Showing posts with label Military Technology. Show all posts
Showing posts with label Military Technology. Show all posts

Wednesday, October 1, 2014

Trivia, Part 3


In Part 1 we began by reviewing old news about how Rupert Murdoch's media empire used intrusive and illegal means to spy on celebrities in the United Kingdom. We then fast-forwarded to the then-breaking scandal whereby Hollywood celebrities were finding very personal photos appearing in public. We next began reviewing how cell phones work, with an eye towards establishing that basically any use of a cell phone can compromise personal material and information. We saw how cell phone towers can be disguised, and we looked at transportable cell towers, which are used to temporarily restore coverage when towers are out. Finally, we looked at reports about devices called "interceptors" and how they are used to spoof cell phones and access information they should not be able to access.

In Part 2 we looked more in-depth at the definitions of 3G and 4G cell phone technology, and saw just how portable legitimate cell phone "towers" can be - they can fit in the palm of your hand. Then, we looked at portable devices that could be used to spoof cell phones, and saw one that wears kind of like a bullet-proof vest under an overcoat. We finished by seeing that, with these concealable interceptors, it was possible to identify a cell phone belonging to a certain person, locate it, and then jam it or intercept the signals for the purposes of surveillance or spoofing, all without the cell phone operator even knowing.

The security breaches used by means of introduction in Part 1 centered on Apple products. It may therefore be worthwhile to review some relatively recent news about technology that specifically spies on Apple equipment.

At the end of last year, the German news magazine Der Spiegel ran an article entitled Shopping for Spy Gear: Catalog Advertises NSA Toolbox (December 29, 2013), in which the magazine called attention to particulars concerning the United States' National Security Agency spy technology. This was when news of the NSA ANT catalog broke to the general public.



It should be noted that this topic is of particular importance in Germany, especially since the story broke that the United States intelligence community collects intelligence on our ally Germany. Particularly noteworthy in the the scandal is the fact that the United States was caught spying on Chancellor Angela Merkel herself.


According to the highly-classified catalog mentioned above, as of six years ago today the NSA had in development something called DROPOUTJEEP, which was described as (I have included explanatory notes and links in [brackets]):

a software implant for the Apple iPhone that utilizes modular mission applications to provide specific SIGINT [Signals Intelligence] functionality. This functionality includes the ability to remotely push/pull files from the device. SMS retrieval, contact list retrieval, voicemail, geolocation, hot mic. camera capture, cell tower location, etc. Command, control, and data exfiltration can occur over SMS [short message service] messaging or a GPRS [general packet radio service] data connection. All communications with the implant will be covert and encrypted.


The catalog explains that the implant had to be installed via "close access methods", but that a "remote installation capability" would be pursued.

In my opinion, it is a safe bet that this been fielded, including with the "remote installation capability", in the intervening six years.

Another software implant that was underdevelopment six years ago, and is likely fielded and improved today, is the GOPHERSET, which pulls information from the target's SIM (subscriber identity module) card, and texts it out to the person who is doing the spying.


In fact, the Interactive Graphic: The NSA's Spy Catalog gives a nice overview of the NSA-advertised capabilities as of the time the catalog was created:

Cell Phone Networks

When it comes to monitoring and tracking mobile phones, the NSA's ANT division has an entire range of products on offer. These include everything from specially equipped mobile phone models that make it possible to physically track another mobile phone, to fully equipped GSM base stations capable of masquerading as a network operator's official mobile phone antennas, and thus monitor and record conversations or text messages from mobile phones within their range. One only has to think of the alleged tapping of German Chancellor Angela Merkel's mobile phone for examples of their potential uses. Several of these specialized mobile phone base stations also have the capability to determine the exact location of any mobile phone user within their range. Then there is a device called "CANDYGRAM" -- referred to by the ANT technicians as a "telephone tripwire" -- which sends a text message to a command center as soon as certain mobile phone users enter its range.



There is also CROSSBEAM, which records voice data and sends it to the guy doing the spying - a wiretap for the on-the-go cell phone generation:



The extensive capabilities that the NSA has fuel the ongoing scandal in Germany, where government officials and ordinary citizens are outraged that the NSA targets Germany with them. An excerpt from NSA, GCHQ have secret access to German telecom networks – report provides background on these capabilities:

US and UK intelligence services have secret access points for German telecom companies' internal networks, Der Spiegel reports, citing slides created in the NSA's 'Treasure Map' program used to get near-real-time visualization of the global internet.

The latest scandal continues to evolve around the US' NSA and the British GCHQ, both of which appear to be able to eavesdrop on German giants such as Deutsche Telekom, Netcologne, Stellar, Cetel and IABG network operators, according to Der Spiegel's report based on material disclosed by Edward Snowden.

The Treasure Map program, dubbed "the Google Earth of the Internet," allows the agencies to expose the data about the network structure and map individual routers as well as subscribers' computers, smartphones and tablets. The German telecoms had "access points" for technical supervision inside their networks, marked as red dots on such a map, shown on one of the leaked undated slides, Spiegel reports, warning it could be used for planning sophisticated cyber-attacks.

Notice that both the US and the UK are involved, with the UK's Government Communications Headquarters (GCHQ) mentioned.

Five powerful countries of the English-speaking industrialized world routinely share signals intelligence data - including communications intelligence - via the Five Eyes program, described in some circles as "the most powerful espionage alliance in world history."

It is worth recalling that we established in Part 1 that Rupert Murdoch's media empire had been intruding into the lives of celebrities in the United Kingdom using a variety of means, including by bribing law enforcement officers in order to gain access to restricted cell phone tracking information.

With that in mind, it is interesting to consider all the capabilities the NSA was advertising it had in its 48-page catalog as of several years ago, when the catalog was leaked. These capabilities are presumably now in the hands of law enforcement throughout the United States, the United Kingdom, Australia, New Zealand and Canada - the Five Eyes program's member countries - and one can similarly assume that the intelligence agenies of the United States at least, if not of other Five Eyes countries as well, have by now even more advanced capabilities.

With all this capability in the hands of all these people - who can be bribed or coerced, and who make mistakes - is there any real expectation of security and privacy as one uses one's cell phone to text a message or take a picture?

More to follow...

Saturday, September 6, 2014

Trivia, Part 2


In Part 1 we touched on how modern communications are reliant on cell phone towers. Then, we ever-so-briefly considered efforts to camouflage these towers, and we saw how mobile cell phone towers can augment cell phone tower coverage in case of damage to a tower or to offer additional capacity when needed. Finally, we introduced the concept of "interceptors", phony cell phone towers that have been surreptitiously placed for some clandestine or illicit purpose.

We will continue by combining the concepts of a cell phone "tower" -- or perhaps "interceptor" is the better term to use here -- with the concepts of camouflage and mobility. However, before we proceed, we need to briefly review some terms used in discussing cell phones.

Most people have heard terms like "3G" and "4G" to describe cell phones and service. What exactly does this mean?

Initially, cell phones were analog devices. The radio frequency spectrum was divided into slices, called channels, and a cell phone would transmit on one channel, while simultaneously receiving on another. This ability to transmit and receive simultaneously is called "full duplexing", and allows for a normal conversation to occur. In contrast, radios tend to be "half duplex" systems, where one party talks while the other listens, and then they switch to where the one listens while the other talks.

Later, digital technology was incorporated, allowing compression and manipulation of the signals which, in turn, increase cell phone call capacity in a system. Even newer technologies in signal processing then allowed for dramatic leaps in data transfer rates, making it possible for cell phones to become handheld computers, and the cell network to work like a Wi-Fi. This was dubbed "3G" for third generation, making analog technology 1G and the first digital technology 2G. Later, anything more advanced than 3G was dubbed "4G", though many people are beginning to realize that most "4G" is, in fact, only an incremental improvement over 3G. Thus, "true" 4G refers to 4G LTE - fourth generation long-term evolution.

Current cell phones use something akin to an operating system. The most common are GSM (Global System for Mobile Communications) used by AT&T and T-Mobile, and IDEN (Integrated Digital Enhanced Network), introduced by Motorola and used by Nextel, which is GSM-based.

For a readable explanation of cell phone technology and how it has evolved, I suggest you begin with How Cell Phones Work.

With this background established, we should begin with the question of just how small and mobile can cell phone "towers" get? To get some idea, we consider excerpts from The tiny cube that could cut your cell phone bill from March 21, 2011:



NEW YORK (CNNMoney) -- As mobile data usage skyrockets, wireless companies are spending billions each year to maximize capacity, and consumers end up footing the cost in the form of higher cell phone bills.

But a cube that fits in the palm of your hand could help solve that problem.

It's called lightRadio, a Rubik's cube-sized device made by Alcatel-Lucent (ALU) that takes all of the components of a cell phone tower and compresses them down into a 2.3-inch block. Unlike today's cell towers and antennas, which are large, inefficient and expensive to maintain, lightRadio is tiny, capacious and power-sipping.

[snip]

When conceiving of lightRadio, Alcatel-Lucent's engineers stripped out all the heavy power equipment that controls modern cell towers, and moved them to centralized stations. That allows the lightRadio cubes to be made small enough to be deployed virtually anywhere and practically inconspicuously: Atop bus station awnings, on the side of buildings or on lamp posts.

Their small size and centralized operation lets wireless companies control the cubes virtually. That makes the antennas up to 30% more efficient than current cell towers. Live data about who is using the cubes can be assessed, and the antennas' directional beams can be shifted to maximize their potential. For instance, radios may be pointed in one direction as people are coming to work in the morning and another direction as they're leaving work at the end of the day.

The lightRadio units also contain multi-generational antennas that can relay 2G, 3G and 4G network signals all from the same cube. That cuts down on interference and doubles the number of bits that can be sent through the air.

Today's cell towers, by contrast, send power in all different directions, most of which is lost, since it doesn't reach anyone's particular devices. They're inefficient in other ways as well: Roughly half of the power from cell towers' base stations is lost before it makes its way up to the antennas at the top of the tower. And they have separate antennas for 2G, 3G and 4G networks, causing interference problems.

[snip]

Each 1.5-Watt lightRadio cube powers about a two-block radius, so in urban areas, they can be deployed throughout the city and stacked like Lego blocks in stadiums or other areas that need extra capacity. In rural areas, they can be deployed atop existing cell towers in arrays.

Since that article was written, these kinds of devices have been deployed to provide cell phone coverage in "dead zones" such as under bridges, inside buildings, and so on.


However, this was intended for the legitimate purpose of providing better cell phone coverage. While this kind of technology could be misused, there are also devices that were intended for surreptitious use. One such device is called an "IMSI Catcher". A brief excerpt from the introduction to IMSI-Catch Me If You Can: IMSI-Catcher-Catchers describes what this is (numbers in [brackets] refer to footnotes in the paper):


IMSI Catchers are MITM (man in the middle) devices for cellular networks [20]. Originally developed to steal IMSI (International Mobile Subscriber Identity) numbers from nearby phones (hence the name), later versions offered call- and message interception. Today, IMSI Catchers can also be used to track handsets, intercept mobile two-factor authentication schemes (mTAN), geo-targeted spam [24], send operator messages that reconfigure the phone (e.g. installing a permanent MITM by setting a new APN, http-proxy, or attack the management interface [32]), or attack SIM cards with encrypted SMS [26] that are filtered by most operators by now.

A company called Gamma Group markets an IMSI Catcher which a person can wear under a coat, kind of like a bullet-proof vest. Here are excerpts from The body-worn "IMSI catcher" for all your covert phone snooping needs, dated September 1, 2013:



"The unit is optimized for short-range covert operation, designed to allow users to get close to Target(s) to maximize the chances of only catching the Target(s') identities and minimal unwanted collateral," one of the marketing pamphlets boasts. "The solution can be used as a standalone device or integrated into wider data-gathering and geo-tracking systems."

At just 41 x 33 x 18 centimeters, the device is small enough to fit under a shirt. It needs from one to 90 seconds to capture the international mobile subscriber identity (IMSI) or international mobile equipment identity (IMEI) of the person being tracked. It works on all GSM-based networks regardless of country and is fully operational even when functioning in a moving vehicle. The same brochure advertises several other varieties of IMSI catchers, including some that work in a totable briefcase and one that receives signals from a covert vehicle roof bar antenna. The James Bond spying tools are sold to government agencies and law enforcement organizations.

[snip]

Other devices available from GammaGroup help snoops physically track and tap a target once his IMSI is known. One device helps spies physically locate a target by locking into his mobile phone signal. It can also intercept the target's SMS messages and "take control of target phones for the purpose of denying GSM service." The devices can even "create a bubble or exclusion zone to deny GSM network coverage without alerting cell phones."

In other words, these devices can identify your cell phone, find where your cell phone is, and then jam it without your cell phone alerting you to the process. Also, your cell phone communications can be monitored, and even spoofed: it is possible your cell phone can receive fake messages, and fake messages can be sent out with your cell phone's signature.

And all it takes to make this happen is to get a small computer-controlled device, which would fit comfortably in a brief case or overcoat, within a reasonably short distance from you - not necessarily close enough for you to notice.

Stick around for Part 3.

Friday, September 5, 2014

Trivia, Part 1

When I have not blogged for nearly a year, and then I resume blogging by beginning with an article that reviews very old news, that should be something of concern.

Three summers ago, there was a big scandal, wherein news outlets of Rupert Murdoch's media empire had used illegal means to obtain information about the highest-ranking members of the British government, as well as information about celebrities and other persons of interest. We begin with excerpts from Murdoch Tabloids' Targets Included Downing Street and the Crown, July 11, 2011:

LONDON — The scandal that has enveloped Rupert Murdoch's media empire in Britain widened substantially on Monday with reports that two of his newspapers may have bribed police officers or used other potentially illegal methods to obtain information about Queen Elizabeth II and former Prime Minister Gordon Brown.

Others on the police payroll have been bribed to use restricted cellphone-tracking technology to pinpoint the location of people sought by the papers in their restless pursuit of scoops, according to two former journalists for the tabloid shut on Sunday, The News of the World.

[snip]

The revelations about the intrusive activities directed at the queen and Mr. Brown have seized the headlines, driving home the realization that nobody, not even the most powerful and protected people in the land, has been beyond the reach of news organizations caught up in a relentless battle for lurid headlines and mass circulations.

A wide segment of British society, from celebrities to ordinary families wrestling with personal tragedies, has been shown to be potentially vulnerable to the newspapers' use of cellphone-hacking, identity theft, tracking technology and police bribery — perhaps even clandestine property break-ins, if some reports circulating in recent days are true.

Recently there has exploded to the surface a scandal in the United States whereby private photos of celebrities were supposedly hacked and published online. At the moment, the issue is still up in the air, with some celebrities denying the authenticity of the photos of them, while other celebrities confirm that the photos of them are authentic; some of these latter are vowing to pursue legal redress.

Many allegations suggest that it was Apple's cloud storage that may have been hacked, but an alternative hypothesis seems like an opportunity to introduce this post.

First, an excerpt from Don't blame iCloud yet for hacked celebrity nudes by Tony Bradley, September 2, 2014:

Boris Gorin, head of security engineering at FireLayers, thinks we shouldn't be throwing stones at iCloud. "The images leaked have been gradually appearing on several boards on the net prior to the post at 4chan—making it reasonable to believe they were not part of a single hack, but of several compromises that occurred over time."

Gorin shared a theory the celebrities may have been hacked while connected to an open public Wi-Fi network at the Emmy Awards. If they accessed their personal iCloud accounts, attackers connected to that network would have been able to intercept and capture the username and password credentials. That's not a security flaw with iCloud and having a strong or complex password wouldn't offer protection against transmitting that password in clear text on a public Wi-Fi network.

Of course, any use of any kind of cell phone could be a security risk, and this is the topic addressed here.

Cell phones communicate via radio frequency (RF) emissions to cell phone towers which, in turn, process the signals and send them into the telephone network. Of course, for years, cell phones have been more than mobile telephones, and so, for years, cell phone towers have also allowed handheld devices to communicate via the Internet.

Consequently, cell phone towers are a key node in modern communications; someone who controls a cell phone tower has access to a significant amount of information.

In an effort to make cell phone towers less conspicuous and more in-tune with the surroundings, efforts have been made to camouflage them. For over two decades, cell phone towers have been disguised as trees, and some of the disguises are not very convincing.


There is also a need for more easily-transportable cell phone towers that can be taken to replace a damaged tower while repairs are being made, or to provide surge capability, for example during a convention or sporting event. These towers can be of a generic nature, useful for not just communications equipment, but emergency lighting and other applications.


A report by Popular Science entitled Mysterious Phony Cell Towers Could Be Intercepting Your Calls from August 27 is beginning to get some attention in the media. The article begins explaining how certain telephones have security-related enhancements that make them far less vulnerable to spoofing, and how these phones have identified the phony cell phone towers (known as "interceptors) that tried to spoof them, providing information that allowed the company which markets the phones to map where the "interceptors" are.


An excerpt from the middle of the article introduces the problem we are examining:

"Interceptor use in the U.S. is much higher than people had anticipated," [Les] Goldsmith [CEO of ESD America, a maker of "hardened" cell phones] says. "One of our customers took a road trip from Florida to North Carolina and he found 8 different interceptors on that trip. We even found one at South Point Casino in Las Vegas."

Who is running these interceptors and what are they doing with the calls? Goldsmith says we can't be sure, but he has his suspicions.

"What we find suspicious is that a lot of these interceptors are right on top of U.S. military bases. So we begin to wonder – are some of them U.S. government interceptors? Or are some of them Chinese interceptors?" says Goldsmith. "Whose interceptor is it? Who are they, that's listening to calls around military bases? Is it just the U.S. military, or are they foreign governments doing it? The point is: we don't really know whose they are."

As this series continues, we will examine the nature of "interceptors", consider the extent of their use, and discuss the question of to whom they may belong.

Thursday, April 29, 2010

Indian Navy Upgrade

Here's an interesting piece of news, entitled India commissions its first stealth warship April 29, 2010:

MUMBAI: India on Thursday commissioned its first indigenously-built stealth warship with sophisticated features to hoodwink enemy radars and gained entry into a top club of developed countries having such capability.

Inducting 'INS Shivalik', the first of the three-ship Project-17 frigates, at the Mumbai-based Mazagon Docks (MDL), Defence Minister A K Antony called it a red letter day for the armed forces.

The 143-metre-long warship, with 6,000-tonne displacement, has "versatile control systems with signature management and radar cross-section reduction features." The other countries having the capability to build stealth warships are the US, the UK, Russia, France, China, Japan and Italy.

[snip]

The Navy currently has a 130-warship-strong fleet which includes an aircraft carrier, 20 landing ships, eight destroyers, 12 frigates and 16 attack submarines based in four commands headquartered in Mumbai (Western Naval Command), Visakhapatnam (Eastern Naval Command), Kochi (Southern Naval Command) and Port Blair (Andaman and Nicobar Joint Command).

Shivalik class warships can deal with multiple threat environment and are fitted with weapon suite comprising both area and point defence systems. It has sensors for air, surface and subsurface surveillance, electronic support and counter equipment and decoys for 'soft kill measures'.

[snip]

"Shivalik is a steep jump in the indigenous design effort of the Directorate of Naval Design that has since 1954 designed 17 warships of different classes with 80 units built out of them. Currently, there are four designs from which 11 warships are under construction," he said.

See also India commissions its first stealth warship, joins elite club and India commissions its first stealth warship, though the Times of India article gives far more information.

For a target to be detected on radar, it must reflect radar energy back to an enemy detector. Stealth technology consists of minimizing this by 1) reflecting the energy in another direction, 2) absorbing it instead of reflecting it, or 3) transmitting it through the target - though this latter approach may be difficult with a large metal warship. Along with stealth features there are typically measures to reduce the target's heat signature and possibly its acoustic signature, as well:

"INS Shivalik has the latest stealth features to outsmart the enemy with low radar cross section, be it of the hull, infra-red or sound signatures," according to Navy's Director General for Naval Design Rear Admiral K N Vaidhyanathan.

India has two island groups, the Andaman and Nicobar Islands, and the Indian Navy typically stages exercises where their forces have to protect these islands from an attacker, hence the need to project power, including landing ships, naval airpower, and submarines.

A powerful enough naval force would also be useful against India's traditional enemy, Pakistan, as the Indian Navy could conceivably execute a landing on Pakistan's coast, outflanking Pakistan's ground forces along the border. Realistically, the threat of such a landing might be more useful than a landing itself, as Pakistan's army might be tied up defending the coastline against possible Indian attack in many places.

An ability to intervene elsewhere in the Indian Ocean is also significant. Myanmar, also known as Burma, has been dominated by the military since the early 1960's, and has been the scene of anti-government instability in recent years.

In the context of power projection, it is worth considering India's fossil fuel situation. It might be useful to begin by examining natural gas.