how are mobile phone users spied on in birmingham? · 2017-02-20 · what data can be captured?...

24
How are mobile phone users spied on in Birmingham? @OpenRightsBrum

Upload: others

Post on 17-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How are mobile phone users spied on in Birmingham?

@OpenRightsBrum

Page 2: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

About ORG Birmingham

@OpenRightsBrum

● Local branch of the Open Rights Group (ORG)● ORG is the UK's only digital campaigning organisationworking to protect the rights to privacy and freespeech online

Page 3: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How are mobile phone usersin Birmingham spied on?

● Many ways to access mobile phone information● Impact of Investigatory Powers Act 2016 AKASnoopers’ Charter

● Different types of surveillance:● Focusing today on direct surveillance via IMSI catchers

Page 4: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

What’s an IMSI catcher?

Page 5: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How do IMSI catchers work?

Page 6: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

What’s the legal basisfor using IMSI catchers?

● Legality of IMSI catchers questionable● In 2015 Home Office cited:

● Police Act 1997● Intelligence Services Act 1994● Regulation of Investigatory Powers Act 2000 (RIPA)

● Confusion about status of IMSI catchers underInvestigatory Powers Act 2016

Page 7: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Vice News documentary:Phone Hackers

Page 8: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How are IMSI catchers used inBirmingham?

● West Midlands Police will not confirm or deny the useof the technology

● West Midlands PCC: “we maintain close oversight ofthis important area of work.”

● Investigation by The Bristol Cable revealed more ● No reliable figures on IMSI-catcher use

Page 9: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

What’s the big deal about IMSI catchers,anyway?

“It is inconceivable that using devices built toindiscriminately intercept and hack up to 500 phonesevery minute within an 8km radius can be lawful,”

Silkie Carlo, a policy officer for human rightsorganisation Liberty

Page 10: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

What can we do to changehow IMSI catchers are used

by the police in Birmingham?

Page 11: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How do we know WMP have them?

Source: Warwickshire Police AGG Minuteshttps://thebristolcable.org/wp-content/uploads/2016/10/09-imsi-4.pdf

Page 12: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

How do we WMP have them?

Source:Warwickshir

e PoliceAGG

Minuteshttps://thebristolcable.or

g/wp-content/uploads/2016/10

/09-imsi-4.pdf

Page 13: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

West Midlands Police

“The Technical Intelligence Development Unit (TIDU) is a small unit ofofficers that have technical expertise around telephony, computersand Information Technology.

They are able to obtain intelligence and evidence to supportinvestigations and can paint a technological picture of a person‟slifestyle and transactions.

The team also operate on-line to obtain intelligence through the useof social networking sites and other media that would be significantlymore expensive to obtain by other covert techniques.”Source: Force Intelligence Update 2012 http://www.westmidlands-pcc.gov.uk/media/203470/10b_pservices_11oct2012_intelligence_update.pdf

Page 14: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Source: https://assets.documentcloud.org/documents/3034490/Cellxion-Brochure-UGX-Series-330.pdf

Page 15: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Source:https://assets.documentcloud.org/documents/3034490/Cellxion-Brochure-UGX-Series-330.pdf

Page 16: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

What data can be captured?

● IMSI, IMEI, TMSI… who you are

● Location data via cell towers and GPS

● Live interception of calls, SMS and internet data

● Deliver malware via silent SMS, SS7 exploits, “manin the middle” attacks

● Denial of service

● 1500 phones a minute!

Page 17: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Detection

Source: 2015Leipzighttps://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki/Unmasked-Spies

Page 18: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Detection

Source: 2015Leipzighttps://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki/Unmasked-Spies

Page 19: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Detection

Source:TaksimSquare inInstanbulhttps://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki/Unmasked-Spies

Page 20: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

AIMSICD

https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector

Page 21: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

SnoopSnitch

https://opensource.srlabs.de/projects/snoopsnitch

Page 22: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Security Tips

● Turn your phone off, remove SIM card, remove battery● Use a faraday bag/pouch● Use encrypted communications apps such as Signal,

VPN, Orbot● Learn more… media.ccc.de is a great resource

with many videos on this topic

Page 23: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Long term goals

● Convince mobile networks to improve their security● Change legislation to improve transparency and

accountability● Make a phone with open hardware and software● Reduce reliance on the phone network

Page 24: How are mobile phone users spied on in Birmingham? · 2017-02-20 · What data can be captured? IMSI, IMEI, TMSI… who you are Location data via cell towers and GPS Live interception

Useful Resources● https://www.openrightsgroup.org/● https://openrightsgroupbirmingham.wordpress.com/● https://thebristolcable.org/2016/10/imsi/● https://wiki.openrightsgroup.org/wiki/IMSI_Catcher#Legal_basis

● https://www.privacyinternational.org/node/454?q=node/454

● https://www.whatdotheyknow.com/user/mr_f_clarke● https://media.ccc.de/● https://ssd.eff.org/● https://whispersystems.org/