May 012021
 
DPAC Logo with text underneath "Disabled People Against Cuts" and then web address dpac.uk.net

Cell Site Simulators/CSS (aka IMEI/IMSI catchers, Dirtboxes, Stingrays etc)
and Police ‘Phone Data Extraction: digital stop and search’

If you are attending a protest or think you could end up being a bystander to one you might want to consider not taking any mobile phone with you, or more pragmatically you could take a basic 2G [Footnote 1] or more capable 4G/5G disposable ‘burner’ phone [Footnote 2], including using a pre-paid SIM card and if needed a top-up voucher, all bought with cash and never do so in conjunction with a shop ‘loyalty card‘. [Footnote 3]

Attending a Protest?
Do not bring your primary phone to a protest, instead, buy a prepaid, disposable phone
Enable ‘Airplane Mode‘ and Turn off: location services and your prepaid device before going home or anywhere that might reveal your identity
Use an ‘off-line’ maps for navigation (try map.me)
Take photos & videos with the screen locked
More excellent tips and hints in ‘Attending a Protest‘ – Print pocket guide (PDF)

 

Remember: just placing a new SIM card into a phone, does not stop the phone itself from being traced or monitored. This is because SIM cards have an IMSI (International Mobile Subscriber Identity) and the phone itself has a unique IMEI (International Mobile Equipment Identity/model and serial number), both of which are transmitted to mobile phone base stations/cells towers to authenticate users and can both be intercepted by Police IMSI Catchers/Cell Site Simulators. See item below: ‘[A] Cell Site Simulators/CSS and why take a ‘burner’ phone to protests?’ for more details.​​​​​​​​​​​​​​

Besides IMEI and IMSI, smartphones also have additional unique identifiers, such as google’s Android ‘Device ID‘ and Apple’s iOS “device-level ID“. Apple’s iOS also has a unique ‘ID for Vendors (IDFV)’ and a ‘Identifier for Advertisers (IDFA)’ similar to Android’s ‘Advertising ID‘. All of these additional unique identifiers are shared with google and apple’s respective app developers to enable persistent tracking and targeted advertising/profiling. See item below: ‘[D] Caution and due diligence’ for more details.

Android user? Use this app to discover many of your device(s) unique indentifiers.

 

Digital and mobile phone self-defence

For in-depth information, check out these EFF resources:

for more UK focused resources visit the websites of the Open Rights Group and Privacy International for Cell Site Simulators/CSS specific information and Police ‘Phone Data Extraction: digital stop and search’ and Cyber Kiosks by the Information Commissioner’s Office and Police Scotland.

Top Tips: For smart-phone users, encrypted message apps like Signal and email service Tutanota are suggested. [Footnote 6] Or consider the decentralised P2P Briar App (Android) via F-Droid, which has messaging, private groups, forum and blog functions and can be used with Tor (anonymity network) or Bluetooth or a shared WiFi network when internet access is not available or use presents a risk, if you want to communicate but not share your phone number or email address.

Having a mobile phone on one’s person is very common place these days and many people cannot manage without them, especially smart-phones. However, smart-phones combine the power of an always-on computer, often with high resolution broadcast quality photo, video and camera functions, internet access and website browsing, a pager/sms/text, mobile phone and additional location related functions like GPS, Bluetooth and WiFi and embed no choice privacy invasive applications (apps) and apps users can install, which leads to them containing vast amounts of data, often of a very personal and sensitive nature.

The use of ‘mobile phone extraction’ [MPE] tools enables police forces to download
all of the content and data from people’s phones.
 This can apply to suspects, witnesses
and even victims – without their knowledge
(including easily recovering ‘deleted‘ content and data)
Phone Data Extraction: digital stop and search‘ – 2020

Related: Podcast on Extraction and article: Police unlocking your online data cloud “goldmine”

 

 

Email is very very important

Traditional email services from likes of gmail, yahoo and outlook are by default an inherently insecure way to communicate, share ideas and files and should be avoided.

However, in recent years tutanota.com and protonmail.com have introduced very easy to use end-to-end encrypted (E2EE) email services, so if Alice emails Bob only they can read them (the ends). These providers E2EE email services are designed so they have no access to users account content and are unable to give law enforcement account access and only retain minimal details of users.

I would then ask you to register a free and secure email account with Tutanota.com
as using an ordinary email is not a secure way to share personal information…
Both of us using such a system is essential for Email Counselling and
gives peace of mind that your privacy and confidentiality can be maintained

https://intunecounselling.co.uk/email-counselling

Therefore it is highly recommended you set up a tutanota.com and or a  protonmail.com account and you should very explicitly and proactively ask everyone you expect to or do communicate with by email to also set up an account with either or both. Both providers offer free account options, tutanota offers the cheapest premium account and also offer a way to communicate with non tutanota users, using E2EE emails, by use of a pre-shared password option and this function is offered to it’s free account users.

If you host your own website, tutanota also offers an end-to-end encrypted contact form option.

—————————————————————————————————————————
If you have general questions about this ‘phones and protests’ post, please set up a new Tutanota email account and then send your query from it to dpac@tutanota.com or use https://dpac.uk.net/contact/ (not recommended)
This email address is under the sole control of DPAC and is strictly for ‘phones and protests’ queries only.

—————————————————————————————————————————

More detailed information below:

[A] Cell Site Simulators and why take a ‘burner’ phone to protests?
[B] But I want to take my smart phone with me to protests?
[C] What about the Police taking my phone to view it’s content?
[D Caution and due diligence
[E] Further reading and videos

[F] Examples of intercepted/leaked text messages, mobile phone calls and data/records

[A] Cell Site Simulators/CSS and why take a ‘burner’ phone to protests?

Police, Prison, Immigration, Military and Security Services use fixed, portable and wearable technology that can simulate mobile phone base stations (Cell Site Simulators/CSS) [Footnote 4]. A CSS can have capabilities that can be passive and or active. On a basic level they can indiscriminately capture the unique IMSI (International Mobile Subscriber Identity) linked to a phone’s SIM card(s) and the associated phone’s unique ‘International Mobile Equipment Identity‘ (IMEI/model and serial number of the phone), as these are used to authenticate users/subscribers/account holders on mobile networks, which can be then used to identify and locate the phone and user(s) and the social networks and people the user engages with so they can be monitored/tracked live or on a retrospective basis. IE: The Where, When and Who.

“Signs of IMSI catchers — also known as stingrays or cell-site simulators
— were found at several locations in the British capital, including UK parliament,

a peaceful anti-austerity protest, and the Ecuadorian embassy
VICE News Investigation Finds Signs of Secret Phone Surveillance Across London‘ – 14.1.16
Met police using surveillance system to monitor mobile phones‘ – ‘Phone Hackers: Britain’s Secret Surveillance

It is possible to identify a phone’s actual number (MSISDN – Mobile Station International Subscriber Directory Number) by use of a silent call or silent text, by knowledge of a specific IMEI/IMSI. [Footnote 5]

This technology can also be used to more actively intercept and read, alter or block SMS/Text messages, listen in on live or recorded voice calls (eavesdropping) and capture/store internet traffic that passes through a CSS, they can be used for other purposes like denial of services (jamming) and distribution of malware to compromise a phone or network(s) it’s connected to. More active and intrusive use of CSS often involves interception of a phone’s traffic which can be made easier if they use weak 2G security protocols or by forcing a phone to downgrade it’s 3G, 4G or 5G connections to 2G [Footnote 1], but this does not mean 3G4G and 5G protocol phone transmissions cannot actively intercepted, especially by State actors, noting:

Unlike the UK, France and the Netherlands are permitted to “tap streaming data” and use it in evidence”
Dutch accuse UK of ‘damaging confidence’ by disclosing details of EncroChat police collaboration‘ – 15.4.21

CSS alone does not give physical access to a phone or data at-rest on it, just telephony transmissions and data which passes through a CSS (some times called a ‘man in the middle attack‘), that level of physical phone/device intrusion in this context is called ‘equipment interference/EI’ and the aforementioned silent calls and silent text [Footnote 5] maybe be considered EI.

There are projects like Seaglass,  FADe and ‘SITCH: Open Source Cellular/CSS Counter-surveillance‘ aimed at discovering and countering CSS use, with one example of apparent discovery being at the House of Commons/Westminster.

Whilst CSS can intercept and store encrypted internet data that passes through them, this does not mean they are able to break the end-to-end (E2E) encryption of cross platform message apps like Signal [Footnote 6] and the  Tutanota email and calendar service, nor the encryption used when using likes of banking websites via a phone’s browser and or financial apps.

[B] But I want to take my smart phone with me to protests?

Many people use smart-phones and installed apps to help with personal safety and to visit locations and use services that are accessible to disabled people. Therefore to mitigate against the worst aspects of CSS you could use E2E encrypted email app services like Tutanota and the E2E encrypted message app Signal. [Footnote 6]

Some other mitigations often suggested are: switching off one’s smart phone when attending protests, putting it into ‘Airplane Mode‘ or placing it in a metal container or bag (a Faraday cage) to block all phone transmissions (Telephony, App and Internet Traffic, WiFi and Bluetooth).

An additional option is to use smart-phone’s ‘full disk encryption‘ (FDE) option and encryption of any added memory card in addition to a password protected screen (finger print, iris or facial recognition protection not recommended especially against State actors), as well setting options that allow a phone’s camera/video and emergency call facilities to be accessible when the screen is locked, which can include any contact number assigned for emergencies.  It is also possible to have a locked screen show emergency and medical info for use by the user, ambulance or medical services and show contact details for legal and arrest advice services and to be able to make emergency calls, to numbers decided by the user. (again whilst the screen is locked)

[C] What about the Police taking my phone to view it’s content?

 

The use of ‘mobile phone extraction’ [MPE] tools enables police forces to download
all of the content and data from people’s phones.
 This can apply to suspects, witnesses
and even victims – without their knowledge
(including easily recovering ‘deleted‘ content and data)
Phone Data Extraction: digital stop and search‘ – 2020
Related: Podcast on Extraction and article: Police unlocking your online data cloud “goldmine”

Police services use technology and Cyber Kiosks for mobile phone extraction (MPE) for physical analysis of a phone, to view or copy it’s content, including contact lists and phone call history/logs, app data, account log-in credentials, photos, videos texts and content of message and email apps.

Police Scotland has created online content that explains it’s Kiosk use, as well as a video.

For more details on MPE, the ICO has produced an Investigation Report: Mobile phone data extraction by police forces in England and Wales.

This is another reason why not taking any mobile phone to protests is a good idea or taking a ‘burner’ phone is less problematic than taking one’s own or any smart phone.

A bystander or protestor’s phone could be seized for MPE if they are arrested, or because they are suspected of an offence or on a opt-in consent basis if they are connected to an offence as a witness, victim or complainant.

Unfortunately there is little oversight or consistent guidance or codes of practice on use of MPE, but CPS does have a guide to “reasonable lines of enquiry” and communications evidence.

[D] Caution and due diligence

Whilst there is wider disclosure of MPE and Cyber Kiosks compared to CSS, there is little in the Public Domain about actual use of either directly associated to protesting in the UK. Even so, individual campaigners and the organisations they work for/with and protest organisers in particular should not only consider the risks they would be exposed to via them being subjected to MPE but all the others that could equally be exposed by Police access to their phone(s) data or via use of CSS. Activists and bloggers should also consider formally becoming a Journalist and joining the National Union of Journalists, as this could help provide legal ‘protection of sources‘ and themselves, it might also be helpful to make it explicit you are acting as Press when attending a protest.

Remember: if you are the subject of a Police/Law Enforcement investigation, they may just seek ongoing online access (assuming lawful authority) to your smart-phone’s integrated Samsung,  Apple/iOS/ – iCloud and Google-Android operating system account(s) log-in credentials and to your installed apps accounts (gmail, Twitter and Facebook etc) ‘data cloud‘ by use of  ‘cloud extraction technology‘, without any need for any ongoing physical access to your phone.. For instance, if you use a Weather App it is likely to be uploading/streaming phone location data constantly to the app’s remote server. Listen to this Podcast and read the report on the ‘Goldmine’ of your phone’s data-cloud contains, or this ‘the secret tech that lets government agencies collect masses of data from apps‘ (PDF) long-read.

The Human Rights Act and other legislation like the Regulation of Investigatory Powers Act 2000 and the Investigatory Powers Commissioner’s Office appear to offer some safeguards or checks and balances. However, when using a ‘burner’ phone or unregistered pre-paid SIM could mean some safeguards are weakened, or do not apply, as the phone or SIM could be said to have no direct relationship to an identifiable individual (natural person). This last sentence is purely speculative, but could give further reasons not to take any phone to a protest, or should prompt you to read the surveillance self-defence guides sign-posted earlier.

Due to present and increased risks of terrorism at likes of Parliaments, Courts and places that enable public gatherings, which are often the places of protests, it would seem reasonable to consider that CSS are deployed at these and other sensitive locations, possibly on a permanent basis. As a point of comparison, consider how widespread Automatic Number Plate Recognition (ANPR) is in use within the UK by Law EnforcementLocal Authorities and private entities like Car Park providers and Service/Petrol Stations, let alone being integrated into CCTV, alongside Facial Recognition technology being in greater use by PolicePrivate companies and via Social Media.

The Police can refuse to disclose it’s use of CSS and other means of surveillance on the grounds of National Security, equally other Public Authorities and Private Companies can say they cannot disclose information when it
could compromise the prevention and detection of crime. Therefore the full scope of how mobile phone use can ascertained or traced back to a user is only based upon what is in the Public Domain.

[E] Further reading and videos

 

Videos

[F] Examples of intercepted/leaked text messages, mobile phone calls and data/records

 

Footnotes

[1] A good reason not to take any phone and especially a cheap ‘burner phone’ to a protest,
is that they often only use weak 2G security protocols that are easy to break by CSS.

Nokia 105 – £17.95
“2G network capability”

‘Weakness of 2G mobile phone networks revealed’
https://www.sciencedaily.com/releases/2016/10/161021094836.htm

[2]  https://www.startpage.com/do/dsearch?query=burner+phone
Or disposable if affordable.

[3] If you do buy a pre-paid SIM card, try not to use the one’s that require the setting up of an online account before you can use/activate it, like GiffGaff, such SIMs can be identified by the fact that the phone number is not displayed when inserted into a phone and not printed on the SIM card holder at time of purchase. Also consider buying a SIM card that already includes usable credit, instead of having to buy a top-up voucher, a card purchased that includes a data allowance may also include credit for voice and texts.

It is beyond the scope of these comments to suggest informed pre-paid SIM card and phone purchase options or cover potential questions and issues. But if you consider you, or the people you know or networks you work with are at risk of CSS or MPE and you have a need to safeguard yourself and others, please consider purchase of SIMs months before you may use them or before the date they or a top-up voucher could expire as cash purchase could be linked back to CCTV footage archives or shopkeeper testimony of the places they are bought at. Use, purchase and activation of a SIM card or phone will also involve retention of phone base station timed specific location data, so be mindful this could also be used to trace back to the identity of the user.

Electronic Point of Sale/Till/Self-Checkout technology and software exists that can overlay purchasing/receipt data with CCTV recording, as well as recording the serial number of items purchased so it can be cross-referenced with a bar-coded till receipt to assist with refunds, returns, device guarantees and to prevent fraud, which may also include database recording a phone’s ‘International Mobile Equipment Identity‘ (IMEI/model and serial number of the phone) and SIM card/IMSI (International Mobile Subscriber Identity) whether or not shown on a till receipt. The Recipero mobile device intelligence and data aggregator is also used to monitor and record sales of secondhand phones. For: anti-fraud, insurance claims, phones leased/rented or sold as part of a mobile carrier contract or through finance/loans and to “monitor stock in real-time for many high-street retailers, warehouses and other distribution facilities” for theft and loss prevention. “Recipero offer a full suite of solutions, from providing automated pre-loss/theft property registration, to integration with POS [Point of Sale] and in-store trade-in systems, right though to active stock monitoring that can provide early warning of stock leakage and logistical losses”

Basic CCTV and ANPR (Automated Number Plate Recognition) data retention examples: LidlCCTV 31 days & ANPR “6 years” by ParkingEye . ASDACCTV 14 to 60 days ANPR 120 days

Essentially all of the comments above are aimed at helping people gain or retain a better level of anonymity, which is not easy in the digital age we live in today, but in many ways now far more important against the backdrop of UK plans and global attempts to undermine rights of protest and UK efforts to fundamentally weaken/backdoor encryption.

[4]  “IMSI catchers are intrusive surveillance tools whose use remains unregulated.
They are often deployed in secret, without a clear legal basis”
https://privacyinternational.org/report/3965/imsi-catchers-pis-legal-analysis

Police secrecy over ‘IMSI-catcher’ mass surveillance of mobile phones
Following an [FOI] tribunal ruling, constabularies in England and Wales can refuse to confirm or deny whether they use mass surveillance devices, known as IMSI-catchers (CSS) to monitor people’s location, phone calls and text messages
https://www.computerweekly.com/news/252485535/Police-secrecy-over-IMSI-catcher-mass-surveillance-of-mobile-phones
> Tribunal decision (PDF) https://informationrights.decisions.tribunals.gov.uk/DBFiles/Decision/i2576/Privacy%20International%20EA.2018.0164%20(18.02.20).pdf + Reporting https://privacyinternational.org/long-read/3925/information-tribunal-decisions-re-imsi-catchers-loss-transparency-and-why-we-will

Description of a IMSI Catcher (PDF) https://privacyinternational.org/sites/default/files/2019-09/Silke%20Holtmanns%20Witness%20Statement%20-%20readacted.pdf
via https://privacyinternational.org/long-read/3925/information-tribunal-decisions-re-imsi-catchers-loss-transparency-and-why-we-will

“Our cell catcher can be configured to include an IMSI catcher, IMEI catcher”
https://cryptome.org/isp-spy/l-spy.pdf

“The IMEI is automatically transmitted by the phone when the network asks for it”
https://cryptome.org/isp-spy/le-tel-spy.pdf

Authorities finally confirm stingray use in the UK—in Scottish prisons
https://arstechnica.com/tech-policy/2016/05/stingray-use-in-the-uk-details-scotland-prisons/
https://www.startpage.com/do/dsearch?query=scotland+imsi+prison+use

The Feds Are Now Using ‘Stingrays’ in Planes to Spy on Our Phone
https://www.wired.com/2014/11/feds-motherfng-stingrays-motherfng-planes/

[5]  Silent Call
In terms of Global System for Mobile Communications/GSM interception, a silent call is a call originated from the GSM Interceptor to a specific IMEI/IMSI, in order to make correlations between IMEI/IMSI and MSISDN (Mobile Subscriber Integrated Services Digital Network-Number, which is actually the telephone number to the SIM card in a mobile/cellular phone). By using the silent call, an GSM Interceptor can find out a certain phone number allocated to a specific IMEI/IMSI. Silent calls are a result of process known as pinging. This is very similar to an Internet Protocol (IP) ping. A silent call cannot be detected by a phone user.
https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki/glossary-of-terms#silent-call

Silent SMS
https://github.com/CellularPrivacy/Android-IMSI-Catcher-Detector/wiki/glossary-of-terms#silent-sms

MSISDN vs IMSI: What’s the Difference and Why Does It Matter for Mobile Identity?

[6] Tutanota E2E encrypted email and calendar services are highlighted, as it has a good free option and a low cost paid version (€12 euros) and has a facility to send encrypted messages to non Tutanota email addresses and organisations can embed an E2E encrypted contact form on their own website. You can compare other similar email services online.

The ‘Signal‘ cross platform message app uses end-to-end (E2E) encryption by default for text messages, voice calls, photos and file sharing and crucially it collects no data from phones and the Signal server only stores the users phone number, ‘and it makes no attempt to link it to their identity‘. Signal is the most privacy protective by design, evidenced by this report on a Court Order/Subpoena and gag order, for user data and account content disclosure: https://arstechnica.com/tech-policy/2016/10/fbi-demands-signal-user-data-but-theres-not-much-to-hand-over/

“I use Signal every day. #notesforFBI (Spoiler: they already know)”
https://twitter.com/Snowden/status/661313394906161152

There are other message apps like Whats App (that uses the Signal E2E protocols), Facebook Messenger and Telegram* and you can compare them online or with the comparison chart below:
(*”Warning: Telegram is not end-to-end encrypted by default” – “WhatsApp’s flaw allows stalkers to track you easily” – “Facebook’s controversial WhatsApp update may be ‘abusive exploitation’ of data, says regulator“)

Acknowledgement

This post has been informed by the work of Cooper Quintin from EFF.

 

 

[suffusion-the-author]

[suffusion-the-author display='description']
 Posted by at 12:40

 Leave a Reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

(required)

(required)