Signs of Secret Phone Surveillance Across London
news.vice.com
news.vice.com
At the time I just dismissed this as some tinfoil hat developer adding some nonsensical warnings to the firmware, but in retrospect, after reading this article - this matches perfectly, chances are - phone was indeed detecting Stingrays. Still no idea how it managed to do it.
EDIT: I had no data/IP connection of any kind at and around the time of seeing this, so this is clearly unrelated to TLS interception.
Do you think it might get triggered on your phone by the presence of the anti-porn filter that UK mobile provider have? For instance, when trying to access "adult" website (I use quotes as sometimes, even non porno website gets filtered out) you end up on your mobile provider page blocking you from the actual website your looking for.
I wish I've taken a screenshot of it!
No exotic measures are required to do this.
Also, how do laws treat waves in public (radio, light) - do they get the same "privacy" treatment as people (that is, no expectation of if in public)?
Edit: actually since joining/browsing an open WIFI network can be considered criminal...
I believe this area is legally fuzzy but courts have determined that police cannot drive around with say, a thermal imager and observe en-mass people in their homes. One could argue that it's just thermal radiation you are viewing from public space.
It seems to me that if you really want people to slow down near the elementary school (as opposed to just issuing tickets and collecting fines), this is EXACTLY what you want to have happen. If you put a cop there, and people warn others of it so they all slow down... mission accomplished!
By analogy, if you've got a target very valuable to the enemy (maybe a stadium for a high-profile sporting event), having phones alert users that they're being monitored might help to ensure that nobody tries anything during the event.
To be really effective, it would be seem specific and personal: text messages that say things like "We can see you. We know what you're up to." Stuff like that.
I installed my own certificate on Android and it warns me about it each time after it boots. It's quite annoying, because there doesn't seem to be a way to disable it (without modifying /system) and I trust my own certificate much more than any other the phone comes with.
That the Met (and other police forces) regularly use IMSI catchers is not new information - here's a ~5 year old Guardian article on the subject:
http://www.theguardian.com/uk/2011/oct/30/metropolitan-polic...
Given that these things are cheap, would any fellow Brits be interested in clubbing together and acquiring one and installing it in or around parliament? I'm sure there would be plenty of buyers for the call records of MPS.
SWIM is interested
Report in english: http://www.aftenposten.no/nyheter/iriks/New-report-Clear-sig...
Given that Police Security Service has a decades long history of illegal political surveillance what shocked me is how muted the political reaction was.
https://en.wikipedia.org/wiki/IMSI-catcher
It doesn't have to "verify" what it collects.
Since your IMSI catcher is basically just a proxy between the mobile phone and the real network, you can therefore easily detect that the IMSI is who it says it is.
Technical ability wise, yes.
Legally, no. The Mobile Telephones (Re-Programming) Act 2002 [0] makes spoofing IMSI, even that of your own, illegal in the UK.
[0] https://www.staffordshire.police.uk/info_advice/crime_preven...
Disclaimer: I am not a lawyer.
> he changes a unique device identifier,
Technically correct for technical discussions is not the same as contextually correct in a court room.
You will change your IMSI by simply changing the SIM card.
If you use pre-paid sim cards then those usually have thin provisioning of IMSI numbers they network buys a certain amount and activates them when the SIM card is activated and deactivates them once the SIM card has been inactive or not been topped off for a certain period of time (usually around 90 days).
When some one has your IMSI they can tie it directly to your personal details, phone number and various other details if they have sufficient access to the global cell system they can also get your location and what tower you are connected to. Historical log data will give them any tower you've been connected too from the first tower during the initial activation and provisioning to the last tower you've been connected too. Depending on the network and device most phones also send out nice diagnostic information about other towers and networks they see all the time regardless of what tower they are connected too at the time that with a given IMSI number will allow some one to triangulate the position of the device to under 10M in most urban areas if some one knows your IMSI they can pretty much pin point what room you are in at your house (give your house have several rooms pointing at different directions ;)).
From legal standpoint, device that spams IMSI catcher with registrations with random IMSIs is mostly same thing as the IMSI catcher itself, ie. device that requires it's own broadcast license to operate, as such device certainly does not meet legal (and technical) requirements for it to be an cellular phone.
On the other hand, generating random IMSI, burning that into ICC and thus producing unusable SIM is probably perfectly legal even when you put that inside normal GSM phone (from network standpoint it will behave mostly same as phone without any SIM). In practice SIMs with completely made-up IMSIs are even commercially available (idea there is that some phones will not fully boot without SIM).
That said, this is completely illegal (unlike the actual surveillance which has been made legal by a series of unfortunate events). So I would not advise anyone to do this. Not to mention that unless you design your own cellular baseband radio circuit (so that you have access to all the docs) building something like this with "off the shelf" parts is quite expensive.
https://f-droid.org/repository/browse/?fdfilter=SnoopSnitch&...
(does not need root)
The baseband still has access to your battery when your phone is off.
Citation needed?
Because the definition of off, for most phones, is exactly that.
http://blog.erratasec.com/2013/07/no-nsa-cant-track-phones-e...
There is NSA method called 'implant', but it requires installation of software (possibly in the firmware). It's not so easy and it can't be used in large scale.
Snowden is right when he says that every phone is vulnerable for targeted surveillance. For people like him, every phone is dangerous even when they are closed.
Mass surveillance is different. NSA can't just pick random person and remotely track their phone when it's turned off.
'Dreamy Smurf handles power management, which according to The Guardian includes "an ability to stealthily activate a phone that is apparently turned off"'
>"The FBI can access cell phones and modify them remotely without ever having to physically handle them," James Atkinson, a counterintelligence security consultant, told ABC News. "Any recently manufactured cell phone has a built-in tracking device, which can allow eavesdroppers to pinpoint someone's location to within just a few feet," he added.
Source: http://blogs.abcnews.com/theblotter/2006/12/can_you_hear_me....
I believe (but cannot cite) that this capability became mainstream when E911 & GPS was mandated.
This stuff is a big reason why BlackBerry was so critical to regulated industries and public company execs. PIN messaging on legacy BlackBerry was secure between devices on the same BES, and there wasn't a direct linkage to the user's identity, which made it easy to lower the value of metadata collection.
The fact that BlackBerry designed around this early on leads me to suspect (as an outside observer with an imagination) that mass metadata collection was known by folks in industry back in the 90s.
Wouldn't a simpler explanation be that it was just over-designed for 90s-era threats in a way that hardened it to some more recent threats?
Consider however that none of their US based competitors managed to do address those threats in a meaningful way.
https://github.com/SecUpwN/Android-IMSI-Catcher-Detector/iss...
For the example of a protest march, if you're a participant or even a bystander walking home wanting to avoid being caught up in a surveillance dragnet, turning your phone off should be sufficient. You'd probably want to take stronger measures if you were involved in organising the protest, though.
I would not trust that any modern smartphone is fully off without yanking the battery.
Are you sure they don't have a backup battery or similar that can continue broadcasting your location after you pull the battery. That would be an ideal countermeasure as pulling the battery would be a great indication you may be about to do something "naughty" and you'd likely do such things shortly after too ...
That is not enough. Use a faraday cage.
Modern phones have two batteries [0].
Burner phones bought in cash from one of the little independent shops we have all over (here in the UK anyway) with pre-paid sims - not a new idea I saw it cropping up in fiction 20 or more years ago but still effective, used for a day or two and then dumped.
Isn't it tragic that the way you have to protect yourself from the state when organising a legal protest is pretty much the same way you would do it if you where a drug dealer or a terrorist (at least a reasonably smart one).
http://www.amazon.com/Mengshen%C2%AE-3-Pack-Blocker-Shieldin...
Big city with millions of people. Two or more cellphones disappear when they approach the same part of the city. When this happens few times, you might get flagged.
That's not a great solution if I want people to be able to call me.
The UK's level of surveillance is extremely unsetteling to me, and quite frankly I think a lot of Americans have forgotten all the reasons why the UK might not be as good of an ally as everyone thinks since the 47 USUK agreement. Thr point being that I really hope our politicians dont start adopting That level of surveillance just because they do it to.
It seems we have quietly been in a surveillance arms race, which isnt good for the population at all.
In the rest of London there are certainly other buildings that are covered by extensive government surveillance, but most of the surveillance in London - and the rest of the UK - is privately owned, and rarely more than passively recording. The level of street level monitoring in the UK is often vastly exaggerated - police often can't be bothered even trying to check CCTV because getting hold of footage is a lot of effort and rarely is of much help.
GCHQ surveillance of networks is another matter.
edit: aside from that utopic reply, what I mean is "any country that has cellphones and want to protect their citizen should implement a legal framework to prevent abuse"
Is this the same technology?