A Cheap Spying Tool With a High Creepy Factor
mobile.nytimes.com
mobile.nytimes.com
Justified or not, these things are coming up in conversation at work and with friends a lot lately, which I find encouraging.
(Settings -> Privacy -> Location).
It's probably not as comfortable as the solutions of iOS/Android, but it gets the job done.
http://msdn.microsoft.com/en-us/library/windowsphone/develop... - 2.7.3
He said he couldn't believe anyone was naïve enough to think the government wasn't monitoring everything already, and that we elected them, so we should trust them. He said that privacy concerns sound pretty trivial compared to preventing incidents like the Boston Marathon bombings or apprehending the suspects, and that he'll gladly cooperate to help stop the bad guys.
We pretty much ruined lunch for everyone with our arguing, but he has since spent more time looking into the nuances of the topic and has said he has changed his mind. The thought of not being able to trust the government is really depressing to him.
I heard Bruce Schneider being interviewed, and he said that people frequently challenge him by saying they have nothing to hide. His two-second retort, especially on call-in shows, is simple: "What's your salary?"
No one wants to answer in public.
- Salary
- Medical history
- Home address
- Phone number
- DOB
- SS number
- Bank account numbers
- Passwords
- Photos of yourself
- Photos of your children
- Job search history (when you are already employed)
- What time you'll be out of the house
- Porn search history
If there were a way I could give you my SSN/bank information/etc without also granting you the ability to impersonate me, I'd gladly do it.
As for pictures of my kids, I don't have any. But it's a pretty terrible argument because it perpetuates the false idea that you must want to hide something for privacy to be necessary.
I'd bet large sums of money Bruce Schneier has never used this line of defense against the "nothing to hide" argument.
I know it's not the only reason for privacy, but it's a common and significant one.
And add:
"Interesting people that shake up the status quo and make this world a better place, from Ghandi to MLK, HAVE had lots of stuff to hide from the government".
"Not to mention that in your shallow mind you only imagine an ever benevolent government. Would you have something to hide if Anna Frank's family asked to stay in your apartment?"
(Well, technically, the amount of taxes paid is public, from which you can make a good guess at salary)
And that's how a libertarian anarchist comes to be.
Find out something embarrasing about said friend, and ask it if it's ok to post in on Facebook.
They reported a CIA officials stated interest in using consumer devices for intelligence gathering. Their analysis of that was to presume it would be abused.
It may not be deep reporting or analysis, but your suggestion that they should be fined would be more in line with how Russia runs things than the media culture of the West.
[0] http://readersupportednews.org/opinion2/276-74/5123-fox-news...
Fox News deliberately aired lies about the contents of milk in the US. They went to court to defend their right to lie.
So yes, I do think it is "silly fearmongering" to suggest that they'll continue to develop and improve their system's capabilities in the specific way you're suggesting.
Why would they not exploit a capability that they have indicated interest in exploiting given that they've already crossed the line into illegally collecting as much private information as they can?
They sold the AT&T facilitated phone tapping as something they would do selectively, with FISA warrants. It turns out they were conducting mass collection of conversations and conversation-related data without warrants. Why would they show restraint with the ability to listen through consumer devices? Talking about scenarios that are likely to happen isn't "fearmongering" it's rational vigilance given where we're at.
It's "silly fearmongering" as long as you have no evidence that they've done such a thing or are attempting to do such a thing.
Preventing government abuses means paying attention to not just what they've already proven to have done, but also attempting to discourage them from taking likely next steps.
Nuance is a hell of a thing.
wget http://att.com/obscure/url?id={1..114000}
Aaaaand that's a prison sentence.I wonder why he only used one pi per channel though, I think they have the horsepower to sniff perhaps three.
The article makes it sound as though it relies on unsecured wifi data, but also states that "Even when he didn’t connect to a Wi-Fi network, his sensors could track his location through Wi-Fi “pings.”" It also talks about iMessage, and dropbox, and other application layer data.
I couldn't make sense of it.
Android phones are completely silent even with the WiFi on when not connected to an access point.
Whereas the system is normally used to provide a device with its location, here it's used to track the device's location. This requires having a network of Wi-Fi access points sharing data.
You could do it for 1/2 the price with a TP-Link TL-WR703N and OpenWRT. Lots of these types of projects are already install-and-go ready for OpenWRT.
http://hackaday.com/2013/04/29/wifi-pineapple-project-uses-u...
With the TL- devices, you have very limited writeable storage, and as it's an append-only file system, the only way to reclaim the space is to reflash the system. A Pi, by comparison, feels like a normal computer system.
Twice the price isn't necessarily a bad deal, unless you're working in such volume that development time is an insignificant part of the overall project cost. Given the choice, I'd go for a Raspberry Pi next time.
I wonder how secure 3g connections are? Because it would seem to one could get a lot more information out of those.
Edit: speling
https://www.defcon.org/html/defcon-21/dc-21-speakers.html Do-It-Yourself Cellular IDS "For less than $500, you can build your own cellular intrusion detection system to detect malicious activity through your own local femtocell. Our team will show how we leveraged root access on a femtocell, reverse engineered the activation process, and turned it into a proof-of-concept cellular network intrusion monitoring system.
We leveraged commercial Home Node-Bs (""femtocells"") to create a 3G cellular network sniffer without needing to reimplement the UMTS or CDMA2000 protocol stacks. Inside a Faraday cage, we connected smartphones to modified femtocells running Linux distributions and redirected traffic to a Snort instance. Then we captured traffic from infected phones and showed how Snort was able to detect and alert upon malicious traffic. We also wrote our own CDMA protocol dissector in order to better analyze CDMA traffic."
The article makes it sound like somehow this "device" (really just a computer - a Raspberry Pi) is somehow some special technology that people should watch out for. When I can do all of these things on any laptop on an open network. And in fact, that's going to be less attention grabbing in a cafe than some mysterious black box under a table.
It's a shame that the take away message wasn't that any open network is a security risk, not just when someone happens to have one of these "gadgets", but anyone on the network with a laptop can do the same thing.
There is a lot of NIH in the comments about the pi on HN and ./
I wonder if there are any known instances of someone monitoring and collecting a high value target's encrypted home wifi (say a CEO before earnings, or someone at the department of labor) with the goal of cracking it.
Now imagine the government placed these nodes everywhere... they would basically have a fixed GPS on you.