Guide to DIY Wiretapping
Geeks are Sexy writes "ITSecurity.com has a nice piece this week on how wiretapping works and how you can protect yourself from people who wants to snoop into your life. From the article 'Even if you aren't involved in a criminal case or illegal operation, it's incredibly easy to set up a wiretap or surveillance system on any type of phone. Don't be surprised to learn that virtually anyone could be spying on you for any reason.'" Maybe I'm on the wrong track here, but I guess I assumed that wiretapping now happened in secret rooms at the telco, and not by affixing something physically to a wire in your home, but I'll definitely be aware next time I hear a stranger breathing next time I'm stuck on hold.
Most of the land line suggestions in that article don't seem to bother with taking care of the noticeable voltage drop caused by adding an extra phone to a call. You can tell when somebody else in your house picks up the phone while you're on it because the person on the other end gets quieter. The same thing would happen if you plugged a phone into the line outside your house. I thought professional surveillance systems did something to make up for this, so there's no noticeable change in volume when the wiretapper starts listening.
ZuluPad, the wiki notepad on crack
Good luck with all that.
The problem with socialism is that they always run out of other people's money. - Margaret Thatcher
If your listening device uses capacitive coupling, then there's no current drain to draw down the nominal 50 volts across an on-hook POTS line. Radio Shack used to sell a little box that coupled like that and also would turn on a recorder when the line went off-hook. Also, since it's a listening only device, there's no risk of being overheard while breathing heavily.
"Do the Right Thing. It will gratify some people and astound the rest." - Mark Twain
Of course you can still tap any POTS line the good old fashion way. Its just a matter of accounting for the voltage drop on the line. Although yes if you are the telco it is just easier to capture everything while it is in digital format on the switch. Now if you don't use analog, inline (some random place between the CO and customer) tapping can be a bit harder. You basically either have to record the signals on the line and decode it later, or toss a non-terminating CSU/test kit in the line without making too much of a disruption in the signal.
Every method I have seen so far requires physical access.
/.!
Quite frankly, it's a threat, but no more than the famous slashdot meme: If you have physical access you have root.
Who would abandon their celly? I take mine to the bathroom w/ me. I don't let strangers in my house, and it doesn't leave my pocket unless I am making/recieving a call.
I think this is really just FUD to freak people out. Hey whats that? Why does my phoen blink? Oh, it's just a reply to a post on
How much is your data worth? Back it up now.
The article also links to this product. They never had toys this fscking cool when I was a kid.
I agree that recommending Skype for security is a bad idea, but for entirely different reasons. I consider my computer safe. Nothing is perfect, but my computer is much safer than the mess at the phone company. However Skype is not secure. It is not even open source. Just like people can do weird stuff at the phone company, they can do weird stuff at Skype. The creators have gone on record saying that the encryption code probably will not stand up to crackers over time.
http://en.wikipedia.org/wiki/Skype
Write your own Choose Your Own Adventure. http://www.freegameengines.org/gamebook-engine/
I sometimes feel bad about flaming Skype. They really are more resistant to eavesdropping than most everything else, and it's nice they used AES256. They almost got it right.
But saying it's mathematically impossible to crack 'em is bullshit, because Skype's design is flawed (in at least one way that we know of -- and there's a lot we don't know about it, because it's closed and hasn't been really audited by crypto-nerds -- that's Skype first problem). AES256 is useless if the key itself has been compromised by MitM, and Skype's design allows that (that's Skype's second problem). Skype depends on a central server to introduce identities to one another, and that central point is potentially subject to compromise (or coercion). There's no reason VoIP users can't (in many cases, at least) cert each other directly, but unfortunately, that's not how Skype works.
Skype can be tapped, and all this talk about how its heavy crypto prevents that, is a smokescreen. AES is believed to be a strong link in this chain, but don't forget that we're talking about a chain.
As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
The Government avoids spying by using STU phones. If tapping stays in the news, I wonder if projects like OpenMoko will incorporate similar techniques. It's good enough for gov't TS - so it is probably good enough for me chatting with my friend about what to do this weekend. It would only be a matter of time before cracking these streams would be easily doable, but at least there would be a small barrier to unfettered access.
... from 30 to 50 MHz. Then scan some of the higher ranges.
Gotta love mixing old and new technologies. It's amazing how many people enter their credit card info into cordless phones. Baby monitors are also easy to pick up. Most conversations aren't worth listening to, though.
About a year after 9-11, I was talking on my phone with my wife. Now, to really understand this story, you have to know that my wife is from Iran, her father was a former General or the Air Force there, and she knows multiple folks who had fairly high positions at one time in the government. And she calls home all the time. We spend 50-60 hours a month connected to Iran via phone.
So I'm sitting in a bookstore, and she calls. Right in the middle of the call there is a strange squeaking noise, reminiscent of digital audio "static" noises, sort of a cross between a cd skip and a modem. Sudden it ends, and we are no longer on the phone alone. Somehow our conversation was crossed with another cell phone conversation.
The strange part is this. The other folks now joined to our conversation were also from Iran. They were speaking Persian.
After about 30 seconds or mass confusion, the call went dead. For about 5 minutes my wife's phone and mine refused to connect out to make a call. Full signal, no access. When we finally got back in contact with each other, she told me that the other people on the line were trying to meet at a restaurant on the other side of Dallas. One had just landed at DFW from Frankfurt, on his way home from Iran. She understood them, I don't know the language.
Now, what are the chances of 4 mobile phones, separated by 20 miles a piece, suddenly crossing conversations at the servers, and being the same fairly limited ethnic/nationality group that just happens to be on the "Axis of Evil" list?
I tell this story to my freinds under the title "My conversation with the NSA" Since then it is a running joke for my freinds to randomly yell "bomb", "assassinate", "Jihad" and "Mohamed" while talking to me on the phone.
Especially in field operations knows how insecure our phone pedestals (the little green and brown enclosers along your neighborhood roadds) are. Typically they use just a standard hex wrench to open. Dress in the right clothing, grab your butt set and go to town. Commercial bldgs are not much different. If you can talk the lingo and have a tool bet, its not hard to use a little social engineering to get into building telco closets. Having worked in telco for many years I can't count how many times I have been let into bldgs by just saying "I am with xyz telecom, and tenant abc needs us to work on their phone". 9 times out of 10 I don't have to present ID, they don't call the tenant they simply unlock the door. I have worked in telco closets where I have tapped onto a copper pair to hear lawyers discussing divorce cases with a cleint. Or a stock broker discussing financials with one of their clients.