Security reporter tells about hacked 911 call that sent SWAT team to his house
arstechnica.com
arstechnica.com
Edit: I had a similar experience, when one of my license plates fell off. I filled out an online form on the police site, never got a response. One day, cop pulls me over, then draws on me and gets 4 other cops as backup. I was under the impression you don't point guns at someone unless you're ready to fire, so I'd assume that if I had made any sudden movements it could have been fatal.
The thing is, I could have filled out that form with anyone's information. There's not even a callback/confirmation. So if you fill out a form for someone who has a concealed carry permit or something, you could probably cause a severe incident.
Was this hyperbole or honesty? Drawing a firearm is a deterrent and is employed in order to prevent things to escalating to a point where an officer has to fire.
Of course its a deterrent, but the only thing that makes it more of a deterrent than a whistle is that the officer is (or presumed to be) ready to shoot.
So, going from what seemed like an ordinary traffic stop to looking down a gun, I figured he was prepared to kill me if he found it necessary. As I could not figure out any reason for him to want to stop me like that in the first place, it seemed logical there was some massive escalation I was unaware of.
I am not certain about the exact distance but I think a hostile person brandishing a knife within 20 or 25 feet is considered to have an advantage / pose serious risk of death (able to inflict serious trauma) over an officer with a holstered weapon. (In NYS)
Police have their own rules.
Is 911 unable to triangulate calls if you hide your caller ID? I doubt it's that simple.
I never did find it; they sent me a new one. By carefully examining the holes, I was able to help them determine that it had been unscrewed, rather than having somehow come out on its own.
We only have rear plates here, so I had no plates for a short time.
Even in the UK, where most of the police don't have guns, they still send armed response teams to deal with armed criminals.
Imagine harder. This kind of thing happens all the time.
Yes, there is.
The full armor, assault rifles, grenades, etc. come into play because of past situations like http://en.wikipedia.org/wiki/North_Hollywood_shootout where cops had to raid gun stores for rifles because their handguns/shotguns weren't cutting it.
When there's a known/probable gunman, it's prudent to take extra precautions - larger team, better armor, weapons that'll work if the criminal's wearing his own armor. No sense getting killed in a shootout that was predictable.
If people start running around with RPGs, I'd expect reports with gunmen waving rocket launchers to be met with armored vehicles and the like.
Luckily, this doesn't seem likely.
http://www.cato.org/publications/white-paper/overkill-rise-p...
At the same time, they need to know when, where and how to use their weapons, so we reduce or eradicate unnecessary casualties.
If you want to respond with anything less than the best possible tools available to ensure you survive the event then you can certainly make that choice. But I couldn't in good faith tell someone else to make that choice. If you're a bystander near a heavily armed criminal the only safe place to be is far away.
Cops certainly do not need to be using 'weapons that belong on the battlefield' as their go-to weapon for any raid unless it is suspected that there may be body armored opposition (an absurdly rare occurrence - worth treating as an outlier). It would not be unreasonable to have one or two rifles on standby, in case a situation escalates beyond what was expected.
I do not like this trend of increasing para militarization of the US police forces. You are supposed to trust a police officer. It is hard to trust someone wearing BDUs and carrying assault weapons - you are more likely to respond fearfully, which can often make things worse.
You mean like in the case where someone deceives them into thinking someone well-equipped and violent is in a certain location?
Swatting is a hard problem. We can't really put strong authentication in place because of the asymmetry of needing anyone to be able to report a violent crime in progress at any time at any location. And the anonymous report is, indeed, cause for suspicion that a crime is being committed, and if that anonymous report further claims that the bad guys are heavily armed and/or wearing body armor, that is cause for suspicion that they may indeed be telling the truth and the bad guys are ready to rock and roll at the drop of a hat.
It's a sticky situation.
The 4th amendment only covers "unreasonable" search and seizures. Anything "reasonable" is still OK.
http://krebsonsecurity.com/2013/03/the-world-has-no-room-for...
At the end of the day, it is the emergency services' responsibility to behave with such considerations in mind.
In this case 9/11 is treating the calls as critical because they are shown to them as coming from the subject's house. If they instead popped up as a pay-as-you-go phone from an unknown person (recall also that all cell providers have to provide credible geolocation of calls, which if you're going through a Western cell tower you cannot spoof) that is ten states away, yeah they might not send the SWAT team.
I have no clue about the level of precision in cell tower geolocation, so I'm not sure how close you would need to be (which obviously ties to how likely it is to get caught).
The Internet seems to work fine with IP, despite it being trivially spoofable. I think your expectations are incorrect.
Edit to add: It's not even desirable, what you're asking. Imagine, for instance, Twilio. If each call had to be immediately traceable, what would that mean? Would Twilio need to require proof of identification before allowing any outbound calls? I think what your suggesting would be extremely detrimental.
While this seems to get stated a lot, it isn't actually true at all: spoofed IP packets get no response (I should also add that most providers flag and drop packets that have no business originating from where they did, so spoofing IP is usually a completely non-starter to begin with), or rather the response goes to an entirely different place (as if you spoofed someone's number to call 9/11 but only the original number can actually hear what the operator is saying). There are a couple of examples of very large providers misusing BGP (usually accidentally), but it is immediately identifiable, completely tracked, and rejectable.
It's not even desirable, what you're asking.
What am I "asking", given that you've gone to such lengths to declare it? If someone has a phone on AT&T or Verizon or even Skype the provider should be able to essentially sign the call initiation. Much like TCP, the world phone system has a routable infrastructure (otherwise it would be impossible to call a number because where does it go?), and such a mechanism is hardly far flung when we're talking about emergency services.
Yeah, there are some services that can't abide by that, and they should properly be flagged as "completely anonymous, untraceable call" and get the credibility such deserves.
You are asking that the originator of a call be identifiable somehow. That's not possible, given the number of resellers and levels. That would require even more trust, getting every provider to have a transitive trust relationship and show ID. A single call might go through 3, 4, even more resellers before ending up at the destination.
These emergency phone calls are two-way communications, exactly unlike the IP spoofing situation (seriously you really want to stick with the wrong IP example?)
You are asking that the originator of a call be identifiable somehow
Wonder of wonders, yes I am. The world phone system is a completely routable system -- providers effective own prefixes or even individual numbers, which is exactly how one can call someone. The notion that if a call comes in that says "Hi I'm 555-5555 from Verizon @ 555 Blaxberry Lane" and it can actually be verified if not authenticated by Verizon is hardly some big technical marvel. It's actually TRIVIAL, and it's exactly how the world pay-phone system works (note that these people aren't spoofing numbers to call pay sex lines because the telcos actually care about that). This whole ball of nonsense is because telcos have zero obligation to give a crap, so they don't.
You're wrong about the compensation bit. It's entirely possible to send fake traffic and get compensation. Cutting that off is an entirely manual process; with someone noticing the fraud and reporting it. It's not some magic authentication that happens.
The reason things like sex lines (either premium rate numbers or just really high-rate areas) often do not work is because the costs are passed on through the various companies (so they'll clip anything over a few cents) or because they simply will not accept calls if they are not within the trusted system. If you have a VoIP line and try dialing a 1900 number, it won't work unless that VoIP provider has made a specific deal. It's not like they look at the calling number, then mail out bills to whoever they think the owner is.
Guess what: Folks don't accept limitations on dialing 911 (or the PSAP admin line, which is just a normal number). They're going to demand 911 be answered regardless of billing relationships.
At both 911 companies I've owned, the routing system depended on being able to "spoof" caller ID. We would have to accept whatever caller ID we were given, because there's it's essentially intractable to know who has the actual relationship with the end user. It's also not knowable if the connection handing me off this call is authorized to use that number. There's simply zero concept of that. Additionally, there's no such thing as a real master database correlating number-address. (That'd make things easy easier!)
Even if there was, it'd still be trivial to swat. Buy a number online, say your address is <target address>. Place a legitimate call that "authenticates". Change address, repeat. Worst case scenario (if you can't make an anonymous payment), hack someone else's VoIP account and change their address and place call.
You are right that this is a large problem. Some PSAPs have come under DoS attacks, getting a flood of fake calls. 9-1-1 is a critical piece of safety, and it's fairly unprotected. Funding is limited. Some of the vendors involved are laughably bad. And, at least a few years ago, there was a massive disconnect between technology/Internet and the emergency response side.