Samsung, Nokia say they don’t know how to track a powered-down phone
arstechnica.com
arstechnica.com
But the dirty little secret is that the baseband processor is still a completely uncontrolled subsystem, loaded with some propietary binary blob by trustworthy companies like Qualcomm. GPS and even the microphones are usually integrated into the baseband, not part of the application processor that runs your Android. So you have a perfectly capable ARM processor running a propietary RTOS system, written completely in C (or C++ occasionally) with access to all the vital periphery and a gigantic attack surface in dealing with all the mobile communication protocols. The only reason there hasn't been a complete breakdown yet is that it's difficult for amateur researchers to exploit, you need expensive RF hardware and the mobile communication protocols are huge bodies of closed committee designed standards. But it is without a doubt in the reach of the NSA, and they are probably actively exploiting baseband processors already.
(Interestingly, since baseband processor have grown in complexity, most smartphones can now update the firmware on them, so there are lots of firmware images floating around. I highly recommend just even running strings on them, its quite enlightening. Some examples from a Nexus 4 radio:
Failed do spoof USB cable disconnection
Assertion os_mutex_pool_ptr[mutex_index_in_pool].is_available == 0 failed
hsu_al_ser_open: hsu_al_ser_base_open for port NMEA (%d) returned failure
Conversion to UTF-16 failed! Returned %d, expected %d
Unexpected IP family %d - assuming IPv4
inflate 1.2.3 Copyright 1995-2005 Mark Adler
Received ARP Request
CxM - Received WLAN Early Grant Release
(Yes, these are format strings! And this device has all the good stuff: classic 2005 zlib, a homebrew network stack, homebrew character conversion routines, homebrew operating system, homebrew USB stack...)Samsung Galaxy S1:
http://www.techinsights.com/uploadedImages/Public_Website/Co...
The internal battery is located at the top-right - a circular coin cell soldered to the board.
Samsung Galaxy S2:
http://i295.photobucket.com/albums/mm148/rprosperojr/IMG_120...
The internal battery is located at the center-top
Edit: In case of the SGS2 it's located next to the WLan/BT module.
Basically, you still need a local clock.
Some people have been trying to implement detection for e.g. silent SMS or IMSI catchers in osmocombb (the first open source baseband), see [1], but there doesn't seem to be any recent progress.
Chaos Computer Club reverse engineered some Qualcomm basebands to find them running in ARM supervisor mode with no NX bit. NSA must love that
Since this technique pre-dates smartphones, it is unlikely to involve installing software on the phone. At best, the NSA might have found that a given model of phone didn't properly power-down its radio when the phone was powered-down. Given access to the cellular network it might be possible to ping the phone and make it disclose its position via triangulation.
Very hard to see how this could be anything other than deliberate disinformation by the NSA though.
Turning on periodically so it can be tracked would be one part of what it takes to implement a room bug.
"a new NSA technique enabled the agency to find cellphones even when they were turned off"
The current administration is very careful with choosing their words. I haven't seen WP's source, but I wonder if this is more about the phone blipping its receivers to record some local MAC addresses and scrambling codes and then uploading the data the next time the phone's powered on.
You know when the word "collect" doesn't mean what you think it does, I wouldn't bet on nailing the word "find". :-)
Yet if I power off the same device, take the battery out and leave it for the same amount of time, then put it back and power it on, its a full battery...
On the same note, my iPhone 4, 15" Mac Book Pro w/ Retina, and Lumia 925, all when turned off completely, eventually the batteries die...
Just slower than if they were turned on...
1. Battery leakage. You can't charge a battery and leave it somewhere disconnected and expect to come back to a full charge. Small amounts of power leak all the time. Look for "self discharge". There are lines of batteries (particularly Sanyo Enelopp) that are marketed as low self discharge i.e. they can be stored charged and will still be usable in time. There is still a high resistance when something is connected which is enough to help with self discharge.
2. Most phones have a non mechanical on/off switch so a tiny bit of current is still used to have soft on/off functionality and watchdog circuitry online.
My old Nokia dumpphone has a battery life of more then 2 weeks. But the Motorola Defy+ will eat a full battery even after shutdown within a week. So it does not even make sense as a water proof camera for sailing.
In result: The Defy+ is eating more battery when powered down, then my old Nokia when powered up. Imho, thats enough power to say "here I am" regularly.
For bonus points, I would arrange for the baseband to transmit only very minimally as necessary, so it isn't noisily detectable from RF pickups such as nearby speakers.
The technical details would get simplified, and management would hear that I can track a "powered-down" phone.
If I had to put this in place I would get something that worked even if there were no cellphone masts in the area. Get the radio to listen to something entirely different, broadcast from some box that could be put in a car or in one of those electronic listening planes the military have. Have it work at the radio level on the phone so the cpu does not need to be used. The reply could be an entirely different identifier to the IMEA or SIM identifier with it being a simple database 'select' to get these codes.
A bit more "out there", maybe it is possible to pick up a powered down antenna? Think that an antenna is a (typically passive) conductor, designed to resonate at a particular frequency. If the antenna is irradiated with that frequency, wouldn't the antenna couple to the field and disturb it is some way? If those disturbances can be measured, then the antenna (and consequently the phone) can be detected.
[1]: https://en.wikipedia.org/wiki/Thing_%28listening_device%29
At the time I thought it was due to poor power management, but now it really makes me wonder.
I wonder if there are ways that a pwned phone could transmit to an attacker without hitting the billing system? Non-billed SMS? Or are there other techniques on GSM? (e.g. network operator updates get pushed to phones and they aren't billed; there must be some other low-level two-way messaging capabilities)
If they start adding RFID tags to 'phones, the only safe way to not be tracked will be not to carry the 'phone.
Other "near field" devices have, such as payment cards and passpoets, have been successfulyy communicated with or exploited using directional antennas from further away than you might think.
It's quite possible to check if a phone is transmitting, without even opening it.
Additionally, it is usually possible to see what parts of a device are consuming power (or at least have current).