>From - Sat Mar 02 00:57:26 2024
X-Received: by 10.180.81.99 with SMTP id z3mr9509211wix.1.1384308408429;
Tue, 12 Nov 2013 18:06:48 -0800 (PST)
X-BeenThere: tscm-l2006_at_googlegroups.com
Received: by 10.152.170.229 with SMTP id ap5ls91092lac.19.gmail; Tue, 12 Nov
2013 18:06:42 -0800 (PST)
X-Received: by 10.112.205.194 with SMTP id li2mr3905465lbc.19.1384308402258;
Tue, 12 Nov 2013 18:06:42 -0800 (PST)
Return-Path: <tsc..._at_shaddack.mauriceward.com>
Received: from 121.235.cust.netway.cz ([85.239.254.200])
by gmr-mx.google.com with ESMTPS id a1si979859ees.1.2013.11.12.18.06.42
for <tscm-..._at_googlegroups.com>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Tue, 12 Nov 2013 18:06:42 -0800 (PST)
Received-SPF: pass (google.com: domain of tsc..._at_shaddack.mauriceward.com designates 85.239.254.200 as permitted sender) client-ip=85.239.254.200;
Authentication-Results: gmr-mx.google.com;
spf=pass (google.com: domain of tsc..._at_shaddack.mauriceward.com designates 85.239.254.200 as permitted sender) smtp.mail=tsc..._at_shaddack.mauriceward.com
Received: (qmail 7283 invoked by uid 0); 13 Nov 2013 03:06:41 +0100
Date: Wed, 13 Nov 2013 03:06:41 +0100 (CET)
From: Thomas Shaddack <tsc..._at_shaddack.mauriceward.com>
To: tscm-l2006_at_googlegroups.com
Subject: Re: [TSCM-L] {6526} tracking powered down cell phones
In-Reply-To: <52829A33.8080904_at_tscm.com>
Message-ID: <1311130137220.0_at_somehost.domainz.com>
References: <528287B4.6090107_at_tscmusa.com> <52829A33.8080904_at_tscm.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
No devices with a pushbutton power control disconnect the battery
physically. In the "off" mode, the device's "brain" is sleeping,
monitoring only power button (in more sophisticated devices there are more
conditions too, and that can be a vulnerability) either via an interrupt
or via periodically waking up and sampling the button's line.
There are service manuals for quite many phones available on the Net,
including schematics. (Same for laptops.) I suggest obtaining and reading
a couple of the schematics to get a rough feel for them; they have many
common patterns across brands as the physics that guides electronics is
the same for everybody.
Use of a DC shunt on the battery is a good way (the adhesive copper foil
used for Tiffany technique in jewellery and stained glass does a good job
for making flat conductors, especially when sandwiched with kapton tape)
to get the conductors through a narrow flat gap, e.g. out of a casing. A
sandwich of copper-kapton-copper allows tapping right into the battery's
terminal. A method other than a shunt uses a Hall-sensor current-sensing
integrated circuit, e.g. the ACS712, for which a convenient breakout board
can be found here:
https://www.sparkfun.com/products/8883
Both methods have advantages and disadvantages; pick what you prefer.
For low-cost data acquisition rig a decent soundcard can be used. I use a
USB soundcard (up to 96 kHz samplerate (some internal soundcards can go up
to 192 kHz), 2 channels at 24 bits) for some tasks. The input circuitry is
AC-coupled internally, so the DC part is stripped (think a couple Hz
high-pass filter). This is however still good when looking for changes.
The input bandwidth is limited, but for rough power consumption changes it
should be sufficient, as the amount of capacitors littering the power
distribution network act as a fairly decent low-pass filter.
For monitoring the concurrent RF activity, a wideband antenna with a
diode-capacitor detector circuit (use a Schottky that can go above the
phone's max transmitting frequency) should do a decent job, when in close
proximity to the phone. (Try it with an added op-amp and headphones, the
acoustic signatures of various signals, from bluetooth to wifi to
microwave ovens, are often telltale.) Its output can be attached to the
second channel of the sound card.
Both channels can be then recorded simultaneously using a conventional
audio editing software. I favor Audacity for this purpose, as it is free
and multiplatform and can handle hours of recording; one of my uses was
recording a cosmic radiation intensity during a commercial flight (and
then counting the pulses from the Geiger in a custom-written software
later - it was a very improvised experiment).
The physical layer of the contemporary systems usually employs some flavor
of orthogonal encoding (OFDM). This packs a number of bits into a single
symbol (often 64 or 256), resulting in much lower symbol rate than bit
rate. For 802.11n, the symbol length is 3.6 microseconds; as packets are
formed from a number of symbols, including a preamble, this brings the
packet length (and corresponding pulse from the antenna/detector circuit)
well within audible range (and therefore the sound card realm).
I should stress that the simplicity of this setup is more suitable for
qualitative indicative tests than precise measurements and there are only
two channels available, however that should be compensated with very low
cost of equipment.
For faster data rates, and for more sophisticated measures, I would
suggest looking at the RTL-SDR software, which together with some USB TV
dongles is a decent low-cost software radio platform. Inferior to "grown
up" equipment but you can't beat it for $30. Some Finns even implemented a
passive radar on this, using two dongles sharing a clock crystal (to
receive in a coherent way), one listening directly to a distant FM radio
transmitter, one watching the sky, the software plotting distance and
Doppler shift of the reflections on a two-dimensional graph, It was
intended for ionospheric research but was able to see airplanes pretty
well. I can find the link on request.
I can't say with certainty that a powered-off (or flight-mode) phone
cannot be convinced to talk with the tower, however I have no idea how it
could be done nor I heard about any specific description of such case. I
won't say it is impossible but would love to see it, or at least read a
good technical report (like published computer software vulnerabilities
are). I also find it somewhat difficult to believe that the phones would
intentionally transmit at so low power to warrant highly sensitive
equipment (not talking about parasitic emissions here); these things
SCREAM (especially in immediate vicinity). A very crude circuit with a
rudimentary antenna managed to hear the packets of a SMS message from a
phone behind two brick walls. (Can be also used to indicate across several
rooms when the microwave oven finished work - the periodic buzz ceases.)
So I would worry here about false positives from interference from the
outside.
As of talking with a phone with main battery off, over wireless, that may
be highly model-specific. The GPS chipset needs few 10s milliamps (see
datasheets) to run, which is quite a lot of current. It usually remembers
the last position and ephemeris data for faster lock next time, so last
acquired position may be somewhat available; the power in any backup power
sources in cellphones known to me (mostly Nokias from the pre-Microsoft
era) is rather minuscule and I don't believe phones would be generally
able to power the wireless transmitter for more than some fraction of
second, not enough to lock to the network. The backup batteries usually
provide power just for SRAMs and realtime clocks. Energy storage takes a
lot of volume, which is at premium in modern electronics. (The stuff these
days is annoyingly densely packed. I'd prefer more hackability in exchange
for 3mm thicker casings but the world goes in other direction. Sigh.)
Again, would love to see a demonstration. (YouTube video, or so? Please?)
(A trick for calculating the likelihood is estimation of the power demand
of the chips in question, then calculating the battery volume needed to
provide that energy (watt-hours per cubic millimeter) and looking for such
battery. Supercapacitors would work too but they have much lower energy
density. Automotive Li-ion batteries have 500Wh/liter, 1.8 watt-second
per cubic millimeter, as a ballpark figure.)
In batteries, I never encountered any higher-capacity memory, whether in
cellphone or laptop batteries. The batteries have an electronics board on
them, with protection (Li-ion ones are fiery little beasts when abused).
The single-cell ones typically contain just a pair of FETs and a guardian
chip, cutting the battery off during undervoltage, overcharging, or
overcurrent. The third (middle) pin of the battery is a thermistor sensing
its temperature and telling the charger to dial it down when things are
getting too hot for her liking. (Some batteries have four terminals. In
some of them, the two pins are thermistor and battery identification, or,
more rarely, some sort of data bus.) This simplicity can be used for
jury-rigging alternative power circuitry for a phone acting as a computer
gateway or just for replacing a stock battery with whatever you got in the
junk box in case of need.
There will be an article about it once I get enough round tuits.
Laptop batteries are more complex. Their circuitry often contains a "gas
gauge" (for tracking charging/discharging and estimating the battery
capacity). The Texas Instruments BQ... chips are commonly used here, and
their datasheets are suggested to refer to; other brands are similar in
principle. These chips communicate over more complex protocols, e.g.
I2C/SMbus. (Battery interface circuitry from laptop manuals will show
more.) However, even those rarely contain more than few dozen to hundreds
EEPROM bytes. There are tools on the Net to reset the battery chips, for
people who are fed up with being gouged by vendors and wanting to rework
their dead batteries with new cells. (Why can't the battery vendors agree
on a small set of cell form factors??? It worked for AA/AAA/C/D, why not
for cellphones and cameras too??? Why all the proprietary vendor-specific
crap that costs 10 or more times what it should cost???)
A word on a side, for salvaging stuff from batteries for experiments or
overall fun. A single-cell phone battery with a dead cell will yield the
module with the protective circuit. Laptop batteries contain (typically)
pairs of cylindrical or prismatic cells, three or four in series; often
only one of the pairs dies. (Check the cell voltage; often you get at
least one, often two, good pairs of cells from one dead battery.) These
single cells (or parallel pairs) can be coupled with the single-cell
protection circuits from dead phone batteries. By taking the pairs apart
and using only single good cells the laptop battery can be renewed for
free (though with just half of the capacity); beware though, as the
charging current per cell will be twice than what's intended. Do NOT
remove the thermal protection/sensing.
The dead cells aren't worthless too. They contain thin copper foil with
multitude of uses, and a (typically) polyolefin membrane with microscopic
holes, which turned out to be suitable for various experiments with
electrolysis (tested with oxygen-hydrogen production, should work also
with chlorates or metal plating or other redox reactions). Discharge to
zero before taking apart though, and be prepared for sparks and flames if
there was still some juice left in (also, the electrolyte, often alkyl
carbonate, is flammable and somewhat odorous - cannot say malodorous as I
kind of like the smell). It won't hurt you if you expect it to bite;
goggles and gloves (and, where appliable, flame-resistant workspace) are
always a good idea when dealing with stored-energy devices. Taking the
cell apart underwater also works. Li-polymer ones, in a sealed plastic
bag, are the best as they can be cut open easily. But I digress.
What brand of phone has battery with such substantial amount of memory,
please? I would love to tear it apart! Not looking for an argument/fight,
looking for knowing more!
--
....It's not a bug. It's a wireless acoustic telemetry transmitter.
On Tue, 12 Nov 2013, James M. Atkinson wrote:
> The article in question, and the inquires it quotes are misleading.
>
> For example Samsung is reported to have said "...without the power source..."
> but most Samsung cell phones do not have the ability to actually disconnect
> the power when you turn them off, to the statement my President Kim is
> misleading.
>
> Apple, (for example) does not actually disconnect the battery on a power down,
> neither does RIM/Blackberry, or a half dozen other companies phones that I
> personally have examined in a lab. The methodilogy that I used as to open the
> phone to access the battery on a copper to copper and to place a current shunt
> (low value resistor) between the battery and the phone and then to use a high
> speed multi-channel analog to digital recorder across this shunt to very
> carefully measure the current flow over a period of many weeks. The use of a
> multi-channel A/D convertor was important as I needed to also carefully
> document RF activity out of the phone and to isolate the RF activity into
> multiple bands specific to that model/version of phone (separating uplink and
> don link channels as well as a few phones are capable to transmitting over the
> receiving channel). Some phones also have internal FM band modulators,
> Blutooth, WiFi, and other circuits, so the circuit and the chips on the phone
> have to be explored with test equipment to find the cute circuits and filters
> that were in place on many phones and PDA's.
>
> I also attached a DSSO (high speed digital oscilloscope) across the shunt to
> watch current draw to and from the battery, and to capture RF that might be
> below thresholds that might otherwise not be noticed, when the phone shoudl
> not be operational (like when "turned off").
>
> I also figured out a way to covertly provoke the cell phone carriers to
> access the phone when it was turned off, and in some cases to provoke the cell
> phone carrier into causing the phone to give up a GPS position when the main
> battery was actually removed from the phone. I also figured out a way to
> provoke the carrier into updating software over the air when the phone as
> actually "turned off" but the battery was still connected or the battery
> charger as in use.
>
> Bottom line: No modern cell phone is actually "turned off" and inside the
> batteries in most phones is a section of memory, and most phones can access
> this battery hidden memory, and in most cases it is large enough in storage
> capacity to hold eavesdropping software. Also, do not trust a cell phone until
> you bake it by placing it into a microwave oven and "baked out the evil" for a
> good half hour of so with the oven on high (or until the fire trucks shows up)
> and then to dump the charred remains into the ocean, and maybe not even then.
>
> -jma
>
>
>
> Mitch Davis wrote:
> > good read, we all need to stay on top of cell phones and capabilities. Just
> > as lethal as a 20 yr old fisher price baby monitor, or AID wing bang:
> > http://arstechnica.com/security/2013/11/samsung-nokia-say-they-dont-know-how-to-track-a-powered-down-phone/
> >
> >
>
> --
> James M. Atkinson. President and Sr. Engineer
> Granite Island Group http://www.tscm.com/
> (978) 381-9111 jm..._at_tscm.com
>
> http://www.linkedin.com/profile/view?id=15178662
> https://www.facebook.com/james.m.atkinson1
>
>
Received on Sat Mar 02 2024 - 00:57:26 CST