Monday, June 5, 2023

The machines that law enforcement uses to monitor your phone’s data

The National Security Agency’s spying tactics are being intensely scrutinized following the recent leaks of secret documents. However, the NSA isn’t the only US government agency using controversial surveillance methods.

 

Monitoring citizens’ cell phones without their knowledge is a booming business. From Arizona to California, Florida to Texas, state and federal authorities have been quietly investing millions of dollars acquiring clandestine mobile phone surveillance equipment in the past decade.

 

Earlier this year, a covert tool called the “Stingray” that can gather data from hundreds of phones over targeted areas attracted international attention. Rights groups alleged that its use could be unlawful. But the same company that exclusively manufacturers the Stingray—Florida-based Harris Corporation—has for years been selling government agencies an entire range of secretive mobile phone surveillance technologies from a catalogue that it conceals from the public on national security grounds.

 

Details about the devices are not disclosed on the Harris website, and marketing materials come with a warning that anyone distributing them outside law enforcement agencies or telecom firms could be committing a crime punishable by up to five years in jail.
 
These little-known cousins of the Stingray cannot only track movements—they can also perform denial-of-service attacks on phones and intercept conversations. Since 2004, Harris has earned more than $40 million from spy technology contracts with city, state, and federal authorities in the US, according to procurement records.

 

In an effort to inform the debate around controversial covert government tactics, Ars has compiled a list of this equipment by scrutinizing publicly available purchasing contracts published on government websites and marketing materials obtained through equipment resellers. Disclosed, in some cases for the first time, are photographs of the Harris spy tools, their cost, names, capabilities, and the agencies known to have purchased them.

 

What follows is the most comprehensive picture to date of the mobile phone surveillance technology that has been deployed in the US over the past decade.

 

 

“Stingray”

 

cellphone_surveillance_stingray_spyshopllc

 

The Stingray has become the most widely known and contentious spy tool used by government agencies to track mobile phones, in part due to an Arizona court case that called the legality of its use into question. It’s a box-shaped portable device, sometimes described as an “IMSI catcher,” that gathers information from phones by sending out a signal that tricks them into connecting to it. The Stingray can be covertly set up virtually anywhere—in the back of a vehicle, for instance—and can be used over a targeted radius to collect hundreds of unique phone identifying codes, such as the International Mobile Subscriber Number (IMSI) and the Electronic Serial Number (ESM). The authorities can then hone in on specific phones of interest to monitor the location of the user in real time or use the spy tool to log a record of all phones in a targeted area at a particular time.

 

The FBI uses the Stingray to track suspects and says that it does not use the tool to intercept the content of communications.

 

However, this capability does exist. Procurement documents indicate that the Stingray can also be used with software called “FishHawk,” (PDF) which boosts the device’s capabilities by allowing authorities to eavesdrop on conversations. Other similar Harris software includes “Porpoise,” which is sold on a USB drive and is designed to be installed on a laptop and used in conjunction with transceivers—possibly including the Stingray—for surveillance of text messages.

 

Similar devices are sold by other government spy technology suppliers, but US authorities appear to use Harris equipment exclusively. They’ve awarded the company “sole source” contracts because its spy tools provide capabilities that authorities claim other companies do not offer. The Stingray has become so popular, in fact, that “Stingray” has become a generic name used informally to describe all kinds of IMSI catcher-style devices.

 

First used: Trademark records show that a registration for the Stingray was first filed in August 2001. Earlier versions of the technology—sometimes described as “digital analyzers” or “cell site simulators” by the FBI—were being deployed in the mid-1990s. An upgraded version of the Stingray, named the “Stingray II,” was introduced to the spy tech market by Harris Corp. between 2007 and 2008. Photographs filed with the US Patent and Trademark Office depict the Stingray II as a more sophisticated device, with many additional USB inputs and a switch for a “GPS antenna,” which is likely used to assist in location tracking.

 

Cost: $68,479 for the original Stingray; $134,952 for Stingray II.

 

Agencies: Federal authorities have spent more than $30 million on Stingrays and related equipment and training since 2004, according to procurement records. Purchasing agencies include the FBI, DEA, Secret Service, US Immigration and Customs Enforcement, the Internal Revenue Service, the Army, and the Navy. Cops in Arizona, Maryland, Florida, North Carolina, Texas, and California have also either purchased or considered purchasing the devices, according to public records. In one case, procurement records (PDF) show cops in Miami obtained a Stingray to monitor phones at a free trade conference held in Miami in 2003.

 

 

“Gossamer”

gossamer-cellphone-surveillance

 

The Gossamer is a small portable device that can be used to secretly gather data on mobile phones operating in a target area. It sends out a covert signal that tricks phones into handing over their unique codes—such as the IMSI and TMSI—which can be used to identify users and home in on specific devices of interest. What makes it different from the Stingray? Not only is the Gossamer much smaller, but it can also be used to perform a denial-of-service attack on phone users, blocking targeted people from making or receiving calls, according to marketing materials (PDF) published by a Brazilian reseller of the Harris equipment. The Gossamer has the appearance of a clunky-looking handheld transceiver. One photograph filed with the US Patent and Trademark Office shows it displaying an option for “mobile interrogation” on its small LCD screen, which sits above a telephone-style keypad.

 

First used: Trademark records show that a registration for the Gossamer was first filed in October 2001.

 

Cost: $19,696.

 

Agencies: Between 2005 and 2009, the FBI, Special Operations Command, and Immigration and Customs Enforcement spent more than $1.3 million purchasing Harris’ Gossamer technology and upgrading existing Gossamer units, according to procurement records. Most of the $1.3 million was spent by the FBI as part of a large contract in 2005.

 

 

“Triggerfish”

 

Triggerfish-cellphone-surveillance

 

 

The Triggerfish is an eavesdropping device. It allows authorities to covertly intercept mobile phone conversations in real time. This sets it apart from the original version of the Stingray, which marketing documents suggest was designed mainly for location monitoring and gathering metadata (though software can allow the Stingray to eavesdrop). The Triggerfish, which looks similar in size to the Stingray, can also be used to identify the location from which a phone call is being made. It can gather large amounts of data on users over a targeted area, allowing authorities to view identifying codes of up to 60,000 different phones at one time, according to marketing materials.

 

First used: Trademark records show that a registration for the Triggerfish was filed in July 2001, though its “first use anywhere” is listed as November 1997. It is not clear whether the Triggerfish is still for sale or whether its name has recently changed, as the trademark on the device was canceled in 2008, and it does not appear on Harris’ current federal price lists.

 

Cost: Between $90,000 and $102,000.

 

Agencies: The Bureau of Alcohol, Tobacco, Firearms, and Explosives; the DEA; and county cops in Miami-Dade invested in Triggerfish technology prior to 2004, according to procurement records. However, the procurement records (PDF) also show that the Miami-Dade authorities complained that the device “provided access” only to Cingular and AT&T wireless network carriers. (This was before the two companies merged.) To remedy that, the force complemented the Triggerfish tool with additional Harris technology, including the Stingray and Amberjack, which enabled monitoring of Metro PCS, Sprint, and Verizon. This gave the cops “the ability to track approximately ninety percent of the wireless industry,” the procurement documents state.

 

 

“Kingfish”

 

kingfish-cellphone-surveillance

 

The Kingfish is a surveillance transceiver that allows authorities to track and mine information from mobile phones over a targeted area. The device does not appear to enable interception of communications; instead, it can covertly gather unique identity codes and show connections between phones and numbers being dialed. It is smaller than the Stingray, black and gray in color, and can be controlled wirelessly by a conventional notebook PC using Bluetooth. You can even conceal it in a discreet-looking briefcase, according to marketing brochures.

 

First used: Trademark records show that a registration for the Kingfish was filed in August 2001. Its “first use anywhere” is listed in records as December 2003.

 

Cost: $25,349.

 

 

Agencies: Government agencies have spent about $13 million on Kingfish technology since 2006, sometimes as part of what is described in procurement documents as a “vehicular package” deal that includes a Stingray. The US Marshals Service; Secret Service; Bureau of Alcohol, Tobacco, Firearms, and Explosives; Army; Air Force; state cops in Florida; county cops in Maricopa, Arizona; and Special Operations Command have all purchased a Kingfish in recent years.

 

“Amberjack”

 

amberjack_cellphone_surveillance

 

The Amberjack is an antenna that is used to help track and locate mobile phones. It is designed to be used in conjunction with the Stingray, Gossamer, and Kingfish as a “direction-finding system” (PDF) that monitors the signal strength of the targeted phone in order to home in on the suspect’s location in real time. The device comes inbuilt with magnets so it can be attached to the roof of a police vehicle, and it has been designed to have a “low profile” for covert purposes. A photograph of the Amberjack filed with a trademark application reveals that the device, which is metallic and circular in shape, comes with a “tie-down kit” to prevent it from falling off the roof of a vehicle that is being driven at “highway speeds.”

 

First used: Trademark records show that a registration for the Amberjack was filed in August 2001 at the same time as the Stingray. Its “first use anywhere” is listed in records as October 2002.

 

Cost: $35,015

 

Agencies: The DEA; FBI; Special Operations Command; Secret Service; the Navy; the US Marshals Service; and cops in North Carolina, Florida, and Texas have all purchased Amberjack technology, according to procurement records.

 

“Harpoon”

 

harpoon_cellphone_surveillance

 

The Harpoon is an “amplifier” (PDF) that can boost the signal of a Stingray or Kingfish device, allowing it to project its surveillance signal farther or from a greater distance depending on the location of the targets. A photograph filed with the US Patent and Trademark Office shows that the device has two handles for carrying and a silver, metallic front with a series of inputs that allow it to be connected to other mobile phone spy devices.

 

First used: Trademark records show that a filing for the Harpoon was filed in June 2008.

 

Cost: $16,000 to $19,000.

 

Agencies: The DEA; state cops in Florida; city cops in Tempe, Arizona; the Army; and the Navy are among those to have purchased Harpoons since 2009.

 

 

“Hailstorm”

 

The Hailstorm is the latest in the line of mobile phone tracking tools that Harris Corp. is offering authorities. However, few details about it have trickled into the public domain. It can be purchased as a standalone unit or as an upgrade to the Stingray or Kingfish, which suggests that it has the same functionality as these devices but has been tweaked with new or more advanced capabilities. Procurement documents (PDF) show that Harris Corp. has, in at least one case, recommended that authorities use the Hailstorm in conjunction with software made by Nebraska-based surveillance company Pen-Link. The Pen-Link software appears to enable authorities deploying the Hailstorm to directly communicate with cell phone carriers over an Internet connection, possibly to help coordinate the surveillance of targeted individuals.

 

First used: Unknown.

 

Cost: $169,602 as a standalone unit. The price is reduced when purchased as an upgrade.

 

Agencies: Public records show that earlier this year, the Baltimore Police Department, county cops in Oakland County, Michigan, and city cops in Phoenix, Arizona, each separately entered the procurement process to obtain the Hailstorm equipment. The Baltimore and Phoenix forces each set aside about $100,000 for the device, and they purchased it as an upgrade to Stingray II mobile phone spy technology. The Phoenix cops spent an additional $10,000 on Hailstorm training sessions conducted by Harris Corp. in Melbourne, Florida, and Oakland County authorities said they obtained a grant from the Department of Homeland Security to help finance the procurement of the Hailstorm tool. The Oakland authorities noted that the device was needed for “pinpoint tracking of criminal activity.” It is highly likely that other authorities—particularly federal agencies—will invest in the Hailstorm too, with procurement records eventually surfacing later this year or into 2014.

 

No one’s talking

 

The FBI has previously stated in response to questions about the Stingray device that it “strives to protect our country and its people using every available tool” and that location data in particular is a “vital component” of investigations. But when it comes to discussing specific surveillance equipment, it is common for the authorities to remain tight-lipped because they don’t want to reveal tactics to criminals.

 

The code of silence shrouding the above tools, however, is highly contentious. Their use by law enforcement agencies is in a legal gray zone, particularly because interference with communications signals is supposed to be prohibited under the federal Communications Act. In May, an Arizona court ruled that the FBI’s use of a Stingray was lawful in a case involving conspiracy, wire fraud, and identity theft. But according to the American Civil Liberties Union (ACLU), when seeking authorization for the use of the Stingray tool, the feds have sometimes unlawfully withheld information from judges about the full scope of its capabilities. This means that judges across the country are potentially authorizing the use of the technology without even knowing what it actually does.

 

That’s not all. There is another significant issue raised by the Harris spy devices: security. According to Christopher Soghoian, chief technologist at the ACLU, similar covert surveillance technology is being manufactured by a host of companies in other countries like China and Russia. He believes the US government’s “state secrecy” on the subject is putting Americans at risk.

 

“Our government is sitting on a security flaw that impacts every phone in the country,” Soghoian says. “If we don’t talk about Stingray-style tools and the flaws that they exploit, we can’t defend ourselves against foreign governments and criminals using this equipment, too.”

 

 

Amazon's Ring used to spy on customers, FTC says in privacy settlement

Amazon's Ring used to spy on customers, FTC says in privacy settlement

An Amazon Ring sign is shown as a security warning at the entrance to a residential home in Encinitas, California
An Amazon Ring sign is shown as a security warning at the entrance to a residential home in Encinitas, California, U.S., September 30, 2021. Picture taken September 30, 2021. REUTERS/Mike Blake

    WASHINGTON, May 31 (Reuters) - A former employee of Amazon.com's Ring doorbell camera unit spied for months on female customers in 2017 with cameras placed in bedrooms and bathrooms, the Federal Trade Commission said in a court filing on Wednesday when it announced a $5.8 million settlement with the company over privacy violations.

    Amazon also agreed to pay $25 million to settle allegations it violated children's privacy rights when it failed to delete Alexa recordings at the request of parents and kept them longer than necessary, according to a court filing in federal court in Seattle that outlined a separate settlement.

    The FTC settlements are the agency's latest effort to hold Big Tech accountable for policies critics say place profits from data collection ahead of privacy.

    Amazon, which purchased Ring in April 2018, pledged to make some changes in its practices.

    "While we disagree with the FTC's claims regarding both Alexa and Ring, and deny violating the law, these settlements put these matters behind us," Amazon.com said in a statement.

    The FTC said Ring gave employees unrestricted access to customers' sensitive video data: "As a result of this dangerously overbroad access and lax attitude toward privacy and security, employees and third-party contractors were able to view, download, and transfer customers' sensitive video data."

    In one instance in 2017, an employee of Ring viewed videos made by at least 81 female customers and Ring employees using Ring products. "Undetected by Ring, the employee continued spying for months," the FTC said.


    In May 2018, an employee gave information about a customer's recordings to the person's ex-husband without consent, the complaint said. In another instance, an employee was found to have given Ring devices to people and then watched their videos without their knowledge, the FTC said.

    As part of the FTC agreement with Ring, which expires after 20 years, Ring is required to disclose to customers how much access to their data the company and its contractors have.

    In February 2019, Ring changed its policies so that most Ring employees or contractors could only access a customer’s private video with that person's consent.

    FTC Commissioner Alvaro Bedoya told Reuters the settlements should send a message to tech companies that their need to collect data was not an excuse to break the law. "This is a very clear signal to them," he said.

    The fines, totaling $30.8 million, represent a fraction of Amazon's $3.2 billion first-quarter profit.

    In its complaint against Amazon.com filed in Washington state, the FTC said that it violated rules protecting children's privacy and rules against deceiving consumers who used Alexa. For example, the FTC complaint says that Amazon told users it would delete voice transcripts and location information upon request, but then failed to do so.

    "The unlawfully retained voice recordings provided Amazon with a valuable database for training the Alexa algorithm to understand children, benefiting its bottom line at the expense of children's privacy," the FTC said.

    Reporting by Diane Bartz and David Shepardson; Editing by Anna Driver and Deepa Babington

    Our Standards: The Thomson Reuters Trust Principles.

 

The FBI Is Locating Cars By Spying On Their WiFi

 
 
The FBI Is Locating Cars By Spying On Their WiFi
  • Car surveillance by the FBI using Stingrays
  • The FBI is using a controversial technology traditionally used to locate smartphones as a car tracking surveillance tool that spies on vehicles’ on-board WiFi.

    Known as a Stingray or a cell-site simulator, the tool masquerades as a cell tower in order to force all devices in a given area to connect into it. Agents can then pick the number they’re interested in and locate the device. Normally that would be a mobile phone, but a search warrant application discovered by Forbes shows it can also be used to find vehicles, as long as they have onboard Wi-Fi. That’s because car Wi-Fi systems act like a phone, in that they reach out to mobile networks to get their data. So it makes sense that police would use it to find a car, though this appears to be the first case on record of it happening.

    The application to use the Stingray was filed by the FBI in Wisconsin in May, as it sought to locate a vehicle - a Dodge Durango Hellcat - it believed was being used by a man indicted for drug dealing and firearms possession crimes.

    The FBI had already been given permission to use other kinds of surveillance to locate another vehicle, a “black Jeep,” associated with the suspect, according to the warrant application. Again, they were surveillance techniques traditionally used to track cellphones, the first being a pen register, which gets data from a cellphone provider to monitor connections made by the device to other phones or electronic devices. The second was a so-called “ping warrant,” which shows the locations of cell towers used by a device. That gave them the location of a car dealership, where they learned the suspect had traded in the Jeep for the Dodge, the FBI wrote in its application.

    After that, the FBI decided to use the cell-site simulator. Towards the end of the warrant application, a federal agent explained why, noting that cars like the Dodge were “frequently equipped with cellular modems inside their vehicles. These cellular modems are assigned a unique cellular identifier and generate historical and prospective records similar to a traditional cellular phone.”

    “These records can assist law enforcement in identifying the location of the vehicle including patterns of travel and areas where the subject may reside or frequent. Most Original Equipment Manufacturers (OEMs) have partnered with AT&T or Verizon to provide cellular connectivity within their vehicles. A check of open source information from AT&T identifies the 2021 Dodge Durango Hellcat as a vehicle that has a built-in WiFi hotspot that is serviced by AT&T.”

     

    The Stingray tool appeared to have helped, with another government document showing the warrant had been executed and that the cell-site simulator had indicated there was a “high probability” the Dodge was located inside a garage.

    The suspect in the case, Shaft A. Darby, has pleaded not guilty to the three charges he is facing. Having been indicted in March, he was arrested in mid-July.

    Stingrays have been controversial in the past as they suck up data from all devices that connect into them, meaning information on many innocents’ phones or cars will be hoovered up. That’s why lawmakers have proposed legislation to mandate warrants with strong probable cause before the surveillance technology is deployed, and why warrant applications come with boilerplate disclaimers like the one in Wisconsin: “The investigative device may interrupt cellular service of phones or other cellular devices within its immediate vicinity. Any service disruption to nontarget devices will be brief and temporary, and all operations will attempt to limit the interference with such devices.” It also promises to delete data recorded from non-suspects.

    The case highlights how cars are no longer just vehicles, but networks on wheels, and all that data can be useful to government agencies. As Forbes recently reported, police can and have acquired location data from a car’s airbag system or brake light module. They’ve also previously requested location data from companies that have in-car systems that track millions of vehicles’ GPS coordinates every day, including GM OnStar, and fleet management providers Geotab and Spireon.

    “Many people don’t realize that modern cars aren’t just wheels and an engine anymore, they are computers and cellphones too,” says Nate Wessler, deputy director of the ACLU Speech, Privacy, and Technology Project. “These features offer convenience and efficiency to drivers, but they also generate sensitive information about where we go and what we do. Strong privacy protections are important for this kind of vehicle information, just as they are for information generated by our cell phones and laptops.”

    Follow me on TwitterCheck out my websiteSend me a secure tip

    I'm a senior writer for Forbes, covering security, surveillance and privacy. I'm also the editor of The Wiretap newsletter, which has exclusive stories on real-world surveillance and all the

    ...

    Powerful Mobile Phone Surveillance Tool Operates in Obscurity Across the Country

    Powerful Mobile Phone Surveillance Tool Operates in Obscurity Across the Country

    CellHawk helps law enforcement visualize large quantities of information collected by cellular towers and providers.

    Until now, the Bartonville, Texas, company Hawk Analytics and its product CellHawk have largely escaped public scrutiny. CellHawk has been in wide use by law enforcement, helping police departments, the FBI, and private investigators around the United States convert information collected by cellular providers into maps of people’s locations, movements, and relationships. Police records obtained by The Intercept reveal a troublingly powerful surveillance tool operated in obscurity, with scant oversight.

    CellHawk’s maker says it can process a year’s worth of cellphone records in 20 minutes, automating a process that used to require painstaking work by investigators, including hand-drawn paper plots. The web-based product can ingest call detail records, or CDRs, which track cellular contact between devices on behalf of mobile service providers, showing who is talking to whom. It can also handle cellular location records, created when phones connect to various towers as their owners move around.

    Such data can include “tower dumps,” which list all the phones that connected to a given tower — a form of dragnet surveillance. The FBI obtained over 150,000 phone numbers from a single tower dump undertaken in 2010 to try and collect evidence against a bank robbery suspect, according to a report from the Brennan Center for Justice at NYU.

    Related

    Feds Are Tapping Protesters’ Phones. Here’s How To Stop Them.

    Police use CellHawk to process datasets they routinely receive from cell carriers like AT&T and Verizon, typically in vast spreadsheets and often without a warrant. This is in sharp contrast to a better known phone surveillance technology, the stingray: a mobile device that spies on cellular devices by impersonating carriers’ towers, tricking phones into connecting, and then intercepting their communications. Unlike the stingray, CellHawk does not require such subterfuge or for police to position a device near people of interest. Instead, it helps them exploit information already collected by private telecommunications providers and other third parties.

     

    Here are the devices law enforcement use to spy on you

    Here are the devices law enforcement use to spy on you

    Just because you're paranoid doesn't mean they're not watching you.

    Here are the devices law enforcement use to spy on you
    Roberto Baldwin
    Roberto Baldwin|@strngwys|December 17, 2015 7:36 PM

    The Intercept obtained the catalog of devices used by federal and local law enforcement to collect and monitor cell phone data. The tracking hardware -- including the infamous Stingray -- in the catalog is accompanied by its capabilities including, limitations, "planning factors," price and manufacturer. From handheld pieces of electronics that can track a few phones to boxes that can target as many as 10,000 unique cellphones the list is chilling reminder that even if you're not under investigation, you're being tracked if you're in the wrong place at the wrong time.

    The publication obtained the list from a source within the intelligence world and it unearths dozens of devices that most were unaware of before today. Judges and privacy advocates have long asked for information about how many of these items work but have been thwarted by claims of national security. Plus, law enforcement agencies sign NDAs before purchasing a tracker. Many local law enforcement agencies purchase these items with Department of Homeland Security grants then use them for crimes that have nothing to do with stopping terrorism.

    The technology found in the catalog is used to spoof cell networks like AT&T, Sprint, T-Mobile and others. In other words, a machine creates a fake cell tower that phones connect too and the device tracks the data that is sent between the phone and device. The information can be used to locate an individual, eavesdrop on calls and text messages, and even extract media from the phone.

    In addition to being used for tasks that have nothing to do with the reason for which they were purchased, the dragnet solution that many of these devices offer violates fourth amendment search and seizure rights. Because judges are unable to determine the scope of capabilities of the technology, many believe search warrants issued that use this type of technology can be overly broad. At least now these judges can see just how powerful these pieces of hardware are before unleashing them upon the public.

    (article reposted from ENDGADGET online, 2015)

     

    Hands On With Flipper Zero, the Hacker Tool Blowing Up on TikTok

    Hands On With Flipper Zero, the Hacker Tool Blowing Up on TikTok

    Don’t be fooled by its fun name and Tamagotchi-like interface—this do-everything gadget is trouble waiting to happen and a whole lot more.

    Across the US, countless buildings, from government offices to your next hotel room door, are protected by RFID-controlled locks. On a recent trek through Manhattan, I passed nearly 20 of these keyless entry systems, which are among the most pervasive in the world. But a playful palm-sized gadget with a Tamagotchi-like interface can likely thwart the locks on many of these doors. 

    The $200 device is called Flipper Zero, and it’s a portable pen-testing tool designed for hackers of all levels of technical expertise. The tool is smaller than a phone, easily concealable, and is stuffed with a range of radios and sensors that allow you to intercept and replay signals from keyless entry systems, Internet of Things sensors, garage doors, NFC cards, and virtually any other device that communicates wirelessly in short ranges. For example, in just seconds, I used the Flipper Zero to seamlessly clone the signal of an RFID-enable card tucked safely inside my wallet.

    If you had only heard about Flipper Zero through TikTok, where the tool has gone viral, you might think that it was a toy that could make ATMs spit out money, cars unlock themselves, and gas spill out of pumps for free. I spent the last week testing one to determine whether the world was as vulnerable to Flipper Zero as social media made it out to be. What I found was mixed: Many of the most dramatic videos posted to TikTok are likely staged—most modern wireless devices are not susceptible to simple replay attacks—but the Flipper Zero is still undeniably powerful, giving aspiring hackers and seasoned pen-testers a convenient new tool to probe the security of the world’s most ubiquitous wireless devices. 

    In reviews, people liken Flipper Zero to a Swiss Army knife for physical penetration testing. But in my week testing Flipper Zero, it felt more like a blacklight—something I could literally hold up to a device that would reveal information, invisible to the human eye, about how it worked, what data it was emitting, and how often it was doing so. 

    Here’s a brief list of some things I’ve learned with the help of Flipper Zero this week: Some animal microchips will tell you the body temperature of your pet. My neighbor’s car tire pressure sensor leaks data to anyone in range of the signal. My iPhone blasts my face with infrared signals every few seconds. My home security system has built-in signal-jamming detection. Some hotel and office bathrooms have soap dispensers that broadcast whether they need to be refilled.

    When I told Alex Kulagin, one of Flipper Zero’s co-creators, about my experiences using his tool to make these kinds of mundane observations, he explained that this is exactly what the device is meant for. “We want to help you understand something deeply, explore how it works, and explore the wireless world that’s all around you but difficult to understand.

    Advertisement

    Kulagin and his business partner, Pavel Zhovner, first came up with the idea for Flipper Zero in 2019. Since then, their company has sold 150,000 devices and they’ve grown their team to nearly 50 people. But as they’ve grown, they’ve encountered some resistance. This summer, payments of more than $1.3 million were held up by PayPal, and in September, US Customs and Border Patrol seized a shipment of devices. According to Kulagin, CBP released the shipment after a month but has yet to tell the company why it held the shipment. CBP declined WIRED’s request to comment about the seized Flipper Zeros.

    Advertisement

    Bob Zahreddine is a lieutenant for the Glendale Police Department and executive officer with the High Tech Crime Cops, an industry group made up of law enforcement officials that, according to its website, “connects cyber cops and investigators.” Zahreddine says that he isn’t necessarily surprised that CBP has taken an interest in Flipper Zero. “Because Flipper Zero is so customizable, the potential is there for it to be used in all sorts of crime,” he says. 

    Zahreddine’s organization maintains a listserv where investigators will often solicit advice from their peers and share news or information about developments in the latest law enforcement technology. He told WIRED that while he hasn’t heard any chatter about Flipper Zero being used in any crimes on his listserv, investigators there are aware of the tool and have been following its development since Kulagin and Zhovner began fundraising on Kickstarter. 

    Indeed, it’s easy to imagine how someone could break the law or even just get up to some petty mischief with this device. For instance, not only was I able to clone a building-entry card with Flipper Zero, I was able to record the signal that my neighbor’s garage door opener makes when he pulls into his driveway. Older cars that don’t use rolling code encryption are likely unlockable with the device, and my Flipper Zero was able to read my credit card number through my wallet and pants.

    But Kulagin isn’t particularly concerned about his tool’s potential for criminal mischief. “Obviously, there are old cars that are vulnerable to Flipper. But they aren’t secure by definition—that is not Flipper’s fault,” he says. “There are bad people out there, and they can do bad stuff with any computer. We aren’t intending to break laws.”

    To that end, Flipper Zero’s firmware, by default, prevents individuals from transmitting on frequencies that are banned in the country the device is in, and Flipper Zero’s Discord server explicitly forbids discussions about alternative firmware with illegal features. (However, because the project is open source, a savvy Flipper user could adjust the firmware to enable additional, perhaps malicious, functionality.) The tool also isn’t able to copy or replay any encrypted signals. For instance, while I was able to read the signal from my credit and debit cards, I was unable to use that signal to actually pay for anything with contactless payment systems—a hardware constraint with the device, and not something someone could pull off with software tweaks. 

    When I asked Kulagin whether he had been contacted by law enforcement about the Flipper, he told me that he hadn’t. “No, not yet at least,” he says.

    While it’s possible to get into trouble with a device like a Flipper Zero, the tool undeniably gives any curious person looking to learn about the devices around them a way to access and dissect the signals and protocols that power our lives. Personally, I am more engaged with the technology I encounter while walking around after my week with the Flipper Zero. I’m thinking more like a pen-tester.

    Update 2 pm ET, January 10, 2023: This article has been updated with new language to avoid the potential exposure of a possible security issue.

     (this article is reposted from WIRED online, all credit goes to WIRED.)