<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phone Hacks Archives - Good Shepherd News - Fastest Growing Religious, Free Speech &amp; Political Content</title>
	<atom:link href="https://goodshepherdmedia.net/category/truthful-news/home-garden/how-to/phone-hacks/feed/" rel="self" type="application/rss+xml" />
	<link>https://goodshepherdmedia.net/category/truthful-news/home-garden/how-to/phone-hacks/</link>
	<description>Christian, Political, ‎‏‏‎Social &#38; Legal Free Speech News &#124; Ⓒ2024 Good News Media LLC &#124; Shepherd for the Herd! God 1st Programming</description>
	<lastBuildDate>Mon, 04 Aug 2025 22:38:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://goodshepherdmedia.net/wp-content/uploads/2023/08/Good-Shepherd-News-Logo-150x150.png</url>
	<title>Phone Hacks Archives - Good Shepherd News - Fastest Growing Religious, Free Speech &amp; Political Content</title>
	<link>https://goodshepherdmedia.net/category/truthful-news/home-garden/how-to/phone-hacks/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Detecting IMSI Catchers: Tools, Apps and Methods You Should Know</title>
		<link>https://goodshepherdmedia.net/detecting-imsi-catchers-tools-apps-and-methods-you-should-know/</link>
		
		<dc:creator><![CDATA[The Truth News]]></dc:creator>
		<pubDate>Mon, 25 Aug 2025 21:49:26 +0000</pubDate>
				<category><![CDATA[Cool Tech & Gadgets 📱⌚🎧⚡]]></category>
		<category><![CDATA[Hackers / Master Programmers]]></category>
		<category><![CDATA[Hardware Pioneers]]></category>
		<category><![CDATA[Home & Garden]]></category>
		<category><![CDATA[Home Defense / Safety]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Phone Hacks]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Zee Truthful News]]></category>
		<category><![CDATA[🎖️🪖Military Tech🤖]]></category>
		<category><![CDATA[🔐Cybersecurity]]></category>
		<category><![CDATA[🔐Hacking Technology]]></category>
		<category><![CDATA[Apps and Methods You Should Know]]></category>
		<category><![CDATA[Cell-site simulators]]></category>
		<category><![CDATA[Detecting IMSI Catchers: Tools]]></category>
		<category><![CDATA[IMSI Catcher]]></category>
		<category><![CDATA[imsi catchers]]></category>
		<category><![CDATA[IMSI catchers: a security threat]]></category>
		<category><![CDATA[Stingray phone tracker]]></category>
		<category><![CDATA[Understanding How IMSI-Catchers Exploit Cell Networks]]></category>
		<guid isPermaLink="false">https://goodshepherdmedia.net/?p=21336</guid>

					<description><![CDATA[Detecting IMSI Catchers: Tools, Apps and Methods You Should Know An IMSI-catcher is a device that intercepts mobile phone communications, acting as a fake cell tower to eavesdrop on calls and track location data. It&#8217;s essentially a &#8220;man-in-the-middle&#8221; attack, placing the device between the target phone and the real cell network. While some security measures exist in [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1 class="entry-title">Detecting IMSI Catchers: Tools, Apps and Methods You Should Know</h1>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-21340" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/Detecting-IMSI-Catchers-Tools-Apps-and-Methods-You-Should-Know.jpg" alt="" width="800" height="800" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/Detecting-IMSI-Catchers-Tools-Apps-and-Methods-You-Should-Know.jpg 800w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/Detecting-IMSI-Catchers-Tools-Apps-and-Methods-You-Should-Know-400x400.jpg 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/Detecting-IMSI-Catchers-Tools-Apps-and-Methods-You-Should-Know-150x150.jpg 150w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/Detecting-IMSI-Catchers-Tools-Apps-and-Methods-You-Should-Know-768x768.jpg 768w" sizes="(max-width: 800px) 100vw, 800px" /></p>
<p><span data-huuid="12916251619821288363">An IMSI-catcher is a device that intercepts mobile phone communications, acting as a fake cell tower to eavesdrop on calls and track location data. </span><span data-huuid="12916251619821288608">It&#8217;s essentially a &#8220;man-in-the-middle&#8221; attack, placing the device between the target phone and the real cell network. </span><span data-huuid="12916251619821288853">While some security measures exist in newer standards (like 3G), sophisticated attacks can bypass these, especially on older networks. </span><span data-huuid="12916251619821289098">These devices, like the <span class="M5tQyf"><strong>StingRay</strong>,</span> are used by law enforcement and intelligence agencies, but their use raises privacy and civil liberty concerns.<span class="pjBG2e" data-cid="0254da5d-6a60-4252-9748-b8be8c5ec492"><span class="UV3uM"> </span></span></span></p>
<h2>IMSI catchers: a security threat</h2>
<div id="aim-chrome-initial-inline-async-container" data-ved="2ahUKEwj5tOPnsMyOAxXsJEQIHf4cG7QQ_ZkOegYIAQgAEBQ" data-hveid="CAEIABAU">
<div data-processed="true">
<div class="CKgc1d" data-scope-id="turn" data-processed="true" data-complete="true">
<div class="Zkbeff" data-subtree="aimc" data-aimmrs="true" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQ2O0OegQIABAA" data-hveid="CAAQAA" data-processed="true" data-complete="true">
<div class="pWvJNd" data-processed="true" data-complete="true">
<div class="mZJni" data-container-id="main-col" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQ3KYQegQIABAD" data-processed="true" data-complete="true">
<div class="Y3BBE" data-hveid="CAAQEg" data-complete="true" data-processed="true">An IMSI catcher, sometimes called a Stingray, is a device that impersonates a legitimate cell tower. It works by mimicking cell tower signals and attracting nearby mobile devices, tricking them into connecting to the device instead of a genuine cell tower. Once a device connects, the IMSI catcher can capture the device&#8217;s unique identifier, the International Mobile Subscriber Identity (IMSI).<span class="" data-wiz-rootname="ohfaMd" data-complete="true" data-processed="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> <button class="rBl3me" tabindex="0" data-amic="true" data-icl-uuid="daf9ecda-6d56-4163-b71b-24f3c7686c4a" aria-label="View related links" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQye0OegQIABAT"></button></span></span></div>
<div class="Y3BBE" data-hveid="CAAQFA" data-processed="true" data-complete="true">This allows the IMSI catcher to:</div>
<ul class="U6u95" data-complete="true" data-processed="true">
<li data-hveid="CAAQFg" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Track the device&#8217;s location</b> by analyzing the signal strength of the phone.</span></li>
<li data-hveid="CAAQFw" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Identify and monitor activity</b>, and potentially even intercept communications, including SMS and calls, depending on the network protocol.</span><span class="" data-wiz-rootname="ohfaMd" data-complete="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> <button class="rBl3me" tabindex="0" data-amic="true" data-icl-uuid="670887ed-08de-4a8c-9ff5-7bf40ef17ffd" aria-label="View related links" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQye0OegQIABAY"></button></span></span></li>
</ul>
<div class="Y3BBE" data-hveid="CAAQGg" data-processed="true" data-complete="true">IMSI catchers can be used by law enforcement, and potentially by unauthorized actors including criminals or foreign intelligence services. The use of these devices raises significant privacy concerns due to the indiscriminate collection of data, which may include bystanders as well as targeted individuals.<span class="" data-wiz-rootname="ohfaMd" data-complete="true" data-processed="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> <button class="rBl3me" tabindex="0" data-amic="true" data-icl-uuid="54c6456f-6f79-45d6-8c0f-760c83c9443a" aria-label="View related links" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQye0OegQIABAb"></button></span></span></div>
<div class="Fsg96" data-processed="true" data-complete="true"></div>
<div class="otQkpb" role="heading" aria-level="3" data-processed="true" data-complete="true">Potential threats</div>
<ul class="U6u95" data-complete="true" data-processed="true">
<li data-hveid="CAAQHQ" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Location Tracking:</b> IMSI catchers can track a phone&#8217;s location and movements.</span></li>
<li data-hveid="CAAQHg" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Communication Interception:</b> Older generation networks (like 2G) are more vulnerable, allowing interception of calls and texts. While 3G, 4G, and 5G networks are more secure, some IMSI catchers can potentially force a device to downgrade to an older, less secure network.</span></li>
<li data-hveid="CAAQHw" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Denial of Service:</b> IMSI catchers can also disrupt mobile network connectivity.</span><span class="" data-wiz-rootname="ohfaMd" data-complete="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> <button class="rBl3me" tabindex="0" data-amic="true" data-icl-uuid="b15d0dc0-c4f4-4750-be02-e68a02eaf8c9" aria-label="View related links" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQye0OegQIABAg"></button></span></span></li>
</ul>
<div class="Fsg96" data-complete="true" data-processed="true"></div>
<div class="otQkpb" role="heading" aria-level="3" data-processed="true" data-complete="true">Detection</div>
<div class="Y3BBE" data-hveid="CAAQIg" data-complete="true" data-processed="true">Detecting IMSI catchers with a smartphone alone can be difficult. Hardware-based detection systems provide a more reliable means of identification.<span class="" data-wiz-rootname="ohfaMd" data-complete="true" data-processed="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> <button class="rBl3me" tabindex="0" data-amic="true" data-icl-uuid="7d40a971-c6b4-42c0-8686-6b9a9a15c3a0" aria-label="View related links" data-ved="2ahUKEwjc6uXnsMyOAxUehu4BHdiqIgUQye0OegQIABAj"></button></span></span></div>
<div class="Fsg96" data-processed="true" data-complete="true"></div>
<div class="otQkpb" role="heading" aria-level="3" data-processed="true" data-complete="true">Protecting yourself</div>
<ul class="U6u95" data-processed="true" data-complete="true">
<li data-hveid="CAAQJQ" data-complete="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Keep software updated:</b> Ensure your phone&#8217;s operating system and applications are up to date.</span></li>
<li data-hveid="CAAQJg" data-sae="" data-complete="true"><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Use encrypted communication tools:</b> Utilize apps like Signal or WhatsApp that offer end-to-end encryption.</span></li>
<li data-hveid="CAAQJw" data-complete="true" data-processed="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Consider using a VPN:</b> A VPN can encrypt your internet traffic.</span></li>
<li data-hveid="CAAQKA" data-complete="true" data-processed="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Enable Airplane mode:</b> When not actively using your phone, switching to airplane mode can help prevent connections to cell towers, including IMSI catchers.</span></li>
<li data-hveid="CAAQKQ" data-complete="true" data-processed="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Be aware of your surroundings:</b> Pay attention to suspicious devices resembling cell towers, especially in sensitive areas or during events like protests or rallies.</span></li>
<li data-hveid="CAAQKg" data-complete="true" data-processed="true" data-sae=""><span class="T286Pc" data-complete="true"><b class="Yjhzub" data-complete="true">Consider a Faraday cage:</b> A Faraday cage can block radio waves and protect your phone from interception.</span><span class="" data-wiz-rootname="ohfaMd" data-complete="true"><span class="vKEkVd" data-animation-atomic="" data-sae=""> </span></span></li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
<p><iframe title="What is an IMSI Catcher?" width="640" height="360" src="https://www.youtube.com/embed/wqhtMiKaLk0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p>IMSI catchers, sometimes referred to as cell-site simulators or fake cell towers, can be difficult to detect since they imitate real cell towers to capture mobile phone data. With proper cybersecurity testing measures, you can effectively be alert to these unwanted interceptions. Take a look at these common tools and methods that can efficiently assist in identifying IMSI catchers:</p>
<h2><strong>Top Techniques and Resources to Detect IMSI Catchers</strong></h2>
<h3><strong>1. Use Mobile Apps and Tools</strong></h3>
<p>Some apps and technologies are designed to monitor and detect irregularities in cell networks.</p>
<p><strong>SnoopSnitch (Android):</strong> This app analyses your phone’s network traffic and alerts you of strange cell tower behaviour. It requires access to low-level network data, which is mostly limited to particular Android phones equipped with Qualcomm chipsets.</p>
<p><strong>Cell Spy Catcher (Android):</strong> After starting the learning process of this app, it collects data on local networks to identify which one among them is a trap. Then it alerts you with a red interface screen.<br />
<strong>AIMSICD (Android):</strong> Detects IMSI catchers and reports on odd network activity, such as quick cell tower changes or downgrades to earlier network technologies (such as 2G). Phones switching to older network technologies usually happen due to IMSI catchers.</p>
<p><strong>Croatian Telecom’s AntiSpy (Android/iOS):</strong> An app that uses radio signal analysis to determine when your phone connects to a rogue cell tower.</p>
<p>Apple’s limitations on low-level network data access have led to a decrease in the number of apps accessible for iOS; however, network abnormalities can occasionally be found by keeping an eye on variations in signals.</p>
<h3><strong>2. Look for Unusual Network Activity</strong></h3>
<p>IMSI catchers can force phones to connect to low-security older networks (2G or 3G) to facilitate communication interceptions. Look out for:</p>
<p><strong>Downgraded connection:</strong> Your phone may unexpectedly switch from 4G/5G to 2G/3G or lose high-speed internet connection. Specifically, if it happens in an area that has outstanding coverage, it could be due to an IMSI catcher.</p>
<p><strong>Frequent disconnections:</strong> When an IMSI catcher is nearby, your phone might keep on disconnecting and reconnecting with the network.</p>
<p><strong>Suspicious network names:</strong> IMSI catchers can also broadcast non-standard or dubious network IDs. For example, a tower with an unusual name or ID might be a fake one.</p>
<h3><strong>3. Observe Battery and Signal Behaviour</strong></h3>
<p>IMSI catchers compel gadgets to transmit at faster speeds and consume more power.</p>
<p><strong>Rapid battery drain:</strong> If the battery on your phone runs out more quickly than usual, it can be because it’s transferring an unusual amount of data to a fake tower.</p>
<p><strong>Unusual signal intensity:</strong> An IMSI catcher may be indicated by abrupt, inexplicable changes in signal strength or highly fluctuating signal bars. Strong signals can be sent by these devices to overpower authorised cell towers.</p>
<h3><strong>4. Monitoring Tools for Experts</strong></h3>
<p>Advanced phone users with proper cybersecurity knowledge can utilise monitoring software or equipment to analyse cellular networks themselves.</p>
<p><strong>Software-defined radios (SDRs):</strong> SDR devices enable users to identify and analyse mobile phone signals. By identifying aberrant radio frequencies and patterns, an SDR can aid in the detection of IMSI catchers if used with the appropriate software.</p>
<p><strong>Cellular anomaly detectors:</strong> These are sophisticated technologies used by security experts and researchers that monitor local signals. These help detect abnormal cell tower behaviour that is essential in the <strong>current rise of data breaches</strong>, unexpected cyber attacks, or traffic demand in Australia.</p>
<h3><strong>5. Network Data Monitoring</strong></h3>
<p>Certified cyber security consultants in Australia suggest users to monitor network data. This includes the phone’s network logs like signal strength, base station ID, and encryption status that certain apps or customised firmware can access. Keeping an eye on this data can help determine when the phone connects to a dubious tower that may have less secure encryption or an unidentified ID.</p>
<h3><strong>6. Physical Indicators</strong></h3>
<p>IMSI catchers are usually non-stationary and can be implanted on vehicles or drones. So if you observe any strange and unknown vehicles or equipment within your local area and your phone network falters near it, it could be a clue.</p>
<h3><strong>7. Use Encrypted Communication</strong></h3>
<p>If you are wary of an IMSI catcher but are tech savvy or cannot locate it, resolve to the simple methods of using end-to-end encrypted apps. Switch to apps like WhatsApp, Signal, or Telegram for calls and texts for that while. These platforms prevent intercepted communications from being decoded, even if you do not know how to use tools for detecting IMSI catcher.</p>
<p><strong>Limitations</strong></p>
<p><strong>False positives:</strong> Certain apps, software, or devices may identify normal network issues as suspicious.</p>
<p><strong>Limited detection on iPhones:</strong> iOS restricts access to low-level radio data, making it more difficult to operate apps that monitor cellular networks. <a href="https://www.cyberneticgi.com/2024/10/15/detecting-imsi-catchers-tools-apps-and-methods/" target="_blank" rel="noopener">source</a></p>
<hr />
<h1 class="entry-title wp-block-post-title">With $20 of Gear from Amazon, Nearly Anyone Can Make This IMSI-Catcher in 30 Minutes</h1>
<p>With some dirt cheap tech I bought from Amazon and 30-minutes of set-up time, I was streaming sensitive information from phones all around me. IMSIs, the unique identifier given to each SIM card, can be used to <a href="https://motherboard.vice.com/en_us/article/zmkj38/emf-camp-imsi-catcher-" target="_blank" rel="noopener">confirm whether someone is in a particular area</a>. They can also be used as part of another attack to take over a person’s phone number and redirect their text messages. Obtaining this information was incredibly easy, even for a non-expert.</p>
<div class="wp-block-savage-platform-primis-video">
<div class="wp-block-savage-platform-primis-video__wrapper">
<div>
<div class="primisslate">
<div id="primis_container_div_687d600c04235">
<div id="primis_playerSekindoSPlayer687d600c04232">
<div id="Player-Div-SekindoSPlayer687d600c04232">
<div id="Video-Div-SekindoSPlayer687d600c04232">
<div id="pixelsDiv"></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p>This attack isn’t revolutionary in any way—IMSI-catchers <a href="https://motherboard.vice.com/en_us/article/nz798m/harris-imsi-catcher-picture-phone-tracking-device-in-the-wild" target="_blank" rel="noopener">are certainly not new</a>, and have become famous because they are commonly (and controversially) used by law enforcement to track suspected criminals. A commercial version made by Harris is called a “Stingray,” and they are sometimes called “cell-site simulators” or “fake cell towers.” This is because they spoof a cell phone tower’s connection, meaning that cell phones in the area will try to connect to it; in doing so, the IMSI-catcher is able to passively collect information about phones in the area.</p>
<div class="code-block code-block-1">
<div id="htlad-post-article-2" class="lngtd-dynamic-inarticle lngtd-dyn-ph">
<div id="vice_D_inarticle_2-1" class="lngtd-dynamic-ad-container" data-label="Advertisement" data-state="loaded"></div>
</div>
</div>
<p>Harris’s Stingray was so secretive that, for years, the <a href="https://arstechnica.com/tech-policy/2015/04/fbi-would-rather-prosecutors-drop-cases-than-disclose-stingray-details/" target="_blank" rel="noopener">FBI dropped criminal court cases</a> that used Stingrays rather than reveal the details of how the evidence was gathered.</p>
<p>But a DIY IMSI catcher is relatively trivial to setup, and the technology is accessible to anyone with a cheap laptop, $20 of gear, and, the ability to essentially copy and paste some commands into a computer terminal. This is about ease of access; a lower barrier of technical entry. In a similar way to so-called spouseware—<a href="https://motherboard.vice.com/en_us/article/53vm7n/inside-stalkerware-surveillance-market-flexispy-retina-x" target="_blank" rel="noopener">malware used by abusive partners</a>—surveillance takes on different character when it trickles down to more ordinary, everyday users. The significance and threat from IMSI-catchers is multiplied when a lot more people can deploy one.</p>
<p class="article__blockquote"><i><b>Got a tip? You can contact Joseph Cox securely on Signal on +44 20 8133 5190, OTR chat on jfcox@<span class="skimlinks-unlinked">jabber.ccc.de</span>, or email <span class="skimlinks-unlinked">joseph.cox@vice.com</span>.</b></i></p>
<p>For legal and technical reasons, our IMSI-catcher did not intercept text messages or phone calls, like more powerful versions can. It only captured IMSIs from devices, as well as provides some additional information such as the country and telecom operator of the phone. Motherboard did not store any of the collected data. You should be aware of the laws in your local region before attempting to do this; Motherboard does not condone or suggest you do anything illegal (and, even if legal, you shouldn’t use an IMSI catcher to do anything creepy.)</p>
<p>We’ll explain what each of these are, but in short, the process was:</p>
<ul class="wp-block-list">
<li>Buy a cheap, software defined radio</li>
<li>Install Ubuntu</li>
<li>Download IMSI-catcher script with its dependencies</li>
<li>Find the right frequency to scan for</li>
<li>Start scanning on that frequency and picking up IMSIs</li>
</ul>
<div class="code-block code-block-1"></div>
<div class="article__media--image"></div>
<p>As the name implies, a software defined radio, or SDR, is simply a radio that instead of having its feature baked in at a hardware level, can be controlled by a computer program. We bought <a href="https://www.amazon.co.uk/NooElec-NESDR-Mini-Previously-Compatible/dp/B009U7WZCA" target="_blank" rel="noopener" data-ml-dynamic="true" data-ml-dynamic-type="sl" data-orig-url="https://www.amazon.co.uk/NooElec-NESDR-Mini-Previously-Compatible/dp/B009U7WZCA" data-ml-id="0" data-ml="true" data-xid="fr1753047054953cei" data-skimlinks-tracking="xid:fr1753047054953cei">the ‘NooElec NESDR Mini’ from Amazon for around $20</a> and received it a few days later.</p>
<p>To get the SDR to talk to phones, I needed to give it some instructions. Fortunately, I didn’t need to write my own, but just take some code from GitHub. I used a Python tool <a href="https://github.com/Oros42/IMSI-catcher" target="_blank" rel="noopener">simply called ‘IMSI-catcher’</a>, written by the hacker known as Oros42. The program requires an up-to-date version of Ubuntu, a particular Linux distribution, that can be downloaded for free and written either to a USB stick or installed inside a virtual machine.</p>
<p>To install the IMSI-catcher software, I just followed the instructions on <a href="https://github.com/Oros42/IMSI-catcher" target="_blank" rel="noopener">the project’s GitHub</a>.</p>
<p>Once installed, I booted up grgsm_livemon, one of the programs included with the project. which presented a slider and a graph, to find a frequency to scan. This required a bit of trial and error—moving the frequency slider until finding a sweet spot where the graph represented a bell curve. The curve meant that the SDR had found what frequency nearby phones were broadcasting on. Depending on where you are, that frequency is going to be different.</p>
<div class="code-block code-block-1">
<div id="htlad-post-article-7" class="lngtd-dynamic-inarticle lngtd-dyn-ph">
<div id="vice_D_inarticle_1-4" class="lngtd-dynamic-ad-container" data-label="Advertisement"></div>
</div>
</div>
<p>Once I found the sweet spot, after a few seconds IMSIs started appearing on my screen.</p>
<figure class="wp-block-image"><img decoding="async" class="attachment-full size-full" src="https://www.vice.com/wp-content/uploads/sites/2/2018/11/1542319074607-IMG_4742.png" alt="imsi-catcher" width="1107" height="584" /><figcaption class="wp-element-caption">Caption: A redacted photo of IMSIs captured by the SDR and related script. Image: Motherboard</figcaption></figure>
<div class="code-block code-block-1">
<div id="htlad-post-article-8" class="lngtd-dynamic-inarticle lngtd-dyn-ph">
<div id="vice_D_inarticle_2-4" class="lngtd-dynamic-ad-container" data-label="Advertisement" data-state="loaded" data-google-query-id="CIOr6aC0zI4DFUjcuAgdCJ0Z_g">
<div id="google_ads_iframe_/16916245/vice/vice_D_inarticle_2_3__container__"></div>
</div>
</div>
</div>
<p>If I wanted to make the IMSI-catcher a bit more portable, I could theoretically run it on a Raspberry-Pi, a miniature computer you can buy for as little as $30 or cheaper, depending on what model you need. Note that the IMSI-catcher would still need to have Ubuntu on the Pi, which it is not traditionally designed for, <a href="https://linuxconfig.org/install-ubuntu-16-04-mate-or-ubuntu-18-04-on-raspberry-pi" target="_blank" rel="noopener">but it is likely possible</a>. I would also need to make sure the SDR is receiving enough power from the USB port.</p>
<p>In all, the process of making an IMSI-catcher didn’t take much time at all, as I thankfully didn’t hit any roadblocks. I just made sure I had the latest version of Ubuntu, followed the instructions carefully, and ended up with an IMSI-catcher on my laptop. <a href="https://www.vice.com/en/article/how-i-made-imsi-catcher-cheap-amazon-github/" target="_blank" rel="noopener">source</a></p>
<p>&nbsp;</p>
<p><iframe title="This $50 Device lets anyone spy and track your phone!" width="640" height="360" src="https://www.youtube.com/embed/PpkLts5fdII?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<blockquote>
<h3><span style="color: #008080;"><a class="url fn" href="https://github.com/Oros42" rel="author" data-hovercard-type="user" data-hovercard-url="/users/Oros42/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" aria-keyshortcuts="Alt+ArrowUp">Oros42</a></span><span class="mx-1 flex-self-stretch color-fg-muted">/</span><strong class="mr-2 flex-self-stretch"><a href="https://github.com/Oros42/IMSI-catcher" data-pjax="#repo-content-pjax-container" data-turbo-frame="repo-content-turbo-frame">IMSI-catcher DOWNLOAD HERE</a> i</strong>MSI CATHER SOFTWARE AND BUILD YOUR OWN!<span style="color: #ff0000;"> TO OF COURSE SOLVE SECURITY FLAWS IN YOUR OWN SYSTEM ONLY </span></h3>
<h3><span class="author flex-self-stretch"><a class="url fn" href="https://github.com/CellularPrivacy" rel="author" data-hovercard-type="organization" data-hovercard-url="/orgs/CellularPrivacy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" aria-keyshortcuts="Alt+ArrowUp">CellularPrivacy</a></span><span class="mx-1 flex-self-stretch color-fg-muted">/</span><strong class="mr-2 flex-self-stretch"><a href="https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector" data-pjax="#repo-content-pjax-container" data-turbo-frame="repo-content-turbo-frame">Android-IMSI-Catcher-Detector DOWNLOAD HERE </a></strong><span style="color: #008080;">IMSI CATHER SOFTWARE AND BUILD YOUR OWN!</span><span style="color: #ff0000;"> TO OF COURSE SOLVE SECURITY FLAWS IN YOUR OWN SYSTEM ONLY </span></h3>
</blockquote>
<p>&nbsp;</p>
<hr />
<h1>Gotta Catch &#8216;Em All: Understanding How IMSI-Catchers Exploit Cell Networks</h1>
<div class="panel-pane pane-node-content">
<article class="node node--whitepaper node--full node--whitepaper--full" role="article">
<div class="node__content">
<div class="field field--name-body field--type-text-with-summary field--label-hidden">
<div class="field__items">
<div class="field__item even">
<h2>Section 1: Introduction</h2>
<p>You’ve probably heard of Stingrays or IMSI-catchers, which belong to the broader category of “Cell Site Simulators” (CSSs). These devices let their operators “snoop” on the phone usage of people nearby. There’s a lot of confusion about what CSSs are actually capable of, and different groups—from activists to policy makers to technologists—understand them differently.</p>
<p>In the research community, there has been a tendency to dismiss the prevalence of CSS and the threat they pose to the public. Congress <a href="https://fcw.com/articles/2019/02/21/cell-site-simulators-congress.aspx">recently asked</a> the Department of Homeland Security for more information about their use by federal law enforcement, as well as state and local partners. It&#8217;s unclear how much oversight the Department has been exercising, and when it comes to state and local law enforcement, only a few cities have any protections at all. Many activists aren’t aware that CSSs could be in use around them without their knowledge, particularly during protests. The truth is that CSSs are significantly more widespread than most policy makers, researchers, and activists are aware, and their danger to privacy is more significant than most realize. Of course, it’s hard to acknowledge the prevalence of CSSs when law enforcement goes to great lengths to keep information about them from the public.</p>
<p>There is a plethora of low-level academic research in the area of cell network security, and many high-level posts that don’t really explain in any meaningful detail what’s going on with “IMSI-catcher” type cell network attacks. Our goal is to bridge that gap, and with this post we hope <strong>to make accessible the technical inner workings of CSSs, or rather, the details of the kind of attacks they might rely on</strong>. For example, what are the different kinds of location tracking attacks and how do they actually work? Another example: it’s also widely believed that CSSs are capable of communication interception, but what are the known limits around cell network communication interception and how does that actually work?</p>
<p>We won’t be updating this post with new kinds of attacks as they come out, and we can’t cover every potentially relevant detail of every attack we explain, but this post should form a basis for non-experts to better understand new attacks.</p>
<h2><a id="BackgroundInfo"></a>Section 2: Necessary background info</h2>
<p>There’s a lot of confusion about what CSSs actually do and how they do it. This confusion comes from the fact that the term “cell site simulator” actually encapsulates quite a variety of different cell network attacks that have evolved significantly over the last 25 years or so. Adding to the confusion is the fact that the term “IMSI-catcher” is both used interchangeably with “cell site simulator” and also refers to specific capabilities that some CSSs have.</p>
<p>A very important distinction when talking about CSSs is which cell network generations they use when operating. The term “cell network generation” refers to the complete set of operating protocols covering everything from how cell towers are laid out geographically to how a mobile phone establishes a connection with a cell tower.</p>
<p>Here’s a high-level overview of the most relevant cell network generations:</p>
<ul>
<li>2G (e.g. GSM): the oldest type of cell network still in use and still very widely used. 2G only supports calling/texting, but in 2.5G the capability to support data transmission (e.g. email and Internet access) was introduced.</li>
<li>3G (e.g. UMTS or CDMA2000): improved upon 2G by having much faster data rates (which could support video calls, for example) and adding better security (more on this later).</li>
<li>4G (e.g. LTE or WiMax): significantly faster speeds and better security.</li>
</ul>
<p>The specifications for these networks are developed by working groups organized by the 3GPP,<sup id="fnref1"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn1" rel="footnote">1</a></sup> an international organization that any group can apply to join (though it has a high membership fee). Members typically include mobile carriers, university research labs, and wireless gear manufacturers (including surveillance tech manufacturers).</p>
<p>It’s important to note that in practice there’s often a lot of variance between what the specifications say and what actually ends up being implemented. This is usually due to (1) implementers needing to differ from the specifications for practical reasons (many parts of the specifications get marked as optional), and (2) mistakes.</p>
<p>There’s a bit more vocabulary and background that needs to be introduced:</p>
<ul>
<li>IMSI (International Mobile Subscriber Identity): the unique identifier linked to your SIM card that is one of the pieces of data used to authenticate you to the mobile network. It’s meant to be kept private (because, as we’ll see later, it can be linked to your physical location and your phone calls/messages/data).</li>
<li>TMSI: upon first connecting to a network, the network will ask for your IMSI to identify you, and then will assign you a TMSI (Temporary Mobile Subscriber Identifier) to use while on their network. The purpose of the pseudonymous TMSI is to try and make it difficult for anyone eavesdropping on the network to associate data sent over the network with your phone.</li>
<li>IMEI (International Mobile Equipment Identity): the unique identifier linked to your physical mobile device.</li>
<li>Ki: a secret cryptographic key also stored on the SIM card used to authenticate your phone to the network (and prove you are who you say you are).</li>
<li>MCC (Mobile Country Code): your mobile country code, but not to be confused with a country’s <a href="https://en.wikipedia.org/wiki/List_of_mobile_telephone_prefixes_by_country">mobile telephone prefix</a>. For example, Canada’s MCC is 302, but its telephone prefix is +001.</li>
<li>MNC (Mobile Network Code): the code that represents which carrier you’re using. For example, 410 is one of AT&amp;T’s MNCs.</li>
<li>Cell ID: each cell tower is responsible for serving a small geographic area called a cell, which has a cell ID attached it.</li>
<li>LAC/TAC (“Location Area Code”): in GSM, groups of nearby cells are organized by ID into “Location Areas” (“LA” for short), with each LA’s identifier being referred to as a “Location Area Code”. In 4G these are respectively referred to as Tracking Area (TA) and Tracking Area Code (TAC).</li>
<li>BTS (“base station”): a more general term for devices like cell towers (and CSSs pretending to be cell towers).<sup id="fnref2"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn2" rel="footnote">2</a></sup></li>
</ul>
<p>It’s important to note that some of this terminology varies by network generation. For example, in LTE a base station is referred to as an eNodeB, and in 3G/UMTS the LAC and Cell ID are replaced by PSC (primary scrambling code) and CPI (Cell Parameter ID). For simplicity, we will be sticking to the above terminology.</p>
<h2><a id="OverviewAttacks"></a>Section 3: Overview of attacks</h2>
<p>To be clear, as far as we know no one (outside of government or surveillance tech vendors) has ever gotten their hands on a commercial CSS (e.g. a Harris Corp Stingray) and published publicly available details of its inner workings, so this information all comes from academic literature and the work of open source hackers attempting to reproduce how commercial CSSs might work.</p>
<p>There are three main categories of attacks that will be covered:</p>
<ol>
<li>Communication interception</li>
<li>Denial of service and service downgrading</li>
<li>Location tracking</li>
</ol>
<p>Practical implementation details are left out of the following explanations for the sake of brevity.</p>
<h3><a id="BasicIMSICatcher"></a>Section 3.1: Basic IMSI-catcher</h3>
<p>Classic “IMSI-catchers” simply record nearby IMSIs, and then don’t interact with their target phones in a significant way beyond that. They quite literally “catch” (i.e. record) IMSIs by pretending to be real base stations and then release the target phones (Paget, 2010). Let’s go over how they work in more detail.</p>
<p>In GSM networks, phones will try to connect to whatever base station is broadcasting at the highest signal strength.</p>
<p><img decoding="async" class="alignnone size-full wp-image-21365" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css.png" alt="" width="2400" height="1200" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css.png 2400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css-1536x768.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/basic_css-2048x1024.png 2048w" sizes="(max-width: 2400px) 100vw, 2400px" /></p>
<p>Once a phone has identified a base station as having the best signal strength, it can begin negotiating a connection to it. The base station first asks the phone to send its encryption capabilities to it. If the base station is a CSS rather than a cell tower, it can then either ignore the response or set it to have no encryption.<sup id="fnref3"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn3" rel="footnote">3</a></sup></p>
<p>After this, the base station sends an Identity Request, which the phone responds to with its IMSI. The phone does this because the IMSI is stored on your SIM card, which was issued by your mobile carrier, and the phone network needs to identify that you are in fact a paying customer associated with a mobile carrier. After receiving your IMSI, the CSS then releases your phone back to the real network and moves on to try and capture another phone’s IMSI. That’s all it takes to collect an IMSI from a nearby phone!</p>
<p>&nbsp;</p>
<div class="caption caption-center">
<div class="caption-width-container">
<div class="caption-inner">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21364" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers.png" alt="" width="1999" height="1000" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers.png 1999w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image4imsicatchers-1536x768.png 1536w" sizes="(max-width: 1999px) 100vw, 1999px" /></p>
<p class="caption-text">The CSS sends an Identity Request to collect the target mobile phone’s IMSI. Afterwards, it proceeds to repeat this same action with other phones.</p>
</div>
</div>
</div>
<p>If law enforcement is operating such a CSS in a geographic area, once they’ve obtained the relevant IMSIs, they can then use legal process to get more data on all the users who were present.<sup id="fnref4"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn4" rel="footnote">4</a></sup></p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21363" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised.png" alt="" width="2400" height="1200" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised.png 2400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised-1536x768.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/a_css_in_a_geographic_area_-_revised-2048x1024.png 2048w" sizes="(max-width: 2400px) 100vw, 2400px" /></p>
<p>From here, many more sophisticated attacks can be launched, but that’s how the most basic kind of IMSI-catchers work: they simply collect IMSIs during the connection procedure, then abort the connection procedure and move on to their next target.</p>
<p>In later protocols (e.g. 4G/LTE), phones are a bit smarter about not connecting to any random base station with high signal strength, so an attacker needs more involved techniques to convince a phone to connect to their CSS. See section 3.3 for details.</p>
<h3><a id="Interception"></a>Section 3.2: Communication interception</h3>
<p>As far as we know, communication interception between a mobile phone and a legitimate cell tower is <strong>only possible in GSM</strong> (as opposed to later 3G or 4G protocols). There are two reasons for this:</p>
<ol>
<li>Communicating over GSM doesn’t always require encryption.</li>
<li>Even when encryption is enabled, several of the cryptographic algorithms used in GSM can be broken (and in real time).</li>
</ol>
<p>Imagine that the CSS is trying to launch an active attack where it intercepts a phone’s communications. The CSS must be able to situate itself between the phone and the tower to be able to do so, which is what’s usually referred to as a “machine in the middle” (MitM) attack.</p>
<p>There are two main steps to completing the MitM:</p>
<ol>
<li>Spoofing authentication: the CSS needs to convince the network that it’s actually the targeted mobile phone. (Section 3.2.1)</li>
<li>Deal with any encryption the network tries to set (i.e. disable it or try to break it). (Section 3.2.2)</li>
</ol>
<h4><a id="Spoofing"></a>Section 3.2.1: Spoofing authentication</h4>
<p>Picking up from Section 3.1 where the CSS has already obtained a phone’s IMSI via an Identity Request:</p>
<ol>
<li>The CSS reaches out to a legitimate cell tower with a Location Update Request. This type of request is used to update the cell network about a phone’s location (specifically, its LAC), which the phone needs to do periodically in order for the network to be able to route calls and messages to it quickly.</li>
<li>In response to the Location Update Request, the cell network asks the CSS to identify itself using an Identity Request. The CSS responds using the stolen IMSI.</li>
<li>At this point the tower responds with a cryptographic challenge that requires the secret key Ki (stored on the SIM card) to solve. Since the CSS doesn’t have access to Ki, it passes it onto the phone to solve. The phone solves the challenge, passes it to the CSS, who then passes it back to the network.</li>
<li>After this, the network accepts the connection between it and the CSS as being authenticated.</li>
</ol>
<p>Reminder: this is only applicable to 2G.</p>
<p>&nbsp;</p>
<div class="caption caption-center">
<div class="caption-width-container">
<div class="caption-inner">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21362" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers.png" alt="" width="1999" height="730" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers.png 1999w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers-400x146.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers-1024x374.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers-768x280.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image2imsicatchers-1536x561.png 1536w" sizes="(max-width: 1999px) 100vw, 1999px" /></p>
<p class="caption-text">An illustration of steps 1-4 from above on how the CSS is able to complete the authentication MitM.</p>
</div>
</div>
</div>
<h4><a id="Encryption"></a>Section 3.2.2: Dealing with encryption</h4>
<p>There are several encryption algorithms used in GSM, and at a high level, they have names like: A5/1, A5/2, etc &#8230; with A5/0 being used to indicate that no encryption is being used.</p>
<p>If the network tries to specify that it wants to communicate using encryption, the CSS can just respond by saying it doesn’t have encryption capabilities and defaults to A5/0. The CSS has now completed the MitM attack and can read the plaintext messages being sent between the phone and the real network.</p>
<p>Alternatively, if the network decides to use the A5/1 algorithm to communicate, this type of encryption can be broken in real time. The details of this attack are beyond the scope of this post, but you can read about it in the Barkan et al 2006 paper. Additionally, the A5/2 algorithm is so weak that its use <a href="https://en.wikipedia.org/wiki/A5/2">has been banned since 2006</a>. While there are <a href="https://en.wikipedia.org/wiki/KASUMI#Cryptanalysis">known attacks against A5/3</a>, there are no known real-time attacks.</p>
<h4><a id="UserAlert"></a>Section 3.2.3: Why aren’t users alerted that encryption is off?</h4>
<p>At this point, many people ask: why doesn’t their phone tell them something’s up? According to the GSM specifications, cell phone users are supposed to be notified when encryption is disabled, and in some markets they used to be. However, this caused a lot of confusion because:</p>
<ol>
<li>People would travel with their phones to places where cell towers were configured very differently (e.g. in some countries cell network encryption is banned) and it would cause a “Warning: encryption disabled” pop-up to come up a lot.</li>
<li>Cell towers everywhere were misconfigured, also causing this pop-up to appear a lot.</li>
</ol>
<p>These issues led to many confused consumers and support calls to mobile carriers, resulting in the warning ultimately being disabled.</p>
<h4><a id="ServiceDowngrading"></a>Section 3.2.4: Service downgrading</h4>
<p>Even though, as far as we know, communication interception is only possible in GSM, it’s trivial to downgrade a target cell phone’s connection from 3G or 4G to GSM (see Section 3.5 for more information). This is because in general the base station gets to pick whatever configuration settings it wants, which includes the ability to request a protocol downgrade. Alternatively, someone could jam the 3G or 4G bands by pumping lots of white noise into them, making it too noisy to establish a connection, and phones will downgrade in search of a usable signal. LTE service downgrading is covered in detail at the end of Section 3.5.</p>
<h3><a id="LTECSS"></a>Section 3.3: LTE CSS connection techniques</h3>
<p>It’s also important to understand how it’s possible for a CSS to get around the safeguards in LTE and other modern protocols that are meant to stop phones from connecting to any base station with a high enough power.</p>
<p>In GSM, phones are always scanning looking for a tower with a higher signal strength to connect to. However, in LTE if the signal strength is above a certain sufficient threshold, the phone will not scan for other towers to connect to in order to save power.</p>
<p>Additionally, in LTE phones keep track of a “nearest neighbors” list that is broadcast from the tower that they are connected to. If for any reason they lose the connection with the tower they’re connected to (or the ability to connect to it), they’ll try to connect to ones that were advertised in the nearest neighbors list first, before doing a full scan of the available LTE bands for other eligible cell towers.</p>
<p>So, how can an attacker force a phone using LTE into connecting to their CSS? One technique would be to masquerade as a tower in the nearest neighbor’s list (e.g. same frequency, same cell id, etc &#8230;) and transmit at a higher power, so the phone will eventually switch over.</p>
<p>But there is a faster technique! It relies on the fact that LTE frequencies are assigned various priorities (this is referred to as “absolute priority based cell reselection”), and if a phone sees that there is a base station operating on a higher priority frequency than the one it’s on, it must switch to it, regardless of its signal strength. To discover the higher priority frequencies used in a given area, all that’s required is to extract them from the unencrypted configuration messages from base stations, which anyone can monitor (Shaik et al, 2017).</p>
<p>Using these techniques, attackers can probably force even an LTE phone to connect to their CSS, which reveals the phone’s IMSI and allows followup attacks.</p>
<h3><a id="TrackingAttacks"></a>Section 3.4: Location tracking attacks</h3>
<p>Often when the dangers of CSSs are being discussed, the focus is on their communication interception ability. However, in practice the consequences of real time location tracking <a href="https://www.eff.org/deeplinks/2017/05/no-hunting-undocumented-immigrants-stingrays">are often much more severe</a>. The potential for location tracking by your cell provider is unavoidable, so the specific threat model being used here is a 3rd party (such as a law enforcement agency) trying to get your location without cooperation from your cell provider.</p>
<p>There are generally two types of location tracking that CSSs are capable of:</p>
<ol>
<li><strong>Presence testing:</strong> check if a phone is present in or absent from a geographic area (where geographic area usually means a “Location Area” from before, i.e. a group of cells)</li>
<li><strong>Fine-grained location:</strong> figure out the exact or rough GPS coordinates of a phone either through trilateration or by getting the phone to tell the attacker its exact GPS coordinates</li>
</ol>
<h4><a id="PresenceTesting"></a>Section 3.4.1: Presence Testing in LTE</h4>
<p><strong><em>Passive Presence Testing</em></strong></p>
<p>The simplest way to do presence testing in LTE doesn’t actually require someone to have what we usually consider a CSS (e.g. a device that pretends to be a legitimate cell tower). Instead, all that’s required is simple radio equipment to scan the LTE frequencies, e.g. an antenna, an SDR (Software Defined Radio), and a laptop. Passive presence testing gets its name because the attacker doesn’t actually need to do anything other than scan for readily available signals (Shaik et al, 2017).</p>
<p>A fundamental aspect of wireless technology is the paging model. When the network has a message it wants to route to a phone, it sends an “RRC paging message” which is received by every phone listening to their carrier’s paging frequency in that area (which is basically every phone),<sup id="fnref5"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn5" rel="footnote">5</a></sup> asking for that particular phone to contact the base station to negotiate completing a connection to receive a call or message. Thus, phones are constantly listening for RRC paging messages and receiving and discarding ones not addressed to them.</p>
<p>RRC is short for Radio Resource Control, which is the protocol used to communicate between a cell phone and a base station. The RRC takes care of connection establishment and paging notifications that you’re getting a message or phone call, among other things.</p>
<p>The exact way paging works varies based on several factors, including the type of message the network is trying to route to you. For example, say the network is trying to route a phone call to you. Phone calls are considered high priority (since there’s someone on the other side waiting for you to connect), so the network notifies every cell tower in the last Location Area your phone was in to send out the RRC paging message addressed to your phone (as opposed to only the last cell tower the phone was using). More on this later!</p>
<p>RRC paging messages are usually addressed to a TMSI, but sometimes IMSI and IMEI are also used. By monitoring these unencrypted paging channels, anyone can record the IMSIs and TMSIs the network believes is in a given area. In the next section, we’ll see how an attacker can correlate a TMSI to a specific target phone, as right now collecting TMSIs simply means recording pseudonyms.</p>
<p>Additionally, phones periodically transmit unencrypted messages about their location and measurements of cell service quality that anyone with the right equipment can easily intercept. Sometimes these messages contain the phone’s exact GPS location, but usually the information about the signal strength of nearby cells is enough to calculate the phone’s location. We’ll look at these measurement reports in detail in the Exact GPS Coordinates section below.</p>
<p><strong><em>Semi-Passive Presence Testing</em></strong></p>
<p>Semi-passive means that the attacker only uses network functions in ways in which they are meant to be used. An example of what it means for an adversary to be “semi-passive”: the attacker can text the person they’re trying to track (assuming they know their phone number) in order to generate a paging message being sent to their phone, but they can’t go and send malicious or malformed data to phones or towers in the area (Shaik et al, 2017).</p>
<p>In this section, we are going to cover two location attacks: one which checks for a phone in a given Location Area (“Basic Location Area Test”), and one which checks for a phone connected to a specific cell tower (the “Smart Paging Test” method, which has a much smaller radius of use).</p>
<p><strong><em>Basic Location Area Test</em></strong></p>
<p>The first step of a basic Location Area test is to trigger about 10-20 notifications to the target’s phone via phone calls while also monitoring the RRC paging messages that are sent out. To not alert the user, the attacker can almost immediately hang up after initiating the call so that the paging message makes it to the phone, but the user doesn’t actually get an incoming call notification.</p>
<p>Because there’s someone waiting on the other line to connect to you, phone calls are considered higher priority, so the network notifies every cell tower in the last Location Area the phone was in to send out the RRC paging message (as opposed to only the last cell tower the phone was using). The attacker can then use set intersection analysis (explained in <sup id="fnref6"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn6" rel="footnote">6</a></sup>) with their well-timed calls to figure out the target’s TMSI from the RRC messages.</p>
<p>&nbsp;</p>
<div class="caption caption-center">
<div class="caption-width-container">
<div class="caption-inner">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21360" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers.png" alt="" width="1999" height="1000" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers.png 1999w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image7imsicatchers-1536x768.png 1536w" sizes="(max-width: 1999px) 100vw, 1999px" /></p>
<p class="caption-text">CSS triggering many RRC paging requests to determine if a phone is in a given LA.</p>
</div>
</div>
</div>
<p><strong><em>Smart Paging Test</em></strong></p>
<p>Usually the radius of a Location Area is quite large, so from here the attacker can use something referred to as “smart paging” (explained below) to figure out the exact cell tower the target is using (which translates to knowing the user’s location within a ~2 km radius) (Shaik et al, 2017).</p>
<p>Because general data messages (e.g. WhatsApp and FB Messenger messages) are not high priority, the network initially only broadcasts paging messages for them from the last tower the phone was known to be connected to (this is referred to as “smart paging”). Thus, once the attacker has confirmed the target’s location in a TA (“Tracking Area”), they can test various cells to find the target’s cell. (Note: we’re switching briefly from the “Location Area” terminology to “Tracking Area” here for the sake of a concept covered below.) Similar to before, they send timed WhatsApp or FB Messenger messages and use set intersection analysis to verify the TMSIs being sent in RRC messages in that cell.<sup id="fnref7"><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fn7" rel="footnote">7</a></sup></p>
<p>Note that in order for this to work, the attacker needs to either have equipment in every cell (which is expensive), or move about through cells repeating this procedure until they get a match.</p>
<h4><strong><a id="ActiveLocationTracking"></a>Section 3.4.2: Active location tracking and exact GPS coordinates</strong></h4>
<p>In this section, the attacker’s assumed goal is to find the target’s exact or rough GPS coordinates. In this section, we’ll be describing active attacks, meaning ones in which the attacker can use any means available to them to figure out their target’s information, including operating a CSS and sending malicious or false information to the phone or other cell towers.</p>
<p>In this scenario, suppose the attacker has a CSS and they’ve managed to lure their target into trying to connect using techniques described in Section 3.3. After completing the initial connection procedure steps, the phone enters into a CONNECTED state.</p>
<p>Now the attacker creates a “RRC Connection Reconfiguration” command, which contains the cell IDs of at least 3 neighbouring cell towers and their connection frequencies and sends this command to their target’s phone.</p>
<p>Usually, the “RRC Connection Reconfiguration” command is used to modify an existing connection to a base station, but the attacker is only interested in the target phone’s initial response to its message. This response contains the signal strengths of the previously specified cell towers, which can then be used to find the phone’s location via trilateration:</p>
<p>&nbsp;</p>
<div class="caption caption-center">
<div class="caption-width-container">
<div class="caption-inner">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21359" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised.png" alt="" width="2400" height="1200" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised.png 2400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised-1536x768.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/trilateration-revised-2048x1024.png 2048w" sizes="(max-width: 2400px) 100vw, 2400px" /></p>
<p class="caption-text">In short, trilateration involves calculating the intersection of circles drawn around the previously specified cell towers, where the radius of each circle is a function of the reported signal strength. Note: trilateration is different than triangulation.</p>
</div>
</div>
</div>
<p>For newer phones and networks which support the “locationInfo-r10” feature, this report will also contain the phone’s exact GPS coordinates, meaning no trilateration calculations are required. The exact GPS coordinates are just a field in the response (Shaik et al, 2017).</p>
<p>In addition to the technique described above, there is another way to get similar trilateration and GPS data by using RLF (“Radio Link Failure”) reports, but we will not cover it in any detail as it’s similar to the techniques just covered.</p>
<h3><a id="DoSDowngrading"></a>Section 3.5: Denial of Service and Downgrading</h3>
<p>Cell network denial of service and protocol downgrade attacks are possible (and can have quite similar implementation details, as we’ll see below). Additionally, downgrade attacks make it such that a target phone can be forced down to a less secure protocol, where more severe privacy invasive attacks can be launched.</p>
<h4><a id="ProtocolDowngrade"></a>Section 3.5.1: Protocol downgrade attacks</h4>
<p>Suppose that the attacker has set up their CSS and tricked the target into trying to connect (which was covered in Section 3.3). After the initial connection procedure, the phone will send a “Tracking Area Update Request” (“TAU” for short). This kind of message is used by the phone to keep the cell network updated about the phone’s most recent location, so that the network can route calls to it faster. TAU Requests are usually sent by phones whenever they’re connecting to a new base station.</p>
<p>The CSS responds with a “TAU Reject” message. Within the Reject message is something referred to as the “EMM cause numbers”, which indicates why the message was rejected. In this case, the attacker sets it to 7 (“LTE services not allowed”).</p>
<p>Upon receiving this EMM value, the phone deletes all information it had about the previous real network it was connected to, and then puts itself in a state where it considers its SIM card to be invalid for LTE. It then searches for 3G and GSM networks to connect to, and will not again try to negotiate an LTE connection until it is rebooted (Shaik et al, 2017).</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21358" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers.png" alt="" width="1999" height="1000" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers.png 1999w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers-400x200.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers-1024x512.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers-768x384.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/image6imsicatchers-1536x768.png 1536w" sizes="(max-width: 1999px) 100vw, 1999px" /></p>
<p>The key reason why protocol downgrade attacks are so bad is that it renders LTE-capable phones vulnerable to attacks that normally only work on earlier protocols (e.g. the communication interception from Section 3.2).</p>
<h4><a id="DoS"></a>Section 3.5.2: Denial of Service (DoS)</h4>
<p>If the attacker is looking to launch a large scale DoS attack, the simplest thing is to jam the LTE frequencies by pumping them full of white noise. However, there are also techniques for DoS attacks that only target individual phones.</p>
<p>Launching a denial of service attack against an individual phone is exactly the same as the protocol downgrade attack described above, except the CSS responds with EMM cause number 8 (“LTE and non-LTE services not allowed”). The phone then puts itself in a state where it does not try to negotiate any network connections until it’s been rebooted.</p>
<p>Additionally, there has been some research done into denying select network services (e.g. only allowing SMS, and disallowing calls and data), but for the sake of space we will not be covering this. Please see Shaik et al, 2017 below for details.</p>
<h2><a id="Detection"></a>Section 4: Detection methods &amp; apps</h2>
<p>At this point you’re probably wondering:</p>
<ul>
<li>Are there ways to detect CSSs?</li>
<li>How to defend oneself from a CSS?</li>
<li>What led to these vulnerabilities in the cell networks and what do we do about them?</li>
</ul>
<p>These are three questions we’re going to explore in this section, and unfortunately they don’t have simple answers.</p>
<h3><a id="Methods"></a>Section 4.1: Detection methods</h3>
<p>To reiterate an important truth from before: a fundamental problem when researching detection methods is that <strong>we don’t know how commercial CSSs work</strong>. Instead we rely on how we think they might work based on research findings. It’s important to keep this in mind when going over some of the known detection methods below. This following list is not exhaustive, and instead is meant to be an introduction to this topic.</p>
<p><strong>Unusual base station parameters or fingerprints</strong></p>
<ul>
<li>There’s been some speculation that commercial CSSs mask themselves as cell towers that are normally in the area, but with some configuration parameters or characteristics being subtly off (e.g. broadcast power is suddenly much higher), enough so that the “fingerprint” of the tower is different. While configuration parameters and other characteristics differ across network operators, they’re usually uniform across a specific operator (Dabrowski et al, 2014).</li>
</ul>
<p><strong>Missing normal base station capabilities</strong></p>
<ul>
<li>It’s unlikely that a CSS manufacturer will have implemented the full set of capabilities of a normal base station. Missing capabilities, such as not broadcasting certain standard System Information Broadcast (SIB) messages, being unable to respond to certain standard requests, or there being very little to no paging traffic coming from the base station might be indicators of a CSS (Dabrowski et al, 2014).</li>
</ul>
<p><strong>Ephemerality</strong></p>
<ul>
<li>It’s generally believed that CSSs don’t stay in a single place for a significant period of time, and so a base station appearing for only a short period of time could be worth investigating. However, there are also many completely normal reasons why something would only appear for a short period of time. For example, it could simply be testing equipment, or if there’s a large event happening, it could be there to help facilitate the increased traffic load.</li>
</ul>
<p>The cell landscape is ever changing. Large scale and long term data collection is the best way to survey an area to be able to determine what’s normal versus what’s unusual. The <a href="https://seaglass.cs.washington.edu/">University of Washington’s Sea Glass project</a> is a great example of this.</p>
<p>You can read much more about this topic in Dabrowski et al’s IMSI-Catch Me If You Can: IMSI-Catcher-Catchers. To reiterate, while these could be indicators that something’s amiss, there are also many completely normal reasons (that have nothing to do with surveillance) as to why we’d be seeing unusual behaviour. E.g. testing equipment, temporary equipment brought in for a large event (e.g. at a sporting event), a cell tower crashed and upon restarting broadcasts temporarily incorrect values until it’s completely finished restarting, and so on.</p>
<h3><a id="Apps"></a>Section 4.2: Detection apps</h3>
<p>Many apps have been released that claim to alert users when it seems likely they’re connected to a CSS. The most popular ones include: <a href="https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki">Android IMSI-Catcher Detector (AIMSICD)</a>, <a href="https://opensource.srlabs.de/projects/snoopsnitch">SnoopSnitch</a>, <a href="https://sitch.io/">Sitch</a>, <a href="https://play.google.com/store/apps/details?id=kz.galan.antispy">GSM Spy Finder</a>, <a href="https://play.google.com/store/apps/details?id=com.skibapps.cellspycatcher&amp;hl=en_US">Cell Spy Catcher</a>. The quality of these apps varies, and some are still popular despite no longer being maintained.</p>
<p>Most of these apps implement at least some of the detection methods listed above and in Dabrowski et al. Even though sometimes multiple apps will have implemented the same detection methods, they won’t necessarily produce the same result when evaluating if a particular base station is suspicious or not (Borgaonkar et al, 2017). Let’s look at some examples of how detection apps have failed to include basic detection heuristics, as well as how there could be discrepancies in the evaluations they produce.</p>
<p><em>Varying power levels</em></p>
<p>One of the previously described detection methods is to track if a tower you’ve seen before suddenly broadcasts at much higher power. In Borgaonkar et al’s <em>White-Stingray: Evaluating IMSI Catchers Detection Applications</em>, researchers analyzed four of the previously mentioned apps and found that while most of them stored regular measurements of BTS power levels, none of them compared new values to historical values. This means that none of the apps could detect when towers had an unusually high broadcast power.</p>
<p><strong><em>LAC change</em></strong></p>
<p>As we saw in Section 3.2.1, when phones move to a new Location Area (or when they’re in the process of connecting to a base station that’s advertising as having a different LAC), they’ll need to update their information. As a result, they’ll eventually respond to an <em>Identity Request</em> (the command that reveals a phone’s IMSI). It’s generally believed that CSSs advertise as having a different LAC than the one that corresponds to the area they’re in, allowing them to exploit this mechanism to force phones to hand over their IMSIs or connect to them.</p>
<p>All previously mentioned detection apps monitor for LAC changes. As Borgaonkar et al point out, one of them checks to see if the LAC matches that of neighbouring base stations, and displays a warning to the user when it’s close to the edge of an LA. Since LAC changes are common when the user is near the edge of a LA, these warnings are often false positives. Another app stores all LACs the phone has seen before, and sends out warnings whenever a new one appears, meaning false positive warnings are constantly sent out when the user travels to new places. Another app defaults to marking anything broadcasting a LAC value between 0-9 as suspicious. This is an example of how even though all the detection apps have heuristics for detecting if a base station is suspicious based on a determination that a required value (the LAC) is unusual, their interpretations of how to do this and their implementations vary so much that they produce different results.</p>
<p>Because we don’t have global standards for what’s normal, and because things vary so wildly by country, carrier, etc, it’s difficult to come up with heuristics that could universally work for detecting CSSs. As a result, the apps that have attempted to tackle this problem so far have ended up having dramatically different thresholds for alerts.</p>
<h3><a id="Defending"></a><strong>Section 4.3: Defending against CSSs</strong></h3>
<p>CSSs have such a wide range of capabilities (based on what we know about possible cell network attacks they could be based on) that there is no feasible way to defend against all of the things they can do. Defense should begin by considering what someone’s specific threat model is and coming up with ways to defend after that.</p>
<p><strong><em>Examples</em></strong></p>
<p>At the time of writing, there are no publicly known confirmed examples of CSSs being used by law enforcement for communication interception or service denial. However, there are <a href="https://www.detroitnews.com/story/news/local/detroit-city/2017/05/18/cell-snooping-fbi-immigrant/101859616/">quite</a> <a href="http://cnsmaryland.org/interactives/spring-2016/maryland-police-cell-phone-trackers/index.html">a few</a> <a href="https://shadowproof.com/2019/05/08/detroit-police-spent-more-than-half-million-dollars-on-cell-site-simulator-to-track-peoples-locations/">examples</a> of CSSs being used for location tracking.</p>
<p>Since the main threat CSSs pose is that of real time location tracking, and there are no adjustable user settings one can change to affect this, there are currently no immediate steps one can take to defend themselves against these devices, other than either not having a cell phone, (which isn’t a reasonable option for many of us) or turning off and/or leaving behind your phone when doing something important.</p>
<p>Despite that, there are many steps you can take to defend against online surveillance, many of which we’ve outlined in EFF’s <a href="https://ssd.eff.org/">Surveillance Self Defense Guide</a>.</p>
<h2><a id="Conclusion"></a>Conclusion: the past &amp; future of cell network security</h2>
<p>The intersection of cell networks, security, and user privacy has historically not been an accessible field, but that’s slowly changing. Each year there is more research in this field being published and open source projects (such as <a href="https://github.com/srsLTE/srsLTE">srsLTE</a>) that enable this research are improving dramatically—and more people are starting to question why more work isn’t being done to fix these issues.</p>
<p>Cell network security <a href="https://www.nytimes.com/2018/12/26/opinion/cellphones-security-spying.html">is broken in some pretty fundamental ways</a>. It’s up to all of us over the next few years to demand lawmakers pay closer attention to the issue, and to put pressure on standards groups, carriers, network operators, and vendors to make necessary improvements. Together, we can protect and defend users’ privacy.</p>
<h2><a id="References"></a>References</h2>
<p><em>IMSI-Catch Me If You Can: IMSI-Catcher-Catchers.</em> Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, Edgar Weippl. <a href="https://www.sba-research.org/wp-content/uploads/publications/DabrowskiEtAl-IMSI-Catcher-Catcher-ACSAC2014.pdf">https://www.sba-research.org/wp-content/uploads/publications/DabrowskiEtAl-IMSI-Catcher-Catcher-ACSAC2014.pdf </a>(Dabrowski et al, 2014)</p>
<p><em>IMSI Catcher Detection Apps Might Not Be All That Good, Research Suggests.</em> Joseph Cox. <a href="https://www.vice.com/en_us/article/neeb5g/stingray-detection-apps-might-not-be-all-that-good-research-suggests">https://www.vice.com/en_us/article/neeb5g/stingray-detection-apps-might-not-be-all-that-good-research-suggests</a></p>
<p><em>Instant Ciphertext-Only Cryptanalysis of GSM Encrypted Communication</em>. Elad Barkan, Eli Biham, Nathan Keller. <a href="http://www.cs.technion.ac.il/users/wwwb/cgi-bin/tr-get.cgi/2006/CS/CS-2006-07.pdf">http://www.cs.technion.ac.il/users/wwwb/cgi-bin/tr-get.cgi/2006/CS/CS-2006-07.pdf </a>(Barkan et al, 2006)</p>
<p><em>Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems.</em> Altaf Shaik, Ravishankar Borgaonkar, N. Asokan, Valtteri Niemi§and Jean-Pierre Seifert. <a href="https://arxiv.org/pdf/1510.07563.pdf">https://arxiv.org/pdf/1510.07563.pdf </a>(Shaik et al, 2017)</p>
<p><em>Practical Cellphone Spying</em>. Kristen Paget. Defcon 18. <a href="https://www.youtube.com/watch?v=fQSu9cBaojc">https://www.youtube.com/watch?v=fQSu9cBaojc </a>(Paget, 2010)</p>
<p><em>White-Stingray: Evaluating IMSI Catchers Detection Applications.</em> Ravishankar Borgaonkar, Andrew Martin, Shinjo Park, Altaf Shaik, Jean-Pierre Seifert. <a href="https://ora.ox.ac.uk/objects/uuid:15738ed0-c144-49e9-a4fa-466362cf7754">https://ora.ox.ac.uk/objects/uuid:15738ed0-c144-49e9-a4fa-466362cf7754 </a>(Borgaonkar et al, 2017)</p>
<h2>Notes</h2>
<ol>
<li id="fn1">The name “3GPP” is confusing since it contains “3G”. While they didn’t exist when GSM (a 2G technology) was originally being developed, they did later absorb some of the organizations that were responsible for developing GSM. It is still one of the main organizations that develops and maintains existing and future protocols. <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref1" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn2">Unfortunately, most phones usually don’t have an ability to specify connection settings. Recently some phones have begun to implement features like “use LTE only” though. <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref2" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn3">Unfortunately, most phones usually don’t have an ability to specify connection settings. Recently some phones have begun to implement features like “use LTE only” though. <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref3" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn4">According to the Department of Justice, some CSSs can directly collect a subscriber’s phone number, meaning LE can skip the step of subpoenaing a service provider to obtain the subscriber’s phone number. See page 6 of https://www.eff.org/files/2015/11/30/illinois.dist_.ct_.stingrays.pdf. <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref4" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn5">Generally, the network will first direct the message to the last known cell tower the phone was connected to, and that tower will send out a paging message to everyone listening on its paging frequency. If it doesn’t get a response, then it will spread out and try all the towers in a given Location Area, and so on. The exact details of how this works varies by type of data being routed (e.g. SMS vs phone call vs LTE data message) and by carrier. <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref5" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn6">Basically, you compare the paging identities in the RRC messages sent out after each short call you initiate, and extract the value(s) that are repeated the number of times you placed calls. You can read a much more here in the R<em>evealing Identities</em> section here: <a href="https://www-users.cs.umn.edu/~hoppernj/celluloc.pdf">https://www-users.cs.umn.edu/~hoppernj/celluloc.pdf</a> <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref6" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
<li id="fn7">Note that Facebook messages have the advantage of not needing to know your target’s phone number to be able to trigger a notification being sent to their phone! (The attacker doesn’t need to be Facebook friends with their target either, as Facebook Messenger messages sent to strangers end up in the ‘Other’ folder, but still trigger LTE push notifications that aren’t displayed to the user.) <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#fnref7" rev="footnote"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/21a9.png" alt="↩" class="wp-smiley" style="height: 1em; max-height: 1em;" /></a></li>
</ol>
</div>
</div>
</div>
</div>
</article>
</div>
<div class="panel-pane pane-entity-field pane-node-field-attachments">
<h2 class="pane-title">Downloads</h2>
<div class="field field--name-field-attachments field--type-file field--label-hidden">
<div class="field__items">
<div class="field__item even"><span class="file"><img decoding="async" class="file-icon" title="application/pdf" src="https://www.eff.org/modules/file/icons/application-pdf.png" alt="PDF icon" /> <a title="whitepaper_imsicatchers_eff.pdf" href="https://www.eff.org/files/2019/07/09/whitepaper_imsicatchers_eff_0.pdf" type="application/pdf; length=999909">Gotta Catch &#8216;Em All</a></span></div>
</div>
</div>
</div>
<p><a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks" target="_blank" rel="noopener">source</a></p>
<hr />
<div class="editor-content title-wrap">
<h1 class="h1 ">Understanding and Detecting IMSI Catchers around the World</h1>
</div>
<p>One of the good things about working in the area of core network security, is the opportunity to find new and unexpected types of attacks. These are attacks you didn’t even know could happen, much less have a chance to prevent. Finding these unexpected attacks doesn’t just happen though, it requires experience and investigation, but most importantly it needs the mindset to dig deeper into any strange events that are encountered, and try to understand them, rather than just assuming they are random malicious events.</p>
<p>In this particular case, we are discussing IMSI Catchers. First off, the term IMSI catcher is a misused and sometimes contradictory term however. As explained <a href="https://www.eff.org/pages/cell-site-simulatorsimsi-catchers" target="_blank" rel="noopener">here</a>, there are actually 2 types of equipment that those in the public (and many in the industry) would conflate into what they would call IMSI catchers.</p>
<ul>
<li>‘Active’ IMSI Catchers, also termed Cell Site Simulators (CSS) or Fake Base Stations – these attempt to force local devices to connect to a Call Site Simulator, in order to decrypt the conversation and texts, and to execute man in the middle interception. These would be considered the more ‘traditional’ type of IMSI catchers most would be aware of. Stingrays are also a common term used for these (named after the brand built by Harris Corporation). A good overview of how the Active IMSI /Cell Site Simulators work is <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks" target="_blank" rel="noopener">here</a>.</li>
<li>Passive IMSI Catchers – these passively listen into the paging of mobile devices as they move and register to new real Cell towers in the local area, in order to get the IMSI numbers of these devices. They are far less precise, and are unable to do any of the more sophisticated type of interception, but involve no interaction between the mobile device and the IMSI Catcher. An overview of how these could work, and how they function is <a href="https://harrisonsand.com/posts/imsi-catcher/" target="_blank" rel="noopener">here</a>.</li>
</ul>
<picture class="wp-image-82879 aligncenter"><source srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png.webp 932w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-300x100.png.webp 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-768x257.png.webp 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-546x183.png.webp 546w" type="image/webp" sizes="(max-width: 800px) 100vw, 800px" data-lazy-srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png.webp 932w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-300x100.png.webp 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-768x257.png.webp 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-546x183.png.webp 546w" /><img loading="lazy" decoding="async" class="entered lazyloaded" src="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png" sizes="(max-width: 800px) 100vw, 800px" srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png 932w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-300x100.png 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-768x257.png 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-546x183.png 546w" alt="two diagrams showing the difference between active IMSI Catcher and Passive IMSI Catcher" width="800" height="268" data-lazy-srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png 932w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-300x100.png 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-768x257.png 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1-546x183.png 546w" data-lazy-sizes="(max-width: 800px) 100vw, 800px" data-lazy-src="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_1.png" data-ll-status="loaded" /></picture>
<p>The primary difference between these two is that the more traditional Active IMSI Catcher/CSSs always involves some form of interaction with the mobile device, whereas the Passive IMSI Catcher doesn’t – it literally just listens in to the paging that occurs in the local areas as the mobile device changes between legitimate cell towers in the vicinity. This makes a big difference when it comes to detection of these IMSI Catcher types.</p>
<p>A lot of research has gone into various ways of detecting Active IMSI Catchers, by looking at how they differ from real Cell towers. One distinctive example of what an Active IMSI Catcher might do is the forced downgrading of their target mobile device to use a less secure radio interface. This detection of an Active IMSI Catchers can be difficult, involves a lot of local measurements and often can and has in the past led to false positives, but it gives some results. From the attacker’s perspective it’s also a trade-off in that they must make the effort to physically deploy an Active IMSI Catchers in a sensitive area, and then hope its radio activity doesn’t give it away. This is often why more sophisticated attackers may often resort to using attacks over signalling interfaces such as SS7 and Diameter to achieve their aims, which can be sent from any part of the world.</p>
<p>A Passive IMSI Catcher changes things somewhat. It still involves physical deployment of a system to listen in the local targeted area, but it is essentially undetectable on the radio interface, as it emits nothing that would allow it to be detected. This makes it very valuable to perform long-term surveillance in sensitive areas, when the goal is to have the least chance of being detected, while still trying to determine the IMSIs of who is in the local area.</p>
<p>The issue with both types of IMSI Catchers, from the attacker’s perspective, is that what they are left with are a collection of IMSIs from around the world. While this information may be useful, often you need more information to profile who has been ‘caught’. For Active IMSI Catcher deployments; the attackers may also intercept calls/text messages etc, so have a better idea of the target, but for passive IMSI catchers they won’t have that. What the attackers really need is the co-corresponding phone number – the MSISDN of the mobile device associated with the IMSI – in order to truly figure out the identities of the mobile device their IMSI catcher has caught.</p>
<p>This is where our analysis and investigation has come in. Over time, we have been seeing patterns of unusual requests over the SS7 interface, for particular IMSIs. Specifically, what we have been seeing is our Signalling Firewalls, deployed at multiple customer mobile operators, receiving suspicious MAP_RESTORE_DATA packets for IMSIs from unexpected sources. A MAP_RESTORE_DATA packet is a particular command that requests that the home operator sends details for a particular IMSI to the roamed-to network. Details in this case includes MSISDN (the actual phone number), call forwarding setting and other specific information. Further investigation showed that we always received this command when these IMSIs were near or attached to specific Cell Sites while roaming in a 3rd country and nowhere else.</p>
<picture class="wp-image-82881 aligncenter"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21343" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/IMSI_Catcher_sequence_wide-1536x662.png.webp" alt="" width="1536" height="662" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/IMSI_Catcher_sequence_wide-1536x662.png.webp 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/IMSI_Catcher_sequence_wide-1536x662.png-400x172.webp 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/IMSI_Catcher_sequence_wide-1536x662.png-1024x441.webp 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/IMSI_Catcher_sequence_wide-1536x662.png-768x331.webp 768w" sizes="(max-width: 1536px) 100vw, 1536px" /></picture> <picture class="wp-image-82881 aligncenter"><source srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide.png.webp 1985w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-300x129.png.webp 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1024x441.png.webp 1024w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-768x331.png.webp 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1536x662.png.webp 1536w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-546x235.png.webp 546w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1060x457.png.webp 1060w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1002x432.png.webp 1002w" type="image/webp" sizes="(max-width: 800px) 100vw, 800px" data-lazy-srcset="https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide.png.webp 1985w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-300x129.png.webp 300w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1024x441.png.webp 1024w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-768x331.png.webp 768w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1536x662.png.webp 1536w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-546x235.png.webp 546w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1060x457.png.webp 1060w, https://www.enea.com/wp-content/uploads/2023/06/IMSI_Catcher_sequence_wide-1002x432.png.webp 1002w" /></picture>
<p>Our working theory, is that what we are observing is what we now call “<strong>IMSI Profilers</strong>”. These IMSI Profilers work in conjunction with IMSI Catchers – they take the list of IMSIs that have been detected and request profile information, in order to feed these phone numbers back to the IMSI catcher operator. The sequence of events that we believe to happen is shown above. From log analysis it also seems likely (but can’t be confirmed 100%) that the IMSI Catcher in the 3rd country is of the passive variety. In this particular case, the IMSI Profiler is using a source SS7 address (called a SCCP Global Title or GT) in a small European mobile operator that we have detected previously in our SIGIL/Signalling Intelligence system to be used by multiple surveillance companies, further confirming our suspicion that it is malicious.</p>
<p>Regardless of the IMSI catcher type used, this method of analysing incoming suspicious signalling activity gives the opportunity for mobile operators to partially protect their subscribers against IMSI Catchers around the world, something they didn’t have in the past. It won’t stop an Active IMSI Catcher from forcing a subscriber to connect to them, but it would stop additional information being retrieved. And in the case of passive IMSI catcher it is potentially one of the <strong>only ways</strong> to detect these remotely and block any more useful information being obtained.</p>
<p>In the long term, improvements in the new 5G radio and core network standards means that mobile operators should be able to greatly improve the ability to block IMSI Catchers over 5G. If these are implemented correctly and no loopholes are introduced then effective 5G IMSI Catchers may never arise. In the interim however, IMSI Catchers – both Passive and Active – are being used globally in the world to track and record individuals without their consent. By analysing incoming signalling traffic, and detecting and blocking these IMSI Profilers, mobile operators now have the opportunity to help protect their subscribers globally, regardless of how stealthy the IMSI Catcher is. <a href="https://www.enea.com/insights/adaptive-mobile-imsi-catchers/" target="_blank" rel="noopener">source</a></p>
<hr />
<div class="et_pb_row et_pb_row_1_tb_body">
<div class="et_pb_column et_pb_column_3_5 et_pb_column_3_tb_body et_pb_css_mix_blend_mode_passthrough et-last-child">
<div class="et_pb_module et_pb_post_title et_pb_post_title_0_tb_body et_pb_bg_layout_light et_pb_text_align_left">
<div class="et_pb_title_container">
<h1 class="entry-title">How to Catch an IMSI Catcher</h1>
</div>
</div>
<div class="et_pb_module et_pb_text et_pb_text_1_tb_body article-excerpt et_pb_text_align_left et_pb_bg_layout_light">
<div class="et_pb_text_inner">IMSI catchers, or fake antennas, are a common cell phone surveillance method. The FADe project helped local NGOs in Latin America detect and document these devices.</div>
</div>
<div class="et_pb_module et_pb_text et_pb_text_3_tb_body et_pb_text_align_left et_pb_bg_layout_light">
<div class="et_pb_text_inner"></div>
</div>
</div>
</div>
<div class="et_pb_row et_pb_row_2_tb_body">
<div class="et_pb_column et_pb_column_4_4 et_pb_column_4_tb_body et_pb_css_mix_blend_mode_passthrough et-last-child">
<div class="et_pb_module et_pb_post_content et_pb_post_content_0_tb_body news-body">
<h2 class="wp-block-heading"><strong>Civil Society Needs Help Catching IMSI Catchers </strong></h2>
<p>Law enforcement, criminals, and repressive governments monitor cell phone signals for the purpose of counter-terrorism, espionage, or political persecution. One common surveillance method is the placement of fake antennas—or <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks#BackgroundInfo" target="_blank" rel="noreferrer noopener">IMSI catchers</a>—which imitate legitimate cell towers in order to track individual mobile subscribers, monitor their communications, or even disable their network connections.</p>
<p>In a high-profile example, <a href="https://nomada.gt/pais/la-corrupcion-no-es-normal/espionaje-ilegal-del-gobierno-aqui-esta-la-investigacion-de-nuestro-diario-parte-i/" target="_blank" rel="noreferrer noopener">a Guatemalan investigation revealed</a> large-scale <a href="https://www.eff.org/deeplinks/2018/12/where-government-hack-their-own-people-and-people-fight-back-latin-american" target="_blank" rel="noreferrer noopener">illegal spying</a> targeting “activists, entrepreneurs, politicians, journalists, diplomats, and social leaders.” Many governments engage in similar practices, often <a href="https://privacyinternational.org/strategic-areas/contesting-government-data-and-system-exploitation" target="_blank" rel="noreferrer noopener">without any meaningful oversight</a> or accountability.</p>
<p>The battle against authoritarian or illegal spying demands a range of methodologies—from legal policies and telecommunications regulations to physical interventions like “Faraday bags,” which shield devices in a casing that blocks electromagnetic transmissions. But the fight between eavesdroppers and victims (often human rights defenders) is not an even one. Most civil society organizations lack the equipment or expertise to effectively monitor phone surveillance.</p>
<h2 class="wp-block-heading"><strong>Equipping Civil Society with Resources to Expose Surveillance</strong></h2>
<p>To help Latin American NGOs level the playing field, <a href="http://www.southlighthouse.org/" target="_blank" rel="noreferrer noopener">South Lighthouse</a> created the <a href="http://fadeproject.org/" target="_blank" rel="noreferrer noopener">Fake Antenna Detection project (FADe)</a>, with support from Open Technology Fund’s <a href="https://www.opentech.fund/funds/internet-freedom-fund/" target="_blank" rel="noreferrer noopener">Internet Freedom Fund</a>. The project’s primary focus was detecting and documenting IMSI catchers—surveillance devices that imitate legitimate cell towers in order to track individual mobile subscribers, monitor their communications, or even disable their network connections.</p>
<p>The FADe team provided training, equipment, and other support to enable local partners to scan for IMSI catchers, analyze their findings and, ideally, make use of the results for advocacy. “A fundamental principle of the program has been partnership and capacitation,” says Andrés Schiavi, Executive Director of South Lighthouse.</p>
<p>FADe’s technology coordinator, Carlos Guerra says, “We wanted to open up a discussion for NGOs about how cell technology works and about how it <em>should</em> work to ensure optimal benefits to people’s safety and people’s rights.”</p>
<p>Using methods initially developed by the <a href="https://seaglass.cs.washington.edu/" target="_blank" rel="noreferrer noopener">SEAGLASS</a> project at the University of Washington and the <a href="https://www.eff.org/pages/crocodile-hunter" target="_blank" rel="noreferrer noopener">Electronic Frontier Foundation (EFF)</a>, FADe partners assembled simple sensors using a few off-the-shelf electronics, a smartphone, and a “feature phone” (a basic device resembling an early mobile phone that is usually more affordable and durable than a smartphone). The sensor setup sits in a moving vehicle and collects signal information over several weeks from local cell towers.</p>
<p>By analyzing the resulting data, groups can differentiate between signals consistent with legitimate cell towers and signals showing anomalous behaviors, such as a “tower” that changes locations (see animation below); or only operates during certain times; or uses frequencies or signal parameters not used anywhere else in the network. Another common warning sign is suspicious instructions sent to a device, such as a request to disconnect from all other towers, or a command to downgrade from 3G or 4G to a 2G network, which will make the device more vulnerable to surveillance.</p>
<p><em>A specific cell tower physically moving among different locations is one of the anomalous behaviors that can help identify an IMSI-catcher.</em></p>
<p>But analysis of these signals can be tricky, says Guerra. “There is no cookie-cutter method,” he says. The data is “noisy,” and cell providers configure their towers differently. It takes many days of monitoring to set a baseline that helps distinguish between legitimate and fake antennas.</p>
<p>The FADe team began working with local organizations in 2018. To mitigate technical and security risks, Schiavi says the first FADe partners were drawn from among South Lighthouse’s network of Latin American organizations. But interest grew rapidly, he says, in part because nothing comparable to the FADe/SEAGLASS approach had ever been available to these organizations. From 2019 to 2022, FADe worked with partners in <a href="https://fadeproject.org/?page_id=38" target="_blank" rel="noreferrer noopener">nine different countries</a>, documenting signals from almost 9,000 antennas, catching more than 150 likely IMSI-catchers.</p>
<p>One of FADe’s local partners, a digital security specialist from Nicaragua, says he was familiar with FADe in 2018 when he read the bombshell reports about Guatemalan surveillance. “The media found the police were using an IMSI-catcher,” he says. “We have known about methods like this in Central America, but we never had the evidence. I said, ‘We need to monitor that. I need to bring this to Nicaragua.&#8217;”</p>
<h2 class="wp-block-heading"><strong>Some of the Findings</strong></h2>
<p>The results in Nicaragua revealed <a href="https://fadeproject.org/?project=managua-2g-2" target="_blank" rel="noreferrer noopener">23 antennas around Managua</a> with anomalies that indicated the presence of an IMSI catcher. The local partner (who is remaining anonymous for security reasons) says the findings informed a wider discussion in Nicaragua about telephone eavesdropping. Although it was common knowledge that the government had an “open door” from the national ISP to eavesdrop online, the FADe data drove new public scrutiny and <a href="https://confidencial.digital/english/39-fake-antennas-discovered-monitoring-cell-phones-in-nicaragua/" target="_blank" rel="noreferrer noopener">media coverage</a> about the use of fake antennas.</p>
<p>Among the other FADe sites, <a href="https://www.reuters.com/article/us-mexico-tech-rights-trfn-analysis/birds-on-the-wire-concerns-over-mexico-cell-phone-surveillance-idUSKBN23J2CC/" target="_blank" rel="noreferrer noopener">Mexico</a> and <a href="https://openinternet.global/news/reality-digital-authoritarianism-venezuela" target="_blank" rel="noreferrer noopener">Venezuela</a> recorded an especially high number of fake antennas, as experts from <a href="https://poderlatam.org/" target="_blank" rel="noreferrer noopener">PODER</a> recounted <a href="https://www.washingtonpost.com/es/post-opinion/2020/05/31/datos-y-llamadas-de-celulares-en-riesgo-de-espionaje-por-antenas-falsas-en-america-latina/" target="_blank" rel="noreferrer noopener">in the Washington Post</a> (ES). Data from Caracas, Venezuela, showed <a href="https://fadeproject.org/?project=caracas" target="_blank" rel="noreferrer noopener">33 different devices</a> with irregular readings that could indicate IMSI-catchers. In Buenos Aires, Argentina, out of 1,000 cell towers monitored, <a href="https://fadeproject.org/?project=buenos-aires-2g&amp;lang=es" target="_blank" rel="noreferrer noopener">suspicious patterns</a> were found in 17 antennas, with most concentrated around the downtown and university areas. Notably, the suspicious antennas found in Buenos Aires were all on the 2G network, with no irregularities seen in the <a href="https://fadeproject.org/?project=buenos-aires-4g" target="_blank" rel="noreferrer noopener">smaller group</a> of devices on the 4G network, which is known to be harder to surveil. For summaries of the observations in all locations, see the project’s <a href="https://fadeproject.org/?page_id=38" target="_blank" rel="noreferrer noopener">results section</a>.  <a href="https://www.opentech.fund/news/how-to-catch-an-imsi-catcher/" target="_blank" rel="noopener">source</a></p>
</div>
</div>
</div>
<blockquote class="wp-embedded-content" data-secret="CwUzk2Zogw"><p><a href="https://goodshepherdmedia.net/cell-site-simulators-imsi-catchers-aka-stingray-phone-tracker/">Cell-site simulators/ imsi catchers aka Stingray phone tracker</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;Cell-site simulators/ imsi catchers aka Stingray phone tracker&#8221; &#8212; Good Shepherd News - Fastest Growing Religious, Free Speech &amp; Political Content" src="https://goodshepherdmedia.net/cell-site-simulators-imsi-catchers-aka-stingray-phone-tracker/embed/#?secret=QHM7OzueSq#?secret=CwUzk2Zogw" data-secret="CwUzk2Zogw" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><iframe title="Pacamarra: IMSI catcher intercepts calls, not personal data | Morning Matters" width="640" height="360" src="https://www.youtube.com/embed/fTCnf6mAgxk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p><iframe title="RayHunter - Building the EFFs IMSI Catcher Detector" width="640" height="360" src="https://www.youtube.com/embed/SbSYSNuAetI?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p><iframe title="NDSS 2025 - Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic" width="640" height="360" src="https://www.youtube.com/embed/jY3idyn11Tc?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p><iframe title="DICT: IMSI catchers may operate in public spaces, tracking, intercepting mobile communications | ANC" width="640" height="360" src="https://www.youtube.com/embed/iUIcCMG30ZY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cell-site simulators/ imsi catchers aka Stingray phone tracker</title>
		<link>https://goodshepherdmedia.net/cell-site-simulators-imsi-catchers-aka-stingray-phone-tracker/</link>
		
		<dc:creator><![CDATA[The Truth News]]></dc:creator>
		<pubDate>Sun, 24 Aug 2025 21:49:24 +0000</pubDate>
				<category><![CDATA[Cool Tech & Gadgets 📱⌚🎧⚡]]></category>
		<category><![CDATA[Digital Pioneers]]></category>
		<category><![CDATA[Hackers / Master Programmers]]></category>
		<category><![CDATA[Home & Garden]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Phone Hacks]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Zee Truthful News]]></category>
		<category><![CDATA[🎖️🪖Military Tech🤖]]></category>
		<category><![CDATA[📱Mobile📱]]></category>
		<category><![CDATA[🔐Cybersecurity]]></category>
		<category><![CDATA[🔐Hacking Technology]]></category>
		<category><![CDATA[Cell-site simulators]]></category>
		<category><![CDATA[Cell-site simulators/ imsi catchers]]></category>
		<category><![CDATA[imsi catchers]]></category>
		<guid isPermaLink="false">https://goodshepherdmedia.net/?p=21346</guid>

					<description><![CDATA[Cell-site simulators/ imsi catchers aka Stingray phone tracker Cell-site simulators/ imsi catchers Cell-site simulators, also known as Stingrays or IMSI catchers, are devices that masquerade as legitimate cell-phone towers, tricking phones within a certain radius into connecting to the device rather than a tower. Cell-site simulators operate by conducting a general search of all cell phones within [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2>Cell-site simulators/ imsi catchers aka <span class="mw-page-title-main">Stingray phone tracker</span></h2>
<p><iframe title="5G IMSI Catchers Mirage5G IMSI Catchers Mirage" width="640" height="360" src="https://www.youtube.com/embed/Bg1HVaw1Sm4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<h2>Cell-site simulators/ imsi catchers</h2>
<div dir="ltr">
<div class="content">
<p>Cell-site simulators, also known as Stingrays or IMSI catchers, are devices that<a href="https://www.eff.org/deeplinks/2015/01/2014-review-stingrays-go-mainstream"> masquerade as legitimate cell-phone towers</a>, tricking phones within a certain radius into<a href="https://www.justice.gov/opa/file/767321/download"> connecting to the device rather than a tower</a>.</p>
<p>Cell-site simulators operate by conducting a general search of all cell phones within the device’s radius, in violation of basic constitutional protections.  Law enforcement use cell-site simulators to pinpoint the location of phones with greater accuracy than phone companies and without needing to involve the phone company at all. Cell-site simulators can also log IMSI numbers, (International Mobile Subscriber Identifiers) unique to each SIM card, of all of the mobile devices within a given area. Some cell-site simulators may have advanced features allowing law enforcement to intercept communications.</p>
</div>
</div>
<p><iframe title="This $50 Device lets anyone spy and track your phone!" width="640" height="360" src="https://www.youtube.com/embed/PpkLts5fdII?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<div dir="ltr">
<div class="content">
<h3><span style="color: #008080;"><a href="https://www.opentech.fund/news/how-to-catch-an-imsi-catcher/" target="_blank" rel="noopener"><span style="color: #0000ff;">DOWNLOAD</span></a> IMSI CATHER SOFTWARE AND BUILD YOUR OWN!</span><span style="color: #ff0000;"> TO OF COURSE SOLVE SECURITY FLAWS IN YOUR OWN SYSTEM ONLY </span></h3>
<h3>How Cell-Site Simulators Work</h3>
<h4>Standard Communication</h4>
<p>Cellular networks are distributed over geographic areas called &#8220;cells.&#8221; Each cell is served by one transceiver, also known as a cell-site or base station. Your phone naturally connects with the closest base station to provide you service as you move through various cells.</p>
<figure class="image"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21348" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-2.png" alt="" width="700" height="373" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-2.png 700w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-2-400x213.png 400w" sizes="(max-width: 700px) 100vw, 700px" /><figcaption>
<div class="image-attribution">Source: EFF</div>
<div class="image-caption"></div>
</figcaption></figure>
<p>&nbsp;</p>
<p>Generally, there are two types of device used by law enforcement that are often referred to interchangeably: passive devices (which we will call IMSI catchers), and active devices (which we will call cell-site simulators.) Passive devices, as a rule, do not transmit any signals. They work by plucking cellular transmissions out of the air, the same way an FM radio works. They then decode (and sometimes decrypt) those signals to find the IMSI of the mobile device and track it.</p>
<p>Active cell-site simulators are much more commonly used by law enforcement, and work very differently from their passive cousins. Cellular devices are designed to connect to the cell site nearby with the strongest signal. To exploit this, cell-site simulators broadcast signals that are either stronger than the legitimate cell sites around them, or are made to appear stronger. This causes devices within range to disconnect from their service providers’ legitimate cell sites and to instead establish a new connection with the cell-site simulator. Cell-site simulators can also take advantage of flaws in the design of cellular protocols (such as 2G/3G/4G/5G) to cause phones to disconnect from a legitimate cell-site and connect to the cell-site simulator instead.  For the purposes of this article we will focus on active cell-site simulators.</p>
<p>It is difficult for most people to know whether or not their phone’s signals have been accessed by an active cell-site simulator, and it is impossible for anyone to know if their phone’s signals have been accessed by a passive IMSI catcher. Apps for identifying the use of cell-site simulators, such as SnoopSnitch, may not be verifiably accurate. Some more advanced tools have been built, which may be more accurate. For instance, security researchers at the University of Washington have<a href="https://seaglass.cs.washington.edu/"> designed a system to measure the use of cell-site simulators across Seattle</a>, and EFF researchers <a href="https://github.com/EFForg/crocodilehunter/">have designed a similar system</a>.</p>
<h3>What Kinds of Data Cell-Site Simulators Collect</h3>
<p>Data collected by cell-site simulators can reveal intensely personal information about anyone who carries a phone, whether or not they have ever been suspected of a crime.</p>
<figure class="image"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-21349" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-3.png" alt="" width="700" height="438" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-3.png 700w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/content_CSS-3-400x250.png 400w" sizes="(max-width: 700px) 100vw, 700px" /><figcaption>
<div class="image-attribution">Source: EFF</div>
<div class="image-caption">Cell-site simulator surveillance: Cell-site simulators trick your phone into thinking they are base stations.</div>
</figcaption></figure>
<p>&nbsp;</p>
<p>Once your cellular device has connected to a cell-site simulator, the cell-site simulator can determine your location and trigger your device to transmit its  IMSI for later identification. If the cell-site simulator is able to downgrade the cellular connection to a 2G/GSM connection then it can potentially perform much more intrusive acts such as intercepting call metadata (what numbers were called or called the phone and the amount of time on each call),<a href="https://www.justice.gov/sites/default/files/criminal/legacy/2014/10/29/elec-sur-manual.pdf"> the content of unencrypted phone calls and text messages</a> and some types of data usage (such as websites visited).  Additionally, marketing materials produced by the manufacturers of cell-site simulators indicate that they<a href="https://info.publicintelligence.net/Gamma-GSM.pdf"> can be configured</a> to divert calls and text messages, edit messages, and even spoof the identity of a caller in text messages and calls on a 2G/GSM network.</p>
<h3>How Law Enforcement Uses Cell-Site Simulators</h3>
<p>Police can use cell-site simulators to try to locate a person when they already know their phone’s identifying information, or to gather the IMSI (and later the identity) of anyone in a specific area. Some cell-site simulators are small enough to fit in a police cruiser, or even on the vest of an officer, allowing law enforcement officers to drive to multiple locations, capturing from every mobile device in a given area—in some cases<a href="https://theintercept.com/2015/12/17/a-secret-catalogue-of-government-gear-for-spying-on-your-cellphone/"> up to 10,000 phones</a> at a time. These indiscriminate, dragnet searches include phones located in traditionally protected private spaces, such as homes and doctors’ offices.</p>
<p>Law enforcement officers have used information from cell-site simulators to investigate major and minor crimes and civil offenses.<a href="https://www.usatoday.com/story/news/2015/08/23/baltimore-police-stingray-cell-surveillance/31994181/"> Baltimore Police, for example,</a> have used their devices for a wide variety of purposes, ranging from tracking a kidnapper to trying to locate a man who took his wife’s phone during an argument (and later returned it to her).<a href="https://gizmodo.com/maryland-police-used-an-indiscriminate-cellphone-spy-to-1774831661"> In one case</a>, Annapolis Police used a cell-site simulator to investigate a robbery involving $56 worth of submarine sandwiches and chicken wings. In Detroit,<a href="https://www.eff.org/deeplinks/2017/05/no-hunting-undocumented-immigrants-stingrays"> U.S. Immigration and Customs Enforcement used a cell-site simulator</a> to locate and arrest an undocumented immigrant. In California, the San Bernardino county sheriff&#8217;s office <a href="https://arstechnica.com/tech-policy/2018/10/eff-sues-county-sheriff-claims-agency-wont-give-up-stingray-related-records/">used their cell-site simulator over 300 times in a little over a year</a>.</p>
<p>Police may have deployed cell-site simulators at protests. The Miami-Dade Police Department apparently<a href="http://cdn.arstechnica.net/wp-content/uploads/2013/09/miami-dade.pdf"> first purchased a cell-site simulator in 2003 to surveil protestors at a Free Trade of the Americas Agreement conference</a>. And it is suspected that they have been used <a href="https://www.law.georgetown.edu/american-criminal-law-review/wp-content/uploads/sites/15/2022/02/59-1-Owsley-George_Floyd_General_Warrants.pdf">more recently than that </a>during protests against police violence in 2020.</p>
<p>Cell-site simulators<a href="http://www.vocativ.com/389656/stingray-devices-in-trumps-america/"> are used</a> by the FBI, DEA, NSA, Secret Service, and ICE, as well as the U.S. Army, Navy, Marine Corps, and National Guard. U.S. Marshals and the FBI <a href="https://www.wsj.com/articles/americans-cellphones-targeted-in-secret-u-s-spy-program-1415917533">have attached cell-site simulators to airplanes</a> to track suspects, gathering massive amounts of data about many innocent people in the process. The<a href="https://www.texasobserver.org/texas-national-guard-spying-devices-surveillance/"> Texas Observer</a> also uncovered airborne cell-site simulators in use by the Texas National Guard. In 2023 it was revealed that ICE, DHS, and the Secret Service have all <a href="https://www.eff.org/deeplinks/2023/03/report-ice-and-secret-service-conducted-illegal-surveillance-cell-phones">used cell-site simulators many times without following their own rules on deployment or getting a warrant</a>.</p>
<p>A<a href="https://www.eff.org/deeplinks/2017/02/bipartisan-congressional-oversight-committee-wants-probable-cause-warrants-0"> recent Congressional Oversight Committee report</a> called on Congress to pass laws requiring a warrant before using cell-site simulators. Some states,<a href="https://www.eff.org/cases/californias-electronic-communications-privacy-act-calecpa"> such as California</a>, already require a warrant, except in emergency situations.</p>
<h3>Who Sells Cell-site Simulators</h3>
<p>Harris Corporation is the most well known company providing cell-site simulators to law enforcement. Their Stingray product has become the catchphrase for these devices, but they have subsequently introduced other models, such as Hailstorm,<a href="https://www.documentcloud.org/documents/3105805-Arrowhead-1-0-1-Release-Notes.html"> ArrowHead</a>,<a href="https://www.documentcloud.org/documents/3105793-Gemini-3-3-Quick-Start-Guide.html"> AmberJack, and KingFish</a>. Harris has stopped selling cell-site simulator technology to local law enforcement agencies but still works with the federal government. Digital Receiver Technology, a division of Boeing, is also a common supplier of the technology, often referred to as “<a href="https://www.revealnews.org/article/chicago-and-los-angeles-have-used-dirt-box-surveillance-for-a-decade/">dirtboxes</a>.”</p>
<p>Other sellers of cell-site simulators include Keyw, Octastic, Tactical Support Equipment, Berkeley Varitronics, Cogynte, X-Surveillance, Atos, Rayzone, Martone Radio Technology, Septier Communication, PKI Electronic Intelligence, Datong (Seven Technologies Group), Ability Computers and Software Industries, Gamma Group, Rohde &amp; Schwarz, Meganet Corporation. Manufacturers<a href="http://www.septier.com/law-enforcement/"> Septier</a> and<a href="https://info.publicintelligence.net/Gamma-GSM.pdf"> Gamma GSM</a> both provide information on what the devices can capture. The Intercept published a<a href="https://theintercept.com/2015/12/17/a-secret-catalogue-of-government-gear-for-spying-on-your-cellphone/"> secret, internal U.S. government catalogue</a> of various cellphone surveillance devices, as well as an<a href="https://theintercept.com/2016/09/12/long-secret-stingray-manuals-detail-how-police-can-spy-on-phones/"> older cell-site simulator manual</a> made available through a Freedom of Information Act request.</p>
<h3>Threats Posed by Cell-Site Simulators</h3>
<p>Cell-site simulators invade the privacy of everyone who happens to be in a given area, regardless of the fact that the vast majority have not been accused of committing a crime. These are <a href="https://www.hoover.org/sites/default/files/research/docs/lynch_webreadypdf.pdf">general searches</a> that violate the Fourth Amendment requirement that warrants “particularly” describe who or what is to be searched.</p>
<p>The use of cell-site simulators have been shrouded in government secrecy. Police have used cell-site simulators to track location data without a warrant, by deceptively obtaining “pen register” orders from courts without explaining the true nature of the surveillance. In Baltimore, a judge concluded that law enforcement had <a href="https://www.aclu.org/other/state-v-andrews-stingray-june-4-2015-transcript?redirect=state-v-andrews-stingray-june-4-2015-transcript">intentionally withheld the information</a> from the defense, in violation of their legal disclosure obligations. For a while, police departments tried to keep the use of cell-site simulators secret from not just the public but also the court system, withholding information from defense attorneys and judges—likely due in part to<a href="http://www.baltimoresun.com/news/maryland/baltimore-city/bs-md-ci-stingray-case-20150408-story.html"> non-disclosure agreements</a> with Harris Corporation. Prosecutors have<a href="https://www.washingtonpost.com/world/national-security/secrecy-around-police-surveillance-equipment-proves-a-cases-undoing/2015/02/22/ce72308a-b7ac-11e4-aa05-1ce812b3fdd2_story.html"> accepted plea deals</a> to hide their use of cell-site simulators and have even<a href="http://arstechnica.com/tech-policy/2015/04/fbi-would-rather-prosecutors-drop-cases-than-disclose-stingray-details/"> dropped cases</a> rather than revealing information about their use of the technology. U.S. Marshalls have<a href="https://arstechnica.com/tech-policy/2014/06/us-marshals-step-in-thwart-efforts-to-learn-about-cell-tracking-devices/"> driven files hundreds of miles</a> to thwart public records requests. Police have <a href="https://www.eff.org/deeplinks/2015/01/2014-review-stingrays-go-mainstream">tried to keep information secret</a> in Sarasota, Florida, Tacoma, Washington,<a href="https://arstechnica.com/tech-policy/2014/11/prosecutors-drop-key-evidence-at-trial-to-avoid-explaining-stingray-use/"> Baltimore, Maryland</a>, and St. Louis, Missouri.</p>
<p>To preserve this secrecy, the<a href="https://theintercept.com/2016/05/05/fbi-told-cops-to-recreate-evidence-from-secret-cell-phone-trackers/"> FBI told police officers to recreate evidence</a> from the devices, according to a document obtained by the nonprofit investigative journalism outlet Oklahoma Watch.</p>
<p>Cell-site simulators often disrupt cell phone communications within as much as a<a href="http://www.theglobeandmail.com/news/national/rcmp-listening-tool-capable-of-knocking-out-911-calls-memoreveals/article29672075/"> 500-meter radius</a> of the device, interrupting important communications and even <a href="http://www.theglobeandmail.com/news/national/rcmp-listening-tool-capable-of-knocking-out-911-calls-memoreveals/article29672075/">emergency phone calls</a>.  Cell-site simulators have been shown to disproportionately affect low-income communities and communities of color. In Baltimore, the use of cell-site simulators disproportionately impacted African-American communities, according to a map included in an <a href="https://www.eff.org/deeplinks/2016/08/civil-liberties-groups-file-fcc-complaint-arguing-baltimore-police-are-illegally">FCC complaint</a> that overlaid where Baltimore Police were using stingrays over census data on the city’s black population.</p>
<p><a href="https://www.eff.org/deeplinks/2018/08/blog-post-wyden-911-disruption-css">Cell-site simulators can also disrupt emergency calls</a>, such as 911 in the US, making them not only a menace to privacy but to public safety as well.</p>
<p>Cell-site simulators rely on vulnerabilities in our communications system that the government should help fix rather than exploit.</p>
<h3>EFF’s Work on Cell-Site Simulators</h3>
<p>For the reasons above, EFF opposes police use of cell site simulators. Insofar as law enforcement agencies are using cell-site simulators in criminal investigations, EFF argues that use should be limited in the following ways:</p>
<ol>
<li>Law enforcement should obtain individualized warrants based on probable cause;</li>
<li>Cell-site simulators should only be used for serious, violent crimes;</li>
<li>Cell-site simulators should only be used for identifying location of a particular phone;</li>
<li>Law enforcement must minimize the collection of data from people who are not the targets of the investigation.</li>
<li>Companies making cell-site simulators must confirm that their technology does not disrupt calls to emergency services.</li>
</ol>
<h4>Litigation</h4>
<p>We <a href="https://www.eff.org/press/releases/eff-files-foia-suit-over-us-marshals-spy-planes">filed a Freedom of Information Act lawsuit</a> to expose and shine light on the U.S. Marshals Service’s use of cell-site simulators on planes.</p>
<p>Along with the ACLU and ACLU of Maryland, we <a href="https://www.eff.org/deeplinks/2015/12/eff-joins-aclu-amicus-brief-supporting-warrant-requirement-cell-site-simulators">filed an amicus brief</a> in the first case in the country where a judge threw out evidence obtained as a result of using a cell-site simulator without a warrant.</p>
<p>We filed an amicus brief, along with the ACLU, pointing a court to facts indicating that the Milwaukee Police Department secretly used a cell-site simulator to locate a defendant through his cell phone without a warrant in U.S. vs. Damian Patrick. (The government then <a href="https://www.eff.org/document/us-v-patrick-government-letter-admitting-stingray-use">admitted</a> to having used it.)</p>
<h4>Legislation</h4>
<p>We were original co-sponsors of the <a href="https://www.eff.org/cases/californias-electronic-communications-privacy-act-calecpa">California Electronic Communications Privacy Act (CalECPA)</a>, along with the ACLU and the California Newspaper Publisher Association. This law requires California police to get a warrant before using a cell-site simulator. Any evidence obtained from a cell-site simulator without a warrant is inadmissible in court.</p>
<p>EFF supported S.B. 741, which requires transparency measures regarding the use of cell-site simulators. We <a href="https://www.eff.org/deeplinks/2016/04/here-are-79-policies-california-surveillance-tech-where-are-other-90">collected many of these policies</a>.</p>
<h4>Further Research</h4>
<p>We have written a report on the <a href="https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks">technical means possibly used by cell-site simulators called “Gotta Catch ‘em All”</a>, and we have developed a proof of concept technical means of <a href="https://github.com/EFForg/crocodilehunter">detecting cell-site simulators called Crocodile Hunter</a>.</p>
<h3>EFF Cases</h3>
<p><a href="https://www.eff.org/cases/state-maryland-v-kerron-andrews">State of Maryland v. Kerron Andrews</a></p>
<p><a href="https://www.eff.org/cases/us-v-damian-patrick">U.S. v. Damian Patrick</a></p>
<p><a href="https://www.eff.org/cases/us-marshals-airborne-imsi-catchers">EFF v. U.S. Department of Justice</a></p>
<h3><strong>Suggested Additional Reading</strong></h3>
<p><a href="https://www.aclu.org/issues/privacy-technology/surveillance-technologies/stingray-tracking-devices-whos-got-them">Stingray Tracking Devices: Who&#8217;s Got Them?</a> (ACLU)</p>
<p><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2437678">Your Secret Stingray&#8217;s No Secret Anymore: The Vanishing Government Monopoly over Cell Phone Surveillance and Its Impact on National Security and Consumer Privacy</a> (Harvard Journal of Law and Technology)</p>
<p><a href="https://oversight.house.gov/hearing/examining-law-enforcement-use-of-cell-phone-tracking-devices/">Examining Law Enforcement Use of Cell Phone Tracking Devices</a> (House Oversight Committee)</p>
<p><a href="http://centerformediajustice.org/resources/the-relentless-eye/">The Relentless “Eye” Local Surveillance: Its Impact on Human Rights and Its Relationship to National and International Surveillance</a> (Center for Media Justice and others)</p>
<p><a href="https://www.justice.gov/opa/file/767321/download">Department of Justice Policy Guidance: Use of Cell-Site Simulator Technology</a> (U.S. Department of Justice)</p>
<p><a href="https://theintercept.com/2016/09/12/long-secret-stingray-manuals-detail-how-police-can-spy-on-phones/">Long-Secret Stingray Manuals Detail How Police Can Spy on Phones</a>  (The Intercept)</p>
<p><a href="https://theintercept.com/2015/12/17/a-secret-catalogue-of-government-gear-for-spying-on-your-cellphone/">A Secret Catalogue of Government Gear for Spying on Your Cellphone</a> (The Intercept)</p>
<p><a href="https://gizmodo.com/american-cops-turns-to-canadian-phone-tracking-firm-aft-1845442778">Cops Turn to Canadian Phone-Tracking Firm After Infamous &#8216;Stingrays&#8217; Become &#8216;Obsolete&#8217;</a> (Gizmodo)</p>
</div>
</div>
<p><a href="https://sls.eff.org/technologies/cell-site-simulators-imsi-catchers" target="_blank" rel="noopener">source</a></p>
<p>&nbsp;</p>
<hr />
<div id="tm-row-687d638d57d7d" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d58012" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-heading-687d638d582dd" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">IMSI Catcher System</h4>
</div>
<div id="tm-spacer-687d638d58705" class="tm-spacer"></div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<p>Cellular Interception Solutions help law enforcement authorities to acquire, intercept, analyze and manage cellular communications such as voice, SMS, and Call Related Information (CRI) data. This becomes vital as terrorists and criminal elements rely upon cellular mobile communications to carry out their subversive operations.</p>
<p>The initial step in the interception of any phone is identifying the presence of target phones in the areas of interest. This can be achieved using IMSI-Catcher. IMSI Catcher Systems are designed to collect basic identities (IMSI, IMEI) of 2G, 3G, and 4G mobile phones working within their coverage area without the knowledge of the service providers and the phone users. This enables the agencies to identify the presence of the target in their area of operation. These phones can then be intercepted by Passive, Semi-Active, or Hybrid Interception systems.</p>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5895d" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d58b4f" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-spacer-687d638d58d40" class="tm-spacer"></div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d58e24" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d590a0" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="imsi_contact" class="tm-button-wrapper tm-animation move-up animate"><a class="tm-button style-flat tm-button-nm tm-button- has-icon icon-right" href="https://www.stratign.com/gsm-interception-system-v2/"><span class="button-text" data-text="Contact">Contact </span><i class="fa fa-phone-square"></i></a></div>
<div id="tm-spacer-687d638d59451" class="tm-spacer"></div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d59563" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5977f" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-heading-687d638d599fb" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Passive GSM Interception System</h4>
</div>
<div id="tm-spacer-687d638d59e54" class="tm-spacer"></div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<p>Passive GSM Interception System is the most advanced monitoring system that does not transmit any information, hence making it completely undetectable by the operator or by the target that is being intercepted.</p>
</div>
</div>
<div id="tm-spacer-687d638d59f14" class="tm-spacer"></div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d59fdc" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5a1c4" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div class="wpb_raw_code wpb_content_element wpb_raw_html">
<div class="wpb_wrapper"><img loading="lazy" decoding="async" class="alignnone wp-image-21350" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png" alt="" width="715" height="455" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png 2560w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-400x255.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-1024x652.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-768x489.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-1536x978.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-PASSIVE-CELLPHONE-INTERCEPTION-SYSTEM-2048x1304.png 2048w" sizes="(max-width: 715px) 100vw, 715px" /></div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5a4d5" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5a6dc" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-heading-687d638d5a934" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Features</h4>
</div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<ul>
<li>System is completely passive, and its presence cannot be detected either by the target or by the service provider.</li>
<li>Capable of intercepting 2G, 3G, 4G and 5G networks.</li>
<li>Capable of intercepting calls and messages.</li>
<li>Location of targets can be displayed on a digital map</li>
<li>Capable of intercepting 4 to 32 at a time from across multiple service providers.</li>
<li>Real-time passive deciphering of A5/1, A5/2, and A5/0 encrypted signals.</li>
<li>System stores intercepted voice calls, SMS, and protocol information on the control PC hard drive.</li>
<li>Addition configuration of Open-Source Intelligence (OSINT), Voice Print Analysis, Link analysis.</li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5af4e" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5b1de" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-spacer-687d638d5b36c" class="tm-spacer"></div>
<div id="tm-heading-687d638d5b46a" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Semi-Active GSM Interception System</h4>
</div>
<div id="tm-spacer-687d638d5b8ad" class="tm-spacer"></div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<p>Semi-Active GSM Interception System can intercept incoming and outgoing communications between the Base Station, and the Mobile Handset using the principle of Man-in-the-Middle, without being detectable by the operator or by the target that is being intercepted.</p>
</div>
</div>
<div id="tm-spacer-687d638d5b96f" class="tm-spacer"></div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5ba45" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5bc44" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div class="wpb_raw_code wpb_content_element wpb_raw_html">
<div class="wpb_wrapper"><img loading="lazy" decoding="async" class="alignnone wp-image-21351" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png" alt="" width="865" height="551" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png 2560w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-400x255.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-1024x652.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-768x489.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-1536x978.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-SEMI-ACTIVE-CELLPHONE-INTERCEPTION-SYSTEM-2048x1305.png 2048w" sizes="(max-width: 865px) 100vw, 865px" /></div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5beb6" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5c149" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-heading-687d638d5c3d3" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Features</h4>
</div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<ul>
<li>Interception does not require the service provider’s assistance or SIM for operation.</li>
<li>Real-time listening of the intercepted cell phone calls.</li>
<li>Capable of intercepting 2G, 3G, 4G and 5G networks.</li>
<li>Real-time deciphering of A5/1, A5/2, and A5/0 encrypted signals.</li>
<li>Capable of intercepting voice, SMS, and Call Related Information (CRI) data.</li>
<li>Location of targets can be determined with an accuracy for up to 5 meters.</li>
<li>Handheld direction finder for better location accuracy</li>
<li>Selective jamming capability using which the operator can disable certain services of the target like outgoing call, incoming call, SMS, etc.</li>
<li>Spoofing and manipulating Text Messages and Calls.</li>
<li>Capable of intercepting 4 to 32 at a time from across multiple service providers.</li>
<li>Addition configuration of Open-Source Intelligence (OSINT), Voice Forensics, Keyword Spotting.</li>
</ul>
</div>
</div>
<div id="tm-spacer-687d638d5c8bb" class="tm-spacer"></div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5c9a5" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5cbf8" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-spacer-687d638d5cd57" class="tm-spacer"></div>
<div id="tm-heading-687d638d5cdf7" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Hybrid GSM Interception System</h4>
</div>
<div id="tm-spacer-687d638d5d1f8" class="tm-spacer"></div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<p>Hybrid GSM Interception system is a combination of Passive and Semi-Active interception systems. The basic functioning of the system is like the passive system and is turned into an active one only when required.</p>
</div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5d378" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5d593" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div class="wpb_raw_code wpb_content_element wpb_raw_html">
<div class="wpb_wrapper"><img loading="lazy" decoding="async" class="alignnone wp-image-21352" src="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png" alt="" width="774" height="493" srcset="https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-scaled.png 2560w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-400x255.png 400w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-1024x652.png 1024w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-768x489.png 768w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-1536x978.png 1536w, https://goodshepherdmedia.net/wp-content/uploads/2025/07/f-HYBRID-CELLPHONE-INTERCEPTION-SYSTEM-2048x1305.png 2048w" sizes="(max-width: 774px) 100vw, 774px" /></div>
</div>
</div>
</div>
</div>
</div>
<div id="tm-row-687d638d5d82b" class="vc_row vc_row-outer vc_row-fluid">
<div id="tm-column-687d638d5d9eb" class="wpb_column vc_column_container vc_col-sm-12">
<div class="vc_column-inner ">
<div class="wpb_wrapper">
<div id="tm-heading-687d638d5dbb8" class="tm-heading left tm-animation move-up animate">
<h4 class="heading">Features</h4>
</div>
<div class="wpb_text_column wpb_content_element tm-animation move-up animate">
<div class="wpb_wrapper">
<ul>
<li>In Passive Mode all features of the passive system will apply.</li>
<li>In Semi-Active Mode all features of the Semi-Active Mode system will apply. <a href="https://www.stratign.com/gsm-interception-system-v2/" target="_blank" rel="noopener">source</a></li>
</ul>
</div>
</div>
</div>
</div>
</div>
</div>
<hr />
<h1 class="entry-title">Detecting IMSI-Catchers by Characterizing Identity Exposing Messages in Cellular Traffic</h1>
<p><strong>Tyler Tucker (University of Florida), Nathaniel Bennett (University of Florida), Martin Kotuliak (ETH Zurich), Simon Erni (ETH Zurich), Srdjan Capkun (ETH Zuerich), Kevin Butler (University of Florida), Patrick Traynor (University of Florida)</strong></p>
<p>&nbsp;</p>
<p>IMSI-Catchers allow parties other than cellular network providers to covertly track mobile device users. While the research community has developed many tools to combat this problem, current solutions focus on correlated behavior and are therefore subject to substantial false classifications. In this paper, we present a standards-driven methodology that focuses on the messages an IMSI-Catcher textit{must} use to cause mobile devices to provide their permanent identifiers. That is, our approach focuses on causal attributes rather than correlated ones. We systematically analyze message flows that would lead to IMSI exposure (most of which have not been previously considered in the research community), and identify 53 messages an IMSI-Catcher can use for its attack. We then perform a measurement study on two continents to characterize the ratio in which connections use these messages in normal operations. We use these benchmarks to compare against open-source IMSI-Catcher implementations and then observe anomalous behavior at a large-scale event with significant media attention. Our analysis strongly implies the presence of an IMSI-Catcher at said public event ($p &lt;&lt; 0.005$), thus representing the first publication to provide evidence of the statistical significance of its findings. <a href="https://www.ndss-symposium.org/ndss-paper/detecting-imsi-catchers-by-characterizing-identity-exposing-messages-in-cellular-traffic/" target="_blank" rel="noopener">source</a></p>
<p>&nbsp;</p>
<blockquote class="wp-embedded-content" data-secret="148xCekYPH"><p><a href="https://goodshepherdmedia.net/detecting-imsi-catchers-tools-apps-and-methods-you-should-know/">Detecting IMSI Catchers: Tools, Apps and Methods You Should Know</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;Detecting IMSI Catchers: Tools, Apps and Methods You Should Know&#8221; &#8212; Good Shepherd News - Fastest Growing Religious, Free Speech &amp; Political Content" src="https://goodshepherdmedia.net/detecting-imsi-catchers-tools-apps-and-methods-you-should-know/embed/#?secret=adQrYGaIcF#?secret=148xCekYPH" data-secret="148xCekYPH" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>HOW I GOT A TRULY ANONYMOUS SIGNAL ACCOUNT</title>
		<link>https://goodshepherdmedia.net/how-i-got-a-truly-anonymous-signal-account/</link>
		
		<dc:creator><![CDATA[The Truth News]]></dc:creator>
		<pubDate>Mon, 29 Jul 2024 20:48:46 +0000</pubDate>
				<category><![CDATA[Computer Hacks]]></category>
		<category><![CDATA[Government Spying]]></category>
		<category><![CDATA[Hackers / Master Programmers]]></category>
		<category><![CDATA[Home & Garden]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Phone Hacks]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Zee Truthful News]]></category>
		<category><![CDATA[📱Mobile📱]]></category>
		<category><![CDATA[🔐Cybersecurity]]></category>
		<category><![CDATA[🙂Fun Facts🙂]]></category>
		<category><![CDATA[TRULY ANONYMOUS Phone]]></category>
		<category><![CDATA[TRULY ANONYMOUS SIGNAL ACCOUNT]]></category>
		<guid isPermaLink="false">https://goodshepherdmedia.net/?p=18430</guid>

					<description><![CDATA[HOW I GOT A TRULY ANONYMOUS SIGNAL ACCOUNT Yes, you can use Signal without sharing your personal phone number. Here’s how I did it. &#160; THE MESSAGING APP Signal is described by security professionals as utilizing the gold standard of cryptography. Unlike many competitors, its default is end-to-end encryption — and on top of that, the app minimizes the amount of [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1 class="post__title">HOW I GOT A TRULY ANONYMOUS SIGNAL ACCOUNT</h1>
<p class="post__excerpt">Yes, you can use Signal without sharing your personal phone number. Here’s how I did it.</p>
<p>&nbsp;</p>
<p><span class="has-underline">THE MESSAGING APP</span> Signal is described by security professionals as utilizing the <a href="https://x.com/matthew_d_green/status/1789688236933062767" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">gold standard</a> of cryptography. Unlike many competitors, its default is end-to-end encryption — and on top of that, the app <a href="https://signal.org/blog/looking-back-as-the-world-moves-forward/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">minimizes</a> the amount of information it stores about users. This makes it a powerful communication tool for those seeking a private and secure means of chatting, whether it’s journalists and their sources, <a href="https://goodshepherdmedia.net/how-to-check-if-your-cellphone-is-infected-with-pegasus-spyware/" target="_blank" rel="noopener">activists and human rights defenders</a>, or just ordinary people who want to evade the rampant data-mining of Big Tech platforms.</p>
<p>Signal continues to introduce <a href="#signal">privacy-enhancing features such as usernames</a> that can be used in lieu of phone numbers to chat with others — preventing others from finding you by searching for your phone number. But the app still requires users to provide a working phone number to be able to sign up in the first place.</p>
<p>For privacy-conscious individuals, this can be a problem.</p>
<p>In response to subpoena requests, Signal can reveal phone numbers. Relying on phone numbers has also led to <a href="https://support.signal.org/hc/en-us/articles/4850133017242-Twilio-Incident-What-Signal-Users-Need-to-Know" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">security and account takeover incidents</a>. Not to mention that the phone number requirement <a href="https://signal.org/blog/signal-is-expensive/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">costs</a> Signal more than $6 million annually to implement.</p>
<p>Signal <a href="https://support.signal.org/hc/articles/6712070553754#username_phone_number_required" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">insists</a> on its site that phone numbers are a requirement for contact discovery and to stymie spam. (Signal did not respond to a request for comment). Other encrypted messaging platforms such as <a href="https://getsession.org/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">Session</a> and <a href="https://wire.com/en" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">Wire</a> do not require phone numbers.</p>
<p>There are <a href="https://theintercept.com/2017/09/28/signal-tutorial-second-phone-number/">some</a> <a href="https://freedom.press/training/secondary-signal-account/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">ways</a> around Signal’s phone number policy that involve obtaining a secondary number, such as using temporary SIM cards, virtual eSIMs, or virtual numbers. But these approaches involve jumping through hoops to set up anonymous payment measures to procure the secondary numbers. And sometimes they don’t work at all (that was my experience when I tried using a Google Voice number to sign up for Signal).</p>
<p>I wanted a way to get a Signal account without leaving any sort of payment trail — a free and anonymous alternative. And thus began my long and tedious journey of registering Signal with a pay phone.</p>
<h2 id="h-finding-a-pay-phone" class="wp-block-heading">Finding a Pay Phone</h2>
<p>The first step was actually finding a pay phone, a task which is dismally daunting in 2024.</p>
<p>The <a href="https://www.payphone-project.com/numbers/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">Payphone Project</a> lists around 750,000 pay phones, but after attempting to cross-check a sampling of the hundreds of alleged pay phones in my town with Google Street View and Google Earth satellite images, I came to the quick realization that the list was woefully outdated. Many of these phones no longer exist.</p>
<p>A Google Maps search for pay phones in my area brought up of a half-dozen pins. Using Street View, I found that four locations seemed to have something resembling a pay phone box. Trekking out to them, however, revealed that one no longer had a pay phone, though discoloration of the store façade revealed the precise spot the pay phone used to be; another pay phone looked like it had been the victim of a half-hearted arson attack; the third and fourth lacked dial tones.</p>
<p>Asking on a community subreddit resulted in suggestions that once again led me to places without any working pay phones, or posts berating me for needing a pay phone in 2024 and inquiring about the legality of the endeavors I wished to pursue which would necessitate pay phone usage.</p>
<p>Failing at finding a functional pay phone through a systemic approach, I resorted to brute opportunism — keeping my eyes peeled for pay phones as I went through the dull drudgery of a modern life made ever bleaker by the lack of public phone access.</p>
<h2 id="h-a-working-pay-phone-that-is" class="wp-block-heading">A Working Pay Phone, That Is</h2>
<p>I didn’t just need to find a working pay phone — no small feat in 2024. I also needed to find one able to receive incoming calls, so I could get Signal’s activation message.</p>
<p>On a recent visit to Tampa, where I travel annually to discuss security matters and <a href="https://www.youtube.com/watch?v=15vqtCBBfjY" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">set things on fire</a>, I spotted a pay phone while leaving Busch Gardens. Picking up the receiver, I was delighted to hear the telephonic equivalent of a pulse: a dial tone.</p>
<p>Now that I had a phone with a dial tone, the next step was to test whether it could receive incoming calls. This is because Signal’s <a href="https://support.signal.org/hc/en-us/articles/360007318691-Register-a-phone-number" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">registration process</a> requires a phone number that can either receive a text message or a verification call.</p>
<p>To test whether a pay phone can receive incoming calls, you need to know one thing: the pay phone’s own phone number. Some pay phones reveal their numbers on the phones themselves, but not always.</p>
<p>If the number isn’t listed on the phone — it wasn’t in this case — there’s a workaround that doesn’t involve a paper trail leading back to your cellphone. Use the pay phone to call what’s known as an <a href="https://en.wikipedia.org/wiki/Automatic_number_announcement_circuit" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">ANAC</a> (automatic number announcement circuit), which provides an ANI (automatic number identification) service. In other words, it’s a phone number you can call which then reads out the phone number you are calling from. Lists of ANAC numbers have been bantered about for <a href="https://groups.google.com/g/comp.dcom.telecom/c/qGNAST4Zixc" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">years</a>, though like pay phone lists, almost all are now defunct.</p>
<p>One stalwart ANAC number that has withstood the test of time <a href="http://digest.textfiles.com/TELECOMDIGEST/vol10.iss0701-0750.txt" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">for over 30 years</a>, however, is 1-800-444-4444. Feel free to try it. Call the number, and it should read yours back to you.</p>
<p>Back at Busch Gardens, I rang up the ANAC and had a number read back to me. The next and final step was to test whether the number actually accepted incoming calls. Unfortunately, when I called the number the ANAC line had read back to me, I reached the Busch Gardens main line, asking me to enter my party’s extension. In other words, this wasn’t actually the pay phone’s number, it was just the general theme park number.</p>
<p>Days later, during a layover on my trip home from Tampa, I noticed a small bay of pay phones at a small regional airport. I repeated the above rigamarole, and lo and behold, when I called the pay phone’s number from the neighboring pay phone, I was able to answer and talk to myself. Finally, success.</p>
<p>I took out a burner phone on which I wanted to set up Signal, which had no SIM or eSIM of any kind, and proceeded to enter the pay phone’s phone number when setting up Signal. Signal first insists on attempting to send a verification code via an SMS text message, so you have to initially go through that fruitless route. But after a few minutes, you can then select the option to receive the verification code via a voice call.</p>
<p>Moments later, the pay phone rang, and I was finally able to set up a Signal account.</p>
<p>The next and final step was to set up a <a href="https://support.signal.org/hc/en-us/articles/360007059792-Signal-PIN" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">PIN and enable a registration lock</a> so that someone else wouldn’t be able to take over the account by going to the same pay phone and registering their own version of Signal with that same number. The registration lock expires after a week of inactivity, so you also have to keep using the Signal account. It took a while, owing to Signal’s onerous registration requirements coupled with the increasing lack of public phone access, but in the end I proved there is a way to use Signal with an untraceable phone number.</p>
<h2 id="h-a-step-by-step-guide" class="wp-block-heading"><span style="color: #ff0000;">A Step-by-Step Guide</span></h2>
<ol class="wp-block-list">
<li><span style="color: #0000ff;"><strong><em>Obtain a phone. It doesn’t need to have an active phone number associated with it, and can be either an old phone you have around or a dedicated burner phone.</em></strong></span></li>
<li><span style="color: #0000ff;"><strong><em>Locate a pay phone. </em></strong></span></li>
<li><span style="color: #0000ff;"><strong><em>Find the pay phone’s phone number (call 1-800-444-4444 if it’s not written on the phone).</em></strong></span></li>
<li><span style="color: #0000ff;"><strong><em>Make sure the pay phone can receive incoming calls.</em></strong></span></li>
<li><span style="color: #0000ff;"><strong><em>Enter the pay phone number into Signal, and use the ‘Call me’ option to receive a verification call (this option shows up only after the SMS timer runs out).</em></strong></span></li>
<li><span style="color: #0000ff;"><strong><em>Input the confirmation code, set up a PIN and enable Registration Lock in the Signal app. </em></strong></span></li>
</ol>
<p><a href="https://theintercept.com/2024/07/16/signal-app-privacy-phone-number/" target="_blank" rel="noopener">source</a></p>
<p>&nbsp;</p>
<h1 class="post__title"><a id="signal"></a>SIGNAL’S NEW USERNAMES HELP KEEP THE COPS OUT OF YOUR DATA</h1>
<p class="post__excerpt">Ephemeral usernames instead of phone numbers safeguard privacy — and makes Signal even harder to subpoena.</p>
<p>an assistant U.S. attorney issued a subpoena to Signal demanding that the messaging app hand over information about one of its users. Based on a phone number, the federal prosecutors were asking for the user’s name, address, correspondence, contacts, groups, and call records to assist with an FBI investigation. Two weeks later, the American Civil Liberties Union <a href="https://signal.org/bigbrother/cd-california-grand-jury/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">responded</a> on behalf of Signal with just two pieces of data: the date the target Signal account was created, and the date that it last connected to the service.</p>
<p>That’s it. That’s all Signal turned over because that’s all Signal itself had access to. As Signal’s website puts it, “It’s impossible to turn over data that we never had access to in the first place.” It wasn’t the first time Signal has received data requests from the government, nor was it the last. In <a href="https://signal.org/bigbrother/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">all cases</a>, Signal handed over just those two pieces of data about accounts, or nothing at all.</p>
<div id="third-party--article-mid" class="newsletter-embed">
<p>Signal is the gold standard for secure messaging apps because not only are messages encrypted, but so is pretty much everything else. Signal doesn’t know your name or profile photo, who any of your contacts are, which Signal groups you’re in, or who you talk to and when. (This isn’t true for WhatsApp, Telegram, iMessage, and nearly every other messaging app.)</p>
<p>Still, one of the main issues with Signal is its reliance on phone numbers. When activists join Signal groups for organizing, they’ve been forced to share their phone number with people they don’t yet know and trust. Journalists have had to choose between soliciting tips by publishing their private numbers to their readers — and therefore inviting harassment and cyberattacks — or <a href="https://freedom.press/training/secondary-signal-account/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">setting up a second Signal number</a>, a challenging and time-consuming prospect. Most journalists simply don’t publish a Signal number at all. That’s all about to change.</p>
<p>With the long-awaited <a href="https://signal.org/blog/phone-number-privacy-usernames/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">announcement</a> that usernames are coming to Signal — over four years in the making — Signal employed the same careful cryptography engineering it’s famous for, ensuring that the service continues to learn as little information about its users as possible.</p>
<blockquote class="stylized pull-left" data-shortcode-type="pullquote" data-pull="left"><p>“Doing it encrypted is the boss level. We had to change fundamental pieces of our architecture.”</p></blockquote>
<p>“Doing it encrypted is the boss level,” said Meredith Whittaker, president of the nonprofit Signal Foundation, which makes the app. “We had to change fundamental pieces of our architecture.”</p>
<p>If Signal receives a government request for information about an account based on an active username, Signal will be able to hand over that account’s phone number along with its creation date and last connection date. So being able to use Signal through usernames doesn’t mean your phone number becomes subpoena-proof — at least not without using the new ability to change your username at will.</p>
<p>That’s because the new Signal usernames are designed to be ephemeral. You can set one, delete it, and change it to something else, as often as you want.</p>
<p>Signal usernames are supported in the latest versions of the Signal desktop and mobile apps— make sure to update your app, in case you’re using an older version. My username is micah.01, if you want to drop me a message.</p>
<h2 id="h-signal-s-new-phone-number-privacy" class="wp-block-heading">Signal’s New Phone Number Privacy</h2>
<p>With the new version of Signal, you will no longer broadcast your phone number to everyone you send messages to by default, though you can choose to if you want. Your phone number will still be displayed to contacts who already have it stored in their phones. Going forward, however, when you start a new conversation on Signal, your number won’t be shared at all: Contacts will just see the name you use when you set up your Signal profile. So even if your contact is using a custom Signal client, for example, they still won’t be able to discover your phone number since the service will never tell it to them.</p>
<p>You also now have the option to set a username, which Signal lets you change whenever you want and delete when you don’t want it anymore. Rather than directly storing your username as part of your account details, Signal stores a cryptographic hash of your username instead; Signal uses the Ristretto 25519 hashing algorithm, essentially storing a random block of data instead of usernames themselves. This is like how online services can confirm a user’s password is valid without storing a copy of the actual password itself.</p>
<blockquote class="stylized pull-left" data-shortcode-type="pullquote" data-pull="left"><p><strong><em>“As far as we’re aware, we’re the only messaging platform that now has support for usernames that doesn’t know everyone’s usernames by default.”</em></strong></p></blockquote>
<p><strong><em>“As far as we’re aware, we’re the only messaging platform that now has support for usernames that doesn’t know everyone’s usernames by default,” said Josh Lund, a senior technologist at Signal.</em></strong></p>
<p>The move is yet another piece of the Signal ethos to keep as little data on hand as it can, lest the authorities try to intrude on the company. Whittaker explained, “We don’t want to be forced to enumerate a directory of usernames.”</p>
<p>To prevent people from squatting on high value usernames — like taylorswift, for example — all usernames are required to have a number at the end of them, like taylorswift.89. Once you’ve set a username, other Signal users can start a conversation with you by searching for your username, all without learning your phone number.</p>
<p>Since usernames are designed to be ephemeral, you can set a new username specifically for a conference you’re attending, or for a party. People can connect with you using it, and then you delete it when you’re done and set it to something else later.</p>
<p>There are some cases you might want your username to be permanent. For example, it makes sense for journalists to create a username that they never change and publish it widely so sources can reach out to them. Journalists can now do that without having to share their private phone number. It makes sense for sources, on the other hand, to only set a username when they specifically want to connect with someone, then delete it afterward.</p>
<p>You can also create a link or QR code that people can scan to add you as a contact. These, too, are ephemeral. You can send someone your Signal link in an insecure channel, and, as soon as they contact you, you can reset your link and get a new one, without needing to change your username.</p>
<p>Finally, while you’ll still need a phone number to create a Signal account, you’ll have the option to prevent anyone from finding you on Signal using your phone number.</p>
<h2 id="h-can-signal-hand-over-your-phone-number-based-on-a-username" class="wp-block-heading">Can Signal Hand Over Your Phone Number Based on a Username?</h2>
<p>Whenever Signal receives a properly served subpoena, they work closely with the American Civil Liberties Union to challenge and respond to it, handing over as little user data as possible. Signal publishes a post to the “Government Requests” <a href="https://signal.org/bigbrother/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">section</a> of their website (signal.org/bigbrother) whenever they’re legally forced to provide user data to governments, so long as they’re allowed to. Some of the examples include challenges to gag orders, allowing Signal to publish the previously sealed court orders.</p>
<p>If Signal receives a subpoena demanding that they hand over all account data related to a user with a specific username that is currently active at the time that Signal looks it up, they would be able to link it to an account. That means Signal would turn over that user’s phone number, along with the account creation date and the last connection date. Whittaker stressed that this is “a pretty narrow pipeline that is guarded viciously by ACLU lawyers,” just to obtain a phone number based on a username.</p>
<p>Signal, though, can’t confirm how long a given username has been in use, how many other accounts have used it in the past, or anything else about it. If the Signal user briefly used a username and then deleted it, Signal wouldn’t even be able to confirm that it was ever in use to begin with, much less which accounts had used it before.</p>
<blockquote class="stylized pull-right" data-shortcode-type="pullquote" data-pull="right"><p>If the Signal user briefly used a username and then deleted it, Signal wouldn’t even be able to confirm that it was ever in use to begin with.</p></blockquote>
<p>In short, if you’re worried about Signal handing over your phone number to law enforcement based on your username, you should only set a username when you want someone to contact you, and then delete it afterward. And each time, always set a different username.</p>
<p>Likewise, if you want someone to contact you securely, you can send them your Signal link, and, as soon as they make contact, you can reset the link. If Signal receives a subpoena based on a link that was already reset, it will be impossible for them to look up which account it was associated with.</p>
<p>If the subpoena demands that Signal turn over account information based on a phone number, rather than a username, Signal could be forced to hand over the cryptographic hash of the account’s username, if a username is set. It would be difficult, however, for law enforcement to learn the actual username itself based on its hash. If they already suspect a username, they could use the hash to confirm that it’s real. Otherwise, they would have to guess the username using password cracking techniques like <a href="https://blog.1password.com/what-is-dictionary-attack/" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">dictionary attacks</a> or <a href="https://www.csoonline.com/article/570931/rainbow-tables-explained-how-they-work-and-why-theyre-mostly-obsolete.html" target="_blank" rel="noopener noreferrer" aria-describedby="targetBlankDescription">rainbow tables</a>.</p>
<h2 id="h-why-does-signal-require-phone-numbers-at-all" class="wp-block-heading">Why Does Signal Require Phone Numbers at All?</h2>
<p>Signal’s leadership is aware that its critics’ most persistent complaint is the phone number requirement, and they’ll readily admit that optional usernames are only a partial fix. But because phone numbers make it simpler for most people to use Signal, and harder for spammers to make fake accounts, the phone number requirement is here to stay for the foreseeable future.</p>
<p>Signal doesn’t publish how many users it has, but the Android app boasts over 100 million downloads. It has achieved this scale largely because all you need to do is install the Signal app and you can immediately send encrypted messages to the other Signal users in your phone’s contacts — based on phone numbers.</p>
<blockquote class="stylized pull-left" data-shortcode-type="pullquote" data-pull="left"><p><strong><em>“You reach a threshold where you’re actually reducing privacy.”</em></strong></p></blockquote>
<p>This ease of use also makes Signal more secure. If Signal removed phone numbers, making it more difficult for Signal users to find each other compared to using alternative messaging apps, there could be a price to pay. “You reach a threshold where you’re actually reducing privacy,” Whittaker said. She gave an example of a person who faces severe threats and normally maintains vigilance but whose mother is only on WhatsApp because she can’t figure out the numberless Signal. The high-threat person would be stuck using the less secure option more often.</p>
<p>Requiring phone numbers also makes it considerably harder for spammers to abuse Signal. “The existence of a handful of small apps that don’t really have a large scale of users, that don’t require phone numbers, I don’t think is proof that it’s actually workable for a large-scale app,” Whittaker said.</p>
<p>It’s entirely possible to build a version of Signal that doesn’t require phone numbers, but Whittaker is concerned that without the friction of obtaining fresh phone numbers, spammers would immediately overwhelm the network. Signal engineers have discussed possible alternatives to phone numbers that would maintain that friction, including paid options, but nothing is currently on their road map.</p>
<p>“That’s actually the nexus of a very gnarly problem space that I haven’t seen a real solution for from any alternatives, and we would want to tread very, very cautiously,” Whittaker said. “There’s one Signal. We’re the gold standard for private messaging, and we have achieved critical mass at a pretty large scale. Those things couldn’t easily be recreated if we fuck this up by making a rash decision that then makes it a spammy ghost town. That’s the concern we’re wrestling with here.” <a href="https://theintercept.com/2024/03/04/signal-app-username-phone-number-privacy/" target="_blank" rel="noopener">source</a></p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MIMO Fake Cell Towers Allow mobile interception device can intercept cellular data to Keep Track of You</title>
		<link>https://goodshepherdmedia.net/mimo-fake-cell-towers-allow-mobile-interception-device-can-intercept-cellular-data-to-keep-track-of-you/</link>
		
		<dc:creator><![CDATA[The Truth News]]></dc:creator>
		<pubDate>Sat, 01 Jun 2024 18:54:23 +0000</pubDate>
				<category><![CDATA[Computer Hacks]]></category>
		<category><![CDATA[Cool Tech & Gadgets 📱⌚🎧⚡]]></category>
		<category><![CDATA[Entertainment]]></category>
		<category><![CDATA[Government Spying]]></category>
		<category><![CDATA[Hackers / Master Programmers]]></category>
		<category><![CDATA[Hardware Pioneers]]></category>
		<category><![CDATA[Home & Garden]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Phone Hacks]]></category>
		<category><![CDATA[Science & Engineering]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Zee Truthful News]]></category>
		<category><![CDATA[💻Tech History]]></category>
		<category><![CDATA[📱Mobile📱]]></category>
		<category><![CDATA[🔐Cybersecurity]]></category>
		<category><![CDATA[🔐Hacking Technology]]></category>
		<category><![CDATA[🛜🌐💻⌨ Pen Test Tools]]></category>
		<category><![CDATA[🛜🌐💻⌨ Wireless Pen Test]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[How to clone cells data]]></category>
		<category><![CDATA[MIMO Attacks]]></category>
		<category><![CDATA[mobile interception]]></category>
		<category><![CDATA[mobile interception device]]></category>
		<guid isPermaLink="false">https://goodshepherdmedia.net/?p=18031</guid>

					<description><![CDATA[MIMO Fake Cell Towers Allow mobile interception device can intercept cellular data to Keep Track of You Fake Cell Towers Allow the NSA and Police to Keep Track of You The Internet is abuzz with reports of mysterious devices sprinkled across America—many of them on military bases—that connect to your phone by mimicking cell phone [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>MIMO Fake Cell Towers Allow mobile interception device can intercept cellular data to Keep Track of You</h1>
<h2>Fake Cell Towers Allow the NSA and Police to Keep Track of You</h2>
<p>The Internet is abuzz with reports of mysterious devices sprinkled across America—many of them on military bases—that connect to your phone by mimicking cell phone towers and sucking up your data. There is little public information about these devices, but they are the new favorite toy of government agencies of all stripes; everyone from the National Security Agency to local police forces are using them.</p>
<p>These fake towers, known as &#8220;interceptors,&#8221; were<a class="multivariate" href="http://www.popsci.com/article/technology/mysterious-phony-cell-towers-could-be-intercepting-your-calls" rel="nofollow"> discovered</a> in July by users of the CryptoPhone500, one of the ultra-secure cell phones released after Edward Snowden&#8217;s leaks about NSA snooping. The phone is essentially a Samsung Galaxy S3 customized with high-level encryption that costs around $3,500. While driving around the country, CryptoPhone users plotted on a map every time they connected to a nameless tower (standard towers run by wireless service providers like Verizon usually have names) and received an alert that the device had turned off their phone&#8217;s encryption (allowing their messages to be read).</p>
<p>Map showing the location of rogue cell towers identified by the firewall on CryptoPhones in August via ESD America, a defense and law enforcement technology provider based in Las Vegas.</p>
<p>While the abilities of these interceptors vary, the full-featured versions available to government agencies are capable of a panoply of interceptions. For example, the VME Dominator can <a class="multivariate" href="http://www.popsci.com/article/technology/mysterious-phony-cell-towers-could-be-intercepting-your-calls" rel="nofollow">capture</a> calls and texts, and can even control the intercepted phone.<a class="multivariate" href="https://paleofuture.gizmodo.com/the-nsa-can-still-bug-your-phone-when-its-powered-off-1585427282" rel="nofollow"> (In an interview with NBC</a>, Snowden revealed that with this kind of technology the NSA is capable of turning on a powered-down phone and essentially using it as a bug.)</p>
<p>This NSA-style surveillance is spreading to local cops. A growing number of police departments are using tower-mimicking devices, &#8220;stingrays,&#8221; to track a cell phone&#8217;s location and extract call logs. Though little is known about the use of these devices, watchdog groups have scored small victories in their attempts to punch through this veil of secrecy. The<a class="multivariate" href="https://www.aclu.org/issues/privacy-technology/surveillance-technologies/stingray-tracking-devices-whos-got-them?redirect=maps/stingray-tracking-devices-whos-got-them" rel="nofollow"> map below</a>, courtesy of the ACLU, shows how the use of stingrays is spreading. The map also shows that despite the ALCU&#8217;s greatest efforts, it is unable to uncover information about stingray use in most of the country.</p>
<p>A recent case provided a glimpse into what stingrays can do and how they are being used.</p>
<div id="dfp-ad-inarticle3-wrapper" class="dfp-tag-wrapper dfp-ad-lazy dfp-ad-count">
<div id="dfp-ad-inarticle3" class="dfp-tag-wrapper mpu-only unstick" data-google-query-id="CL-c1qeDsIYDFVpaCAQdXtYNJw">
<p>In January, Tallahassee, Florida, police<a class="multivariate" href="https://www.aclu.org/blog/national-security/privacy-and-surveillance/police-hide-use-cell-phone-tracker-courts-because?redirect=blog/national-security-technology-and-liberty/police-hide-use-cell-phone-tracker-courts-because" rel="nofollow"> used</a> one to track a stolen cell phone to a suspect&#8217;s apartment. The police then entered the home without permission, conducted a search, and arrested the suspect in his home. Not only did the police not have a warrant, but they did not disclose to a judge that they were in possession of a stingray because the department had received it on loan from the manufacturer on condition of secrecy.</p>
<p>Only after a judge granted a motion filed by the ACLU to unseal the transcripts of the case (the federal government had previously <a class="multivariate" href="https://www.aclu.org/blog/victory-judge-releases-information-about-police-use-stingray-cell-phone-trackers?redirect=blog/national-security-technology-and-liberty/victory-judge-releases-information-about-police-use" rel="nofollow">demanded</a> the proceedings be sealed, going so far as to try to invoke the Homeland Security Act as the reason) was it revealed that between 2007 and 2010 the department used stingrays without getting warrants around 200 times. Additionally, the department had two devices; one mounted on a police vehicle, and the other carried by hand—and both were evaluating nearby cell phones in order to find a suspect. This means that information like location and phone data was pulled from innocent bystanders as well as the target of an investigation.</p>
<p>In the wake of the militarized response by the police in Ferguson, Missouri to protesters, many are taking a closer look at how the government may be abetting law enforcement in surreptitious cell phone surveillance. The purchase of such equipment is often funded by Homeland Security grants for which state and local police departments can apply. The gradual uncovering of this paper trail reveals new details about surveillance technology use. For instance, a Tacoma, Washington <a class="multivariate" href="http://usaspending.gov/explore?fiscal_year=all&amp;comingfrom=searchresults&amp;piid=DJD13HQG0264&amp;typeofview=complete" rel="nofollow">purchase order</a>, uncovered by <em><a class="multivariate" href="http://www.thenewstribune.com/2014/08/26/3347665_documents-tacoma-police-using.html?rh=1" rel="nofollow">The News Tribune</a></em>, revealed that a major reason there&#8217;s been a recent surge in requests for upgraded stingrays is the spread of 4G service.</p>
<p>Older stingrays, like the kind used by police departments, force phones using 4G or 3G down to 2G in order to more easily de-crypt data in real time. But 2G service is expected to be shut off soon—AT&amp;T<a class="multivariate" href="http://arstechnica.com/information-technology/2012/08/att-will-kill-2g-network-by-2017-to-clear-spectrum-for-3g-and-4g/" rel="nofollow"> announced</a> it would do so in 2017. If a stingray can&#8217;t knock a 4G phone down to 2G, however, it can&#8217;t do its job.</p>
<p>Last week, the city of Oakland, California, released documents<a class="multivariate" href="https://www.documentcloud.org/documents/1280786-sharpscanoaklandnet-com-20140826-180929.html" rel="nofollow"> revealing</a> that three local jurisdictions applied for a Homeland Security grant to obtain a &#8220;state-of-the-art cell phone tracking system&#8221; with 4G tracking abilities. Other areas, including Tacoma; Baltimore; Chesterfield, Virginia; Sunrise, Florida; and Michigan&#8217;s Oakland County are also seeking upgrades.</p>
<p>Since the news of the phony cell phone towers broke, Les Goldsmith, the CEO of ESD America, which is marketing the CryptoPhone500 in the U.S., told <em>Newsweek </em>that sales have been &#8220;exceptional.&#8221; He added, &#8220;We should get far greater units in the field to report interceptors.&#8221; <a href="https://www.newsweek.com/what-cell-ls-those-ominous-phony-towers-268589" target="_blank" rel="noopener">source</a></p>
</div>
</div>
<hr />
<h1 class="post-title single-post-title entry-title">Awesome Resources explains how anyone with a mobile interception device can intercept cellular data</h1>
<p>Mobile networks are dominant in the age of communication and are used to relay mobile communication signals to <a href="https://privacyinternational.org/explainer/1640/phone-monitoring" target="_blank" rel="external noopener" data-wpel-link="external">Public Switched Telephone Networks</a> (PSTN). There is a lot of information that is exchanged on a daily basis. But is your mobile network confidential?</p>
<div id="attachment_82278" class="wp-caption alignnone">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-18035" src="https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-Interception-systems-chart.webp" alt="" width="952" height="694" srcset="https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-Interception-systems-chart.webp 952w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-Interception-systems-chart-400x292.webp 400w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-Interception-systems-chart-768x560.webp 768w" sizes="(max-width: 952px) 100vw, 952px" /></p>
<div class="code-block code-block-7">
<table>
<tbody>
<tr>
<td>Your mobile phone can be used for industrial espionage, unauthorized transfer of data, or for trading secrets of the enterprises. All this is done through interception of mobile signals, voice calls or using your mobile as a bug. You’d be surprised to hear what’s to follow in this article.</p>
<p>We bring you devices, types, and techniques for mobile interception. Sit tight as we prepare you against being a victim of malicious interception practices.</p>
<h4>What is mobile interception?</h4>
<p>Mobile interception technology is the storage, recording, tracking, and interception of cellular communications like phone calls, internet usage, SMS, etc. This technology is primarily used for gathering intelligence regarding terrorist or criminal activities.</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>Even though it started out as an ethical technology for security, there are reports about the misuse of the technology doing the rounds.</p>
<p>However, for those concerned about their privacy during calls, using tools like <a href="https://apps.apple.com/us/app/call-recorder-icall/id1447098963" target="_blank" rel="external noopener" data-wpel-link="external">Call Recorder iCall </a>can provide an added layer of security by recording and securely storing conversations.</p>
<h4>How does mobile interception work?</h4>
<p>There are three types of mobile networks – NGN (Next Generation Networks like 3G, 4G, and 5G), GSM (Global System for Mobile communications) and CDMA (Code Division Multiple Access). All three of them are targets of multiple surveillance technologies.</p>
<p>When the mobile phone data travels over these networks, they are passively intercepted between the mobile phone and the base station it is communicating to. Both uplink signal (outgoing voice or data) and downlink (incoming voice or data) signals can be intercepted.</p>
<div id="attachment_82280" class="wp-caption alignnone">
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-18032" src="https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-networks.webp" alt="" width="952" height="717" srcset="https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-networks.webp 952w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-networks-400x301.webp 400w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mobile-networks-768x578.webp 768w" sizes="(max-width: 952px) 100vw, 952px" /></p>
<p id="caption-attachment-82280" class="wp-caption-text">Source: Cobham Survaillance</p>
</div>
<h4>Who can intercept your mobile signal?</h4>
<p>Mobile Interception technology is extensively used by law enforcement agencies, military &amp; defense, or authorities like government and federal &amp; local law enforcement agencies (LEAs). These are also termed as <a href="http://4g5gworld.com/blog/lawful-interception-architecture-lte-evolved-packet-system" target="_blank" rel="external noopener" data-wpel-link="external">Lawful Interceptions</a>. But there are unauthorized intercepts too!</p>
<p>Our expert <a href="https://www.awesomeresources.co.uk/about-us/" target="_blank" rel="external noopener" data-wpel-link="external">Sam Tilston</a> from <a href="https://www.awesomeresources.co.uk/" target="_blank" rel="external noopener" data-wpel-link="external">AwesomeResources.co.uk</a>, a professional in cyber security for more than 20 years believes that anyone with a mobile interception device can intercept cellular information like- voice, data transmission, and metadata.</p>
<h4>Lawful Interception (LI) – The modern legal interception protocol</h4>
<p>Lawful Interception or LI refers to a specific facility in telecommunications where LEA or government with court orders or legal authorization can intercept mobile signals. In common parlance it’s also called selective wiretapping or authorized wiretapping.</p>
<p>Lawful interception is different from the <a href="https://en.wikipedia.org/wiki/Dragnet_(policing)" target="_blank" rel="external noopener" data-wpel-link="external">dragnet-type mass surveillance</a> and is usually carried out by intelligence agencies. The data is merely passed through a fiber-optic splice where its extracted and filtered.</p>
<p>Many countries follow local, national, and global standards for lawful interception laid down by <a href="https://www.etsi.org/deliver/etsi_ts/133100_133199/133107/12.09.00_60/ts_133107v120900p.pdf" target="_blank" rel="external noopener" data-wpel-link="external">ESTI</a>. Governments and authorities require PSPs (Public Service Providers) to install a (LIG) legal interception gateway and LIN (legal interception nodes) for real-time interception.</p>
<h4>Lawful Interception architecture</h4>
<p>Currently the global standard for Lawful Interception and its architecture is provided by ESTI. The standard architecture in recent use is 3GPP Evolved Packet System (EPS) that provides IP based services.</p>
<p>The ESP architecture attempts to define an extensible and systematic means by which LEAs and network operators can interact. There are three stages in the architecture:</p>
<ol>
<li><strong>Collection:</strong> target-related call content and data are extracted from these PSP networks.</li>
<li><strong>Mediation: </strong>data is formatted to match the specific standard.</li>
<li><strong>Delivery: </strong>The content and data are delivered to the law enforcement agencies.</li>
</ol>
<p>Delivery function in the architecture is what is used to hide your sensitive interceptions from Intercepting Control Element (ICE). Even when there are multiple targets on the same number, the authorities have no idea about it.</p>
<h4>What is the need for mobile interception?</h4>
<p>Apart from the malicious effects like snooping and eavesdropping, mobile interception can be used for security. Want to know the uses?</p>
<p><strong>1. Administration Security</strong></p>
<p>The Administrative function (ADMF) keeps all the intercept activities of individual LEAs separate and interfaces to the intercepting network.</p>
<p>After configuring authorized user access within the network, password protection can be enabled using one of the following security mechanisms:</p>
<ul>
<li>CUG/VPN</li>
<li>COLP</li>
<li>CLIP</li>
<li>Authentication &amp; Encryption</li>
</ul>
<div id="browsi_adWrapper_ai_2_ati_1_rc_0">
<div id="browsi_adContainer_ai_2_ati_1_rc_0" data-google-query-id="CIOU0PrMr4YDFdlHCAQdc8YCtw">
<div id="google_ads_iframe_/22181265,22606297331/llb_970v_2_2__container__">The systems or illegal use can be prevented by intercepting the signals in the administrative network.</div>
</div>
</div>
<p><strong>2. IRI (Intercept Related Information) security</strong></p>
<p>In case of communication failures, IRI can be buffered in the 3G network. After successfully transmitting IRI, the content buffer and total buffer can be deleted via a command or a timer. This prevents the IRI data from being exposed to illegal use.</p>
<p><strong>3. CC (Call Content) security</strong></p>
<p>Data inconsistency, log files, and critically important data like billing information can be suppressed to be viewed by only a fraction of the users over the network. This data can also be deleted after successful transmission to the required personnel.</p>
<h4>Can your mobile be intercepted?</h4>
<p>If you’re in the crosshairs of the authorities, then chances are that you may be under surveillance right now. Don’t worry, if you’re under one, then you’re not alone!</p>
<p>Lawful interceptions are very common, in fact there are 2000-3000 mobile signals being intercepted and analyzed every day. In fact, if you have a few selected smartphone models from Samsung, chances are that <a href="https://gadgets.ndtv.com/mobiles/news/researchers-demonstrate-way-to-intercept-calls-made-by-samsung-phones-764656" target="_blank" rel="external noopener" data-wpel-link="external">your calls are being intercepted</a>.</p>
<p>The presence of Shannon-branded baseband chips, a tracing IC (integrated circuit) and RF (radio frequency) transceiver make it a device that can be easily intercepted. Calls and messages can be intercepted by creating a proxy base station by frankly anyone with a device.</p>
<h4>What is the future of mobile interception market?</h4>
<p>The market of mobile interception is estimated at $1.8 billion globally, and $ 226.1 million in the U.S. alone. The market is estimated to grow at a tremendous rate of 5.8% annually for the next decade.</p>
<p>With new developments of communication frequencies, networks and channels, integration with newer interception systems will create a little hurdle. New and portable devices are being deployed every day across the world to hamper the mobile interception market.</p>
<h4>In summary</h4>
<p>Mobile interception is a debatable topic. On one hand, you are always on someone’s radar and that’s something that you can’t live with knowing. On the other hand, it’s a crucial and apt technology for intercepting malicious calls and threats.</p>
<p>As hard as it may sound, it’s hard to negate the importance of mobile interception, as long as it’s legal, and meets the global standards of lawful interception.</p>
<p>Hey, as long as it continues to save millions of lives by combating increasing criminal activities and security threats, it’s always a handy technology and probably will be in the future too. <a href="https://londonlovesbusiness.com/the-current-state-of-mobile-interception/" target="_blank" rel="noopener">source</a></p>
<hr />
<h1 class="entry-title">Understanding MIMO (Multiple Input, Multiple Output) – Cellular Speed &amp; Booster Implications</h1>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-18033" src="https://goodshepherdmedia.net/wp-content/uploads/2024/05/understanding-mimo.webp" alt="" width="736" height="1102" srcset="https://goodshepherdmedia.net/wp-content/uploads/2024/05/understanding-mimo.webp 736w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/understanding-mimo-267x400.webp 267w, https://goodshepherdmedia.net/wp-content/uploads/2024/05/understanding-mimo-684x1024.webp 684w" sizes="(max-width: 736px) 100vw, 736px" /></p>
<h2>The Wonders of MIMO</h2>
<p>For RVers and Cruisers, understanding what MIMO technology is, how it works, and how it can be used to enhance cellular speeds has the potential to make finding great mobile internet on the road an easier experience.</p>
<p><strong>For anyone who knows a thing or two about wireless communications, modern 4G/LTE and 5G cellular radios are borderline miraculous.</strong></p>
<p>Consider the first iPhone &#8211; which launched in 2007 with a maximum theoretical cellular speed of around 500 Kbps using AT&amp;T&#8217;s 2G EDGE cellular network.</p>
<p>A decade and a half later &#8211; the latest flagship cellular devices were able to support maximum theoretical speeds of over 2,000 Mbps.</p>
<p><strong>That&#8217;s more than a 4,000x increase!</strong></p>
<p>And as the 5G era has matured and become more mainstream, we see peak theoretical speeds are approaching 10 Gbps, another 10x increase!</p>
<p>Of course, theory rarely equals reality &#8211; and the cellular networks need to be substantially upgraded and built out to even come close to being able to deliver speeds like this to real people outside of a lab.</p>
<p>And in the real world &#8211; you will be sharing this speed with perhaps hundreds or thousands of others connected to the same cell tower.</p>
<figure id="attachment_18947" class="wp-caption alignleft" aria-describedby="caption-attachment-18947"><img loading="lazy" decoding="async" class=" wp-image-18947" title="" src="https://rvmobileinternet.com/wp-content/uploads/2015/10/MIMO-Stereo-300x208.gif" alt="An early MIMO prototype..." width="350" height="243" /><figcaption id="caption-attachment-18947" class="wp-caption-text">An early MIMO antenna prototype?</figcaption></figure>
<p>But real-world 4G/LTE speeds over 50Mbps are actually not at all uncommon, and speeds over 100Mbps are now widely reported, and things just keep getting faster. Mid band 5G is has become lot more common on most of the carriers and we are now seeing the gap between really good LTE and good mid band 5G become way more prevalent in everyday connectivity. If you are in a mmWave 5G area, the speeds can be blazing fast.</p>
<p>One of the key technologies making these sorts of speeds possible is known as MIMO (Multiple Input, Multiple Output) &#8211; an incredibly clever technique for putting multiple antennas to work to increase both data transmission speed and reliability.</p>
<p>MIMO technology is fundamental to both 4G/LTE, 5G, and WI-Fi radios &#8211; but cellular boosters and MIMO have some&#8230; challenges&#8230; working together.</p>
<p>Read on to get a grasp of what MIMO is, how it works, and how you can use a little bit of MIMO awareness to potentially increase your cellular speeds.</p>
<h2>MIMO In A Nutshell</h2>
<p>MIMO is one of the core technologies enabling 4G/LTE and 5G cellular, and almost every modern mobile device (whether a phone or a hotspot) has two or more cellular antennas on board to enable the magic of MIMO.</p>
<p>On the other end of the line &#8211; cell towers typically have multiple antennas working together in tight synchronization to communicate with you.</p>
<p>With more antennas transmitting a signal, there are more possible echoes and reflections (read the &#8220;how it works&#8221; section below to understand the magic here) for the receiving device to catch a signal.</p>
<p>The ability to make multiple connections on the cell tower the better the transmit speeds, even with weak signals.</p>
<p>The cell tower will have a number of transmit/receive antennas and many LTE devices had two antennas.  This allows those devices to utilize 2&#215;2 MIMO.</p>
<p>Devices with four antennas for 4&#215;4 MIMO is now common, with consumer devices such as flagship hotspots such as the <a href="https://www.rvmobileinternet.com/gear/nighthawk-m6/">AT&amp;T Netgear Nighthawk M6 Pro Hotspot Pro</a>, the <a href="https://www.rvmobileinternet.com/gear/inseego-m3100/" target="_blank" rel="noopener">Verizon &amp; T-Mobile MiFi X Pro 5G hotspots</a>, plus all the the latest flagship smartphones from Apple, Samsung, and Google.</p>
<p>Although the latest cellular standards (Category 18 &amp; higher) support 8&#215;8 MIMO, consumer devices with 8 antennas are not common.</p>
<p>These antennas connect to a cell tower that will usually have at least four antennas &#8211; and as many as 128!  The number of antennas on the tower gives devices more options to get a good, high-performing connection.</p>
<p>This figure illustrates a relatively simple 4&#215;2 MIMO deployment.  In this case, 4&#215;2 means four transmit/receive antennas on the tower, and two on the user device:</p>
<figure id="attachment_18944" class="wp-caption aligncenter" aria-describedby="caption-attachment-18944"><img loading="lazy" decoding="async" class="wp-image-18944 size-full" title="mimo-antennas-to-mifi" src="https://www.rvmobileinternet.com/wp-content/uploads/2015/10/mimo-antennas-to-mifi.png" sizes="(max-width: 603px) 100vw, 603px" srcset="https://www.rvmobileinternet.com/wp-content/uploads/2015/10/mimo-antennas-to-mifi.png 603w, https://www.rvmobileinternet.com/wp-content/uploads/2015/10/mimo-antennas-to-mifi-300x145.png 300w" alt="4x2 MIMO illustration" width="603" height="292" /><figcaption id="caption-attachment-18944" class="wp-caption-text">A basic 4G/TE network 4&#215;2 deployment &#8211; with 4 antennas on the cell tower and 2 in the mobile device working together. The device itself is using 2&#215;2 MIMO.</figcaption></figure>
<p>This 4&#215;2 configuration isn&#8217;t the only one possible, however, upgraded cell towers can have many more transmit/receive antenna elements. The latest devices typically have four antennas to better take advantage of the cell towers antenna array.</p>
<p>MIMO is one of the key technologies that allow these devices to have such great performance &#8211; it really is pretty darn amazing stuff! <a href="https://www.rvmobileinternet.com/guides/understanding-mimo-multiple-input-multiple-output-lte-speed-cell-booster-implications/" target="_blank" rel="noopener">source</a></p>
<h2><span id="MIMO_vs_Boosters_Video" class="ez-toc-section"></span>MIMO vs Boosters Video</h2>
<p><iframe title="MIMO vs Boosters: Do Cellular Boosters Provide the Best Signal &amp; Data Performance?" width="640" height="360" src="https://www.youtube.com/embed/14tWiAsqfJk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<div class="teaser-content">
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<hr />
<div class="teaser-content">
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">
</div>
</div>
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The U.S. Department of Justice is collecting data from Americans’ cellphones with surveillance planes that “mimic cellphone towers,” according to a <a href="http://online.wsj.com/articles/americans-cellphones-targeted-in-secret-u-s-spy-program-1415917533">Wall Street Journal report</a>.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The program is designed to catch criminals, but collects data from innocent people as well, sources familiar with the operation told the Journal.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">The program bears some resemblance to the <a href="http://www.washingtonpost.com/world/national-security/in-nsa-intercepted-data-those-not-targeted-far-outnumber-the-foreigners-who-are/2014/07/05/8139adf8-045a-11e4-8572-4b1b969b6322_story.html?itid=lk_inline_manual_4">National Security Administration’s dragnet approach</a> to collecting information while tracking terrorists.</div>
<div data-qa="article-body"></div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">A Justice Department official would not confirm or deny the existence of the program to the Journal: “The official said discussion of such matters would allow criminal suspects or foreign powers to determine U.S. surveillance capabilities. Justice Department agencies comply with federal law, including by seeking court approval, the official said.”</div>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The program has existed since 2007, and is operated by the U.S. Marshals Service’s Technical Operations Group. It deploys Cessna aircraft from at least five airports that, combined, have a flying range that covers most of the U.S. population.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">According to the Journal story, by Devlin Barrett, the planes carry a device called a “dirtbox” — the name is inspired by Digital Receiver Technology Inc., the Boeing subsidiary that makes the device — that acts like a cellphone communications tower.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Cellphones register user locations with towers every few minutes, even if they aren’t making a call.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">By intercepting these signals, the dirtboxes can identify phones’ unique registration information — even phones with encryption like the new iPhone 6.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The device can pinpoint the location of a cellphone within 10 feet and manipulate the phone by jamming its signal. It can extract text messages and photos from phones, too.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Instead of asking cellphone companies for subscriber information, which law enforcement has done with <a href="http://www.nytimes.com/2012/07/09/us/cell-carriers-see-uptick-in-requests-to-aid-surveillance.html?pagewanted=all&amp;_r=0">increased frequency</a> in recent years, agencies can now find it themselves.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<div id="gift-share-inline" class="PJLV PJLV-ilotWTr-css hide-for-print" data-testid="gift-share-inline">
<div class="wpds-c-kPqOkS wpds-c-kPqOkS-jtSXsT-hasSubsText-false" data-testid="gift-share-interstitial-trigger"><span class="wpds-c-hBJqc"><span class="wpds-c-dzSncg">Share this article</span></span><span class="wpds-c-eCvjpK"><span class="wpds-c-enedHQ wpds-c-enedHQ-cCitdK-isShown-false">Share</span></span></div>
</div>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">In a single flight, the device can collect information about tens of thousands of cellphones. People familiar with the program told the Journal the device can identify phones linked to criminal suspects and keep that information, but “lets go” of information from other phones.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">It’s unclear whether the government is keeping data about non-suspects gathered by the device.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Describing it as a “a dragnet surveillance program,” Christopher Soghoian, chief technologist at the American Civil Liberties Union, told the Journal: “It’s inexcusable and it’s likely — to the extent judges are authorizing it — [that] they have no idea of the scale of it.”</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Courts are <a href="https://www.aclu.org/how-government-tracking-your-movements">still catching up</a> to technology like cellphone scanners. The Supreme Court has never considered whether this type of surveillance is a search requiring a warrant.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Earlier this year, the U.S. Court of Appeals for the 11th Circuit <a href="https://www.aclu.org/sites/default/files/assets/q_davis_opinion_0.pdf">ruled</a> law enforcement needs a warrant to get people’s phone location histories. However, the 5th Circuit <a href="http://www.nytimes.com/interactive/2013/07/30/technology/historic-cell-data-appeals-court-ruling.html">took the opposite view</a> last year.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The most recent Supreme Court case is <a href="http://public.cq.com/docs/weeklyreport/weeklyreport-000003976652.html">United States v. Jones</a>, a 2012 decision involving a GPS tracking device attached to a suspect’s car for month with no warrant. The Court <a href="http://www.scotusblog.com/case-files/cases/united-states-v-jones/">decided</a> attaching a device that gathered detailed information over time was a search, but didn’t say whether a warrant was required.</p>
</div>
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Civil liberties groups have already sued to challenge law enforcement use of similar devices, such as the Stingray, used on the ground by law enforcement to gather mobile data in a given area.</p>
</div>
<p>&nbsp;</p>
<hr />
<div class="teaser-content">
<div class="wpds-c-PJLV article-body" data-qa="article-body">
<h1 id="main-content" class="PJLV PJLV-ihMAsLZ-css overrideStyles" data-testid="headline" data-qa="headline"><span class="PJLV" data-qa="headline-text">Report: Secret government program uses aircraft for mass cellphone surveillance</span></h1>
</div>
</div>
<p><iframe src="https://goodshepherdmedia.net/wp-content/uploads/2024/05/Mimo-Cell-Stealing-Network-Calls-2112.02096v2.pdf" width="900" height="1100"><span data-mce-type="bookmark" style="display: inline-block; width: 0px; overflow: hidden; line-height: 0;" class="mce_SELRES_start">﻿</span></iframe></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>WiPhone, A Phone for Hackers and Makers</title>
		<link>https://goodshepherdmedia.net/wiphone-a-phone-for-hackers-and-makers/</link>
		
		<dc:creator><![CDATA[The Truth News]]></dc:creator>
		<pubDate>Fri, 23 Jun 2023 17:11:38 +0000</pubDate>
				<category><![CDATA[Computer Hacks]]></category>
		<category><![CDATA[Cool Tech & Gadgets 📱⌚🎧⚡]]></category>
		<category><![CDATA[Hackers / Master Programmers]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Phone Hacks]]></category>
		<category><![CDATA[Science & Engineering]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Zee Truthful News]]></category>
		<category><![CDATA[📱Mobile📱]]></category>
		<category><![CDATA[🔐Cybersecurity]]></category>
		<category><![CDATA[🔐Hacking Technology]]></category>
		<category><![CDATA[🛜🌐💻⌨ Pen Test Tools]]></category>
		<category><![CDATA[🛜🌐💻⌨ Wireless Pen Test]]></category>
		<category><![CDATA[A Phone for Hackers]]></category>
		<category><![CDATA[A Phone for Hackers and Makers]]></category>
		<category><![CDATA[A Phone for Hackers Makers]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[phone hacking]]></category>
		<category><![CDATA[Wi Phone]]></category>
		<category><![CDATA[WiPhone]]></category>
		<guid isPermaLink="false">https://goodshepherdmedia.net/?p=14747</guid>

					<description><![CDATA[WiPhone, A Phone for Hackers and Makers Here Introducing an all-new WiPhone, A Phone for Hackers and Makers. Moreover, WiPhone is a VoIP mobile phone designed to be easily modified, repurposed, and adapted. Basically, It’s designed to enable hackers by making it easy to extend and modify the electronics and software. Something typical phones are not good [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>WiPhone, A Phone for Hackers and Makers</h1>
<p><iframe title="Crowdfunding Video - ESP32 WiPhone" width="640" height="360" src="https://www.youtube.com/embed/Xxi0X3o1RHA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p>Here Introducing an all-new WiPhone, A Phone for Hackers and Makers. Moreover, WiPhone is a VoIP mobile phone designed to be easily modified, repurposed, and adapted.</p>
<p>Basically, It’s designed to enable hackers by making it easy to extend and modify the electronics and software. Something typical phones are not good for. However, WiPhone is also a VoIP mobile phone. It uses WIFI to make HD voice calls, for free. Though, This means that there is no required service contract.</p>
<p>Additionally, WiPhone solves these problems and gives hackers, makers, and engineers the tool we all wish our phones could be. However, It is direct access to I/O, an easy to program ESP32 processor. However,  All the basics are already set up the user interface, power management, and on/off the circuit, working code.</p>
<p>Furthermore, you also can get straight to work building projects, not setting up the boring parts like power management again and again. Though, No rats nest of wires or ugly stack of dev boards just to get the basic functionality.</p>
<p>WiPhone Tech Specs:</p>
<table width="400">
<tbody>
<tr>
<td width="64">Screen</td>
<td width="336">320 x 240</td>
</tr>
<tr>
<td>Size</td>
<td>120mm x 50mm x 12mm</td>
</tr>
<tr>
<td>Weight</td>
<td>80g</td>
</tr>
<tr>
<td>Battery</td>
<td>700 mAh, 8 hours talk/1 week standby time</td>
</tr>
</tbody>
</table>
<hr />
<h1 id="h:what-is-the-wiphone" class="page-anchor">What is the WiPhone?</h1>
<p><iframe title="WI Phone - Phone For Hackers ??? Hindi" width="640" height="360" src="https://www.youtube.com/embed/rqFVHzSsRgA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<p>WiPhone is a unique, minimal phone.</p>
<p>It&#8217;s designed to enable hackers by making it easy to extend and modify the electronics and software. Something typical phones are not good for.</p>
<p>WiPhone is also a VoIP mobile phone. It uses WIFI to make HD voice calls, for free. This means that there is no required service contract &#8211; and it&#8217;s yours for life.</p>
<h1 id="h:for-hackers" class="page-anchor">For Hackers:</h1>
<div class="template asset" contenteditable="false" data-alt-text="WiPhone: Business In The Front, Party In The Back" data-caption="WiPhone: Business In The Front, Party In The Back" data-id="24546391">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/546/391/725b922e3013bb3a34f7a47a698de795_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553612832&amp;gif-q=50&amp;q=92&amp;s=11b031c0ac1f3e79b9b547ef1ede3191" alt="WiPhone: Business In The Front, Party In The Back" data-src="https://ksr-ugc.imgix.net/assets/024/546/391/725b922e3013bb3a34f7a47a698de795_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553612832&amp;gif-q=50&amp;q=92&amp;s=11b031c0ac1f3e79b9b547ef1ede3191" data-airgap-id="160" /><figcaption class="px2">WiPhone: Business In The Front, Party In The Back</figcaption></figure>
</div>
<h1 id="h:yet-so-stylish-and-s" class="page-anchor"> Yet So Stylish And Sophisticated!</h1>
<div class="template asset" contenteditable="false" data-alt-text="WiPhone: Perfect for both hardware hacking AND trips to the business factory." data-caption="WiPhone: Perfect for both hardware hacking AND trips to the business factory." data-id="24222197">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/222/197/f69493d004457b84ab711290b0491dfe_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551220707&amp;gif-q=50&amp;q=92&amp;s=3225d407f6e2cfb48eda680d3c27187c" alt="WiPhone: Perfect for both hardware hacking AND trips to the business factory." data-airgap-id="161" /><figcaption class="px2">WiPhone: Perfect for both hardware hacking AND trips to the business factory.</figcaption></figure>
</div>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24255856">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/255/856/dd773d9ebcbb57151e57cffd48719f57_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551456235&amp;gif-q=50&amp;q=92&amp;s=3677d8f5ba63877fb13fb63dc1cba318" alt="" data-airgap-id="162" /></figure>
</div>
<h1 id="h:wiphone-pro-with-cle" class="page-anchor"> WiPhone Pro with Clear Front Face:</h1>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24251782">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/251/782/fd58066bbd5bd5642dd879a5d4d4dd96_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551425726&amp;gif-q=50&amp;q=92&amp;s=ff1135719f24b54823fda1669c3bcf8a" alt="" data-airgap-id="163" /></figure>
</div>
<p><a href="https://www.kickstarter.com/projects/2103809433/wiphone-a-phone-for-hackers-and-makers" target="_blank" rel="noopener">source</a></p>
<h1 id="h:smartphones-are-a-li" class="page-anchor">Smartphones Are A Little Too Smart</h1>
<p>What&#8217;s the best platform you can imagine for electronics hacking?</p>
<p>It should probably be adaptable, powerful, and programmable. Small and portable would be nice. Maybe with a durable case? What about a built in user interface with things like an LCD screen and button panel? A battery and built-in charging system? Wireless connectivity?</p>
<p>Hey&#8230; we just described a mobile phone!</p>
<p>But why aren&#8217;t people building more projects based on their smartphones? Well, there are a few issues:</p>
<ul>
<li>no electrical connectors to directly connect to the outside world</li>
<li>no way to easily control the low level hardware, like processor output pins</li>
<li>opaque development environment and huge IDE</li>
<li>not designed for easy disassembly, repair, or modification</li>
</ul>
<h1 id="h:enter-wiphone" class="page-anchor">Enter WiPhone:</h1>
<p><iframe title="Wiphone" width="640" height="360" src="https://www.youtube.com/embed/UFpWSblVyhw?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe></p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24255271">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/255/271/b31d8c4e2aa7767626622438c8387ab6_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551453727&amp;gif-q=50&amp;q=92&amp;s=60ac17fdb31424a6f1ca9117cab7d4a2" alt="" data-airgap-id="164" /></figure>
</div>
<p>&nbsp;</p>
<p>WiPhone solves these problems and gives hackers, makers, and engineers the tool we all wish our phones could be. Nice package, direct access to I/O, an easy to program ESP32 processor. All the basics are already set up: user interface, power management and on/off circuit, working code.</p>
<p>You can get straight to work building <span class="bold">your</span> project, not setting up the boring parts like power management again and again. And once you&#8217;re done it&#8217;s durable and looks great. No ratsnest of wires or ugly stack of dev boards just to get the basic functionality.</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24229542">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/229/542/c40e0be8c36c5213706c407564860e68_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551275978&amp;gif-q=50&amp;q=92&amp;s=1fb3665207d872a01f0149f4411ce9c7" alt="" data-airgap-id="165" /></figure>
</div>
<p>Modern smartphones are more and more a tool we don&#8217;t own, but instead one we&#8217;re only allowed to carry around. One that serves the interests of various tracking networks, corporate boards, and government organizations. You don&#8217;t own it, it owns you. It tracks you, serves you ads, and sucks away your time with mindless dopamine hits. <span class="bold">We want a phone that&#8217;s back in our control, optimized for our convenience</span>.</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24544306">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/544/306/de2e13e8060894347c6e9c18c9049064_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553601806&amp;gif-q=50&amp;q=92&amp;s=21330f469ea046b89091ac367c4378f6" alt="" data-airgap-id="166" /></figure>
</div>
<p>&nbsp;</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24252142">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/252/142/3cd5e50c8b8a6427adb8afe55d893ac0_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551429044&amp;gif-q=50&amp;q=92&amp;s=b0b9086239fdfe041426b2fe8ee28674" alt="" data-airgap-id="167" /></figure>
</div>
<h1 id="h:free-calling-no-hack" class="page-anchor">Free Calling! No Hacking Required!</h1>
<p>WiPhone is different beast from most smartphones these days. WiPhone uses the existing WiFi around you to make HD Voice calls. For free. Buy it once and it&#8217;s yours.</p>
<p>Works on most broadband WiFi networks (including most home WiFi connections). No service contract required, and you can even upgrade the firmware or expand the hardware to do things it wasn&#8217;t originally intended for.</p>
<h1 id="h:what-is-this-magical" class="page-anchor">What Is This Magical Free Calling You Speak of? Tell me more&#8230;</h1>
<p>Free calling starts with a SIP account. SIP stands for Session Initiation Protocol, and it&#8217;s a standard way to make call over the internet. VoIP is a related term that you may have heard of. There are commercial services that provide SIP/VoIP accounts, and some of them have free accounts. Most consumers use VoIP apps like Skype and Whatsapp, but we can still use the underlying technology directly. After the campaign we&#8217;ll spend more time testing services to make our software and instructions work as seamlessly as possible.</p>
<p>Step 1: Get a SIP account (many different ways to do this, but we wrote up a simple <a href="https://docs.google.com/document/d/1uPa_2V09S3YnJV_ouEUT19nDvY82nd5PcWwRDm2ayhY/edit?usp=sharing" target="_blank" rel="noopener">how-to</a> that might get you started).</p>
<p>Step 2: Log in on your WiPhone using the credentials from your SIP account (user name, password, and server):</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24513831">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/513/831/d1dcbd2c61c9729cf514cead81b2af06_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553356372&amp;gif-q=50&amp;q=92&amp;s=ad45f1b0273373250e07e5128ec77ed7" alt="" data-src="https://ksr-ugc.imgix.net/assets/024/513/831/d1dcbd2c61c9729cf514cead81b2af06_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553356372&amp;gif-q=50&amp;q=92&amp;s=ad45f1b0273373250e07e5128ec77ed7" data-airgap-id="168" /></figure>
</div>
<p>Step 3: Make a Call:</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24541699">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/541/699/4bdbec0ee2d667864d5e3225013ad6af_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553578318&amp;gif-q=50&amp;q=92&amp;s=488d481066e71a4783f5a0975b7d86f9" alt="" data-src="https://ksr-ugc.imgix.net/assets/024/541/699/4bdbec0ee2d667864d5e3225013ad6af_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553578318&amp;gif-q=50&amp;q=92&amp;s=488d481066e71a4783f5a0975b7d86f9" data-airgap-id="169" /></figure>
</div>
<p>That&#8217;s it!</p>
<p><span class="text-italic">Note: we&#8217;re still working through compatibility with various SIP providers since many of them implement the standard in various ways. Once the WiPhones ship we&#8217;ll update our getting started instructions to use the servers we find to be most reliable.</span></p>
<p>&nbsp;</p>
<h2 id="h:what-people-are-sayi" class="page-anchor">What people are saying about WiPhone:</h2>
<p>“This is a great cross over between what people know (phones) and what people really want to do (hack).&#8221; -Nathan Seidle, Sparkfun Founder</p>
<p>“The WiPhone is a really rather neatly put together project.” -Alasdair Allan, Hackster.io</p>
<p>“If you want a phone that respects your right to repair, this is the project to look at.” -Brian Benchoff, Hackaday.com</p>
<p>“So excited by this project I tried to make one myself” -Random Guy On Our YouTube Channel</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24543472">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/543/472/4cb761f641f0009d022cd69a54f4c397_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553595797&amp;gif-q=50&amp;q=92&amp;s=3f82b07a069401df8f7c078a95abb7ef" alt="" data-airgap-id="170" /></figure>
</div>
<p>&nbsp;</p>
<h1 id="h:first-class-expansio" class="page-anchor">First Class Expansion Capabilities</h1>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24541911">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/541/911/3861b2e7c7dfdf688b7bbc718b92151c_original.png?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553580000&amp;gif-q=50&amp;lossless=true&amp;s=d669c40de6e0da86d72904b200e7e533" alt="" data-airgap-id="171" /></figure>
</div>
<p>WiPhone is expandable through daughter boards. The whole back of the phone is a replaceable panel that accepts a standard 1.6mm thickness PCB, which you can use to add whatever functionality you like.</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24545020">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/545/020/239cb3957a5e27694d899dec89c2f183_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553606165&amp;gif-q=50&amp;q=92&amp;s=33ac0a3bc4add4a010f2ce56acbfda88" alt="" data-src="https://ksr-ugc.imgix.net/assets/024/545/020/239cb3957a5e27694d899dec89c2f183_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553606165&amp;gif-q=50&amp;q=92&amp;s=33ac0a3bc4add4a010f2ce56acbfda88" data-airgap-id="172" /></figure>
</div>
<p>&nbsp;</p>
<div class="template asset" contenteditable="false" data-alt-text="Daughterboard PCB Design, Keepout Areas" data-caption="Daughterboard PCB Design, Keepout Areas" data-id="24531375">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/531/375/ba6a85f2b43253a185a4e16151f6cd09_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553523496&amp;gif-q=50&amp;q=92&amp;s=bba564de1873e9b3b463d622c51f8ac9" alt="Daughterboard PCB Design, Keepout Areas" data-src="https://ksr-ugc.imgix.net/assets/024/531/375/ba6a85f2b43253a185a4e16151f6cd09_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553523496&amp;gif-q=50&amp;q=92&amp;s=bba564de1873e9b3b463d622c51f8ac9" data-airgap-id="173" /><figcaption class="px2">Daughterboard PCB Design, Keepout Areas</figcaption></figure>
</div>
<p><span class="bold">Some Examples</span></p>
<p>We made a WiPhone into an RC car:</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24545000">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/545/000/0d6bfaae0497cf0b7c6d0660f0406bbe_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553606039&amp;gif-q=50&amp;q=92&amp;s=06603bd79d14fe6b6cc48dd010a2c210" alt="" data-src="https://ksr-ugc.imgix.net/assets/024/545/000/0d6bfaae0497cf0b7c6d0660f0406bbe_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553606039&amp;gif-q=50&amp;q=92&amp;s=06603bd79d14fe6b6cc48dd010a2c210" data-airgap-id="174" /></figure>
</div>
<p>And we also made the coolest way to ever to answer a phone:</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24544793">
<figure><img decoding="async" class="fit js-lazy-image" src="https://ksr-ugc.imgix.net/assets/024/544/793/c528bbec359944e4a2a8b1801018dcde_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553604903&amp;gif-q=50&amp;q=92&amp;s=1adf9204c1b6b67a26eece41a76a30e4" alt="" data-src="https://ksr-ugc.imgix.net/assets/024/544/793/c528bbec359944e4a2a8b1801018dcde_original.gif?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553604903&amp;gif-q=50&amp;q=92&amp;s=1adf9204c1b6b67a26eece41a76a30e4" data-airgap-id="175" /></figure>
</div>
<p>The daughterboard headers have power, digital I/O, and all the common embedded busses like SPI, I2C, and UART.</p>
<h1 id="h:easy-development" class="page-anchor"> <span class="bold">Easy Development</span></h1>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24529712">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/529/712/7d12ba1dfe13cc7c3ef1533453d3665c_original.png?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553512065&amp;gif-q=50&amp;lossless=true&amp;s=59ec16ec20dd3e229d8ce14c275aadb9" alt="" data-airgap-id="176" /></figure>
</div>
<p>Develop in Arduino/C++ or Python. We&#8217;ll also provide basic tutorials covering how to write to the screen, connect to the hardware, save data to memory, etc.  We&#8217;ll let you give us feedback on what&#8217;s most important to you.</p>
<h1 id="h:no-mess-prototyping" class="page-anchor">No-Mess Prototyping</h1>
<div class="template asset" contenteditable="false" data-alt-text="Build Your Prototype Right On The Back Of The Phone" data-caption="Build Your Prototype Right On The Back Of The Phone" data-id="24241686">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/241/686/8c3708d5a0f83859bc663253c3a94ab8_original.jpg?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1551361066&amp;gif-q=50&amp;q=92&amp;s=bfcff3e1c6f3691fb40091b6c92f50a9" alt="Build Your Prototype Right On The Back Of The Phone" data-airgap-id="177" /><figcaption class="px2">Build Your Prototype Right On The Back Of The Phone</figcaption></figure>
</div>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24544472">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/544/472/4dc09cb787144151c1021ad2ed368eac_original.png?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553602904&amp;gif-q=50&amp;lossless=true&amp;s=b24ac9d1cc51fab5a82fcc72e893ca7d" alt="" data-airgap-id="178" /></figure>
</div>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<h1 id="h:note-based-on-the-ba" class="page-anchor">Note: Based on the backer survey, we&#8217;ll prioritize adding a cellular radio (LTE), and secure communications after the campaign. Back now to get first access to the new hardware as it becomes available.</h1>
<p>See the relevant <a href="https://www.kickstarter.com/projects/2103809433/wiphone-a-phone-for-hackers-and-makers/posts/2480089" target="_blank" rel="noopener">Project Update</a> for details.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>We have big plans for the WiPhone, but we also need to start off on solid footing. We&#8217;ve set a relatively low funding goal of $40k that will let us cover the costs to finish production of the phones themselves and not much more. That way we can get phones in the hands of people that want them.</p>
<p>But there&#8217;s a lot of potential waiting to be unlocked. If we reach $100k of phones, we&#8217;ll have enough of a cushion to thoroughly test the design and ultimately deliver a better product. It will also allow us to start taking on extra work. If we reach $100k we&#8217;ll start letting backers choose stretch goals.</p>
<p>Some stretch goals would add software features to the WiPhone itself. Others will be to take on design and production of daughterboards and other accessories.</p>
<div class="template asset" contenteditable="false" data-alt-text="" data-caption="" data-id="24544626">
<figure><img decoding="async" class="fit" src="https://ksr-ugc.imgix.net/assets/024/544/626/a3aa4450abe695ae88e859e9f531abe1_original.png?ixlib=rb-4.0.2&amp;w=680&amp;fit=max&amp;v=1553603824&amp;gif-q=50&amp;lossless=true&amp;s=a2a908ca9d9bf8347193d3b1cb663b24" alt="" data-airgap-id="179" /></figure>
</div>
<ul>
<li> <span class="bold">Wireless Firmware Updates:</span>Wireless firmware updates will allow you to easily upgrade your firmware.</li>
<li> <span class="bold">Integrated Python Interpreter: </span>Currently we&#8217;ll ship the WiPhone with a separate firmware that allows running MicroPython apps. This stretch goal would allow us to merge the Python interpreter into the main phone firmware to run user apps directly within the phone firmware.</li>
<li> <span class="bold">Remote Desktop: </span>View and control your WiPhone through a webpage.</li>
<li> <span class="bold">Encrypted Communications: </span>Add secure communication to calls and messages</li>
<li> <span class="bold">Threaded Messaging: </span>Add an advanced view to text messages for a more modern chat experience</li>
<li> <span class="bold">Additional Colors: </span>Add some variety to the clear/gray options we have now for face colors.</li>
<li> <span class="bold">Advanced Tutorials: </span>Deeper tutorials than the basic ones we&#8217;ll ship for the basic campaign. We could go step-by-step through writing a complete app, using the phone to build an entire project, or designing a daughterboard from scratch. We&#8217;ll let you give us feedback on what&#8217;s most important to you.</li>
</ul>
<p><img loading="lazy" decoding="async" class="wp-image-14748 alignright" src="https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout.jpg" alt="" width="812" height="513" srcset="https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout.jpg 2337w, https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout-400x253.jpg 400w, https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout-1024x648.jpg 1024w, https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout-768x486.jpg 768w, https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout-1536x971.jpg 1536w, https://goodshepherdmedia.net/wp-content/uploads/2023/06/pinout-2048x1295.jpg 2048w" sizes="(max-width: 812px) 100vw, 812px" /></p>
<article id="post-351574" class="post-351574 post type-post status-publish format-standard has-post-thumbnail hentry category-crowd-funding tag-crowd-funding tag-crowdfunding tag-kickstarter tag-wiphone">
<header class="entry-header">
<h1 class="entry-title">PHONE FOR HACKERS LAUNCHES A CROWDFUNDING CAMPAIGN</h1>
<div class="entry-meta"><span class="entry-date">April 3, 2019</span> by Brian Benchoff 26 Comments</div>
</header>
<div class="entry-content">
<p>Based on the WiFi / Bluetooth wunderchip, clad in a polycarbonate frame, and looking like something that would be an amazing cell phone for 2005, the WiPhone is now available on Kickstarter.</p>
<p>We’ve seen the WiPhone before, and it’s an interesting set of features for what is effectively an ESP32 board with some buttons and a screen. It’s become something of a platform, with expansion daughterboards for LTE, LoRa, a camera, a Bus Pirate, and a programmable NFC/RFID doohickey. If you’ve longed for the day of big ‘ol Nokia brick phones, want to hack your phone, but don’t really care about actually having cellular connectivity, this is something that’s right up your alley.</p>
<p>Although the WiPhone looks like a usable product that was designed by someone with a sense of design, it still is Open Source. You can build your own, and there are dozens of expansion boards that will plug into the back of the WiPhone for prototyping, experimentation, and RGB Gaming LEDs. There’s no cellular modem on the WiPhone, though; for calls you’ll have to turn to SIP or VoIP apps.</p>
<p>Considering how difficult it is to source a cellular modem in small quantities and the desire for a cell phone that respects your Right to Repair, we’ve got to hand it to the WiPhone for creating something people want. It gets even better when you consider this looks more like a product than the 3D printed pieces of electronic cruft we usually see, and we’re happy to see this crowdfunding campaign just passed its goal and is completely funded.</p>
</div>
<footer class="entry-footer"><span class="cat-links">Posted in Crowd Funding</span><span class="tags-links">Tagged Crowd Funding, crowdfunding, kickstarter, WiPhone</span></footer>
</article>
<article id="post-344213" class="post-344213 post type-post status-publish format-standard has-post-thumbnail hentry category-crowd-funding tag-crowd-funding tag-wiphone">
<div class="entry-featured-image"></div>
<div class="entry-mobile-image"></div>
<header class="entry-header">
<h1 class="entry-title">THE WIFI PHONE THAT RESPECTS YOUR RIGHT TO REPAIR</h1>
<div class="entry-meta"><span class="entry-date">February 6, 2019</span> by Brian Benchoff 49 Comments</div>
</header>
<div class="entry-content">
<p>Phones are getting increasingly more complex, more difficult to repair, and phone manufacturers don’t like you tinkering with their stuff. It’s a portable version of a John Deere tractor in your pocket, and Apple doesn’t want you replacing a battery by yourself. What if there was a phone that respected your freedom? That’s the idea behind the WiPhone, and soon it’s going to be be a crowdfunding campaign. Yes, you will soon be able to buy a phone that respects your freedom.</p>
<p>We took a look at the WiPhone a few months ago, and the idea was solid: make a simple, cheap, handheld device based on the ESP32 WiFi/Bluetooth wonder microcontroller. There are a few other various bits of electronic ephemera for scanning the buttons, an audio codec, and a speaker driver, but the basics of the build are just an LCD and ESP32. The entire idea of this phone is to make calls through WiFi, and given the state of VoIP, it’s a marketable product.</p>
<p>Astute readers may notice that the WiPhone doesn’t have a cellular modem. Yes, this is true, but putting a baseband in a small, low-volume project is incredibly hard. You’re limited to 2G if you don’t want to deal with Broadcom or Qualcomm, and they’re not going to be interested in you if you’re not moving a hundred thousand units, anyway. Also, you’ve got service plans to deal with, multi-country radios, and you’re probably next to a trusted WiFi network right now, anyway.</p>
<p>The WiPhone is designed to be hackable, with daughter boards that turn it into a rainbow or RC car, and easy to assemble. It’s also going to be a crowdfunding campaign at the end of the month. If you want a phone that respects your right to repair, this is the project to look at, even if you don’t need a cellular modem all the time.</p>
</div>
<footer class="entry-footer"><span class="cat-links">Posted in Crowd Funding</span><span class="tags-links">Tagged Crowd Funding, WiPhone</span></footer>
</article>
<article id="post-321932" class="post-321932 post type-post status-publish format-standard has-post-thumbnail hentry category-wireless-hacks tag-esp-32 tag-feature-phone tag-nokia-brick tag-open-source tag-open-source-cellphone tag-smartphone tag-wiphone">
<div class="entry-featured-image"></div>
<div class="entry-mobile-image"></div>
<header class="entry-header">
<h1 class="entry-title">THIS HACKABLE PHONE MAKES WIFI CALLS.</h1>
<div class="entry-meta"><span class="entry-date">August 24, 2018</span> by Brian Benchoff 24 Comments</div>
</header>
<div class="entry-content">
<p>Over the years, we’ve seen dozens of projects that sell themselves as an ‘Open Source’ cellphone, a hackable cellphone, or some other confabulation of a microcontroller, screen, and a cellular module. The WiPhone is not one of these projects. That’s not to say it’s not an Open Source phone that’s intended to be hackable. No, this is a DIY phone that doesn’t make cellular calls, because this is a phone that only works with SIP and VoIP apps. It’s a WiPhone, and something a lot of us have been waiting for.</p>
<p>The hardware for this WiFi enabled phone is extremely minimal, but there are some interesting tricks up its sleeve. Instead of letting the main microcontroller handle capturing all the button presses, the team behind the WiPhone are using a SN7326 key-scan controller. This cheap part is able to scan 64 buttons, although there are only 25 buttons on the phone. The audio board is a  WM8750BL, a cheap codec with a stereo microphone interface and a 400 mW speaker driver. The display is a simple SPI TFT, and apart from the microcontroller, that’s about it.</p>
<p>But it’s the microcontroller that makes it, and for that we turn to the incredible ESP-32. This chip has enough power to play Doom, be a Game Boy, and in this case, make and receive calls from a VoIP provider, scan and connect to WiFi networks, and yes, it can even play snake.</p>
<p>While this is just about the simplest phone you can imagine, and it only works where there’s a WiFi network, a device like this could be invaluable. And really, these days how far are you from a WiFi network you’re already connected to anyway? <a href="https://hackaday.com/tag/wiphone/" target="_blank" rel="noopener">source</a></p>
</div>
</article>
<p>&nbsp;</p>
<hr />
<h2>First Class Expansion Capabilities &#8211; People Like The WiPhone Hack It Like It&#8217;s Yours</h2>
<div class="container-fluid">
<div class="row py-3">
<div class="left-column col-10 col-sm-9 content">
<section>WiPhone is built for hacking, not for some big corporation&#8217;s bottom line. Complete disassembly in less than a minute, using only 6 screws. The operating system firmware is easily modified, and simple enough to be understood entirely by one motivated person.Not only is WiPhone capable of completely free calling, it&#8217;s <em>also</em> an open source, self-contained Arduino development platform. Unlike most other dev boards it comes in a nice package, with a battery, power supply, and on/off circuitry. Once your project is done, instead of an eyesore of tangled wires and stacked boards, it&#8217;s compact and visually appealing.<video autoplay="autoplay" loop="loop" width="300" height="150" data-mce-fragment="1"></video></section>
<section>
<div class="section-heading text-center">
<h2>A Phone You Can Own</h2>
<p class="text-muted">(Not One That Owns You)</p>
</div>
<div class="row">
<div class="col-lg-8 my-auto">
<div class="container-fluid">
<div class="row">
<p>Modern smartphones are more and more a tool we don&#8217;t own, but instead one we&#8217;re only allowed to carry around. One that serves the interests of various tracking networks, corporate boards, and government organizations. You don&#8217;t own it, it owns you. It tracks you, serves you ads, and sucks away your time with mindless dopamine hits. <b>We want a phone that&#8217;s back in our control, optimized for our convenience</b>. <a href="https://wiphone.io/" target="_blank" rel="noopener">source</a></p>
<p>&nbsp;</p>
</div>
</div>
</div>
</div>
</section>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
