Why Snowden Asked Visitors in Hong Kong to Refrigerate Their Phones
thelede.blogs.nytimes.com
thelede.blogs.nytimes.com
Edit: Also tried a cookie can. (And anti-static bags -- see below.) Faraday cage my ass.
Clarification: I use a Nokia. Maybe the technique works only on iPhones? I've heard they have some reception issues.
You might even be better off wrapping the phone in aluminium foil, but the problem is then going to be ensuring that all seams in the "cage" are actually conductive.
All in all, I think the fridge's insulation probably acts as a good sound barrier, and the hum from the compressor probably adds quite a bit of noise. Probably a smart thing for someone in Snowden's position to demand.
Snowden is a false flag exercise, which would be obvious to anyone who read Catch-22.
You can never be paranoid enough, because they have a million people with TS clearance thinking of ways to get into your heads. That's just in the US.
The crime rate in Hong Kong is relatively low, especially compared to Snowden's country of origin.
Had visitors not brought cell phones in the first place, it wouldn't be an issue.
Car wise, well, that could be impracticable: 1) does one have a car in HK? Or did one fly in and hire a cab? 2) Has one just walked up a tower block to get to Snowden? All go down, and come up again? That would be annoying. 3) If I take all the phones and put them in a box, I know I have the phones. I have control.
In a normal apartment, I reckon a fridge is possibly the best place to put turned off phones to isolate them as best you can at short notice with out super spy resources. Not prefect, but looking round my place, I don't see something better than a fridge for the purpose.
Clearly, this whole "cell phone in a fridge" thing is a clever attempt to make Snowden lose his nerd cred.
(How exactly they do this I'm not quite sure, given that the frequency of a phone and the frequency of phones is quite similar.)
^: Where "sane" means "not gamma waves"
The eye has very poor heat dissipation mechanisms, and they showed in the 70's the RF exposure could cause cataracts in rabbits. (I think dogs were exposed too -- it was a new field, so they didn't know what would happen)
https://ieeexplore.ieee.org/xpl/login.jsp?tp=&arnumber=45025...
dB is a logarithmic scale, so this kind of back-of-the-envelope reasoning is sometimes made easier and sometimes counterintuitive.
(I'm assuming you meant frequency of a phone and microwave oven.) That's not quite accurate. Cell phones use many frequency bands [1]. I only see one frequency on the list (2500 MHz) that is close to the frequency used by consumer microwave ovens (2.45 GHz) [2]. I don't think 2100 MHz is close enough to be attenuated by a microwave oven, but of course I'm just speculating because it depends on the design of the oven's shielding.
Don't forget that phones switch to a frequency on which they have signal. If you don't have 4G coverage, your phone will use 3G, etc. These operate at different frequencies. So attenuating one or two of the frequencies on the list is probably not good enough.
I assumed that the design was that of a Faraday cage, which blocks the frequency it's designed for and all lower frequencies. anotherhue noted however that it's a tuned RF choke, which will only block a certain frequency.
For reference, I'm in Australia with a 3G phone on Optus, so the frequencies here are a little less scattered [1].
Also, from experiments I've conducted, a cookie can will work for certain frequencies; for example, the RF transmitters in anti-theft devices. I suspect the material is too thin to stop phone transmission though.
Maybe your refrigerator and the other objects you're using to test this theory don't have a thick enough layer of metal?
Here are some excerpts from a nifty Analog Devices tutorial about RF shielding[1]. This is probably the most relevant part:
The longest dimension (not the total area) of an opening is used
to evaluate the ability of external fields to enter the enclosure,
because the openings behave as slot antennas.
Remember those big rubber seals on the doors of most refrigerators?It then goes on to describe an equation for approximating the shielding effectiveness at a given frequency:
Let λ = wavelength of the interference
Let L = maximum dimension of the opening
Shielding Effectiveness (dB) = 20 * log10(λ/2L)
And here's a nice rule of thumb: A rule-of-thumb is to keep the longest dimension less than 1/20
wavelength of the interference signal, as this provides 20 dB
shielding effectiveness.
There's other stuff in there, such as how to properly shield cables entering or exiting the box. (Unshielded wires penetrating the box can also act as antennas.)Worth a read, if you're curious.
[1] "EMI, RFI, and Shielding Concepts", Analog Devices, http://www.analog.com/static/imported-files/tutorials/MT-095..., Page 10
A fridge will act as a fantastic acoustic shield but probably not a functioning Faraday cage. I think this blog post has taken a few artistic liberties in suggesting its use was as a Faraday cage, especially as the article she links to doesn't mention the fridge's purpose as a Faraday cage.
Assuming this story isn't stretched and exaggerated (I have a hard time believing it isn't) and the fridge was on, this could be a fast way to trigger condensation to form inside the phone when the device is removed back into a warmer environment, depending on the ambient humidity. I just wouldn't dream of putting my phone in a cold fridge for anything other than the briefest time for this reason.
The compressor isn't on all the time. It turns on intermittently when the temperature inside the fridge exceeds a certain threshold. It would be unlikely of much use most of the time.
Putting the phones in a bag does nothing to solve the issue of condensation. What happens is the phones would cool down substantially in the fridge. When they're removed, the cold surfaces (inside and out) would cause moisture in the warmer air to condense into water droplets, possibly causing issues with the battery and the other circuitry. Hong Kong is quite a humid place and it appears that he was at an acquaintance's home at the time of the frigid phone incident. It's unclear how well air conditioned this acquaintance's home was, which could lead to some especially nasty condensation issues. It's also unlikely this acquaintance's fridge would have been brought up to room temperature just for the sole purpose of storing phones for a couple of hours. This is why I'm inclined to believe the anecdote is BS.
Modern, high-efficiency fridges have compressors that operate continuously. It's more efficient than cycling. My fridge draws about 60 watts continuously.
It's still thermostatically controlled, of course, so if the doors are left open, it will kick up higher.
What fridge do you have out of interest?
Here's a report about variable-power compressors:
http://www.panasonic.com/industrial/includes/pdf/invertercom...
I was introduced to refrigeration nerdery by talking with a friend who designs the cryocoolers for JWST (http://www.jwst.nasa.gov/cryocooler.html) who nodded sagely and said "more efficient that way" when I mentioned my new fridge did not cycle on/off. Now that's a fridge nerd!
I'm not a fridge nerd either, but my understanding is that adding thermal mass to the fridge will reduce the heating spikes from things like opening the door which will reduce the frequency at which it cycles up. So you can make your fridge more efficient if you have the space to put big jugs of water in the fridge and big blocks of solid ice in the freezer.
You might only save a buck that way, but if the space isn't being used for anything else you have nothing to lose.
So if you're worried about the government spying on your computers via RF and want something more convenient than a fridge, drop me a line...
http://www.erikyyy.de/tempest/
DIY (collaborative) tempest emissions.
We weren't handling lost wifi connections gracefully so the user would get the wrong error message if their wifi dropped. The tester was simulating this by placing the DS in a microwave.
We test a production device here that makes a LOT of noise, and we put it inside a mini-fridge to dampen the noise so it doesn't drive the testers crazy. Works quite well. I doubt you'd pick up any outside conversation if you were trying to eavesdrop (especially if the freezer was humming).
Still, the phone could be recording audio to upload at a later time. Audio storage capacity isn't likely to be a problem on modern phones.
I used to do a bunch of micro-sites -- small websites targeted around specific topics. One I did a few years back was http://gps-cell-phone-tracking.net/
I really learned a lot setting that site up, and it was one of the reasons I became such a privacy freak. Our cell phones are basically tracking devices the government monitors which we happily adorn to our bodies each day. Weird.
To get to my point, one of the questions on the site was whether your phone could be tracked, either location or having the audio monitored, without your knowing it. Location is easy -- yes. Audio was a bit weirder. Obviously you'd have to install an app, and who would want to do that?
Then I learned that cell providers will "help" governments by putting tracking code inside the auto-update of the phone. They can even push it at night and have it install without your having any knowledge at all.
As far as I know, pulling the battery still kills things, but then somebody said most phones have a dual battery to keep the memory refreshed. Somebody even said something about the possibility of "illuminating" phones from a distance and picking up audio that way. Of course, "somebody said" doesn't count for much, and with all the secrecy in place good luck figuring out what is what.
Fun stuff. Since the micro-site business didn't take off, maybe there's a future in selling tin-foil hats?
Smartphones are a beacon of constant info...GPS and signal pinging can get your coordinates (at least general area), and Wifi can triangulate the position [0]. Cameras and microphones are just icing and still require a device to be compromised, whereas signals, require carrier network access...which is what PRISM revealed [1].
[0] http://thenextweb.com/apple/2013/03/26/what-exactly-wifislam...
[1] http://news.cnet.com/8301-1009_3-57589100-83/nsa-whistleblow...
http://en.wikipedia.org/wiki/Verizon_Wireless#Radio_Frequenc...
If they were using a carrier in Hong Kong, most of the carriers use a higher spectrum, usually around the 1800-2100MHZ range. While it doesn't give you great penetration in buildings like the lower frequencies Verizon use, I'm guessing the overall density of the towers is significant which would help this issue.
If he said they want into the basement of a building THEN put the phones in the refrigerator, it would be a little more believable. Just putting it in the refrigerator probably won't do a lot to block the signal.
Though aas has been pointed out, a fridge probably isn't electrically continuous at the door gasket. Depending on the construction, you could replace the rubber gasket witha rubber core metal mesh gasket.
The microwave oven would be much, much better.
Or just turn on the microwave for a few seconds. :)
Now turn everything on "high", including the shower ("hot & steamy"), and run.
Snowden's guests will have done that a while ago of course...
The fridge itself had a false back. Snowden's associates in SPECTRE/Wikileaks then used their covert physical access to the phones, for the duration of the dinner, to copy the phones' contents and install new malware.
Now, they know what the lawyers know -- including whether any are double/triple/etc-agents.
I'm sleeping in the bunker tonight.
Instead they explained the logic behind the seemingly unreasonable request. How is that being malicious?
Maybe you have faith in your newspapers, and to be totally honest I don't actually know how Americans feel about their news papers. But you do have Murdoch floating around, so Americans are being manipulated somewhere. But I sure as hell dont take them at their word. For me, newspapers are as accurate as "the internet".
But to me, that read like a slightly more sophisticated that a UK tabloid smear job.
I do how ever accept that my UK perspective on the press might well be very different to a US one.
Also there's the pretty fucking obvious fact that the battery suddenly lasts for months instead of hours.
Also -- that's the whole point -- otherwise Snowden would just say "Please turn your phones off".
They are wrong. Which is not unusual, news outlets get technical information wrong all the bloody time. Hell, they get things wrong more often than they get them right.
> I don't pretend to understand it, but there is some technique that makes your phone into a remote listening device even when off.
Nope.
> Also -- that's the whole point -- otherwise Snowden would just say "Please turn your phones off".
Snowden is a dramatic source, not an accurate one. I'm glad he blew the whistle because it brings the NSA into the media's focus, but technical accuracy is clearly not his strong suit.
In this case, the ideal source would explain why this is so frequently misreported, not simply assert that it is always misreported. Also, it would explain why it was an impossibility.
Combine this kind of thing with a database of phone remote expoits and it's easy for the NSA to "upgrade" your phone's software and turn it into a bug. This is what Snowden means when he talks about "poor endpoint security." It doesn't matter how secure your fancy encryption applications are when the phone itself can easily be hacked.
Sometimes they don't even have to remotely push software. There was a recent scandal about Carrier IQ, a system on smartphones (Android players and iPhone) that by default was recording every tap, every virtual key pressed, every incoming/outgoing SMS, and more. Anyone with the device connected to a PC could take the forensic log off the phone and see basically everything, even in the past. With per IP logging and billing on mobile plans, as Snowden's Verizon leaks showed, the NSA can just have your phone upload that log anytime they like, without a trace on your bill or data usage.
It's a scary world of surveillance in 2013.
Smartphones do the same thing. But that's triggered by a hardware interrupt (you physically connecting power to an input). You CAN NOT do that remotely, as there must be power on the receiver to receive the signal in the first place.
Or here, let's simplify it. Power off your cell phone, then have someone call it. Does it ring? No, of course it doesn't. Your argument is that by changing the caller from your friend to the NSA that somehow the phone would now be able to react to that signal. Which is utterly idiotic.
http://www.disaster-survival-resources.com/faraday-cage.html
By the way, it's also useful against solar flares...
If you want to keep your computer in there you also have to be careful designing the ports for wires coming in/out.
A 2 meter cable also receives on 144 MHz any spurious signals (amateur radio band). If that was an EMP, it would send a voltage spike up the port and blow out whatever it hit.
(sorry, couldn't resist :)
It can be kind of tricky to do this stuff actually, the martini shaker one is actually something I'll be using.
Were there any iPhones in the fridge?
He may be pulled in by the same rumours as everyone else and being overly cautious. Just because he does this doesn't indicate he has confirmed or denied the existence of a slave microphone bug.
Just that he believes strongly enough in the possibility to be cautious.
The actual cases I've seen (some linked on this page) are of specifically targeted individuals having their phone receive a command to turn into a bugged phone. I don't think all phones are bugged by default. This fits with Snowden wanting people around him to sound-proof their phones as they might be targeted.
The NSA leak was important enough, we don't need to pretend like he's some kind of privacy McGuyver.
Battery removal can be equally deceptive. Even once one figures out how to extract the primary battery, there may be additional power sources within the apparatus. “Some phones use an additional battery for memory management; it’s unclear whether this battery could be used by logging and/or tracking systems such as Carrier IQ,” Mr. Harvey explained, referring to software that monitors mobile phone users.
(not saying that I believe that there's any way these phones are recording when the battery is removed, just that it is doable)
You'd have to expand the claim to not only include hidden reserve power, but also hidden reserve memory, CPU, and audio system. Not to mention somehow convincing phone OEMs to actually spend the money adding this system to their motherboards and building it - there's no way in hell you are randomly sneaking that in at the factory without the OEMs knowledge. So now you also have to somehow keep the OEMs quiet about it.
In a word, "bull-fucking-shit".
One of these bags is fine. (http://www.elcomltd.com/metsheildingbags.html)
Some people are saying that mobile phones have a second secret battery, and that battery is used to power the phone to record anything the microphone can hear, and then later when the phone has a signal and normal battery power that recording is secretly sent out to some secret spy agency?
Battery removal can be equally deceptive. Even once one figures out how to extract the primary battery, there may be additional power sources within the apparatus. “Some phones use an additional battery for memory management; it’s unclear whether this battery could be used by logging and/or tracking systems such as Carrier IQ,” Mr. Harvey explained, referring to software that monitors mobile phone users.