Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Michael Downey 🧢
@downey@floss.social  ·  activity timestamp 2 weeks ago

Most of you reading this probably won't be surprised by this, but it's worth spreading the word (along with recommendations to mitigate risks) ....

🗨️ "Law enforcement officials may have deployed a secretive cellphone surveillance technology last weekend at Portland’s Immigration and Customs Enforcement (ICE) facility."

https://san.com/cc/exclusive-fake-cellphone-tower-likely-surveilled-protesters-at-portland-ice-facility/

#Portland #PDX #PortlandOR #PortlandOregon #Oregon #ICE #privacy #infosec #Stringray

  • Copy link
  • Flag this post
  • Block
⠠⠵ avuko
@avuko@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@downey

Warning! A lot of acronyms ahead! Welcome to Telco land...

TLDR: Anyone with the "fake cellphone tower" device mentioned can track BOTH your SIMcard, AND your mobile device.

So you better leave them at home, or bring a burner1 phone with a burner1 SIM.

IMSI vs IMEI

The " #IMSI" in #IMSIcatcher is an identifying number tied to your SIM(card).

But what #IMSIcatchers can also capture is your device's #IMEI 2.

The supposed purpose of an IMEI is stated clearly in the official documentation:

"The main objective is to be able to take measures against the use of stolen equipment or against equipment of which the use in the PLMN3 can not or no longer be tolerated for technical reasons."4

Mobile device manufacturers are obligated to produce device unique IMEI's:

"The IMEI shall be unique and shall not be changed after the ME’s [Mobile Equipment] final production process. It shall resist tampering, i.e. manipulation and change, by any means (e.g. physical, electrical and software)."4

IMSIcatcher vendors state their equipment can also capture IMEIs.5 6

So, every phone in the neighborhood of IMSIcatchers in use by law enforcement, are certainly in a batch of "to be tracked".

Did I mention law enforcement (through a legal warrant, they'll need help from mobile operators) can track phones based on IMEI alone (so even if you remove the SIM)? Yes, I believe I did.

PS: a phone connecting to or connected to an IMSIcatcher, is not on the network. Not being able to reach emergency services could lead to physical harm, including death. Just saying.

1 https://ssd.eff.org/glossary/burner-phone

2 International Mobile Station Equipment Identity

3 Public Land Mobile Network: wireless communication services offered by a specific operator in a specific country.

4 https://www.3gpp.org/ftp/Specs/archive/22_series/22.016/

5 https://x-surveillance.com/imsi-stingray-device/

6 https://www.stratign.com/imsi-catcher-system/

  • Copy link
  • Flag this comment
  • Block
Michael Downey 🧢
@downey@floss.social replied  ·  activity timestamp 2 weeks ago

@avuko

💯

Screenshot of corner of Android UI with white text over a light blue background: icons for VPN (key), WiFi (cone), Airplane Mode (plane), and a battery icon with 86%.
Screenshot of corner of Android UI with white text over a light blue background: icons for VPN (key), WiFi (cone), Airplane Mode (plane), and a battery icon with 86%.
Screenshot of corner of Android UI with white text over a light blue background: icons for VPN (key), WiFi (cone), Airplane Mode (plane), and a battery icon with 86%.
  • Copy link
  • Flag this comment
  • Block
⠠⠵ avuko
@avuko@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@downey

Warning! A lot of acronyms ahead! Welcome to Telco land...

TLDR: Anyone with the "fake cellphone tower" device mentioned can track BOTH your SIMcard, AND your mobile device.

So you better leave them at home, or bring a burner1 phone with a burner1 SIM.

IMSI vs IMEI

The " #IMSI" in #IMSIcatcher is an identifying number tied to your SIM(card).

But what #IMSIcatchers can also capture is your device's #IMEI 2.

The supposed purpose of an IMEI is stated clearly in the official documentation:

"The main objective is to be able to take measures against the use of stolen equipment or against equipment of which the use in the PLMN3 can not or no longer be tolerated for technical reasons."4

Mobile device manufacturers are obligated to produce device unique IMEI's:

"The IMEI shall be unique and shall not be changed after the ME’s [Mobile Equipment] final production process. It shall resist tampering, i.e. manipulation and change, by any means (e.g. physical, electrical and software)."4

IMSIcatcher vendors state their equipment can also capture IMEIs.5 6

So, every phone in the neighborhood of IMSIcatchers in use by law enforcement, are certainly in a batch of "to be tracked".

Did I mention law enforcement (through a legal warrant, they'll need help from mobile operators) can track phones based on IMEI alone (so even if you remove the SIM)? Yes, I believe I did.

PS: a phone connecting to or connected to an IMSIcatcher, is not on the network. Not being able to reach emergency services could lead to physical harm, including death. Just saying.

1 https://ssd.eff.org/glossary/burner-phone

2 International Mobile Station Equipment Identity

3 Public Land Mobile Network: wireless communication services offered by a specific operator in a specific country.

4 https://www.3gpp.org/ftp/Specs/archive/22_series/22.016/

5 https://x-surveillance.com/imsi-stingray-device/

6 https://www.stratign.com/imsi-catcher-system/

Stratign

SDR IMSI Catcher System - Stratign

SDR IMSI Catcher System can collect IMEI and IMSI identities of cell phones without the knowledge of the service providers and cell phone users.

Directory Listing /ftp/Specs/archive/22_series/22.016/

Burner phone

A phone that is not connected to your identity, is only used for a small set of calls or activities, and can be discarded if and when it is suspected of being tracked or compromised. Burner phones are often pre-paid mobile phones bought with cash.
  • Copy link
  • Flag this comment
  • Block
⠠⠵ avuko
@avuko@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@downey

Warning! A lot of acronyms ahead! Welcome to Telco land...

TLDR: Anyone with the "fake cellphone tower" device mentioned can track BOTH your SIMcard, AND your mobile device.

So you better leave them at home, or bring a burner1 phone with a burner1 SIM.

IMSI vs IMEI

The " #IMSI" in #IMSIcatcher is an identifying number tied to your SIM(card).

But what #IMSIcatchers can also capture is your device's #IMEI 2.

The supposed purpose of an IMEI is stated clearly in the official documentation:

"The main objective is to be able to take measures against the use of stolen equipment or against equipment of which the use in the PLMN3 can not or no longer be tolerated for technical reasons."4

Mobile device manufacturers are obligated to produce device unique IMEI's:

"The IMEI shall be unique and shall not be changed after the ME’s [Mobile Equipment] final production process. It shall resist tampering, i.e. manipulation and change, by any means (e.g. physical, electrical and software)."4

IMSIcatcher vendors state their equipment can also capture IMEIs.5 6

So, every phone in the neighborhood of IMSIcatchers in use by law enforcement, are certainly in a batch of "to be tracked".

Did I mention law enforcement (through a legal warrant, they'll need help from mobile operators) can track phones based on IMEI alone (so even if you remove the SIM)? Yes, I believe I did.

PS: a phone connecting to or connected to an IMSIcatcher, is not on the network. Not being able to reach emergency services could lead to physical harm, including death. Just saying.

1 https://ssd.eff.org/glossary/burner-phone

2 International Mobile Station Equipment Identity

3 Public Land Mobile Network: wireless communication services offered by a specific operator in a specific country.

4 https://www.3gpp.org/ftp/Specs/archive/22_series/22.016/

5 https://x-surveillance.com/imsi-stingray-device/

6 https://www.stratign.com/imsi-catcher-system/

Stratign

SDR IMSI Catcher System - Stratign

SDR IMSI Catcher System can collect IMEI and IMSI identities of cell phones without the knowledge of the service providers and cell phone users.

Directory Listing /ftp/Specs/archive/22_series/22.016/

Burner phone

A phone that is not connected to your identity, is only used for a small set of calls or activities, and can be discarded if and when it is suspected of being tracked or compromised. Burner phones are often pre-paid mobile phones bought with cash.
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login