Radio Hacker Can Hijack Emergency Sirens to Play Any Sound
wired.com
wired.com
EAS was designed in the late eighties, when infosec was not a well-established, household-name field. It works by relaying an unencrypted signal; that rather unsettling data burst you hear when there's an Amber Alert or a thunderstorm warning. There's no authentication on this. There's no encryption. Literally anyone with software to generate NOAA SAME tones, together with a software-defined radio and amplifier, can walk near one of a handful of "primary entry points" and belt out an alert that gets mindlessly repeated across the country. It's already happened on a local level by simply logging into network-connected endecs at TV stations; probably none of them changed the default passwords.
Every day I see something like this, I'm reminded of why anyone still considers security-by-obscurity to be a sound strategy. State actors are the prime target of vulnerabilities you call obscure.
So a fake alert can be sent out nationwide from broadcasting to just one access point??
I believe OP meant "country" as in "countryside", which is feasible when you're up on a hill and your signal can reach a distribution source antenna (which will then distribute your spoofed alert to its attached sirens).
I wonder why it hasn't been abused/trolled on a large scale, though. Really, if I were interested in trolling that's what I'd do: next to zero chance of the cops catching you as you won't leave a trail, plus the entire country will be wide awake once the sirens ring and it will likely need months or years until the government secures the stuff.
[1] https://www.washingtonpost.com/news/the-intersect/wp/2017/04...
They kept up the ruse for quite a while by being subtle at first with their mischief.
Target: http://www.bbc.com/news/technology-34556644
Fred Meyer: http://www.phonelosers.org/zine/pla025/
General Info: https://www.mattwilson.uk/2015/12/16/stores-pa-systems-attac...
Hilariously enough? I work for a telecom startup now.
Thanks for the trip down memory lane :)
Though at a previous job, I got on the elevator one day to hear a telemarketer's voice coming from the emergency speaker. I'm guessing it happens, but just very rarely?
The other time, same elevator, it was someone asking for a specific person that I had never heard of.
I think the answer to your question is "they don't".
Good thing no one ever leaves their PBX connected to the internet with a default admin password. Or puts edit access to their voicemail greeting behind a PIN like 1234# or 0000#.
* about the ISEE-3 space probe reboot: https://www.youtube.com/watch?v=NTljlMH-0oM
* visualizing flights in airspace: http://youtu.be/a623A6JVuek
(I'm the Dorkbot A/V geek, but these aren't my recordings.)
In my college town, there was a tornado siren placed very close to the biggest multistory residence hall. I learned (through the ham radio club) that it had a long history of mischief before my time.
New York City can get crowded around 1 World Trade Center. A false alarm could kill, not to mention cause tremendous economic damage.
Of course it is. Publishing this - at all - is advertising. Giving it a name and branding is an even more ostentatious form of it.
They should check with the FCC before making threats like that.
Basically anything other than the cell bands is trivial to receive and decode w/ $15 SDR dongle.
"However, we wish to point out these are technically sophisticated people who have devoted significant time and effort to this task. Before customers panic too much, please understand that this is not a trivially easy thing that just anyone can do."
https://static1.squarespace.com/static/5ab64621aa49a10ba0d06...
> ATI wrote that Bastille's findings are "likely true" and that it's testing a software update it plans to roll out soon. "Before customers panic too much, please understand that this is not a trivially easy thing that just anyone can do," that earlier statement notes. "At the same time, a certain level of concern is justified. As technology evolves, the level of threat evolves."
If you can do it via a Baofeng there's a 99% chance this is just obscured DTMF tones + possibly PL tone which is freaking trivial to do on any FM radio.