Hacker News new | ask | show | jobs
by trhway 2995 days ago
>It would be very risky to operate, even briefly, a portable imsi catcher in a briefcase and move it around WA DC, nevermind one that remained in fixed locations for hours.

how about quick switching between several [semi-stationary or briefcase carried] catchers (by analogy with an old Russia/USSR anti-aircraft tactic of quickly switching between several radars to avoid being detected and locked-in by an anti-radar missile :).

1 comments

Theoretically possible. Using current off the shelf tech, several imsi catchers could be networked together by normal LTE data networks with battle tested VPN crypto. Doable with any mifi type hotspot device or even just a modern phone and tethering. People with high end spectrum analyzers and directional antennas would struggle to locate a thing that only powers on for 1-2 minutes, and the relocated to a random location. If I were trying to find such things I would need three separate DF (direction finding) teams, and try to establish a pattern of behavior or movement on the part of the operators to narrow down the target areas. Could take weeks.
I'm not a wireless expert, but then wouldn't it also be theoretically possible to have a network of direction finders? Isn't direction finding also a repeatable set of steps that can benefit from automation?
Yes, though DF can be much more efficient with directional (yagi, parabolic, horn) antennas. If fully automated by network the antennas connected to the spectrum analyzers need to be on two axis motorized platforms.
It would be easier to, you know, secure wireless communications to begin with. It's not like the Feds couldn't arrange to have stingrays that are properly keyed. (And there's always CALEA.) Yes, I know, it would only be easier for new kit, but it will take a long time to get it deployed. But every year we delay this makes the pain worse.
"The best time to plant a tree was 20 years ago. The second best time is now."
Phased arrays of antennas can compute the incoming direction of a signal entirely through signal processing and do not require a motorized platform.
purely Rx phased arrays, unless very large, do not have nearly the gain (in dBi) of a good parabolic or horn. and not nearly as much directional discrimination as a good sized (90cm) parabolic.

in a phased array that is also a Tx this can be partially compensated for with higher dBm output power from the radio itself, but that's not the usage scenario we're talking about here.

Can LTE carrier networks not act as an enormous observation system for unauthorized IMEI catchers?
> networked together

The manufacturer bears responsibility for misuse given the current state of the market; this is why markets exist, to trade information. If there is a genuine inability to communicate, then the market ceases to exist.

Open societies favor markets for a reason: communication, open lines of communication, and stable ones at that. There are all kinds of ways a computer virus can infect a system that is automatic; consider the possibility that a virus has infected an "autonomous" control system for a moving vehicle. A mechanical coupling usually makes this impossible, a steering wheel.

I'm sorry, but ... what?