of choices there: I don’t miss the distraction or privacy implications of my personal phone, yet I expect a company to issue me a phone which comes with distraction and privacy implications (the subject surveillance of the article disregards whether a pocketed phone is corporate because it can work with numbers directly), and I also don’t maintain a landline to sit for a phone screen to find that opportunity in the first place, so I expect to talk to you over Zoom (ceding more privacy; surprise, cellular call content is legally sensitive for LE, video packets aren’t) or in person.

You probably don’t realize nor intend this, but that can be a large red flag for your candidacy from the other side of the table, particularly if the role involves security because you’re broadcasting a slight misjudgment of your threat vectors and exposure. The number of resumes most folks go through, expecting ravens from Winterfell will get you dropped fast. Torvalds could probably get away with making initial hailing frequencies that difficult, but you or I should just buy a phone number of some kind, as much as it sucks.

The phone isn’t the problem if you apply opsec correctly, buy the right one, and operate it like a compromise hazard. (It is.)

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#78
post #20
post #15

Earlier quoted context omitted.

I lost my phone somewhat recently. It's been great: I read more books, and get a lot less distractions throughout the day. The privacy implication is a huge bonus. The main drawback have been that people rarely label apartment doorbells anymore, so if you don't know which button to press you're in trouble. Another is getting hold of old friends if you don't know their email address (I don't have Facebook either). Ove…

You must not be looking for work, or for that matter have a job. My phone is indispensable for the kind of work that I do, I literally couldn't do my job without it.

Sounds more like it's related to your work. I don't need a phone for my job at all, but it makes some things more convenient

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#79

The hacker was exposed because of poor OPSEC (due to tracking of his IP address). > Rigmaiden had received boxes and boxes of criminal discovery that would help him understand how the government planned to prosecute its case. In the penultimate box, he saw the word “stingray” in a set of notes. The authorities were exposed because of poor OPSEC as well. They weren't supposed to ever mention “stingray”.

If I had to guess, I might say poor OPSEC is somewhat common...

EDIT: while we're here, do you have a single "start here" article/site for the basics of less-poor OPSEC?

Re: How a Hacker Proved Cops Used a Stingray to Find Him

#80
post #64
post #9

I value the privacy so I don't own or use cellphone.

the probability of this affecting you if you're not a criminal is probably lower to that of you dying everytime you take your car to go anywhere. It's a really big sacrifice in expected utility.

Instead of "criminal", I think you mean "intentionally engaged in an illegal enterprise". From the context, I doubt you mean to restrict the statement to those already convicted of crimes. Beyond that, it's very tough to know if you're currently committing any crimes (or any non-criminal illegal activity), as we don't even know how many laws we have.[0]

I agree that the vast majority of those that will have trouble are intentionally engaged in illegal activity. But, at any given time, there must be both fair fair number of people who are unintentionally committing illegal acts and those who are falsely believed by law enforcement to be committing illegal acts.

There is an argument to be made that everyone should be more careful about privacy, thereby increasing the cost (and opportunity cost) of invasive investigations and forcing law enforcement to be more selective about the degree of certainty they have before employing more invasive investigation techniques.

[0] https://www.youtube.com/watch?v=d-7o9xYp7eE

Post reply on HN