Bluetooth signals can be used to identify and track smartphones
ucsdnews.ucsd.edu
ucsdnews.ucsd.edu
>BLE [snip] imperfections are introduced by the shared I/Q frontend of the chipset (Figure 1). They result in two measurable metrics in BLE and WiFi transmissions: Carrier Frequency Offset (CFO) and I/Q imperfections, specifically: I/Q offset and I/Q imbalance.
links to the paper:
https://cseweb.ucsd.edu/~nibhaska/papers/sp22_paper.pdf
https://www.researchgate.net/publication/360655420_Evaluatin...
A fun exercise would be to synthesise the detection of all phones in the area. By monitoring CFO over a period of time for lots of phones distributed over an area, maybe it would be possible to build a temperature profile of the area under surveillance and compensate the CFO measurements for temperature. Whilst crystals do drift with temperature, the frequency of a given crystal is highly repeatable as a function of temperature.
Multi-lateration of cell phone radio transmission via precise shared clocks at the base stations gives telcos a ~100m (these days) position that is updated very frequently. In the USA this stored by telcos for 2-5 years and is often sold to both private and government purchasers.
And anyone moderately skilled in SDR with a few thousand dollars can do the same for a small area (much larger than a bluetooth area though).
To private purchasers?
For 2-5 years?
No need for a judge issued warrant?
Just sold?
I can't find the article because Google search terms for stuff like "locating any phone by number" are SEOed to death by scammers trying to exploit would-be stalkers
edit: found it https://krebsonsecurity.com/2018/05/tracking-firm-locationsm...
https://www.mrao.cam.ac.uk/~pjds/temp/index.htm
https://www.theguardian.com/technology/2000/aug/17/efinance....
But this doesn't apply to selling to private companies who then sell their services to the government. And it also doesn't apply to the "anonymized" aggregate data of all locations of all cell users. This is still available and sold to both private and direct government purchasers. And with 2-5 years of high cadence 100m data it's very easy to see where someone lives, works, etc and de-anonymize their paths. The commercial sale of this is big business and has been covered innumberable times on HN over the years.
https://news.ycombinator.com/item?id=17094213 , https://news.ycombinator.com/item?id=17081684 , https://news.ycombinator.com/item?id=17069459
I have plenty of options besides cell phones. I could have a landline, or get my ham license, or pen a letter!
I'm just a subscriber to a private service, after all.
If that is true then that means there is no data privacy protection in the US?
There may be some very specific data privacy laws (like two-party consent states), but yeah, you should assume no data privacy protection in the US.
I have a bit of an issue with that, since one generally expects that they can license any data they own, and it makes things like model releases confusing.
And the laws seem to define new private spaces that formerly didn't have expectation of privacy for most people.
But perhaps it's necessary anyway to prevent even bigger issues.
I can definitely see the problem with a cell company being able to sell data to someone's abusive stalker, even though in general I don't like censorship of observation, for the same reason I don't like ag-gag.
Cambridge Analytica Style desinformation targeting is just one option. Personal location and contact info can easily be used for criminal or political abuse.
At least for recent Apple devices, that's not true anymore (intentionally, as it is used to support "Find my iPhone" even with a dead battery or on a phone that's been switched off):
Zebra devices have always-on bluetooth beacon capability, and even a second bluetooth radio in the battery(!): https://techdocs.zebra.com/emdk-for-android/9-1/mx/beaconmgr...
https://arstechnica.com/information-technology/2017/11/austr...
"Snack packets are made with a foil that combines aluminum and mylar plastic, making them electrically conductive and ideal as a temporary electromagnetic shield for mobile devices—as long as the packet is closed and grounded—and you don't mind a few crumbs on your device."
I'm not sure if that's really true, or why that is... and if it is, how one could do it while on the move.
Whether that charge is equal to ground or not is irrelevant I thought.
I will make the sacrifice tonight and eat a packet of chips for testing I guess. It is a hard life.
So far the trend is towards the latter...
That's scary if you think in terms of a scary state surveilling its citizens. But as soon as you have multiple parties doing ubiquitous surveillance on each other it gets interesting: counter surveillance becomes a thing. Counter surveillance could be a crucial tool to enforce rules related to e.g. privacy.
For example, the act of violating somebody's privacy would be observed by potentially many third parties, some of which might not be friendly. Doing so covertly would get a lot harder and now would have a risk of legal escalation. In fact doing anything covertly would become extremely hard. People will get to watch each other, but not covertly and probably under some very strict and extremely hard to dodge rules.
And of course you having little side chats with other people about helping you out in exchange for something would count exactly as a situation where that conversation might not actually be private anymore.
I would assume that in hundred years, people will spend most of their time in virtual worlds. Would it be important what people do and think if all they do is moving some bits around?
wat.jpg
Google scholar has papers going back at least 18 years on this.
Cool!
Targeting variation in the signal itsel (rather than the content) seems on its face to be much harder to prevent. But I am not a radio (or any electrical) engineer so what do I know? :)
This has been known for years, check out https://wigle.net/
Here's a Defcon talk on it as well: https://www.youtube.com/watch?v=fSsTgazmHCw
(You can go opt out, but if you didn't know it existed, you've been in there a while. It's why I like to turn off my radios when not using them.)
>For Bluetooth, this would allow an attacker to circumvent anti-tracking techniques such as constantly changing the address a mobile device uses to connect to Internet networks.
Maybe not easy, but also not hard. The only thing that screws you up is someone playing with the airplane mode toggle of their phone while moving within your detection radius.
If I'm ever in such a horrible police state that I would want to turn bluetooth off, I would be more worried about the mandatory ankle bracelet all citizens would probably be wearing.
But don't have access to matlab...
This new report works around that.
Philz Coffee in Palo Alto, CA and major department stores in the US have been doing this for years to track foot traffic. If you don't want to be tracked, turn off BT and Wifi and demand the protocol stds body and mfgrs support even stronger randomized hw addresses.
Also of interest, your iOS BLE "Random" MAC transmits every few seconds and can take up to 48 hours to change. I wrote some software for the Pi that would allow me to enroll a phone when someone was nearby (By RSSI) and then with a directional antenna later in the day, you could confirm presence in a house / building.
You can also infer presence of anyone in a house because of this. Oh hey, 2 iPhones in the ex girlfriends apartment, Wonder what's going on in there...
Yeah creepy.
You can even use ultrasonic sound signatures so your phone doesn't even need to be broadcasting using bluetooth, wifi, or cell. Just the speaker alone at a pitch you cannot hear is enough to track you.
Edit: I enjoy how this gets downvoted for pointing out that technology has downsides...
So to your point of it being installed, it already is. Being enabled is whether we trust the governments involved with that switch.