Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
tomshardware.com
tomshardware.com
If you're in a city with 1,000+ home burglaries a year, nobody cares that you clear one and arrest some meth head. But, solve some gruesome or politically-tinged crime and you're holding a press conference and getting praise left and right.
We do the same thing as software engineers. Every large company has some lore about what types of work get you promoted, and many engineers prefer to work on that.
Often the police know who the criminals in town are. However they lack evidence to prove anything. Thus a camera feed showing an already known criminal is enough to get their attention as while they might not care about you directly they criminal who hit you may have also hit a high importance target but they cannot prove it in court - thus convicting them of hitting you helps them for cases they cannot prove.
Actually crime against persons (murder, assault, armed robbery) have higher priority than simple burglaries. Having your property taken away is infuriating but no one can argue that stoping a violent criminal is more important.
First, a lot of simple assault arrests are for objectionable but ultimately trivial stuff - people getting into drunken brawls, spitting on each other, and so on. A series of burglaries targeting a local small business can be far more devastating to the owner than that.
But your argument also doesn't hold because it's clear that there are property crimes that are investigated with zeal. For example, in the SF Bay Area, a person was recently charged with "hate crimes" for taking down some pro-Palestine signs. I'm not making some political point here, but we can agree that the investigation wasn't motivated by the severity of the crime, right?
Rape is s notoriously hard crime to prove and murders are either done in gang neighbourhoods where there sre few cameras and people don't talk to police.
I don't know of any actually actionable improvement ideas to improve solve rate.
Police juke stats and in a number of urban centers are effectively a legalized gang.
you must of have read over the "detectives"--pural--part of that sentence. I have had a burglary in one home, and then a few years later had a home invasion where the person was very obviously identified to the police. The responding officers were able to look him up, have a positive witness ID made, and then see that this was a "bad guy". No arrest made.
Not true at all. Police love footage that provides anything useful when they have time to work on a case and, importantly, the footage is actually useful.
A lot of DIY security camera installs provide useless footage: Cameras are mounted too high to catch faces, lighting is bad, license plates are blurry, and the list goes on. If you can actually catch faces, license plates, or anything else identifiable then it goes into the case.
> We've been told directly by detectives that they are too busy to look at emails with evidence.
That's a polite way of saying your case isn't a priority for them. Caseload is high and most departments have to filter and prioritize aggressively.
Unfortunately, anything involving e-mail evidence gets messy very quickly because e-mails require legwork from specialists to verify and admit with a proper chain of evidence. Forwarding an e-mail to a police officer or sending them a screenshot of something might be useful as a hint in an active case, but it's not going to meet the bar for admissable evidence unless they can get more resources on it.
I was responding to the parent commenter's complaints that police wouldn't look at e-mails in some case (not related to video).
i guess i could have worded that more clearly. the email wasn't the evidence. the email was just providing information for the detective on who to talk to with much more information that would not have a questionable chain as you're suggesting.
It is only recent history that cell phone cameras have become ubiquitous and it has caused a huge shift in the authorities ability to squash their abusive behaviors
In the same way that TV played a fundamental part of progress in the civil rights and Vietnam wars, one of the best tools the average person has to hold people accountable is to control the narrative via video
My only concern is that gen AI will mean that nobody will ever trust video evidence again. I hope we get some kind of signature based crypto verification on recordings to prove they aren’t fake. Like every device is keyed to authenticate the recordings it produces
I would like to opt out of this nightmarish safety hellscape. I never use the phrase Orwellian because it’s so often misused, but yikes is this some 1984 badthink.
My knowledge of the law here is virtually nonexistent. It seems likely that I could still be subpoenaed to turn over footage under some circumstances. But at least I'm in control of that footage and it's not automatically being given to some third party.
https://www.news.com.au/technology/online/security/amazons-r...
(Although Amazon claim to be "sunsetting" that as of a couple of weeks ago: https://www.npr.org/2024/01/25/1226942087/ring-will-no-longe... )
I'd also like to opt-out of having cameras everywhere in public but the fact of the matter is they are here to stay. Additionally, most of the cameras which capture your image in public are not cameras which you installed and they're not cameras which you have the authority to remove. Adding your own cameras to the mix is functionally equivalent to exercising your freedom to speak; really, to document, in this context.
> David Brin is worried, but not just about privacy. He fears that society will overreact to these technologies by restricting the flow of information, frantically enforcing a reign of secrecy. Such measures, he warns, won't really preserve our privacy. Governments, the wealthy, criminals, and the techno-elite will still find ways to watch us. But we'll have fewer ways to watch them. We'll lose the key to a free society: accountability.
Note this was published in 1999, so one can argue about how far we went in either direction. I think we mostly ended up with a collective shrug.
The privacy implications are astounding. But, as you say, this is all inevitable (I intentionally left out your "nearly" there), and it's a very good question about how that's going to change society and whether we (I) want to live in that.
"Before he was George Orwell, he was Eric Blair, police officer" -- https://www.nytimes.com/2024/02/05/books/review/george-orwel...
Today's "nightmarish safety hellscape" is brought to you by (amongst others) Toby Roberts, a former technical surveillance officer at the UK's Eastern Region Special's Operations Unit, and the Raspberry Pi Foundation where he's the official "Maker In Residence". -- https://www.theregister.com/2022/12/09/rpi_maker_in_residenc...
Stopping short of that, there'd still be value in being able to cryptographically prove that your home surveillance video (or dash cam video) came from _your_ camera and is unaltered from the original recording.
I think going forward, the "circle of trust" for the next "capital insurrection type event" video evidence will be founded on multiple videos of the same scenes from multiple angles and from devices owned by un related individuals.
Although, the biggest category of cameras these days is cell phones, and all (most?) of them have some sort of hardware trust store with private keys that are extremely difficult to extract, so it wouldn't be to much of a stretch to consider having Android and iOS default camera app being able to digitally sign photos/video - all without "a centralized signing administration" and piggybacking on existing token security methods...
Like, ok, every device is keyed to authenticate the recordings it produces, using a unique key signed by the manufacturer - as long as a few valid device keys ever leak from the device or the manufacturer, any fake video can get signed with a valid key from Camera#1234 from ShenzhenCameraCorp567, ltd.; you're not going to make every $1 camera module in cheap embedded devices tamper resistant.
For web CA's to work, all you need is that the single certificate for the site you're choosing to visit is good - but if you want to use a similar system to verify trustworthiness of viral images originating from strangers through social media, you need 100% of the camera certificates to be valid - if there are any leaked certificates, then manufacturers of fake images will use those; and on the other hand if you "revoke" everything from any compromised manufacturer, people won't just replace their cameras, they'll simply keep posting data with their valid-but-invalid certificates and you'll either have to automatically mistrust lots of genuine true content or be vulnerable to fake data, and most people will choose the latter.
assault gets less time than that, and i'd hope that getting attacked physically would rate worse than the loss of possessions on your chart
Who said or implied that?
Also, non-Western countries generally don't have a great track record with things like gay rights, women's right, etc. So I'm mostly happy that we do things the Western way and not otherwise.
Give the car thieves 3 chances and the muggers zero.
Increasingly, cameras are the way that security companies dispatch their guards. They are far more actionable than traditional intrusion alarms. Depending on the police department, alarm reports with video may be treated as crimes in progress while intrusion alarm activations alone are not.
Unfortunately the technical standards around video verification are not widely implemented and so in practice it usually requires getting your intrusion alarm, surveillance, and security response all from the same vendor. There are common standards but the consumer security industry today is heavily organized around walled gardens and there isn't much adoption of the industry standards outside of commercial.
In the commercial world these types of systems are often referred to as "pre-intrusion" since the monitoring center observes the cameras in realtime and, in theory, could dispatch guards to suspicious activity before any intrusion alarm would be triggered. In the consumer world, for cost and privacy reasons, the monitoring center usually only receives video after the activation of an intrusion alarm.
What people expect:
- triggering an alarm so the theives don't spend the night looking at every nook and cranny of the house
- having proof that it was burglars and not the drunk neighboor forcing his way to the wrong house (if so, you'd also want proof of that though)
- get the cops and insurance to be on board and have the incident processed swiftly. "solving" here basically means getting the insurance monney to buy the missing stuff.
Edit: it's also very useful to me to keep video logs of my shop and other areas. I can easily go back to see what happened if something goes wrong (stuff falling, me forgetting stuff somewhere, figuring out why there were big car tire tracks across my yard, etc).
Yep.
Dashcams don't prevent traffic accidents. But they _do_ make it much much easier for the not-at-fault party to make their insurance claim.
It'd be nice of home security cameras "stopped crime", but they are much more useful in documenting your insurance claim. Which is still worthwhile (assuming you have insurance to claim on).
What else do you need except that you got stolen n items when doing your insurance claim?
I was notified by the motion alarm in my driveway and then my front door and was able to hit the Siren button and scare them off.
Without that, I would have had 6 "armed" intruders inside my house with myself+partner+4 year old.
The camera system prevented the crime being far more serious than it would have been (both cars+valuables stolen and maybe a stabbing or 3).
I was also considering the safety glass option, given that we had a porch door with "all" glass (just a small wooden frame). I'm a distracted and clumsy at times so I was worried about running through the glass in the door. After talking to the window manufacturer, I learned that I didn't need the safety glass option since the extra sound insulation meant the construction was laminated, hence acted much like a laminated safety glass.
Haven't tried to break them yet, but after helping getting them mounted (about 50kg for a 1x1m window, heavy!) it seems to me it'll take some effort to get through them. Proper anti-burglary glass is likely much better, but wouldn't surprise me if a group of teens would struggle.
Anyway, wasn't my primary consideration but I sleep slightly better at night compared to the old windows which could easily have been shattered with a simple rock, including the porch door.
edit: Also sleeping much better due to the sound insulation. The triple-pane does most of the damping I imagine, but between them it was a vast difference. I had three ~10 yo boys running around screaming (or playing as they'd say) 10m from my wall, and once I closed the new window to my room I could barely hear them. Not at all like the old windows.
edit 2: We also got the option for IR blocking, it adds just the slightest blue tint but cuts 60% of the IR. Made a massive difference in keeping especially the living room cool during summer.
The windows have a U value that's significant lower than what the old would be due to the three-pane glass. The lack of cold flowing compared to the old windows was very noticeable as we got them mounted during the winter, so had an almost direct comparison. This winter we had a week below -25C and even then it was hardly any noticeable "cold shower".
The IR filter was incredibly noticeable when opening the porch door on a bright and sunny day when outside temps were roughly same as inside temps, holding one hand behind the main window and one in the door opening in direct sunlight. The difference in radiant heat from the sun on each hand was striking. It was also very noticeable on the living room floor during summer if the porch door was left open for a while, standing with one foot on a patch lit by the window and the other on a patch lit by direct sunlight. Though it wasn't unexpected given the blackbody radiation from the sun[1].
The additional sound proofing I'll agree on though. It wasn't that significant on paper, IIRC listed as 5-6 dB reduction, maybe less.
But we had waited and bought them during a 50% off campaign which included the extra options, so we went for it as it didn't add that much after the 50% reduction and my SO is really affected by noise.
[1]: https://en.wikipedia.org/wiki/Sunlight#Composition_and_power
Inspiring, thanks for sharing!
I know of at least 2 countries where police will be immediately dispatched to a robbery in progress if a person is caught on camera by the alarm system and the owner confirms it's a robbery (e.g. on a phone call). By law, police won't be dispatched unless a person is caught on video, due to false alarms.
I know this because that's what happened when my home was robbed and I was out of town. Fortunately, since the police response was quick the thief didn't have enough time to take anything (!), as he must have been in and out in 2 minutes at most.
It also helped that there was no jewelry or cash inside the house, of course.
Although unsolicited calls are not a problem here, fortunately.
2) You might be right about some places and are definitely wrong about quite a few others.
Having clear face images of "troubled youth" known to the cops has led to arrests in Australia, for one.
Generally they are in and out in a few minutes long before police or a security service can dispatch someone.
My system has a large battery backup for an old lantern or something, recording, 4G fallback, is wired, and I regularly spend time outside.
All of which is invalidated by people staking out a place and wearing a mask.
I saw a burglar with almost all of my neighbors things and appliances. Thought they were moving or upgrading and waved.
My favorite part of the beginning of the pandemic was going to the bank in a hankerchief like an Old West bank robber. Just as effective today as back then...for hiding your identity just slightly better than Clark Kent taking off his glasses.
On a health-level, how is this remotely controversial? Bandanas--especially draped "bank robber" style--are simply a bad choice:
> Loosely folded face masks and bandana-style coverings provide minimal stopping-capability for the smallest aerosolized respiratory droplets.
-- https://pubs.aip.org/aip/pof/article/32/6/061708/1068115/Vis...
Dude, re-read the thread:
1. You specifically framed it as during "the beginning of the pandemic."
2. You brought up people wearing masks (implicitly for health concerns.)
3. You said those particular masks were amusingly ineffective (for disguising identity in the bank.)
4. I wryly noted those particular low-quality masks were indeed ineffective in multiple ways. (The health concerns that motivated them in #2.)
I can't make you enjoy my reply, but stop acting like this is some kind of shocking non-sequitur leap into forced realms of conversation. You more than set the stage yourself.
From that observation I infer masks are effective at eliminating virus transmission, which is quite extraordinary given the virus is so small.
And whether you can distinguish between those and rhinoviruses / adenoviruses / etc?
There was another poster on that thread who said they were able to smell colds. I wonder if this is just extremely common and / or if we can all be trained to do it like with wine?
> From that observation I infer masks are effective at eliminating virus transmission, which is quite extraordinary given the virus is so small.
This inference doesn't really make sense to me. I bet putting a cigarette in your mouth, or a chopped onion in front of your face, would achieve the same frustration of this ability.
This brings up another point, which is that one of the best things you can do for your security is to be well known by your neighbors. If no one knows your appearance and habits then all kinds of crazy stuff can go down while you're away and your neighbors won't know anything's wrong.
The other glaring flaw with cameras is that they always face perpendicular to the street, so even if the getaway car has plates you'll never get a shot of them. Not that the car isn't stolen anyway...
On the other hand, if a place has visible cameras and ADT signs, do they have valuables worthy of protection and worth the risk?
With security ops like this, it is important to understand that they are not targeting joe schmoe. They are targeting specific orgs/people that have a lot to lose.
Using the "Lockpicking Lawyer" as an example: "Oh they can get into a security shed, who cares." It's not about meemaw's security shed, its about a cop's trunk with guns in it.
Approximately 6 years ago, I saw a face detection demo, which detected the face of a man behind a snow mask while running in the night with minimal lighting from a side-shot. I think seeing the eye and nose geometry was enough.
The only time the system saw the face was from another camera in the same system head-on. I don't remember whether it was masked or not.
If this is available for defense, it can be made available for civilian applications, too, but it won't be, because then you won't be able sold it to that price because of depreciation.
For what it is worth, more recent nest cameras have battery backup and buffer up to an hour of video if the WiFi is out (https://store.google.com/gb/magazine/compare_cameras?hl=en-G...)
So in theory if the perps cut the power you are ok, and if they jam the WiFi you are ok too.
A month or two ago 3 guys actually did try to break in (without jamming) and the police took the videos but still weren't able to catch them. It gives me some.hope that perhaps one day maybe they do catch these guys and it serves as evidence.
I now have the cameras hooked up to Home Assistant so if they detect a person (and not e.g. a fox) and we are out, a Raspberry Pi starts playing loud barking noises and a few lights turn on. During our breakin attempt, the guys were on their 7th (!) attempt at kicking in our front door and you can see from the videos that within literally a second of a light going on (...when we woke up) they turned and ran off so signs of life from the inside seems to be a strong deterrent.
I use cameras with ethernet and PoE, those are also cheaper than wifi. On the other side of the cable there is PoE injection, ethernet switch, recording and object detection server, all connected to a UPS battery. If power goes down, I still have cameras and network running for a few hours, notifying and alarming if anyone trespasses. When power goes down, I also get notification with snapshot of the incoming electricity box on the street, to know if it was local issue caused by a person, or something else.
For me as well it was quite reassuring to be able to piece together exactly what happened.
So rather than just being woken up by the noise of someone trying to batter the door down, I was able to go back and piece together 3 or 4 minutes of what happened - the cameras caught their car arriving, caught them going down a side road, caught them climbing over a fence at the back of my house, caught them trying to climb up onto the roof, caught them creeping around in the garden looking through windows, caught them trying to kick the door in, and then caught them running off and driving away.
I had enough that I was even able to write a post mortem with timestamps etc. This helped us make some security improvements, but for me personally it helped me process the whole situation - it was less traumatic for me to feel like I at least had "complete" info and was in control and generally feel less victimised and helpless.
Unifi restricts choice but everything works in a few clicks and both the web app and mobile app management interfaces.
With WiFi cameras I was just able to spur into nearby power which was already wired into the house. Each camera took maybe 30 minutes to do a neat clean permanent install. Running ethernet and making good would have taken many days potentially weeks, and as others have said it is mostly about deterrent and peace of mind.
It is easy (and kinda fun!) to get paranoid and get carried away planning all this stuff out and thinking about "what if..." scenarios, but ultimately home burglaries are typically just opportunistic things without much premeditation or planning. Sure if you are a specific high-risk target and people are going out of their way to target you then sure go ahead, but you'd probably just be better off with dogs at that point!
With Scrypted I could even plug them in as HomeKit Secure compatible cameras.
Steal the camera
Totally possible of course, but why not just burgle the house next door that doesn't have any cameras. You don't you need to outrun the bear, only the other humans nearby.
We were evil kids and possibly part of the reason there are randomized passwords now.
Anyway, this is basically the same attack, just with a B&E and a lot more temporary. I'm actually most surprised that these devices don't appear to do any buffering when a connection is lost. And even then, the internet will not stay active if the thieves just go to the neighborhood junction box and pull the plug on the house.
:sigh: too much reliance on technology...
It was an easy fix, but hilarious.
1: Get the other house's TV sighted in the eyepiece.
2: Move your eye out of the way and hold the remote control up to the eyepiece.
3: ...
4: Move back and observe the confusion.
If I shine a laser through, does it really focus on the sighted spot? Does the coating on the telescope not filter IR? I thought most did maybe not. Could I shine a flashlight through and illuminate the room? How is that not the same?
2. Maybe! Cheap ones might not even have a coating.
3. You can do this! See (1) for how much brightness you can expect.
If it worked, it’s due to televisions having a relatively low activation threshold for user comfort, so you don’t have to aim the remote accurately, or often at all! Often secondary or even tertiary (or more) IR reflections will trigger television functions. For a quick sample, try aiming your remote at the opposite wall and seeing if the tv turns on. I don’t doubt this story, but I also believe it would have worked merely by pointing the remote at the TV, telescope or no.
But first make sure it isn't radio controlled. The remotes at my old house were all assigned a cable box and you could control that box with its remote from anywhere in the house.
> But first make sure it isn't radio controlled.
Based on my experience, this isn't actually a problem for people interested in trying it with their TV as RF remotes included with STBs, streaming sticks, etc., still have IR transmitters built in to control the TV.
Specifically, the actual device (e.g. cable box) is controlled with RF signals (often bluetooth) but the power and volume buttons are often controlled via IR because those are functions of the TV and most TVs have IR receivers. TV power/volume can also be conttolled via HDMI-CEC in theory, but in practice I've run into compatibility issues more often than not that way whereas doing it over IR just works.
> All refractive optics require IR filters.
The reason seems to be it prevents "bloating" of bright points of light - eg stars, and increases contrast in the visible range by cutting off UV and IR (which CCDs are apparently sensitive to), so it is in fact desirable to have IR filtered out.
Now, does that mean it's default? Maybe not.
IR filters are generally pretty effective too, so just having one anywhere will do the trick unless you're dealing with a lot of light. Cameras which would be undesirably sensitive to IR would usually have the filter built in, basically right on top of the sensor. No need for added coatings on the telescope itself.
Thus the reason behind the security mantra, "If it's not secure by default, then it's not secure".
Because normies know very little, if anything, about IT security. And to be fair, they shouldn't have to. When you buy a house or a car, how often do you take time to examine the mechanism in the door locks, and check to see how easy it is to pick them? Or do you rely on the locks generally being secure, albiet far from Fort Knox-grade.
When it comes to IT they expect someone else to do it. The problem is no one else cares about your security as much as you do.
Never, based on how easy some cheap locks are to pick.
I suspect it was a plug in ESP32 dongle or something hiding in the restaurant.
Some prankster would feel bad when asked to explain themself to a parent or detective.
But my point wasn't that they'd get caught, but that those who were only (non-sociopath) pranksters would feel bad, when they started to realize that pranks can have serious unintended effects for themselves and others. Few teens would intentionally show goatse to a young child. The prankster just didn't think this one through, past "wouldn't it be funny if someone saw goatse due to a clever hack of mine", past the misdirected teen impulses to stir things up.
Of course it's less useful now, even the cheap prepaid mobile phone plans will get you a usable internet connection.
So does every wannabe be l33t hax0r.
Also made sure to check my myspace. Never did anything particularly evil. Definitely downloaded some movies off Kazaa via my neighbor's wifi, because it was faster than my wifi.
Realistically, if you're going to have wireless security gear, it needs to detect when it's being jammed and immediately sound the alarm. That's the only way it's even remotely viable. Just recording people stealing your stuff isn't enough.
Not to me. As far as I'm concerned, you improved the status quo by punishing the laziness of corporations. They half-ass the products with complete impunity. You showed them what happens when they do that.
An example: all wireless protocols can be trivially jammed by just spamming noise, like anything else, but most can also be smart jammed by various methods: spamming disconnect packets, malformed packets that crash the device, noise jamming very specific parts of various transactions, like the alignment section of OFDM QAM on 4/5G, etc. This means, instead of needing some multiple of the targets transmit power to cover a wide area, you can use as much or less power than the target which is extremely bad from an EW standpoint.
We need to build smarter wireless protocols that can both resist casual assholes, but also higher sophistication adversaries up to and probably including nation state actors for the safety of our infrastructure.
And yes, that means insulin pumps probably shouldn't have radios in them.
You don’t want federal crimes because you jammed someone’s wifi
I think it’s more likely just a bit harder to find a known good RF jammer than a rock. And a rock was usually fine. Or used to be, anyway.
Aliexpress sellers will happilly mail you whatever RF jammer you want.
Virtually every microwave I've tested is an excellent jammer for 2.4 GHz. It even has a user interface for how long like you'd like to jam communications!
I'm legally allowed to "jam" your WiFi so long as I am using the spectrum for communications because I am licensed user unlike the majority of 2.4 GHz users. Even if you file an FCC complaint they aren't going to do anything.
Now if you move up to 5+ GHz range it really depends. If you start jamming the DFS bands it'll eventually get noticed.
By pumping microwave energy into the water molecules. At around 2.45GHz[1]. So it doesn't take much drift and crappy shielding to crap all over adjacent spectra. This is extremely well documented and "they should build better microwaves" hasn't reached give-a-shit level for most of the world.
[1] https://iopscience.iop.org/article/10.1088/0031-9120/39/1/00...
They had lots of complaints about the quality of wireless they had in their house. I dropped in more access points even after everything worked perfectly when I was there. Then they got a call when I was there and everything stopped working. This was before 5GHz was really common, but B/G/N would just stop functioning.
http://www.arrl.org/getting-licensed
If you do that though, you get a bunch of bands from DC to light where you can argue with old people about gout and the government.
You can also petition the FCC for an experimental license provided you have a valid reason. It isn't uncommon to see experimental licenses with allocations like 2 MHz - 60 GHz provided no transmission is 24/7 or unattended.
Is there an FCC overlord watching these signals?
https://www.pcmag.com/news/fla-man-fined-48k-for-jamming-cel...
Also he ran the jammer every day along a very specific route. It's like robbing the same liquor store 3 nights in a row. Eventually even the laziest cop just waits around back for you to show up.
First way, they get reports from people/companies/band users and will maybe act on them. This assumes it's in a band they care about, people report stuff in the ham bands all the time but they nearly universally ignore those.
Second way, you interfere with something safety critical, such as an airport, where they may have installed equipment to monitor RF in particular bands.
TL;DR: unless your neighbor is an RF professional and can determine that they are being interfered with instead of "huh, the wifis no workie...shrug", they just won't do anything.
Everyone is supposed to get along and play nicely, and jamming is the definition of not doing that.
Intentionally sending disconnects/de-authentications too, if the intent is denying lawful use for someone.
Yeah if you rig up a 1kw tube amp and start splattering a big chunk of the FM boardcast band, jam their cash cow mobile networks or run around with a GPS jammer near an airport you'll get a near immediate PP slap but beyond that they'll maybe send a car eventually. They don't have the ability to detect and locate this stuff in real time and, IMO, probably shouldn't for privacy reasons.
Marriott was jamming for years, until they were forced to stop. Keyword: years.
If someone is making temporary jamming attacks (even on GPS or cell), unless you do it at your house or stationary, you ain't getting caught.
I know 'a friend at the hackerspace' who did a .25w GPS spoof to make the city look like it was in Moscow, Russia. Nobody responded.
There's lots of types of jamming, not just white noise static.
"A first offense is a misdemeanor punishable by up to a $10,000 fine and/or up to a year in jail. Subsequent offenses are felonies punishable by up to 2 years in prison. In practice, this might result in only a civil action by the FCC. But it is forbidden by Congress and can be punished by imprisonment." https://law.stackexchange.com/questions/94617/is-deliberate-....
You can fuck with RF as much as you want, as long as you A: don't do it constantly, B: don't do it in the same location every time (at home), and C: don't do it in a band belonging to someone who has their FCC field office's number on a post-it note and has paid the FCC lots of money.
The FCC told the police they didn't care, it took a bunch of HAMs running around to find the source and politely ask them to maybe fix it or at least consider turning it off if someone else complains again.
Ideally, the operators of such venues would go and place an appropriate amount of picocells inside the stadium, but these cost a ton of money to install and they are only used maybe once a week for two hours, so there is no financial incentive for the providers (particularly if the general public has gotten so accustomed with a baseline of enshittification that they don't even protest any more).
For example, take the Munich Oktoberfest. The Theresienwiese is 42ha large and fits about 600.000 people without tents or ~200.000 in the full Oktoberfest buildout - and each year, every provider literally spins up hundreds of cells of all sizes, to accomodate the up to 20, 30 terabytes of data each day that all these people create [1]. But since that is two weeks of full load, it's worth the effort in the end financially.
[1] https://www.golem.de/news/netzabdeckung-mobilfunk-beim-oktob...
I don't know why they don't bring them to sporting events and then take them out at the end. Probably labor.
It might be the word of these drivers against the stadium owners/operators, but I am still willing to entertain these accounts enough to see people perform preliminary investigations.
I would like to see signal strength maps across different times of the day and week for each of the major cellular providers in an around these venues and compare them to comparable maps for busy downtown areas.
I assume some of this data is already collected by each individual cellular service provider for their own network in order to access performance and areas of future investment.
Kicking in doors is also illegal.
Not really, it is, but nobody gives a shit.
Before zero-trust was the latest cool buzzword on the block, there was the Jericho Forum[1].
I vividly recall attending a Jericho affiliated event where one speaker was banging on about how insecure those bluetooth phone dongles were.
Nothing changes. Security remains an afterthought.
But back to the topic at hand, security camera, home WiFi, asking for trouble really. There are some things for which you really should just run a damn cable.
Even many WiFi attacks which can be executed by off-the-shelf WiFi hardware require specialized driver/firmware hacking to execute, since most WiFi firmware isn't designed to send frames "out of turn" or with the wrong flags set.
This is all evolving rapidly and I fully expect this to be one of the hottest topics in coming years. Flipper Zero is an obvious example of the change here - it was absolutely nothing new hardware or software wise, but providing easy access to standard BLE primitives and years-old sub-Ghz radio chipsets triggered a variety of meltdowns.
More powerful SDRs and basic "building block" libraries for SDR are only becoming cheaper and more available every day.
People are routinely being tracked via bluetooth for example but very few people think about it or bother to disable bluetooth because of it. Companies (and anyone else interested) just get to scoop up all that data and use it for whatever they feel like.
Data cabling is omitted from new builds because it doesn't sell homes and is just a cost.
The only recent comparison I can think of is how some cities actually required lead pipes for drinking water for decades.
I don't think so. I think he's suggesting that without a code that does require it nobody is going to bother including it even though they really should.
Very very few people had interest in the slight added expense of the cable and labor to do as such -- all insisting that they only needed it to / from cable modem area to their aspirational wifi router location.
This is like turning down indoor plumbing and instead putting a nice heated, carpeted breezeway out to an outhouse you rent.
⸻
1. The other irritating thing was discovering that the light switches were attached only to the faceplate which in turn was attached only to the drywall.
Good call. Although, I just had it done recently and I was pleasantly surprised at how noninvasive it was (the electricians worked really hard, so that's part of it). We moved things out of the way for where we wanted the jacks installed and they ran the cables through the wall with a minimal amount of holes. Definitely would have been even easier if we didn't have anything in the house at all, but there was way less ceremony on my part than I was expecting.
We already have. Powerline is a thing, and for smart home stuff you don't need high bandwidth.
Ideally, you put conduits in the wall then upgrading cables is easier.
At the very least for this particular case, WPA3 mandates Protected Management Frames (PMF) to prevent de-auth attacks on Wi-Fi networks.
A device that looks like solar-powered garden lights, but it has a wifi jammer built inside, and you plant them outside businesses such as banks, in the perimeter of their buildings (banks usually have large setbacks and include huge planter boxes (as bollards - see fed reserve SF that had to remodel the planter boxes because OWS folks were camping in them) to keep vehicles from ramming through doors
But "jamming-bombs" might be really interesting.
Is it illegal to spam noise on any frequency? Whats required? the SSID youre attempting to jam?
If so, just scan for networks and pick one... then spam it with auth requests with a rotating table of MAC addresses/IMEIs etc...
And if we think someone is pulling a stunt like that, we can call the FCC direct, and when we do, they do care, and they bring pretty impressive tech when they show up. Sometimes, as I understand it, with the FBI in tow.
(have micro RF 'jammers' that are the size of peas (they just emit enough RF noise to the local APs - - and throw a handfull in an area so RSSI RTLS is moot for the main jammers....
(more of a comic cyber - Ronin type comic that happens in a retro future Tokyo) https://i.imgur.com/jBc4jtv.jpg
I used bank as a blanket example, OWS DNA...
or take out a Blackrock office...
I was just saying that cyber crime/terrorism/activism are all going to use the same tools against the same folks sooner than you can drop a packet.
You mean just like it has been forever? Gosh, I guess we need to figure out that thing we've known about for decades. Thank gawd someone omn the internet clued us in.
And the idea Blackrock somehow doesn't have better opsec than we do. They have and order of magnitude more money than us, and far more reputational risk!
Bless your heart.
And banks and blackrock seem to trigger you for some reason. Oligarchy Sycophant much?
-
But seriously, yes I am sure Blackrock DOES have great opsec... but that doesnt preclude them from being a desirous target.
we need more OWS, and less smart-ass flippant comments, such as yours, as well as things I have said in the past (Ill own I get flippant and emotionally irrationally at times - but seriously - private equity doesnt need a hair-cut, it should be scalped.
Standard kit now is you get an RF extender that bridges the distance from a key inside someone’s house to the car; then the car just lets you open it and drive it away. Much faster and simpler than the old slim Jim ways!
The dashboard will immediately warn you that a key is not present (audio and visual icons), but both cars will not do anything to immobilize the car after the key has been left.
The device is actually two sets of equipment. When the unsuspecting victim parks and locks the car, a thief standing not far away holds the first device, which is used to pick up and amplify the electronic signal as it is sent between the car and the key fob.
That signal is relayed to a second device, which tricks the car into thinking that the key fob is near the car. That disarms the security system, unlocks the door and authenticates the engine to start.
https://www.latimes.com/business/la-fi-hy-mystery-car-steali...
once it’s started and in drive the key isn’t needed.
If you start a car, and then take the key out of the vehicle, you will get a message like this: https://i.ytimg.com/vi/Jo6gzVfAElc/maxresdefault.jpg
You will be able to drive the vehicle until it is put into park or shut off, and you won't be able to drive it again until the key is present again.
This has stranded some people who have done the following:
* start the car
* get out for some reason
* leave the key by accident
* get back in the car and drive away
* park at their destination
* they are now stranded without a key
My 1996 Mustang had a bad battery, so it would barely start. I took the remote fob off the key ring and left the car running, but locked it (using the physical door-lock button). When I came back later, the fob would not open the door.
WTF? Had to have another key brought from home.
Another good one: If you open the back door of a Mini Clubman (or the regular Cooper, most likely) and then accidentally drop your fob into the car and close the rear doors or hatch... the car will re-lock itself and you're fucked. This is great when it's a hot day and you just put a dog in the car, which is in the sun. Now you get to break a window. Yay German engineering.
At least in the two Hyundai's I've owned with this type of system - an Ioniq hybrid and a Kona EV - it drives just fine once started even if you chuck the key out the window.
This was surprising to me. In a previous car, I had a remote start that would specifically kill the engine if you pressed the brake without the key in the right position. So the stopping the engine was something that I just assumed would happen as well. Unless there's a concern about just having the engine stop while actively being driven???
The majority of cars depend on the engine to provide power assist on the brakes and steering. Without power assist the physical effort required to stop and steer goes up significantly. Suddenly having the control dynamics of a multi-ton chunk of metal change dramatically while at speed isn't something most people are capable of responding to correctly. Having the engine stop in the middle of a busy intersection is another way to have a bad time.
> I had a remote start that would specifically kill the engine if you pressed the brake without the key in the right position.
Being able to start the car remotely and being able to put the car in gear and drive without the key in the ignition are independent features.
It'll keep running. Can you imagine if it stops detecting the keys because the coin-battery is dead and the car all of the sudden stalls?
Only when you stop the car and then try to start it you'll notice.
Annoying though, I've really enjoyed not having to dig through pockets to open the car :(
I know that NFC itself does not require an internet connection, but the whole point of requiring a smartphone at all here is to have an app that millions of people MUST install, to collect data to sell. I won’t at all be surprised when they arbitrarily lock NFC keyless behind a required internet connection.
I’m tired boss.
Car: "please respond to challenge blah" Key: ENC(car-public-key, SIGN(blah)) Car: "too slow"
Physics itself limits how quickly you can do a round-trip to a device that's a certain distance away. If the timeout for the operation is set near enough to those physical limits, a relay attack won't work.
(the attacker's parts don't need to be high delay themselves, could be a pair of gain antennas and amplifiers.)
Keyless entry + keyless start means your vehicle could be gone before you've even got your shoes off after you get home.
Burglary perps are primarily worried about a 9mm penetration to their skull by a $100 hi-point.
If you’re going to put up a security system sign, make sure it’s for a system that works differently than the one you actually have.
Such houses are extremely rare. I'm going to assume you have never attempted this silly scheme for obtaining free guns. Most police cars have a shotgun under the front seat; have you tried looting those? I don't recommend it. This has to be the most ridiculously out-of-touch comment I've ever seen on HN.
There's a variety of things going on here:
1. The bar for "gun worth stealing" is often "any gun". Just in the same way that the bar for stealing a car is "any car". Thieves aren't exactly targeting Kia and Hyundai because of their great resale or scrap value.
2. The vast majority of houses with guns aren't keeping them locked up in safes.
2. The vast majority of houses with guns aren't keeping them locked up in safes.
This is false. Source or gtfo.
22% in a safe
https://www.rand.org/research/gun-policy/analysis/essays/per...
> The 2016 survey found that 46 percent of gun owners stored all household guns locked, of whom 22 percent stored them in a gun safe or cabinet, 13 percent in a gun rack, 6 percent in a locked gun case, and 5 percent in another locked location
Cabinet = crowbar opens in seconds
Rack = easier than a cabinet
> Mostly from cars
It's like 50% from cars, yes. Still well over 100k stolen from houses
Also the reason why people end up with guns in cars is often because of dumbass laws like forcing you to abandon the weapon before going into a liquor licensed restaurant, park, daycare, post office, etc. Theyd rather the gun get stolen and carried by a crim than a licensed carrier walk into the post office.
Removing carry restrictions I think would significantly lower accounts of unsecured (car) storage. Only takes one time of going into post office or picking up your kid at daycare and now you're tossed into stats of someone who doesnt keep all guns secured at the home safe.
No idea, I'd guess it doesn't get included in the numerator or denominator
> Also the reason why people end up with guns in cars is often because of dumbass laws like forcing you to abandon the weapon before going into a liquor licensed restaurant, park, daycare, post office, etc. Theyd rather the gun get stolen and carried by a crim than a licensed carrier walk into the post office.
Yes I think this is pretty much correct.
No, they are not. The most common storage system I've encountered is a wood cabinet with a framed glass door. Some people have safes they'll keep some of their guns in: it's where you keep the nice ones to prevent hanger rash. The rest are near a door, on a night stand or behind a truck seat.
Find a neighborhood with a lot of hunters. There will be zero burglaries.
A gun rack of full of long guns is a prime target.
I guess an ESP8266 costs way less than all the chunky passives required to do powerline comms though.
You also have plug in phase couplers that you can put wherever you have a 220v appliance like a dryer or range. Handy especially for older houses where running new cable can be a significant challenge.
I don't know if I'd want to depend on incidental capacitive coupling to carry signal between phases. I guess if it works it's likely to go on doing, but I feel like there's got to be some pretty sharp bandwidth constraints for noise, especially in residential...
There are powerline home control protocols. X10 is the big one but it is old and flawed. UPB and PLCBUS are new ones but they are proprietary. Insteon is interesting one that can do wireless and powerline but recent products have dropped powerline.
I think Matter is going to kill need for powerline. Matter goes over Wifi, Bluetooth, Thread, and Ethernet. Thread is low-power mesh like Zigbee, but should be able to use Wifi or Ethernet to bridge gaps.
In every IoT scenario other than window and moisture sensors, you generally have access to a plug of some kind. I'm honestly surprised that HomePlug isn't built into IoT devices more often.
I think it is mostly used for industrial applications at the moment, but don't see why it cant be used in consumer applications as well
Flipping a house in gentrifying neighborhood. House burglarized a total of 3 times.
After first time, installed cameras covering every possible angle.
Both 2nd and 3rd time - They wore masks and did so in the early morning hours (3am-5am) Had several people case the house without masks. Either they didn't notice the cameras or they didn't care.
3rd time I had some choice words for the foe through my Video doorbell and let him know I would be there before the police and suggested he be gone before I get there. I got there in 10 minutes flat ready to beat him to a pulp with a tire iron.
I wish we instituted harsher punishments for thieves when they get caught. It may be unpopular opinion, but I am glad I have the right to kill someone and defend my property if I see fit if they're in a ski mask ready to take my things.
With the destruction of the middle class it's true for a lot more people than it used to be.
In a stroke of luck, I also saw him a few minutes after I arrived onsite (did a drive around the neighborhood) and he took off. I literally saw which apartment building he disappeared into.
Lets say there are 12 units in a building (it's a smaller complex built in the 90s) it would not take them long to catch this guy.
They did nothing. I gave them his face in HD and where he was located.
What did you expect them to do? Search all twelve apartments without warrants?
That's not how the constitution works.
No one said they had to go inside. BTW, these apartments I am referring to are completely open. Anyone can access. They're ghetto.
A variety of races are residents, I’d imagine. But nice try.
Now, of course no one could have answered or they could have told the police to go away, but knocking on someone's door doesn't require a warrant.
Maybe he would have been dumb enough to open the door himself.
In any case, hope the $200 camera he stole was worth it. Almost cost him his life.
He had on a ski mask and appeared to have a metal object in his hand on the video.
Oh yeah, and before anyone says that is what insurance is for... HA! They don't cover that shit.
If you arrived to the house and killed them with a tire iron you would likely have been charged with murder.
I strongly recommend reading The Law of Self Defense by Andrew Branca.
Between my vehicle and the “I’ll shoot you” signs, no one disturbed the residence.
It was a pain sleeping on a blow up mattress for two weeks.
I don't understand why Minnesota is catching strays for a problem that affects the entire country. The hot new tech is the problem here, not Mark Tyson's cute naive northerner strawmen.
Companies like ADT hopped on the IoT bandwagon because it's cheaper and it gives the sheen of advanced technology. In reality, wireless security systems are far more vulnerable than their older, wired alternatives. You can jam them. They can simply drop connections on their own due to interference. Many of them rely on cloud services that introduce their own points of failure (that's not really Wi-Fi's fault, but with one form of bullshit usually comes the other).
Edina is notorious in the Twin Cities because it's where the old money lives - it's immensely wealthy compared to almost everything surrounding it. 100% of the blame rests on the companies taking rich-person home security budgets, and using it to install low-end Wi-Fi cameras. The victims here could certainly afford a wired solution, and I'd hazard a bet that they paid enough that a wired system could have been installed.
[1]: https://en.wikipedia.org/wiki/Fallacies_of_distributed_compu...
But naturally anything like this wouldn't exist in default consumer land.
Wired cameras hooked up with power over ethernet has been around almost as long as I have!
This requires significantly more upfront and ongoing costs... and most criminals aren't sophisticated enough to cut power or jam wifi. Lots of times they won't even wear masks.
The average property crime is still an opportunistic smash and grab. Stick up wifi cameras are an affordable "good enough" for most cases.
The real point here is, even if you capture a super-clear 1080p picture of the criminal(s) face, the police mostly won't care. It's just a little security theater that you put on for yourself, and sometimes your insurance company.
That's why you figure out who they are and publish it on social media/other sources.
Basically, if you want to burglarize a building with a decent protection system, simultaneously employ WiFi and mobile phone jammers, attach a high-voltage generator to the phone and power line and fry everything attached, then enter and ransack the building. If you're lucky, the alarm system will be so damaged that not even the sirens will sound, and as you cut the phone line and jam mobile backup, the alarm system can't alarm anyone either.
The worst thing is, you can get all of what's needed here for a few hundred bucks on the Internet or make it yourself.
Further, I was sitting here typing "surely a wifi jammer is more accessible", but if modifying a defibrillator is easy, maybe it really is even more theater than I thought.
Of course, in the real world, some of these mitigations will be a deterrent. But point taken, for a dedicated attacker/target, you're going to have to get more creative.
Accessible as in "physically accessible to an intruder". In Germany's urban areas, it's more difficult as we tend to bury power and phone lines, but on the countryside, it's bare power wires and trivially openable jumper boxes for the phone lines.
For a house, you'll have a lot of different entry points to run destructive power attacks as well: outdoors sockets or lighting fixtures, cameras, wifi APs, solar cells, basically everything that can be reached without a larger ladder should be considered an entry point for a determined attacker.
> Further, I was sitting here typing "surely a wifi jammer is more accessible", but if modifying a defibrillator is easy, maybe it really is even more theater than I thought.
it's easy from a pure technical viewpoint but incredibly dangerous. A defibrillator dispenses >300 joules worth of energy in a matter of milliseconds, that's around the same order of magnitude as a 9mm pistol bullet - this is also the reason why automated defibrillators will warn you to not touch the person while it dispenses energy: it's enough to send a healthy person into serious cardiac problems.
And if you're messing around with the mains power supply wires, typically these are fused for hundreds of amps. If you manage to touch an exposed wire, you die.
That's why these kinds of attacks aren't commonplace, because a burglar will simply go for the neighbor that doesn't have an alarm system installed... but once everyone has upped their game, the burglars will as well. In Germany, for example, bank robbers escalated to ATMs... they pump ATMs full of explosive gas, blow it (and with it, often enough the building...) up and take the cash that's flying around, then drive off in a high-speed car [1]. In some cases, the power of the explosion is bad enough to threaten the structural integrity of the building [2].
[1] https://www.tagesschau.de/investigativ/report-mainz/geldauto...
[2] https://www.zeit.de/news/2022-06/18/nach-geldautomatenspreng...
Wifi canaries.
That's exactly what the cheap wifi security cameras do. They capture the video on onboard microSD cards and wifi is only for viewing of that data. If you loose wifi, it will still record.
Don't all cameras do that nowadays?
Super proactive detection and response
We didn’t get the cameras for security, we got them to watch the feral cats in the area to help catch them for TNR, but security is a nice extra, so we are considering replacing the Rings with something wired.
I am more afraid about a fire that would burn stuff and memories. I have offsite backups of my photos but I am not sure I would have the energy to go through all of them to reprint photo albums.
Hardest part would be finding a consumer system that still uses hardwired cameras
POE cameras grow on trees. Sold individually or in kits complete with POE NVRs. If you're handy you can put up a decent system, completely independent of any cloud service, for ~$1000.
To run Ethernet, I'd've had to run the cable through two rooms, around a fireplace and kitchen appliances, and probably have to drill an additional two holes for each camera (and ideally figure out a way to run the cable out of sight). It's not really worth the extra effort when the cameras record locally (microSD) and they're primarily a deterrent anyway.
Not 100% fool proof, but my solution is wired cameras, and all on a UPS.
Plus a pack of giant dogs..
Wired and wireless systems are not all that different in terms of what they transmit at this point, but wired systems have the advantage of keeping their communication stream isolated in the wire as opposed to the shared EM spectrum. It's essentially another layer of security. Can someone tap the wire? Sure, but it requires extreme physical proximity that an RF attack does not.
When I design factory automation systems or surgical robots it's all wired.
Anything mission critical needs to be, or the mission is not critical.
As for cutting power? UPS/battery backup. That's defeatable too. At some point you have to say you've reached your limit. Generally you just have to be more secure than comparable targets, though.
Someone using WiFi jamming on poorly thought out security is looking for easy targets, not complicated heists.
I could kill all data communication in most buildings out there just by sneezing in the wrong cabinet (personally experienced). And then what are your wired cameras going to do? If the answer is "make loud noises", well, that's pretty much exactly what wireless cameras could also do.
There's a reason 'professional' alarms generally prefer wireless connection and battery power (and loss of connection is generally an alarm-raising event).
one of my favorite moves, is to deposit, carbon or marking chalk, on the sill where tha sash covers it. window entry means you get it all over everything, and maybe leave prints.
old school methods, and a distinctive character to alaskan criminality, help finding those responsible
stolen items sold online in the small village/ rural region they were stolen from.
snow for seven months of the year makes tracking, trivial, and deep cold pushes all but the most desperate to operate for 2-3 months after breakup.
so well known persons, likely time and place of operation, and a lack of forethought planning a crime, make an easy catch, during 'spring cleanup'
They make more mess than the chalk thing, but they're way softer and more fun.
It's also highly dependent on the dog. A chihuahua maybe not so much, a big Rottie maybe yes.
It seems like a weird thing to generalize. It's like saying "people are good or not good at fighting". Well, which people fighting how?
Dogs aren't always a deal breaker for criminals, especially little dogs (which tend to be the loudest). Barking dogs can even be a signal that owners aren't home to shut them up. The idea that neighbors or police are going to investigate a barking dog and catch a bad guy is very optimistic thinking. Kind of like how people just ignore car alarms even while being annoyed by them.
And I get how this would help narrow down possible suspects from a list, but I don't think it's going to be very effective at finding suspects in the first place, which is usually the biggest challenge.
And before you say deterrence doesn't work, just put a sign outside proudly proclaiming your residence to be a gun free zone. Go for it!
If I put that sign in front of my house, nothing would happen. The implication that somehow I would suddenly be robbed left and right I don’t think holds that much water to begin with but especially doesn’t make sense in many places people live, like a small town like mine. Just going to confuse the neighbors.
If they still continue to break in after seeing you are armed with a firearm, you can just simply just shoot them once they get inside as your life was in danger and you also solve that from ever happening again from that person.