DoD: Turn Off Your Fitbit, Garmin, Apple Watch GPS
breakingdefense.com
breakingdefense.com
One military site had the rule that nothing electronic left the main gate site without being handed over to the guards, processed, and i believe destroyed before it left (not that you ever saw it again anyway). They were serious...
You drove to the site knowing it would all be gone and a strong warning not to turn around if you were near the gate because you just remembered you had your phone in your rental car.
We went through a lot of equipment.
But that site as far as anything I could have done, secure. I don't even know what the faculty looks like as it was blind folds and guards all the way to the equipment (well you could see the bathroom....with an MP.. there).
I feel like those kind of policies are the way of the future. There is no other way at this time.
For military, yes. For civil, that's going a bit too far into the dystopian realm.
Destroying the devices might go a bit far, but there are plenty of jobs that require things like phones going into a drawer before a shift starts. Not everyone is always on all the time.
Not sure if it's apocryphal, but I heard a company in Seattle (Starbucks?) had a policy of no visible tattoos. At some point there wasn't enough people to hire and they overturned the policy.
I can see it playing out both ways.
The vast majority of companies had this policy up until about ~2005.
I still remember being extremely surprised the first time I saw an employee with a nose ring working at CVS (around ~2005).
It honestly frustrates me that so many of my friends and family can't fathom this. They're all on their phones 24/7 and can't seem to handle the fact that my job requires me to (from their perspective) ignore them for eight-to-ten hours a day.
Hell, back before mobiles it wasn't a problem to only call someone after hours, otherwise you'd get an answering machine.
They don't destroy the devices, but all travel phones/laptops are "burners" and get given away instead of ever used for work again.
https://www.defcon.org/images/defcon-19/dc-19-presentations/...
(Note slide 116 there - about 7 up from the end: "Attacking the OS kernel")
https://www.v3.co.uk/v3-uk/news/2099616/black-hat-charlie-mi...
http://www.karosium.com/2016/08/smbusb-hacking-smart-batteri...
Check out: https://www.malwaretech.com/2015/04/hard-disk-firmware-hacki...
The devices aren't given away however, they're just wiped and reused as burners. Not 100% secure as a nation state would have access to BIOS rootkits but it's better than nothing.
(chucking a random assortment of straws on top of your laptop then taking a photo, with the idea that it will be more difficult/time consuming/impossible to recreate exactly like in the photo).
Also - the Australian Government banned the NBNCo from using any Huawei gear in out National Broadband Network. Sadly that's _probably_ either just racist political point scoring, or effective lobbying (or outright bribery) from the non-Chinese based network gear companies - rather than any real intent to improve security based on evidence from people/organisations capable of making that sort of determination...
Tape on phone screens and always with someone(me).
Although I feel like social engineering is really the easy way in. "forgetting ID" if you were a cute girl or young kid would be too easy.
probably because they know what one is capable off when able to access/compromise given devices.
>that's going a bit too far into the dystopian realm.
Imagine it's the year 1999 and someone tells you what flying in 2018 will be like.I expect you'd say the exact same thing. And yet here we are. :(
People will get used to any degrading inconvenience if you claim it's for their own good and are willing to pay a lot of money to get the initial momentum going.
I think part of that is the fact that the TSA is so bad at their jobs that it feels like a joke going through it. The worst part is that they know that they are a joke -- they freely admit that they miss between 70%-80% of weapons passing through.
Growing up without something really makes you not know what you're missing; if you don't know what you're missing, it won't feel so awful when you don't have it.
A tiger born in a cage who experiences nothing but being fed every now will behave and feel very much worse than a free one. Children who were never treated with respect and never saw anyone else treated with respect don't suffer less harm in their development just because they don't know the difference.
I think at some very basic level, privacy is an obligatory requirement of becoming an individual person. An important part of the person grows when reflecting, when being alone with one's conscience, that's just as necessary as facing others. If you get all of either and none of the other, there's going to be a price.
Or take lead for example, if we increased our average exposure by a lot, that wouldn't mean that it now doesn't damage our central nervous system and organs anymore, not even for those who never knew lower levels of exposure. You can have the negative consequences without awareness of what is going on, and without any means to make it better.
A lot of the pressures already get relieved by consumerism at best, cruelty towards victims and identification with abusers at worst -- instead of being channeled towards the causes, it gets channeled towards what will make it worse. I think the rock bottom of that would a world unrecognizable even to Edgar Allan Poe.
The problem with privacy is not that people try to take it away. It's that most people don't care.
So to my thinking it isn't even the dystopian aspect of big brother watching and prodding, it's the further disgust of big brother separating the haves and have nots. Some animals are more equal than others.
And here's the kicker, you can get TSA pre by paying for premium seats. At this point having non-pre passengers having to take their laptops, shoes and jackets off is just a way to inconvenience us and has nothing to do with security.
Don't forget that getting TSA Pre involves an in-person background check interview (complete with fingerprinting). There's no escape; you just get to decide if you want to pay to have a "not a criminal" permanent file created for you, or be treated like a criminal for free, repeatedly and in small doses.
Yeah, it feels really different.
Why no one set off a bomb in a TSA cattle line I cannot understand. USA built a perfect target. I assume the TSA is some sort of jobs program but I cannot understand who benefits from it.
Those contract workers come from giant firms like Aramark.
Last time I flew in Australia domestic flights allowed non-passengers up to the waiting area, yes.
Or cancelling flights for 'bad weather' reason, when all other flights departed just fine from the airport - in this case, airline doesn't have to compensate anything (freakin' Easyjet - I realized I am not rich enough and don't have enough extra vacation to use such a crappy random-quality services).
They distributed us and our luggage across a couple of planes flying out to Vienna.
My luggage arrived on an earlier flight and had to hear from the Austrian police, while I explained that it was Lufthansa's own doing.
It happens all the time that bags get to a flight that the passenger misses and passengers get to a flight that bags miss. Not remotely unusual. It's happened to me recently too.
It actually literally happened to me in November 2001, even for an international flight: I missed my flight due to a 3-hour line at MDW, but my luggage had already boarded. I was assured by everyone concerned that it would be offloaded, but it flew ahead, and was (somewhat miraculously) still waiting for me at the luggage claim when I got there over 12 hours later.
Essentially you ask their service desk for a companion pass and tbeu run your ID and print you our a ticket to go through security. I use it because I have family that do not speak English test visits me and I walk them to their gate...but if you just want a hug you can, they don't need a reason to issue one.
But I understand what you are saying, and the ability to be at the gate to drop off or meet domestic passengers brought back old memories.
Buying something in the duty free shop, only to have them take it away at the next airport on connecting flights.
On some flights they don't even serve drinks anymore (unless you pay). Great recipe for dehydration.
Seats are so cramped that more and more people suffer from thrombosis after flying.
There's no space for your hand luggage because the airline charges extra for checked baggage and everyone takes the biggest suitcase they are allowed to take on the plane.
Ridiculous forms you need to fill out online (hoping you don't fall for a scam website), where you can pay only by credit card (not so common in many countries), just to fly through a country that is visa free? Flying via US or Canadian airports has become a major hassle...
Flying used to be different.
I remember that on one flight you could just walk to the front, and watch the pilots fly the plane through the open cockpit door.
Yeah, it was. Expensive.
Robert Gorden in The Rise and Fall of American Growth:
surprisingly, the period of most rapid decline in the real price of air travel occurred before the first flight of a jet plane. As shown in figure 11–10, the price of air travel relative to other goods and services declined rapidly from 1940 to 1960, declined at a slower rate from 1960 to 1980, and has experienced no decline at all in its relative price between 1980 and 2014. The growth rate of passenger miles traveled has mirrored the rate of change of the relative price except with the opposite sign, because lower prices stimulate the demand for any good or service.
Flights that don't serve free drinks tend to be (at least in my experience) SUPER cheap budget airlines. In the bygone age of luxurious leisurely air travel, you weren't flying from San Francisco to San Diego for $50 or from Paris to Barcelona for 30€.
If you're dehydrated tell a hostess, free water will be provided (costs them a lot less than being sued).
And sadly, that's the only change that matters. Cockpits are now closed and locked.
I remember that on one flight you could just walk to the front, and watch the pilots fly the plane through the open cockpit door
That changed in the USA even before 2001, at least by typical policy if not statute.I recall a trip in the late 1990s flying Aur Canada (maybe YYZ-SFO) and while in Canadian airspace, I was invited in right behind the copilot to hang out for 20 minutes or so. I was surprised how much air traffic could be seen just with the naked eye.
This happened to me in 2007. Arrived at a regional airport at 6am bleary eyed and without my wallet. Had to jump through some hoops and I assume some regulations might have been bent/broken but I made my flight. Someone made a judgment call and waved me through.
The safest way to deliver a message will be on the beach, face to face. And a random uber courier is going to be more secure than electronic communication.
I was naturally curious but I got the feeling knowing anything would be looked down upon. I could guess but it would be just wild speculation, there was no information to make anything near an educated guess. Military site is all I knew. It could have been anything.
I was happy to do the job and go home.
Forgive my denseness (maybe it's because I just woke up), but I'm having a hard time figuring this bit out. If you're near the base, as in not-quite-on the property, you could be anyone, with any arbitrary selection of interesting equipment that needs to drive up to the base then away again. Is it timing - as in, driving away and back will take far too long and make you late?
> We went through a lot of equipment.
On your own dime? :/ I would hope a base like this provides all contractors a reasonable "security enforcement viability" fund, or something like that :)
> I don't even know what the faculty looks like
Wait. What gate were you referring to before, then? Some point you were transported from, but which wasn't the actual location? Hm, perhaps this explains the "don't turn around" bit.
--
Unfortunately I can't find it right now, but I remember the (possibly-apocryphal?) story of the random server, deep in a secure facility, that was part of a botnet. The person who found it didn't think it looked particularly like a honeypot; it was an actual database or equivalent sort of machine. The person informed various higher-ups, but despite the report being acknowledged nothing was ever done to fix it.
Usually there's a large sign "Foo Air Force Base" (or whatever) by the civilian road, then you turn off and drive on a military road for half a mile or more (sometimes much more), then you come to the gate with the guards.
But you've still been on military land, and subject to military rules and laws, from the instant you enter their property.
Edit: just checked. The guardhouses for two of the gates at a local facility are respectively about 800/1,000 feet away from the public road, and about 600/800 feet inside the perimeter fence (the one with signs reading "patrolled by dogs", "deadly force authorized", etc.).
If the government wants to do something legally beyond that, they probabbly would feel it is worth it to discourage such behavior.
Also I got the impression that even if they checked you at the gate and you didn't account for something in your car or on you and they found something you shouldn't have, they could deny you entry right there and you weren't getting back in anytime soon. Someone panicking and driving away might set off some dude's suspicions and you weren't going to fix things... and it took a while to schedule everything.
It was as much about protocol and just making good choices / customer service (don't scare your customer) as anything else.
No idea on equipment costs; it's likely that OPs company had an overhead disbursement for mistakes.
The gate itself was probably a good ways away from the actual facility. If they weren't driven all the way from hotel to site by a driver, then they almost certainly stopped and parked at the gate and were driven the rest of the way under escort and blindfold.
(And, even if someone's equipment doesn't look like the kind of thing that would capture signals, the thoroughness required to prove that a piece of equipment is benign, is too high a cost to pay for every random passer-by. You don't want a security strategy that allows guerillas to DoS your guards by just constantly bringing benign equipment near them.)
This response assumes, though, that the equipment isn't e.g. connected to a satellite uplink and streaming the data out in real-time. (These sites aren't in reach of any cell towers, but satellite phones will still work.) I'm not sure what answer modern military counterintelligence has for that particular threat.
I work on Redstone Arsenal. I don't work with anything especially secured, but I've met people who do. They work inside a SCIF; no network, no personal electronics in the SCIF, but there's no particular requirements outside.
People can just drive down a random stretch of desert road near Groom Lake and start catching signals from passing test craft. At some scale you’ve got to give up on the concept of an SCIF and just deal with the fact that people are going to be catching some of what you’re putting out, doing whatever you can to mitigate the damage from there. (Which—if you can at least know where such people are from a satellite view and get guards to them within 10mins of the perimeter breach when they’re still either making their way deeper in, or are driving back out through a bunch of nothing—translates to “you can catch up to them and wreck their equipment.”)
Like I said, I’m not sure how this strategy adapts to the existence of satellite phones. I don’t think it does. So far, instead, satellite phones have adapted themselves to it: you can’t get an Iridium phone without a security screening. I’m not sure what will happen if “private cubesat satphone networks” become a cheap commodity thing to insert into orbit—I think the US and other governments are simply trying to stall that process as long as possible. (Look at the history of satphone networks that competed with Iridium to see what I mean.)
Though, to be clear, "security screening" is a bit of a misnomer here. It isn't a one-time thing. The point of giving someone a security screening isn't really the pre-screening that occurs when you first sign up; it's the continuous monitoring you are implicitly signing up for.
My understanding, from conversations over beers with a few friends retired from the US Navy and NSA:
Signing up for a satphone (or a NEXUS card, or a private pilot's license, or any of a number of other things—including, obviously, secret clearance or access to a security compartment) marks you as a Person Of Interest in PRISM and other monitoring systems. In response, the monitoring systems begin actually caching the event data they see about you into an online data warehouse, rather than just feeding it all into a data lake. The data warehouse is queried out, for each new PoI, to build an individualized ML model (Palantir Intelligence, I think is the software?), where the data initially gathered during your pre-screen is used as the training data—in est, a behavioural baseline. Once the individualized ML model for you is established, it will be run as a batch process (along with thousands of other ML models), about once per day, against any/all newly-arrived PoI event data in the data warehouse. The ML model spits out prediction error; and the system flags anyone with consistently high prediction error as being in need of re-investigation.
In other words, by signing up for a satphone, you're asking the government to keep a detail on you to see if you do anything out-of-character. Just, y'know, a detail that's 99% automated.
I got the feeling the whole driving away thing was more about that if anyone felt things were suspicious, you weren't getting in, and just wasted everyone's time. Protocol was a big deal.
In theory some random joe could somehow drive to this gate, but I'm not sure how, it wasn't exactly on the way to anywhere. I was also told they would know you were coming long before you got there and not just because of the schedule (not sure if that was true, but someone told me that) ;)
It is all curious to talk about now but when you're alone and serious business guys are around you with guns you just behave as innocuous as possible.
As for equipment I belive the customer paid for each visit, equipment included. Everyone knew the rules outright so they paid a ton for everything.
Beyond just one visit sending hardware to sites for repairs and never getting anything back was SOP even for some security minded private companies, so that wasn't all that unusual. Laptops taken... was quite unusual as at the time laptops were quite expensive.
> In theory some random joe could somehow drive to this gate, but I'm not sure how, it wasn't exactly on the way to anywhere.
Ah, that explains a lot.
> As for equipment I belive the customer paid for each visit, equipment included. Everyone knew the rules outright so they paid a ton for everything.
Wow. Part of me says that's crazy, the other part wants to know where to sign up, since this sounds like it paid well :D
(Of course I'm inordinately curious what equipment was being maintained, but we'll just drop that one on the floor since it's probably quite boring)
Horses only (can't trust donkeys).
Deposit your horse shoes here and we'll provide you secure shoes for the ride home.
/s
It's expected that people will drive there and go from there ;)
Unless you have so few visitors that building additional security infrastructure isn't cost effective.
I'm sure the facility that makes nuclear warheads has an electronics inspection x-ray. If they need maintenance on that, you'd expect him/her to have a detailed background check, and to be shown as little of the facility as possible, and not to be allowed to leave with USB memory sticks or suchlike.
Of course, who knows how many facilities really need that level of security, and how often it's paranoia or theatre?
Humiliation would be if they mocked you for being blindfolded or once you were blindfold stripped you naked and paraded you through the canteen. It's just part of the process, everyone in your position goes through it and no one there would see any humiliation in that.
Also there's nothing like having different accesses than your boss, so when you go to certain meetings or do certain things, you can't tell him exactly what you're doing.
Basically everyone had to turn off their monitors while I walked past.
Not as bad as a blindfold, but a bit embarrassing the times I've had to do it. That and being escorted to the bathroom while they wait outside.
So essentially they had to interrupt a couple dozen people just to get you through a corridor. I can see why a blindfold may seem like a more pragmatic approach.
Honestly.... that could be a good policy rather than have a dude leave something out or wrongly classify a building or something.
Clearance does not mean you can now see everything. There will be compartmentalisation and you will only see what you need to know.
I remember reading about sites in WW2 where people didn't know what the people in the next building did, or often what the project was. Bletchley Park is one example but I also saw a programme about a female chemist working in Cheshire ( I think ) who didn't know she was a key part of the atomic bomb project.
This was before smartphones were super prevalent so not taking your phone really wasn't a big deal. Had my car broken down near the facility I suspect that I would have had "help" pretty quickly ;)
For all I know it was unnecessary, guys at the gate didn't talk much, although I did see them "inspecting" cars.
I got instructions from my company and folks familiar with that customer, it's possible they were just extra cautious. This wasn't like visiting a frequently visited facility or anything where you can look up the rules or anything.
Such a waste, just like most military spending.
- "5 minutes, 100 steps, 55 minutes zero steps" (meeting)
- "5 minutes, 100 steps, 55 minutes zero steps" (meeting)
- "8 minutes, 200 steps, 52 minutes zero steps" (bathroom)
- "45 minutes, 999 steps, 15 minutes zero steps" (lunch)
- "5 minutes, 100 steps, 55 minutes zero steps" (meeting)
By correlation stand/sit times you start to edge pretty close to a rough determination of who is in meetings together, or walking from room A to room B at the same time."Strava heatmap can be used to locate military bases"
https://news.ycombinator.com/item?id=16249955 (267 comments)
[0] https://www.wired.com/story/strava-heat-map-military-bases-f...
Doesn't this really only apply to devices with GPS?
By producing or removing signal, above what would have occurred normally information, leaks out of the system.
It's not fitbit, that's the problem with Android in general.
Also, the leader of Chechnya, Dudaev, was killed in 1996 by tracking his satellite phone signal - https://en.wikipedia.org/wiki/Dzhokhar_Dudayev#Death_and_leg... (more detailed and more conspiracy style version - 2nd paragraph at https://jamestown.org/program/alla-dudaeva-describes-being-i... )
That's not a part of the article.
The article and memo clearly focus on geolocation data. Not a feature I can find in insulin pumps after a cursory search.
An attacker could change that.
So when you consider new ones use wirelessly communicate with continuous glucose monitors (mine uses 802.15.4) which it then uses to adjust delivery of insulin. This feedback loop has been shown to give measurably better outcomes so it not something I would want to disable. Toss in that they connect via USB for reporting upload they become a potentially attractive platform for data exfil.
If you work in a secure facility consider the "insulin only" model.
In SCIFs all non-approved transmitting devices are banned, so if you are an attacker an insulin pump has a potentially excellent exfil method.
Jamming is done at the receiver, not the transmitter. The fact that the power is so low makes it far easier to jam.
Military bases already have rules covering use of electronics like laptops, cameras, and phones, so adding smart watches to that list isn't very surprising.
On an side note, like other federal laws, the DoD is subject to endangered species laws, and actually take a lot of care to make sure they do not endanger them, which is made fun of here:
https://terminallance.com/2017/01/17/terminal-lance-453-ceas...
Back when this controversy was first stirred up it seemed unlikely that anything sensitive was really exposed. Other comments in this thread indicate that the military is perfectly capable of restricting the use of personal electronic devices when they care about it. This seems like a case of the public demanding "something must be done" and the military responding with "okay, we did something".
A proper solution is technological, not social. Selective location GPS jammers, only letting through a different frequency or encryption for military GPS.
If the last decade had a TL; DR, it would be "technology offers second-rate solutions to social problems." If your soldiers lack the discipline to turn off their phones on command, you've got a bigger problem than RF leakage.
Disobeying is a social problem. Imperfect repetition is not.