What happened to all the phone apps that made an effort to detect IMSI catchers, like SnoopSnitch, which appears to be abandoned (F-Droid reports some fishy anti-features?).
Probably removed by the respective app stores under pressure from law enforcement agencies. A lot of free “snoop” or network detection apps have been removed or paywalled.
Here is it working in action while law enforcement is flying a spy plane arouns a neighborhood
In case you, like me, were wondering wtf stingrays are (besides a type of fish). This is from their report :
Cell-site simulators, also known as "Stingrays" or IMSI catchers, are devices that masquerade as legitimate cell-phone towers, tricking phones within a certain radius into connecting to the device rather than a tower.
Cell-site simulators operate by conducting a general search of all cell phones within the device’s radius, in violation of basic constitutional protections. Law enforcement use cell-site simulators to pinpoint the location of phones with greater accuracy than phone companies. Cell-site simulators can also log IMSI numbers (unique identifying numbers) of all of the mobile devices within a given area.
...
The fact that government agencies are using these devices without the utmost consideration for the privacy and rights of individuals around them is alarming but not surprising. The federal government, and in particular agencies like HSI and ICE, have a dubious and troubling relationship with overbroad collection of private data on individuals.
Wait, people didn't know about StingRays?
They've been around for like a decade now.
But uh, yeah, basically, they're fake/spoof/honeypot cell towers that man-in-the-middle all nearby cell network traffic.
This is how they do the whole... everything dragnet, all the time, basically all cop cruisers have them in them, active all the time, this is why you just don't bring your phone to a protest unless you really know what you're doing.
So how do they break my SSL connections?
It's a little less about reading what you're saying or looking at on your phone, it's mostly about tracking where your phone goes and figuring out who you are that way.
They don't really need to.
They get all your phone's metadata, and thats usually enough to plug in to a bunch of other databases that they can add you to a watchlist of some kind.
I mean really at this point we are all in a giganto mega watchlist, its just that its so big that the problem is actually sorting through that list and 'accurately' assigning threat levels, but thats what Palantir is for.
Like, they get your IMSI code, unless you are somehow regularly/randomly resetting that, uh, they can easily get a bunch of other info from cell providers, they just can't (usually) specifically use that info alone to convict you of something, but...
They know who you are, roughly where you were and when.
So thats a pretty good starting point for a subsequent investigation, or just throwing it onto the dragnet data pile.
When someone finds one of these simulators, what would they do?
Based on this link, the proper thing to do should be to report it to the FCC. I am not sure how much Trump's FCC will pay attention to the report, though....
Whatever you do, you shouldn't accidentally spill saltwater on it. That could destroy a very expensive piece of spying equipment, and would be a terrible, tragic accident that could interfere with the advance of nazism.
Report it to your favorite news media ig
Also alert your friends/colleagues that there are IMEI/IMSI scanners at the event, so that they can prepare accordingly by leaving their phone at home, putting it in a farraday bag, etc.
It doesn't matter if there are IMSI catchers or not, they should be leaving their phones at home.
Or use GrapheneOS in airplane mode.
That's probably best case scenario but I have one and left it at home last time.
Someone needs to document the event. 🙂
There's no shortage of professional photographers and videographers
And a camera makes you the prime target for a fascist force.
See IDF shooting journalists.
All the more reason...
It's been tested at actual protests FYI. It works.
Use your imagination what that means you can do when you find one.
Fucking cool, and also remember to leave your phone at home, or at least on airplane mode.
In airplane mode and even while turned off, phones have been known to still transmit data via background services. Leaving it behind, or a Faraday bag are the only assured options I'm aware of
Modern phones will still ping the Bluetooth low energy networks like Find My for Apple devices even when off or on airplane mode. That’s how things like AirTags work.
What is the correct hardware?
Any of the 5 or 6 cheap wireless hotspots listed in the link in the article.
Is there a good one for Canada in specific though? As far as I can tell the Orbic only works in the US, and as a result I'm not sure if I can trust the other devices, even if they're the same ITU region. Would the TP-Link work? The docs suggest it should work in the US as well as Europe.
Probably should have read the article hahahah. Thanks.
In your defense, it seems like just a link to a repository.
That's why I don't click it. But like. I could have. I have the power. Of click.
I've taken too many phishing tests. I have lost the power of clicking.
What if the cops have a trace buster buster?
Then you would just wanna bring along your trace buster buster buster.
Who are you calling buster, buster?
Who YOU gonna call? Trace Busters?
Always crazy seeing a The Big Hit reference in the wild
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.