They say you can tell a lot about a woman by what’s in her purse. More generally, you can tell a lot about any person by what they always carry. In my case, I never leave the house without my keys, my wallet, and my cellphone. The keys are pretty self-explanatory – I’ve never left home without planning to get back in later – and my wallet is there so I can buy lunch. My phone, though, seems to just tag along to cause stress. Powered on, but idle, I wonder why it uses so much more battery than, say, a tablet. A partial answer to that question is that, several times per minute, my phone sends a small message to the cell tower1. Much as I would love better battery life, this makes sense. Without that “ping” to the cell tower, my phone would have no way to know of, for example, incoming text messages.
Unfortunately, the procedure a cellphone uses to connect to the tower is completely unauthenticated, meaning so-named Man-in-the-Middle (MITM)2 attacks are relatively easy to carry out. The basic idea of a MITM attack is very simple: Say I tell you I am someone I am not. For example, a police officer. You would probably want to see some identification for me to prove it. Many software systems do not ask for this identification, meaning they will just send data to anyone who asks for it.
Not this kind of Stingray…
(Source: http://eskipaper.com/stingray-4.html)
This is bad for two reasons: First, whoever owns the Stingray can record calls, (SMS/MMS) messages, and any unencrypted data. Secondly, your phone can be requested to send triangulation data about other cell towers in range, making it possible to track location with very good accuracy in real-time3.
Neither of these things sound great for privacy but, as we’ve
already talked about in class, we aren’t too uncomfortable when
such aggressive tracking is used in a criminal case. Of course, this
is where everything starts to get messy. The first problem is that
these Stingrays are often used without a warrant1, despite
having precedent from other cases that real-time tracking amounts to
a fourth-amendment search, and thus requires a warrant4.
Added to this is that in cases where Stingrays are used, law
enforcement often tries to conceal that fact, even going so far as to
drop cases when they would potentially be forced to reveal the use of
a Stingray.
The second privacy problem is that everybody’s
cellphone within the Stingray’s range of operation is intercepted.
This is by necessity – the way a Stingray works means it’s not
possible to target an individual phone – but that doesn’t make it
any less of an invasion of privacy. When court orders do authorize
the use of Stingrays, there is often very little mention of what
happens to the “collateral” data collected5.
It may be immediately deleted, but it could also all be shoveled into
some database. Given the secrecy surrounding law enforcement’s use
of such devices, we have no real reason to choose one over the other.
However, as the NSA was willing to collect massive amounts of data
about American’s phone calls under the Patriot Act, it wouldn’t
be unreasonable to believe that they collect and store information
gathered by stingrays from unknowning citizens.
However, the
worst news is yet to come. Although it would be, at best,
questionably legal to own such a device, they are relatively easy to
build and are available for purchase outside of the US6.
This means that, quite aside from law-enforcement, it isn’t beyond
belief that other individuals or organizations have the capability to
perform mass surveillance by use of cell site simulators.
Given that, what can you do to protect yourself? Unfortunately, very little. The obvious answer is to switch your phone off and remove the battery. This is foolproof but impractical. Alternately, you could write to your cellphone provider and complain that they need to upgrade their security. This is not likely to be effective because it would cost the company money and because they would most likely have to retain the older, insecure system for backwards-compatibility.
Given the vast amounts of data it is possible to obtain using a Stingray, including live location information and calls, messages, and data, I think it is clear that law enforcement should require a warrant before using a Stingray, keeping in mind a plan for what to do with “collateral” data. However, this does not address the privacy concern that anyone can build a cell-site-simulator for $5007. Though a warrant should definitely be required to use this technology, the real problem is that cellular authentication and encryption are both totally broken and ought to be upgraded.
1https://www.eff.org/deeplinks/2012/10/stingrays-biggest-unknown-technological-threat-cell-phone-privacy
2Personal knowledge supported by https://en.wikipedia.org/wiki/IMSI-catcher
3https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-What-data-can-a-cell-site-simulator-collect?-
4https://www.eff.org/deeplinks/2016/04/eff-and-aclu-expose-governments-secret-stingray-use-wisconsin-case
5https://www.eff.org/sls/tech/cell-site-simulators/faq#faq-If-I%E2%80%99m-not-a-target-of-a-criminal-investigation,-why-do-I-have-to-worry-about-cell-site-simulators?