In short
The 404 Media Podcast: Episode Summary
Episode Title
How to Detect Phone Spying Tech (with Cooper Quintin)
Key Participants
- Joseph: Host of the podcast
- Cooper Quintin: Security researcher and senior public interest technologist at the Electronic Frontier Foundation (EFF)
Episode Overview In this episode, Joseph interviews Cooper Quintin about IMSI catchers, also known as Stingrays or cell site simulators, which are devices used to track mobile phones and intercept communications. They discuss the implications of this technology, the development of Rayhunter—a tool for detecting IMSI catchers—and the importance of understanding the surveillance landscape.
Key Concepts Discussed What is an IMSI Catcher?
- Definition: A device that acts as a fake cellphone tower, tricking nearby phones into connecting.
- Functionality:
- Collects the International Mobile Subscriber ID (IMSI) from phones.
- Can intercept calls and text messages.
- Potential for deploying malware.
Technology Limitations
- Exploits Telecommunications Design: IMSI catchers take advantage of how cell networks are structured, where phones continuously seek the nearest tower without verifying its authenticity.
- Tracking Limitations: While mobile phone companies can provide location data, IMSI catchers can pinpoint locations more accurately.
Use Cases and Ethical Concerns
- Law Enforcement:
- Used for tracking suspects but raises concerns around privacy and civil liberties.
- Potential misuse for mass surveillance during protests or sensitive locations (e.g., abortion clinics, mosques).
- Scams: Criminals also use IMSI catchers to send phishing messages.
Rayhunter Project Development Background
- Inception: Originated from Cooper’s involvement at the Standing Rock protests where there were concerns about IMSI catcher usage.
- Goal: Create an easy-to-use tool for journalists and activists to detect IMSI catchers without needing advanced technical skills.
How Rayhunter Works
- Device: Utilizes modified mobile hotspots to log mobile traffic and identify suspicious activities.
- Detection Method: Looks for abnormal behaviors such as a suspicious downgrade to 2G, which is uncommon in the U.S.
- User Accessibility: Designed to be simple to install and use, making it accessible for non-technical users.
Future Aspirations
- Gathering Reliable Data: Continue collecting data to confirm or dispel fears of IMSI catchers at protests.
- Promoting Awareness: Educate the public about the real threats posed by IMSI catchers compared to other surveillance technologies.
- Encouraging Manufacturer Action: Urge tech companies to integrate stronger protections against IMSI catchers directly into devices.
Conclusion The episode highlights the critical dialogue surrounding surveillance technologies and their impact on privacy rights. Cooper Quintin’s insights and the introduction of tools like Rayhunter empower individuals and communities to safeguard their digital privacy while fostering informed conversations about technology misuse.
Additional Resources
- [Rayhunter GitHub Repository](https://github.com/EFForg/rayhunter)
- [YouTube Conversation](https://youtu.be/vEFPPaOn0ts)
This summary encapsulates the main points and discussions from the podcast, providing a clear understanding of the topics covered regarding IMSI catchers and the efforts to combat their potential misuse through technical means.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding IMSI Catchers
1:42 to 3:02
Discussion on what IMSI catchers are and how they function.
“So I don't know if everyone is going to be really aware of what an ImsiCatcher is, a Stingray, a CellSite Simulator.”
Telecom Security Exploit Mechanics
3:02 to 3:54
Explaining how telecom networks can be exploited by IMSI catchers.
“your name, your address, and all of that stuff.”
Capabilities of IMSI Catchers
3:54 to 4:50
Exploring the various capabilities of IMSI catchers beyond tracking.
“Because the phone company has to know what towers you're connected to, to locate you, to be able to send you messages most efficiently.”
Concerns Over IMSI Use
4:50 to 6:10
Discussing potential misuse of IMSI catchers for surveillance.
“There's no getting around the fact that your cell phone is constantly tracking you and that MZ catchers can take advantage of that because there are so many messages, right?”
Criminal Use of IMSI Technology
6:10 to 7:20
How criminals are using IMSI catchers for scams and attacks.
“Like, are these capable of doing anything else?”
Law Enforcement vs. Criminal Usage
7:20 to 8:30
Comparison of law enforcement and criminal use of IMSI catchers.
“just shortly before we were recording this, WebLock is this tool that ICE has bought, which uses location data probably sourced from the ad ecosystem.”
History of IMSI Catchers
8:30 to 10:10
The origins and evolution of the term 'Stingray' in telecom tech.
“And that, to me, that is much more concerning if police are just using MC catchers to, you know, find a kidnapped person, right, or to, like, find somebody who is accused of murder, right?”
Cultural Impact and Terminology
10:10 to 14:04
The cultural significance of the term 'Stingray' and its usage.
“I don't know what the ultimate financial...”
Understanding the Stingray Phenomenon
14:04 to 15:40
Learn about the evolution and public perception of Stingray devices.
“Federal law enforcement, the FBI, DOJ had had MC catchers before that.”
The Scary Use Cases of Cell Site Simulators
15:40 to 17:41
Discover alarming potential uses of cell site simulators in espionage.
“Because as you say, it could be also for messages and calls.”
Show all 21 chapters
The Legal Landscape for IMSI Catchers
17:41 to 21:08
Explore recent legal changes affecting the use of IMSI catchers by law enforcement.
“Before we get to sort of what we've seen over the years, I guess just because you brought up ICE, what do you think they could plausibly use it for?”
The Shift in IMSI Catcher Manufacturers
21:08 to 22:14
Learn about the companies currently manufacturing IMSI catchers and their market impact.
“So now Harris only sells to federal law enforcement and they no longer sell to local police departments.”
The Evolution of Cellular Technology and Exploits
26:45 to 28:00
Understand the cat-and-mouse game in cellular technology advancements and exploits.
“Here, there's, well, we've moved to 3G, then the IMSI catches need to deal with that, then 4G, then 5G.”
Understanding Cellular Security Vulnerabilities
28:00 to 31:40
Learn about the vulnerabilities in various generations of cellular technology and their implications.
“And because it's a standard when exploits are found, they're slow to get patched.”
Introduction to Ray Hunter Tool
31:40 to 36:35
Discover the origins of the Ray Hunter tool and its purpose in detecting IMSI catchers.
“because you have all of that context from cell site simulators.”
Field Research on IMSI Catchers
36:35 to 42:00
Explore findings from the Ray Hunter project regarding the use of IMSI catchers at protests.
“you know, last generation mobile hotspot.”
Concerns About MCCatchers at Protests
42:00 to 43:16
Learn about the misconceptions surrounding the use of MCCatchers at protests and the need for accurate threat modeling.
“And a lot of people were very concerned about MCCatchers being used at protests, right?”
User-Friendly Installation of Detection Tools
43:16 to 45:28
Discover the simplified installation process for detecting cell site simulators and the goal of increasing accessibility.
“that activists do need to start being worried about yeah that makes sense i will just say before I ask, I think probably my last couple of questions is that I have installed this myself.”
Challenges in Tracking MCCatchers
45:28 to 46:57
Understand the difficulties of physically tracking down MCCatchers and the significance of accurate data.
“And, you know, we're trying to minimize the number of false positives so that when people get an alert, they can feel, you know, pretty confident in something.”
Future Aspirations for MCCatcher Awareness
46:57 to 49:50
Explore hopes for decreasing fear around MCCatchers while simultaneously increasing awareness of other surveillance technologies.
“I think one of the things I really liked about the Crocodile Hunter project was that we could actually physically track down cell site simulators.”
Technological Protections Against MCCatchers
49:50 to 52:40
Learn about current technological advances aimed at protecting users from MCCatchers and the role of device manufacturers.
“And Google has already done a really great job of this.”
Transcript
Automatic transcript. May contain errors.0:05Cooper Quintin:Hello, and welcome to the 404 Media podcast, where we bring you unparalleled access to hidden worlds both online and IRL. 404 Media is a journalist founded company and needs your support. To subscribe, go to 404media.co. As well as bonus content every single week, subscribers also get access to additional episodes where we respond to their best comments. And they get early access to our interview series too, like this episode. Gain access to that content at 404media.co. This week, I'm speaking to Cooper Quinton, a security researcher and senior public interest technologist with the Electronic Frontier Foundation.
0:49Cooper Quintin:Cooper has done a lot of work looking into IMSI catchers, or as you'll hear us talk about, Well, maybe we should probably actually describe them as cell site simulators. These are these small devices that pose as a phone tower to then sweep up information about nearby mobile phones. Cooper has helped develop this tool called Ray Hunter, which allows people to detect if maybe there is an IMSI catcher or a cell site simulator around me somewhere. This is a really, really interesting conversation that gets much more in the weeds than I think a lot of coverage would. So I'll throw it to the interview and I really, really hope you enjoy the conversation.
1:41Cooper Quintin:Cooper, thank you so much for coming on the show. Really, really appreciate it.
1:46Joseph:Yeah, really excited to be here. Of course.
1:48Cooper Quintin:So I don't know if everyone is going to be really aware of what an ImsiCatcher is, a Stingray, a CellSite Simulator. I don't say that one that often. That's why it's a little bit tricky to get out. How about to get the conversation going? Could you just tell us what is an ImsiCatcher and how does it work exactly?
2:13Joseph:Yeah, for sure. So Stingray, Cell Site Simulator, and MC Catcher are terms that are often used interchangeably. And they pretty much all mean the same thing. It's usually a fake cell tower that police are able to use to trick your phone into connecting to it instead of the real cell tower. And this is usually used to find the identity or MC of your phone. MC stands for International Mobile Subscriber ID. This is a unique ID that's used by your SIM card to identify it to the base station, to the tower, right? And to the phone company for the purposes of billing, most importantly, in their eyes.
2:50Joseph:Every phone has an EMSI. Every SIM card has its own unique EMSI. And this can uniquely identify you. So once your phone connects to an EMSI catcher, the police get your EMSI. and then they can go bother the phone company until they give the police your subscriber details, your name, your address, and all of that stuff. Right.
3:10Cooper Quintin:So it's funny because as with a lot of stuff in telecom security, the way these networks are exploited or attacked in various ways often comes down to simply how telecommunications networks work, right? Like this is able to function as a fake cell phone tower because phones simply in virtue of how they work are always trying to talk to a cell phone tower that's nearby or I guess the nearest free or something like that. Is that fair?
3:42Joseph:Yeah, that's completely fair. Yeah. MC catchers really just take advantage of how the cell phone network was designed to work. Right. Right. Your phone is, to a degree, always tracking you. Right. Because the phone company has to know what towers you're connected to, to locate you, to be able to send you messages most efficiently. Right. So if you get a text message, there's two ways to wrap this to you. Right. There's there's one is to send that text message to every cell tower in the United States. Right. And everybody tries to read it and sees it's not for them and then discards it. right or the you can with your mz let the phone company know what you know what part of what region you're in and then the phone company can send route the message to that region right and so like you're always connecting to the towers you always have this unique id and there's really no way to get around that you always have to have an mc right some phone companies there's a couple of interesting companies out now that are doing interesting things like rotating your mz those are interesting ways to sort of get around that issue.
4:44Joseph:But in general, especially with the big three now, AT &T, Verizon, and T-Mobile, right? There's no getting around the fact that your cell phone is constantly tracking you and that MZ catchers can take advantage of that because there are so many messages, right? Your phone is always looking for the strongest. Your phone is always looking for the best connection, right? And it is happy to connect to a new tower that pops up, especially if that tower looks stronger than the other surrounding towers.
5:12Cooper Quintin:Which is what a cell site simulator will do, right? Does it look like the strongest tower nearby?
5:18Joseph:Yeah, that is often what they do, is they'll look like the strongest tower nearby, or they will advertise themselves as available, advertise other towers as not available. They will pretend to be another tower that you're really connected to, and they can send a message that looks like it's from that tower that says, hey, please disconnect from me right now and rejoin on this other tower, which is also from the MC catcher, right? So they can trick your phone into connecting to it that way. And then there's all these messages that your phone sends to the tower and the tower sends back to your phone without any sort of authentication ever happening, right?
5:51Joseph:And some of those messages can contain your MC and the tower can specifically request your MC and the phone happily gives up that information.
5:59Cooper Quintin:Right, totally. And I think we'll get a little bit more into this in a minute, But broadly, what are some of the capabilities beyond just grabbing an IMSI? Like, are these capable of doing anything else?
6:13Joseph:Yeah, absolutely. So the purported use of IMSI catchers is to track down a specific person, right? The reason police say they need these is for like a manhunt, right? Or, you know, locating somebody who's been kidnapped, right? Or search and rescue operations, things like that. And they are useful for that, right? The cell phone company can give you somebody's location, but only down to, at best, 150 meters, and not any sort of verticality. If somebody's in a big apartment building, what the MC catcher can do is really track them down to the specific apartment they're in. This is the most fine-grained location data, and it's the most accurate.
6:55Joseph:You can always get it. You're not always going to get data from... There are a lot of other location things. Like I said, you can get location from tower pings, from phone companies. You could get location from a tool like Penlick, from WebLock. But people aren't always going to be in the WebLock database. The phone pings aren't always going to be the most accurate. With a tool like an MCCatcher, you can always very accurately locate somebody.
7:18Cooper Quintin:Yeah. And for those who may not have read this piece that we published actually, just shortly before we were recording this, WebLock is this tool that ICE has bought, which uses location data probably sourced from the ad ecosystem. But what you're saying here, of course, and absolutely correct, and ImsiCatcher is so much more powerful because it's using much more of the telecommunications backbone than, I don't know, is this person maybe in this advertising data set? Like, who knows?
7:44Joseph:Right, right. Exactly. Exactly. And you can't fool it by turning off location services, right? Or not having any apps on your phone that are not giving location data to any apps that have ads, right? The MC catcher will still work. The other concerns, though, with an MC catcher, the concern is that you could use it, for example, to identify who is in a particular location, right? So the theory, and we haven't seen any examples of this, to my knowledge. But the theory is that police could sit outside of a protest, right, and gather up all of the identities of the people going to that protest or sit outside of an abortion clinic or sit outside of a mosque, right?
8:26Joseph:Anywhere where they want to identify all of the people in that area. And that, to me, that is much more concerning if police are just using MC catchers to, you know, find a kidnapped person, right, or to, like, find somebody who is accused of murder, right? I could still find issues with the way they're using it, but if they're getting a warrant and they're only using it for that and they're minimizing the data, I have bigger fish to fry. But if they are using this to surveil free speech, if they're using this to figure out who is engaging in their constitutionally protected right to protest, that's a problem.
9:03Joseph:Another problem is that because of the way MC Catchers work, they could be used and have been used in the past, we know for sure, to man-in-the-middle calls and text messages, which aren't encrypted, right? So you could use these to listen in on people's calls, read people's text messages. One of the ways that they're commonly used right now, not by police, but by scammers, is to send people text messages from, you know, quote-unquote legitimate phone numbers, right? So there was a story, I think a couple of years back now, about a woman who was driving around France and got pulled over and they saw some weird equipment in the back of her car, called out the bomb squad.
9:40Joseph:Bomb squad came out and called out the IT guys, right? And it turned out that it was actually an MC catcher in the back of her car.
9:47Cooper Quintin:We've had similar in Southeast Asia recently as well, I think. Yeah. Where they just drive around with these cars with an MC catcher in it.
9:54Joseph:Yeah. Yeah, exactly. They drive around and they broadcast text messages. In the France case, it was. from the French health ministry, right? Claiming to be from the French health ministry, just SMS scams, right? Like trying to phish people's health logins, I guess, out of them. I don't know what the ultimate financial... Right. I mean, this isn't America, right? Like there's universal healthcare. So I don't know what you're seeking to get in that case.
10:22Cooper Quintin:But that brings up something interesting in that obviously at the same time, the technology is sophisticated in that law enforcement agencies are using it, that sort of thing. And then on the flip side, it's really not that sophisticated in some cases because somebody's driving around with a car. It just shoved in the back, like almost common criminal level. So is there a disconnect there where maybe the law enforcement people have the more sophisticated one, I imagine, and the criminals have something else, you think?
10:52Joseph:I think so. I mean, I think it's different use cases, right? But like the, and I mean, you can build an MC catcher right now with a$20 software defined radio.
11:05Cooper Quintin:I've done just that. Maybe I'll put a link to that in the show notes as well. But yeah, I can't remember who published it. Someone published a guide and I followed it and just wrote about it. But it's crazy cheap and easy to do it on a very crude level.
11:17Joseph:Yeah. Yeah, exactly. And so I think that what police are really paying for, right, is more powerful radios and perhaps more sophisticated attacks and also, most importantly, tech support, right? Right. Somebody puts all of this in a truck, right, puts 13 high-end$1 ,000 software-defined radios in it, provides all this really nice, easy-to-use software, and maybe some more sophisticated exploits, but then also gives them tech support. And I think that's really, you know, I mean, the contracts that police are signing for these are close to a million dollars, right? Like that's the contract that ICE just signed was for 900 and something, 900 something thousand dollars, right?
12:03Joseph:A lot of the contracts that we've seen are for close to a million dollars. Like that's a pretty standard rate for a truck filled with software-defined radios that are acting as an MC catcher.
12:13Cooper Quintin:Right. And you're totally right in that. it's mostly the tech support, the customer support, where law enforcement want to buy a tool that works. They don't want to be going, oh man, I better log into my Ubuntu terminal to figure my software to find... They don't have time for that. They might be trying to locate people who they think are undocumented. They might be trying to locate somebody who's actually been kidnapped and is missing or something like that. They don't want to be messing around with a terminal.
12:42Joseph:Yeah, exactly. They're not trying to fix their Python dependencies and, you know, install PIP and do all of that, right? They're not going to go out and learn C and C++, you know.
12:53Cooper Quintin:Exactly. And of course, that's a common thing across the surveillance industry where even with the malware stuff is much more about the company providing a service. And that kind of, I'm going a little bit back in time, but that brings up the idea of Harris, right? Where the name Stingray comes from. And I feel like fewer of us use the word stingray now because it was a much more popular term 10 years ago. Can you just explain sort of where that term came from and sort of why we called it that at the time?
13:22Joseph:Yeah, for sure. So that term, that was a brand name from a company called Harris Corporation. L3 Harris Corporation, which still exists and still makes lots of equipment for police and national security and all those. They actually also bought a cybersecurity company called Azimuth, interestingly, recently, which is interesting and might signal a shift to offensive cybersecurity. But that's another story. So the Stingray was their first really big—it wasn't the first MC catcher. But it was the first one that really got a lot of attention and was really widely used by local law enforcement, right?
14:04Joseph:Federal law enforcement, the FBI, DOJ had had MC catchers before that. Triggerfish, I think, was a really early one that was used to catch the hacker Kevin Mitnick. But the Stingray was the first one that was bought by local police departments, SFPD, NYPD, Chicago PD. And the first one that really caught on in the public imagination, the first one that people really started looking into. And so, you know, it almost became sort of the Kleenex, right? I think there's a term for this phenomenon that I forget at the moment, right? But it became the Kleenex of MC catchers, right?
14:42Cooper Quintin:Or the Google, like that becomes a verb. Yeah, exactly.
14:45Joseph:It became a verb. Every MC catcher is a stingray. You're going to get stingrayed, right? Right, right. Yeah, it became very common. And then like a lot of us in the space, right, started trying to use the term cell site simulator to be like slightly more pedantic and accurate. But I think actually Stingray still resonates with a lot of people. When I talk about this often, I'm like, who's heard of a cell-side simulator? Nobody. Who's heard of an ImsiCatcher? Maybe a couple people. Who's heard of a Stingray? Oh, yeah. Right. Everybody raises their hands.
15:15Cooper Quintin:Yeah. I mean, it's a catchy name. And it does resonate with people and it sticks with them. And I should... I mean, I actually haven't covered ImsiCatchers really recently. You know what I mean? Just like I kind of did that back then and kind of been focused on some other stuff. But next time I do, I'm going to try to say cell site simulator because even IMSI Capture doesn't capture the full capabilities of the tool. Because as you say, it could be also for messages and calls.
15:42Joseph:Yeah, it doesn't. It really doesn't. There was another actually really interesting, really, really kind of scary use of cell site simulators, which was that there was a report from Amnesty International that some gentleman who had had NSO Group's Pegasus spyware installed on his phone, they thought that it was incredibly likely that this had been installed via use of an MC catcher. Right? Via use of a, sorry, not an MC catcher, but a cell-side simulator. It's okay.
16:10Cooper Quintin:We can use them interchangeably. Yeah. The listeners will know what we're talking about.
16:15Joseph:But this is the, right, why those terms don't quite encompass it. because this technology wasn't just catching his MC, right? It was capturing his entire connection and man-in-the-middle-ing it and then redirecting some plain text query he made to a query to download NSO Group's spyware. Yeah. I think that that, especially in military contexts, I don't think that's an unlikely usage for this. I don't think that that's something that ICE is necessarily going to be doing right now. I certainly don't think that's something that your local police department are going to be doing, right? But like, that is something that can be done, right?
16:57Joseph:And that like at the sort of nation state espionage level, that is a concern.
Read the full transcript
17:03Cooper Quintin:Yeah, absolutely. And of course, even before local police, or maybe it was the same time, it was kind of such a long time ago, but IMSI catchers, cell site simulators, of course, were being flown in aircraft above literal war zones like Afghanistan and Iraq, whereas it is used as a surveillance weapon of war. And probably to, you know, in use cases that some people might see as more legitimate than others, like, I'm not going to go down that role. But what I'm trying to say is that I think you're right in that ICE isn't going to be using an IMSI catcher to deliver malware, because that's, I mean, that's very expensive as well.
17:41Cooper Quintin:Yeah, absolutely. Before we get to sort of what we've seen over the years, I guess just because you brought up ICE, what do you think they could plausibly use it for? And the thing that comes to mind for me is I think there was a BuzzFeed news report a long time ago, or maybe it was another outlet, where an Imsy catcher was used to track down somebody that enforcement of removal operations were actually trying to find. what could you see more plausibly ICE using this sort of technology for if it's not delivering malware?
18:16Joseph:Yeah, there was actually a more recent case and I think I want to say Forbes reported on it where ICE used an MC catcher to track down somebody in Orem, Utah. Right, yes.
18:33Cooper Quintin:From Tom Fox Brewster, you're right, yes.
18:35Joseph:Yes, that's right. Yeah, yeah, yeah. Shout out to Tom. great journalist um so yeah yeah they so they had recently used used it for that right and it's interesting case because i was in the court documents they say you know we had gotten this guy's home address from cellular records right we figured he was at home because of the time of day and like we we went and did visual inspection and his car was in the driveway and then we got out the mc catcher just to make triple sure that he was actually at home a little bit of fun yeah Yeah, just like, well, we got to use this thing, right? And we got the warrant, so why not?
19:12Joseph:The interesting thing about MC catchers is that, and I think the reason they've fallen off from sort of being the thing that everybody is concerned about and that a lot of research is going towards, is because in, I want to say 2020, there were some legal cases that resolved in that law enforcement would need to get a warrant to use an MC catcher. And before that, they were often, it seems, being used without getting a warrant, right? And then courts decided, no, you actually do need to use a warrant for this. This is a general search, right? And I think that ever since then, police departments are using MC catchers a lot less, or maybe, you know, really only for their intended purpose or just to justify the fact that they bought it, right?
20:01Joseph:Like, that use by ICE almost seems like just a justification. Like, you're like, well, we bought this thing. We got to use it. Otherwise, you know, we're not going to be able to buy one again. Right.
20:13Cooper Quintin:Right. I mean, can you briefly just touch on that? Because I was going to ask where there was this time, as you say, where these local police didn't meet a warrant and they were sort of just going around and using these. Can you remember or do we know sort of what cops were using them for then before the warrant requirement came in? Is it sort of everything we've been speaking about already?
20:37Joseph:Unfortunately, we don't because there's been so much secrecy around Imsi catchers and how they're used, right? And I mean, that's been one of the big problems for years is that like, especially with Harris, right? Harris would encourage police and DAs to drop cases if it seemed like evidence acquired from an Imsi catcher was going to come up in court because Harris really did not want their information, their trade secrets, right, being revealed in court. And actually, Harris has stopped selling to local law enforcement because this kept happening so much that MC catchers kept coming up in court and information kept getting leaked about how they work through this method.
21:20Joseph:So now Harris only sells to federal law enforcement and they no longer sell to local police departments. And it seems like maybe they're even getting out of the game entirely. The recent purchases that I've seen for MC catchers tend to come more from a company called Jacobs, which bought a company called KeyW. That was a big MC catcher manufacturer. And the other one that I'm seeing a lot is Octastic.
21:45Cooper Quintin:I've literally never heard of these. So Octastic is an Israeli company.
21:51Joseph:Yeah, no, super crazy name. So Octastic is an Israeli company that's now selling MC catchers that they claim operate natively on 5G. And so, yeah, we're seeing really like Harris is no longer, you know, seems to not really be in the market at all anymore. And these other smaller players have come and taken that over in the US. But yeah, we don't know what they were being used for, right? I mean, you know, we can, I think, assume that they were being used for all the things I mentioned, right? Being used to intercept calls, being used to locate people, right? Being used to determine presence in a specific area.
22:27Joseph:I think all of those are very likely.
22:37Cooper Quintin:A thoughtfully built wardrobe really comes down to pieces that mix well and last. Instead of chasing trends, I've been trying to simplify things. Fewer items, better quality, stuff that works year round. That's where Quinz has really stood out to me. They make everyday essentials that feel effortless to wear and dependable as the seasons change. I've been rotating through their lightweight cashmere sweaters, linen shorts, and Pima cotton tees, the kind of versatile pieces that actually make getting dressed easier. The fabrics are the real difference. Their cashmere is 100 % Mongolian, the same material luxury brands use.
23:12Cooper Quintin:The Pima cotton is long staple, so it stays soft and doesn't pill. And the European jersey linen is breathable and lightweight, which is perfect once the weather warms up. Quince works directly with top factories and cuts out the middlemen. So you're not paying for retail markups, just quality clothing that holds up to regular wear. Quince has quickly taken over my wardrobe. As spring begins here in LA, I've stocked up on some nice heavyweight t-shirts to go with my sneakers, a sweater, and a linen button down that's also in my rotation. Stop overcomplicating your wardrobe. You don't need a closet full of options.
23:45Cooper Quintin:You need a few pieces that actually work. Right now, go to quince.com slash 404media for free shipping and 365-day returns. That's a full year to build your wardrobe and love it. And you will. Now available in Canada too. Don't keep settling for clothes that don't last. Go to quince.com slash 404media for free shipping and 365-day returns. quince.com slash 404media. What's the latest trend in hiring? skills-based hiring, which emphasizes capabilities over education and direct experience. Someone can have a resume or education that looks good on paper, but can they actually do the job? That's what you need to focus on.
24:27Cooper Quintin:Well, if you're an employer who's adopted skills-based hiring, the best way to ensure that your applicants have the right skills is ZipRecruiter. ZipRecruiter recommends smart screening questions to help you hone in on that perfect match for your role. And right now you can try it for free at ZipRecruiter.com slash 404media. ZipRecruiter's powerful matching technology finds qualified candidates fast. And you can easily put ZipRecruiter screening questions into your job post so you get high quality applicants who are actually available and actively looking on the site. No wonder ZipRecruiter is the number one rated hiring site based on G2.
25:03Cooper Quintin:Let ZipRecruiter help you find amazing candidates with the skills you seek. Four out of five employers who post on ZipRecruiter get a quality candidate within the first day. And now you can try it for free at ziprecruiter.com slash 404media. That's ziprecruiter.com slash 404media. Meet your match on ZipRecruiter. At some point, every side hustle hits that moment. You're not just selling to friends anymore. Orders are coming in. People you don't know are buying your stuff. And suddenly you realize this might actually be a real business. That's the point where you need tools that can keep up. That's when you need Shopify.
25:40Cooper Quintin:Shopify powers millions of businesses worldwide and about 10 % of e-commerce in the US. From major brands to people launching their first store to, of course, 404 Media. With Shopify, you can quickly and easily take yourself from side hustle to real business by building a professional storefront with ready-to-use templates that match your brand. And using Shopify, you can run email and social campaigns so customers actually find you. Plus, Shopify handles everything behind the scenes. Payments, inventory, shipping, analytics, all in one place. And that iconic purple ShopPay button helps customers check out faster, which means fewer abandoned carts and more completed purchases.
26:17Cooper Quintin:It's time to turn those what-ifs into... With Shopify today. Sign up for your$1 per month trial today at shopify.com slash media. Go to shopify.com slash media. That's shopify.com slash media.
26:44Cooper Quintin:you mentioned 5g just there and as before we start to move to the second section i just wanted to bring up this sort of there's this cat and mouse dynamic right not as much as the exploit industry where an so group or whoever will make or buy an exploit then google or apple will patch it and that just goes on and on and on forever, essentially. Here, there's, well, we've moved to 3G, then the IMSI catches need to deal with that, then 4G, then 5G. What is going on there? Like, do they break 5G? Do they downgrade a target? Like, what's happening there as far as we know?
27:20Joseph:Yeah, for sure. I mean, the issue with cellular networks, right, the core issue here is that cellular standards are governed by a body called the 3G PPP, the 3G public-private partnership. And this is a standards body consisting of like hundreds of large companies, all of the largest companies, right? All of, you know, representatives from various governments that all have to come to an agreement on how cellular technology will work. And then they publish a, you know, thousand page standard on how, you know, 3G or 4G or 5G is going to work. And then the phone companies only sort of follow it. And so because it's such a complex standard that's designed by committee and has to work everywhere and is only barely followed, right, this leaves a lot of room for exploits, right?
28:10Joseph:And because it's a standard when exploits are found, they're slow to get patched. Really, like, often you can't patch them until the next generation of cellular technology, right? And you have to keep supporting all the previous generations of cellular technology because people will still have phones that only work on 2G or only work on 3G or only work on 4G. So, for example, with 2G, MC catchers were really easy to build because in 2G, the phone had to authenticate itself to the network as being a real subscriber using its MC. But the network never had to authenticate itself to the phone. so you could very easily set up an entire man in the middle situation to listen to all the phone calls and read the text messages and all of that in 4g one of the big innovations other than you know speed and and and that stuff is that the phone and the network now had to mutually authenticate each other right but unfortunately all of that mutual a lot of messages get sent including the IMSI before that mutual authentication ever happens, right?
29:16Joseph:And a lot of messages are just not authenticated. So it's not like HTTPS, where, you know, when I visit a website, every, you know, as soon as I don't send anything to that website until that website verifies its authenticity, and then we establish a encrypted tunnel to communicate over, right? It's more like there's a bunch of unencrypted stuff that happens. And then after that, some encrypted stuff might start happening, but the phone and tower can still send unencrypted, unauthenticated packets to each other. So this is how like even on 4G, a cell site simulator can spoof a tower and say like, hey, please disconnect from me, this tower that I am, and connect to this other tower that's over here.
30:03Joseph:That's way stronger. Trust me. It's a mess. you know that's what it sounds like it's a huge mess yeah it's a huge mess and so 5g fix a lot of those problems it is definitely a step up from 4g right now the the mc is always sent encrypted right or it is it is always like the the actual mc which is called the i think it's the subscribed user permanent identity and the subscribed user concealed identity something like that i might be messing up the su part but it's permanent identity concealed identity so the permanent identity is the analog to the MZ. And then the concealed identity is changed each time and derived from a key that both the user and the tower have.
30:44Joseph:And this is the only one that's ever sent in 5G. So police are still able to use MZ captures over 5G by downgrading users to 4G, right? That has been the case for a bit. But also there was actually just a paper that was released at Black Hat this year, the big hacker conference in Las Vegas, the big cyber, I shouldn't and call it a hacker conference, the big cybersecurity industry conference in Las Vegas. There was a paper this year called 5G Titanic where a researcher demonstrated the ability to man in the middle conversations in 5G. So I think it's curtains for 5G, man.
31:21Cooper Quintin:Yeah, yeah. So we already need to jump to the 8G or whatever, but it's exactly that dynamic where there are improvements and then we find more vulnerability. I mean, and that's just cybersecurity and offensive security as well. Absolutely. Yeah, it's just the same thing here. Well, let's shift gears a little bit and let's talk about Ray Hunter because you have all of that context from cell site simulators. You've helped build and release this tool. Could you first just tell us where the idea for it came and then maybe tell us what it is? How did this actually come about, first of all?
31:59Joseph:Yeah, for sure. So I actually had a previous project called Crocodile Hunter, and we named it Crocodile Hunter because stingrays had killed Steve Irwin, and we were going to take one back for Steve. So basically, I had gotten excited about MCCatchers after I got asked to come out to the Standing Rock Reservation in North Dakota during the No DAPL pipeline protests. This was a Dakota Access Pipeline. It was a big oil pipeline that was going to cut across Indian land and go all the way across the U.S. and leak oil all over the place and be generally horrible for the environment. The protesters there were worried about MC catchers and had some apps that were telling them that maybe MC catchers were present.
32:43Joseph:So I went out there to go see if I could corroborate this, right, because I'd be concerned about that. And what I figured out quickly was that I had no idea what I was doing. and I had no idea how to actually tell if there was an MC catcher. I had some apps that were saying some things that maybe could be MC catchers, maybe could not be MC catchers. I had some software-defined radios I really had no idea what to do with. And I realized that we needed a better method to actually determine if MC catchers were being used and actually prove it. So we started out with a project called Crocodile Hunter, where the idea was that using some high-end software-defined radios and some programs I had written on Linux.
33:25Joseph:We could take these around and map out all of the cell networks in a specific area and then look for any anomalies, any changes, right? Cell towers that are moving, cell towers that are not where they should be, right? Cell towers that are broadcasting an extremely high, you know, signal, extremely high volume, basically. And then we could actually physically track those down, right? And look at them with our eyes, right? And if it's an established cell tower that's 200 feet high, that's probably fine. It's probably just misconfigured. If the signal is coming from the back of an unmarked truck and four dudes with buzz cuts jump out, that's probably a good sign that it's an MC catcher.
34:04Joseph:The problem with this is that it was a great system for me. It was a really good system for somebody who compiles their own kernel for fun and likes to program in C and C++ and is a huge nerd. but i really wanted journalists and activists to be able to use this on their own because i can't be everywhere all at once right and most journalists for good reason don't have the same amount of technical acumen that say for example you do joseph i mean maybe but i also don't have much time
34:39Cooper Quintin:right whereas you are already an expert and you can kind of jump into it i right i i simply can't
34:46Joseph:do that yeah yeah i mean that that was the other problem right is that the few journalists who did use this right like i needed to be there as backup to actually interpret the results right because they weren't easy to interpret it so we we kind of scrapped this idea also it required you know at least a thousand dollars worth of of software defined radios which is you know really unaccessible so i scrapped this idea and went back to the drawing board and then a friend of mine Matthew Garrett showed me this device, this little Orbit hotspot, right? And this was a couple of years later. And he said, hey, you know, I've rooted this device.
35:21Joseph:And it turns out it has this Diag protocol on it, which I bet you could use to get a log of the mobile traffic, right? The traffic going between the modem and the tower itself. And I thought, oh, that's interesting. And so I started taking a look at it, right? And it turned out that we can. So Qualcomm chips, Qualcomm is one of the big cellular motor manufacturers and their chips have this built-in diagnostic protocol that on a rooted device you can access and it'll give you raw you know packet logs of the control data going back and forth between the device itself and the tower that it's connected to and so what we decided was that we could turn this device into sort of a you know intrusion detection system or you know uh uh antivirus for mc catchers right right so so by looking at that traffic we can look for the things that mc catchers that one might expect mc catchers to do right so this is what became ray hunter um and it's because it's called ray hunters we're again hunting for stingrays um we had cooler names in mind but they were all trademarked so ray hunter is what it came to be.
36:34Joseph:But yeah, you go by a older, you know, last generation mobile hotspot. They're like$20,$10 on eBay. You installed our custom firmware on it. You throw it in your pocket and you go about your day. When it detects something, there's a little green line at the top of the screen. That line turns red if it detects something. And then you can connect to the hotspot, connect to the web interface and go download the files, the packet captures and send them to us or send them to another friend who's really into LTE for further analysis, right? But we have some signatures to detect what we think are signs of an EMSI catcher.
37:13Joseph:And this is things like, did the tower request your EMSI when it shouldn't have? Or did the tower try to downgrade your connection to 2G in a way that's suspicious, right? And other things like that. Those are the sorts of things we're looking for. kind of really obvious signs or not obvious but like you know really high quality signs of mc
37:32Cooper Quintin:catchers yeah like a 2g downgrade is very very unusual for a normal tower yes yeah especially
37:43Joseph:in the us where there are no more we've shut down our 2g networks in the us right so if you see a 2g downgrade in the us that's a pretty strong sign that something weird is going on right Right. The IMSI one, unfortunately, is much harder to get right because, like I've said, the cellular network is bad. It was designed by hundreds of companies, all with competing interests, right? And it turns out that towers request your IMSI fairly often for legitimate reasons. So if we just naively notified you every time your MC was requested, this would cause a lot of false positives. And it did when we first started this, right?
38:19Joseph:And we've had to figure out smarter ways to determine when a request looks suspicious. So we have a few goals with this project. One is to get a better understanding of how MC catchers work in the U.S., right? One of the problems with MC catcher research is that we've never had a ground truth, right? We've never had baseline data about how MC catchers work. And now for the first time, we have actual packet captures from actual MC catchers, like confirmed commercial MC catchers. And we can say exactly how they work on a very technical low level.
38:55Cooper Quintin:Right, because you never had packets before. And I know we're kind of glossing over that, but kind of to spell it out for listeners, packets are almost like the ground truth of what is happening. I'm trying to think of a way to make it accessible at the same time but it's the gold dust basically of cyber security or security research and that sort of thing you want packets basically it shows what's actually going on
39:19Joseph:exactly, it's the raw
39:25Joseph:stenographic court log of exactly what two computers said to each other this is something that I can pass to another researcher I can have my own interpretation of it, but I can pass it to another researcher and they can confirm or disprove my interpretation. But we're all working from the same ground truth, and that's not something that we've had in the past. So that's huge. One of the other goals of this was to get something that people could actually use and bring with them, right? Like, this is something that's really easy for a journalist to use. It's really easy for activists to use, right?
40:02Joseph:The hardest part is, you know, opening a terminal on your computer to actually run the program to install it on the device. But once that's done, right, it's something you just throw it in your pocket and go about your day and see if the line turns red. And so that's been great. And because it's so cheap, a lot of people can use it all over the country. This lets us get to our other goal, which is we wanted to find out whether MCCatchers are being used to surveil First Amendment protected activities like I was talking about earlier. So we want to know if these are being used at protests or being used at mosques and abortion clinics.
40:39Joseph:And as we've had people carrying these around, what we've found is no evidence to support that MC catchers are being used at protests in the US. We have found several instances that we think are likely to be MC catchers, right? In the US and also outside of the US, we have found data from the Ray Hunter Project that suggests the use of an MC catcher in the area, but none of them were at protests.
41:04Cooper Quintin:Right, that's very, very interesting because for years, the narrative is too strong. But one of the concerns, obviously, was that, well, this pretty indiscriminate technology, which may or may not be deployed without a warrant, obviously depends on the year we're talking about, but a massive concern was that, well, you could put this protest and you get all of the IMSIs of the people who were at this protest and then use that for later. A completely fine theory to have. And now it's really interesting because you and others and people using this tool are going out into the world and almost like collecting scientific data, which is not supporting that that is actually going on.
41:44Cooper Quintin:So that's fair to say.
41:46Joseph:Yeah, yeah, that's absolutely fair to say. And I mean, that was a big impetus behind this project. I'm fairly deeply connected to the activist community around the US and the sort of anarchist community around the US. And a lot of people were very concerned about MCCatchers being used at protests, right? And there was this sort of idea, right, that these must be at every protest, right? And that, like, you know, maybe every cop had one. We don't even know, right? And people were really unreasonably scared of these. And as a cybersecurity person, I want people to have accurate threat modeling, right?
42:23Joseph:People are going to take risks, and I want them to take informed risks, right? I want them to know what the actual risks they're taking are. I actually, I felt pretty strongly that cell-says similators were not being used as often as activists tended to think. But yeah, exactly. This lets us do some, you know, sort of citizen science and actually gather data from the field all over the place to, you know, show with evidence whether or not these are being used at protests. And the evidence points to that they're most likely not being used in the U.S. at protests right now. but that could also change right um ice has definitely escalated their tactics right and i wouldn't be surprised if they just decided you know we don't we don't actually need warrants for this for to use this thing right who's going to stop us you no right so like that's we want people to keep using this because we want to know if that situation does change right and if this is a threat that activists do need to start being worried about yeah that makes sense i will just say
43:26Cooper Quintin:before I ask, I think probably my last couple of questions is that I have installed this myself. I can't remember the exact process, but it was incredibly painless. It was so smooth. And it kind of reminded me of the setup process of a Graphene OS phone, where with Graphene, you plug the phone into your computer, you open a web browser and it installs. It's like magic. This was very close to that in that I installed it. I was like, oh, is that it? I'm detecting into catchers now. It was really, really smooth. So I thought it was very interesting in that respect where you took something that was so technologically obscure, as you were saying, and now basically anybody can do it if you can open the terminal and you feel like a badass doing it if you've never opened a terminal before.
44:11Cooper Quintin:You're like, you get to have that fun experience. But yeah, very easy to use for sure.
44:17Joseph:Yeah, we've been... That's one of our design goals has been to make it as easy to use and as easy to install as possible. definitely we want to get to that Graphene level where you can just do it over a browser. That's something we have definitely looked into and are trying to figure out how best to do. The only thing really stopping us there is that the easiest way to install on these a lot of times is over the wireless interface, right? By actually connecting to the Wi-Fi interface that these hotspots provide is usually the easiest way to install these. So that's not something that can work sort of the same way that Graphene does because Graphene works over the USB connection that Glenn is able to access.
44:57Joseph:But anyway, sorry, getting way too into the weeds there.
45:00Cooper Quintin:No, that makes complete sense. It's very interesting, actually. It is a different problem because you are manipulating, connecting to a literal Wi-Fi hotspot, and you kind of need to do that in virtue of what the device is, yes.
45:11Joseph:Yeah, but we're working on a graphical installer right now so that people no longer have to open the terminal. They can just open a normal GUI program and then click the install button that it installs. That's one of our big priorities coming up here. So yeah, we're trying to, we're really, really always trying to make it as easy as possible to use. And, you know, we're trying to minimize the number of false positives so that when people get an alert, they can feel, you know, pretty confident in something. Because we don't want to be in the position of spreading even more fear about MC Got Chikis.
45:46Joseph:Like a lot of people ask, why don't we make this an app, right? And there's a couple of reasons. One is that you can't get this sort of low-level data on the phone very easily. You can really only get it from certain phones if you root your phone. And I don't want to be in the position of telling people to root their phone, because that's far worse for security a lot of times, right? I think most people should be much more concerned about rooting their phone than about an MC catcher, right? More people should be concerned about mobile forensic tools, like Celebrite, right? If you're out of protest and you get arrested, you're much more likely for your phone to interact with a Celebrite device, which is a mobile forensic device that'll vacuum up all of the data on your phone and store it for later analysis by police, than you ever are to interact with an MCCatcher.
46:32Joseph:And if your phone is rooted, it's going to be so much easier for Celebrite to do all that.
46:37Cooper Quintin:It's already easy when it's not rooted, relatively speaking. Exactly. You've just opened the door for them. Yeah.
46:43Joseph:So that's why we haven't done it as an app. But we're trying to make it as easy as possible. And we're trying to make it as reliable as possible so that people are given actually an accurate picture of what's going on. I think one of the things I really liked about the Crocodile Hunter project was that we could actually physically track down cell site simulators. And that's still something I very much want to do. Like I was saying, the problem that we're facing is that people are sending us all this data and it's great. And I can look through the data and say, yes, I am 90 % confident that this was an MCCatcher that you saw in downtown Chicago on this day.
47:24Joseph:But who was running that MCCatcher? Can we be sure there was an MCCatcher? Why were they using it? We can't answer any of those questions. And if you could actually physically track it down, you would A, have proof that there was an MCCatcher being used, and B, be on your way to figuring out who was using it and possibly why. And so that's something we're trying to figure out how to do on this device as well. But it's a bit of a harder problem.
47:50Cooper Quintin:Yeah, I bet. So I think just to wrap up, beyond that sort of technical stuff where you're making these improvements to the interface and the capabilities of this tool, what are you hoping for for the future? Is it that just more people download and use this and gather data even if, I don't know, they don't find anything? Because most people are probably not actually going to find anything, an interesting problem, or I guess a scientific issue. But what are your hopes for this project going forward beyond the technical stuff?
48:21Joseph:I mean, we hope you won't find anything, right? That's the... Right. But also, I hope you will, and I hope you'll send it to me. But yeah, our hopes for this project, I think, are one, to decrease the amount of fear that people have about MC catchers, right? And I kind of hope that this is already starting to work, right? We've put out a blog post. We've put out a report, you know, kind of talking about what we found so far and highlighting the fact that we haven't really found this at protests, right? So I'm hoping that, you know, the sorts of people like me who intended to give technical advice to protesters will kind of, you know, disseminate that information as well and say, like, you know, we can kind of get to a point where we're like, look, these aren't being used to spy on protesters.
49:05Joseph:And that's good. But the bad news is these aren't being used to spy on protesters. And there's a lot of other technologies that we know are being used to spy on protesters, like facial recognition, like license plate readers, like tools from Penlink, like Weblog and Tangles, right? And Celebrate, right? But the good news is that all of the things that you want to do to protect against those, like putting on airplane mode, turning off location services, or just turning your phone off entirely, right? Those are also useful protections against NIMSY Catcher. So if an MCCatcher does show up and you've already protected yourself against these much more likely technologies, you get free protection from MCCatchers just for doing that.
49:46Joseph:So I'm hoping for that information to get out there. The other thing that I hope for from this project is now that, you know, as we sort of gather a ground truth of how MC catchers work, that companies who are higher up in this chain, right, companies like Apple and Google, companies like Qualcomm, right, who make a lot of the bulk of the cellular modems, right, that they can start to integrate protections against MC catchers directly into their devices, right? And Google has already done a really great job of this. So on modern Pixel devices now, you can turn off your 2G modem entirely. And I think with Apple phones on lockdown mode, they will also not connect to 2G connections.
50:30Joseph:Interesting. So this is a great first step. Not connecting to 2G already stops a lot of the man-in-the-middle type attacks, sort of the worst attacks that an MC Hatcher can perform. right google phones will also now let you know if your phone connects to a tower and that tower suggests not using any encryption for the connection between the phone and the tower right this is another good way to do a man-in-the-middle attack and it shouldn't usually happen the reason that's there is only really for 9-1-1 calls or emergency service calls where like if you have a phone that's not a part of that network you should still be able to connect to the nearest tower and make a 9-1-1 call that's the most important thing right and so they need the And you need to not have encryption for that because that network doesn't have any key material to set up an encrypted connection.
51:18Joseph:But if you're not making a 911 call and a tower says, hey, let's not use encryption, right? That's a pretty big red flag. So Google is now alerting people on that on the latest Pixel phones, right? And I would like to see Apple catch up with that. I would actually like to see, and there's been some movement on Qualcomm to allow OEMs to sort of build these protections in. And the Qualcomm chip will raise a flag to the phone when something weird happens, but nobody's really implementing this yet. To put that in a simpler way, Qualcomm chips have some really neat anti-MC catcher protections that they started building in a while back.
51:55Joseph:But unfortunately, none of the phone manufacturers are using those. So I'm hoping that as this project gets some success and we can say, here are the actual attacks that we know are happening in the wild. right and here's the evidence here are the packet captures that people from these companies will start to build in protections on the phone because that's where it's actually needed right right hunter can't protect you from an MC catcher it can just let you know that one was maybe there right but your phone should be the one actually protecting you from an MC catcher yeah that
52:27Cooper Quintin:totally makes sense uh or of course telecommunications networks actually affecting themselves but that's not gonna happen the phone companies should be the ones protecting you from
52:35Joseph:this and they could actually detect these really easily because they have the picture of the entire network landscape but they are not no that's not going to happen um ocupa thank you so much
52:46Cooper Quintin:for joining us on the show this week i thought that's a fascinating conversation um thank you
52:51Joseph:so much i really really appreciate it yeah thank you super happy to be here big fan of 404 media and and all you guys and all the work you've done in the past as well and uh yes it's a it's an honor to be on the podcast. Of course.
53:03Cooper Quintin:Thank you so much.
53:43Thank you.
54:01Thank you.
From the publisher
Joseph speaks to Cooper Quintin, a security researcher and senior public interest technologist with the Electronic Frontier Foundation (EFF). Quintin is one of the people behind Rayhunter, an easy to install tool that can detect nearby IMSI-catchers. This tech, sometimes known as Stingrays, poses as a fake cellphone tower to track a phone’s location, intercept calls and texts, and can sometimes even deliver malware.
Rayhunter GitHub: https://github.com/EFForg/rayhunter
YouTube: https://youtu.be/vEFPPaOn0ts
Learn more about your ad choices. Visit megaphone.fm/adchoices
