Slashdot Mirror


Can the NSA Really Track You Through Power Lines?

mask.of.sanity writes Forensics and industry experts have cast doubt on an alleged National Security Agency capability to locate whistle blowers appearing in televised interviews based on how the captured background hum of electrical devices affects energy grids. Divining information from electrified wires is a known technique: Network Frequency Analysis (ENF) is used to prove video and audio streams have not been tampered with, but experts weren't sure if the technology could be used to locate individuals.

71 of 109 comments (clear)

  1. Interessting in any case by gweihir · · Score: 4, Interesting

    While I also doubt that this is possible today, I am sure the NSA is looking at placing the respective sensors. Then we will have to do "analog routing" and mix in mains hum form several places to obscure where and when things have been recorded. Maybe we should start to offer recordings of local grid noise. Would not be that difficult to do.

    Well, fighting fascism is difficult. But there really is no alternative for anybody with at least a shred of noncompromised personal ethics. The price of doing nothing is just way to extreme.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re:Interessting in any case by AndyKron · · Score: 4, Funny

      I'm gonna use Star Trek TNG Ambient Engine Noise (Idling for 24 hrs)

    2. Re:Interessting in any case by Amouth · · Score: 5, Insightful

      While the article, you, and i'm sure more to come keep mentioning the need to "place senors" the reality is any Utility company worth it's salt already has this data logged as part of normal operations through SCADA/DCS systems.

      This systems monitor (and log) so many different variables that it forces the companies to store everything in databases for reference & analysis. When it comes to power generation nearly all power generation is done by a "utility" company all of which are heavy government regulated. In a lot of areas it is actually the government which determines bill rates and adjustments to generation capacities (or at least responsible for the play book the operators work by).

      It would be far easier and less far fetched to believe that the NSA would have access to theses logs/DBs for what ever use they wanted. Especially with most major power generation sites being covered under FERC regulations and several of the regulation requirements for Reliability requires operators to track and monitor this exact data that the NSA would need.

      And trust me when i say that these sites log everything and keep it incase of an Audit. The consequences for failing to be able to provide the data in case of an Audit or Incident Investigation is worse (for the company) than just about any incident would be. They log it, they keep it, even if they will will never look at it again, because the government might come asking for it (and they will give it when asked with no questions as they are required to by regulations).

      Honestly going this route i'd say compared to the wiretapping network the NSA has put together, this would be trivial for them to do (not cheap or quick, just not all that difficult).

      --
      '...if only "Jumping to a Conclusion" was an event in the Olympics.'
    3. Re:Interessting in any case by Patent+Lover · · Score: 1

      Man that would produce the best sleep ever.

    4. Re:Interessting in any case by TWX · · Score: 4, Insightful

      While I also doubt that this is possible today, I am sure the NSA is looking at placing the respective sensors. Then we will have to do "analog routing" and mix in mains hum form several places to obscure where and when things have been recorded. Maybe we should start to offer recordings of local grid noise. Would not be that difficult to do.

      It's not even that complicated.

      Many power lines have optical fiber strung in the middle of them, it's called optical power ground wire (OPGW) (scroll down a bit). That fiber is used as Internet backbone, as telecom voice, and as diagnostic for when there are power grid problems. If a line goes down then they can use an OTDR to determine the distance to the break instead of having to hunt for it.

      All that they'd have to do would be to put devices at termination points and use dark strands. Sure, the equipment to transceive on single-mode fiber at those distances would be pricey, but it's completely within the technology that we have right now.

      --
      Do not look into laser with remaining eye.
    5. Re:Interessting in any case by HornWumpus · · Score: 2

      Consulted for the industry.

      They already feed the data (substation instantaneous V and phase for each leg) to the dispatch floor data centers, the plant owners data centers, the transmission area control floor (if different from the dispatch floor), the 'Independent System Operator' data centers. Maybe all the same entities in neighboring regions.

      One thing Electric utilities don't generally lack (ETSA not withstanding...EDS supplied their office network.) is bandwidth.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    6. Re:Interessting in any case by AHuxley · · Score: 3, Informative

      Cities and states are already helping with the next gen of contractors via networked street lights.
      A city gets basic energy saving with a lot of optional extras to contain any freedom of assembly and association.
      Voice as in mic, voice stress, gait, wifi and everything a camera offers over every road or public area.
      Fun with wifi funds? 'SPD will shut off its new Wi-Fi after privacy backlash" (November 15, 2013)
      http://seattletimes.com/html/l...
      CIA Chief: We’ll Spy on You Through Your Dishwasher (03.15.12) for the next generation of basic consumer appliances.
      http://www.wired.com/2012/03/p...
      Add in a smart meter https://en.wikipedia.org/wiki/... with a rapid communications setting.
      Then you have your tame game console with "webcam" from bands who love to help all govs over all product lines.
      As for Network Frequency Analysis, it sounds like something others have hinted at from the TEMPEST generations. https://en.wikipedia.org/wiki/...

      --
      Domestic spying is now "Benign Information Gathering"
    7. Re:Interessting in any case by Trogre · · Score: 4, Interesting

      Smart TVs are almost certainly involved and if they aren't already, soon will be.

      Gullible people seem quite happy to install TVs with inbuit cameras and microphones in their living rooms and connect them to the Internet. What could possibly go wrong?

      --
      "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
    8. Re: Interessting in any case by ArcadeMan · · Score: 1

      Wow, your UPS has an upgraded version of Sark's Carrier? It must be fucking huge!

    9. Re:Interessting in any case by Runaway1956 · · Score: 2

      I read something about this - quite a long time ago. Two years, maybe even three? Can't really recall now.

      It wasn't JUST the humming of the power grid that was being used, as I recall.

      Anyway - how hard would it be to force a generating plant to INTRODUCE a unique identifier, if one didn't exist already?

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    10. Re:Interessting in any case by NormalVisual · · Score: 1

      Available soon: The 60" Sony LCD Panopticon!

      --
      Please stand clear of the doors, por favor mantenganse alejado de las puertas
    11. Re:Interessting in any case by Anonymous Coward · · Score: 1

      That seems more difficult than just applying a sharp notch filter at 60Hz, then adding in some random noise over that band.

    12. Re:Interessting in any case by mysidia · · Score: 1

      While I also doubt that this is possible today, I am sure the NSA is looking at placing the respective sensors.

      The NSA almost certainly have placed sensors, either just a few to test the principle, or completed their deployment many years ago.

      And whether it's effective or not: classified, probably

      On the other hand... if it is effective... I am sure the NSA would like the world to think it is ineffective, which is easily accomplished using propaganda and some nudges to the media.

      Therefore... I think the only responsible thing to say here, unless, you've spent thousands of man hours studying this possibility and devoted technical resources into looking for meaningful or predictable data in video random background noise, is We don't know, this might or might not be possible, and they might or might not have this capability.

      If you're concerned about being surveilled: I think you need to assume that this is possible and well within their reach.

    13. Re:Interessting in any case by gweihir · · Score: 1

      I don't doubt they have data. I just doubt they have the precision required and the clock-sync required that the NSA needs for precise targeting. Also, the respective literature goes into looking at disturbances as well (large AC starting, that kind of thing) and these may not even be visible at the utility-end, as the net has very low impedance there. I also expect that the NSA wants real-time capability as they will want to vector in drone strikes.

      But yes, for very rough after-the-fact localization, the data may already be available.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    14. Re:Interessting in any case by gweihir · · Score: 4, Interesting

      Inserting a localizer signal using ultra-wide band would be very, very simple. These are basically very brief spike signals at "random" times that you cannot measure unless you know the cryptographically generated sequence in advance. They look like low-level noise to most equipment. But as soon as you know the sequence and look for it, they become glaringly obvious.

      So maybe "inserting the sensors" is the wrong idea and "inserting the UWB localizer beacons" is more what they will be doing.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    15. Re:Interessting in any case by AmiMoJo · · Score: 1

      The police have used the technique to prove the authenticity of recordings or the time when they were created before. In one case the defendants claimed that the police had stitched together separate recordings to make them sound incriminating, but they used this technique to show that they were in fact continuous.

      Faking it would certainly be possible. Masking it should be possible too, with a single 50Hz signal generator and power amplifier.

      One huge flaw in this technique is that it assumed that the recorder has a fairly robust clock. If the clock wobbles a lot it is going to screw up the correlation with the mains frequency. Many cheap recording devices so have poor quality clocks, often RC oscillator based rather than a dedicated timing crystal, or a cheap crystal that is a way off the desired frequency. You could deliberately speed up and slow down the recording to imitate this effect.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    16. Re:Interessting in any case by AHuxley · · Score: 1

      Just try and read more news "AC"
      Big Brother is watching: Fears over 'homeland security' streetlights that can record your conversations and track your movements (28 October 2011)
      http://www.dailymail.co.uk/new...

      --
      Domestic spying is now "Benign Information Gathering"
    17. Re:Interessting in any case by budgenator · · Score: 1

      GPS chips are pretty much everywhere and would provide an extremely accurate time reference, this could allow locations to be infered from power line conditions. Knowing this is at least plausable, counter-measures would be vary from trivial to very complicated, one could even record conditions at one location and inject them into a video recorded in a different country.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    18. Re:Interessting in any case by budgenator · · Score: 1

      GPS chips provide a pretty solid time signal.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    19. Re:Interessting in any case by gweihir · · Score: 1

      That would work if the NSA would be hacking devices anywhere. They do not do that. Not because of any ethical concerns or because they cannot, but in order to protect their tools and methods. Whenever they hack something, they risk losing the vulnerability used. As vulnerabilities are expensive and not in unlimited supply, they cannot use them for minor things such as a sensor point somewhere.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    20. Re:Interessting in any case by TWX · · Score: 1

      Yes, but they do use the OTDR method.

      --
      Do not look into laser with remaining eye.
  2. Not likely in modern communications by BitZtream · · Score: 4, Informative

    Due to the amount of signal processing that goes on with modern television, its highly unlikely. MPEG compression probably stops it at the source since its instantly fuddled with and massive amounts of the data they use is lost right then and there.

    If you were actually afraid of the NSA finding you, as a whistle blower, getting around this form of tracing is trivial.

    Use a UPS for power, unplugged from the power grid. No power line tracking.

    Or the more old school way that people have done for a while, record it and leave before broadcasting it. Locating the source of the recording doesn't mean much if the target is already 800 miles away.

    --
    Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
    1. Re:Not likely in modern communications by sumdumass · · Score: 2

      Or the more old school way that people have done for a while, record it and leave before broadcasting it. Locating the source of the recording doesn't mean much if the target is already 800 miles away.

      Just don't use your mom's basement or rent a recording studio that keeps logs on who was there and when, or else you will still get popped.

      A generator, tarp for a back drop, and a semi- isolated spot in the middle of nowhere (like 800 miles away as you suggest) should be good. Leave your work cell phone and regular cell phone if you are a government employee somewhere else too. If work provides it, they might track it and for the government, they can accidentally search the NSA records and stumble onto you with as much crap they collect.

    2. Re:Not likely in modern communications by mysidia · · Score: 1

      Due to the amount of signal processing that goes on with modern television, its highly unlikely. MPEG compression probably stops it at the source since its instantly fuddled with and massive amounts of the data they use is lost right then and there.

      It might, but you can't really be too sure that there isn't enough data surviving; MPEG compression was never designed as a feature for ensuring privacy, and there will still be human-imperceptible recorded noise.... or, maybe intentional "canary" noise signals / watermarks transmitted by the feds to help aid them in this endeavor. A video camera with a GPS and a secret way of "watermarking" the output files with analog patterns incorporating the location and/or IP address data would also be a great aide, and many modern cameras already have the GPS capability too.

      Imperceptible but recorded visual noise from the background lighting in the room and orientation of cosmic background radiation noise alone may be revealing.

    3. Re:Not likely in modern communications by richlv · · Score: 1

      look at the reconstruction of that lander video. from nothing to understandable things. i wouldn't be that sure nothing can be obtained

      --
      Rich
    4. Re:Not likely in modern communications by StripedCow · · Score: 1

      Imperceptible but recorded visual noise from the background lighting in the room and orientation of cosmic background radiation noise alone may be revealing.

      Also, simulating the universe from the big-bang will reveal your location.

      --
      If Pandora's box is destined to be opened, *I* want to be the one to open it.
    5. Re:Not likely in modern communications by BitZtream · · Score: 1

      And if they record to a VHS tape, I might be concerned. Once it hits the MPEG encoder, not so much. The entire point of MPEG is to throw out as much data as possible if it isn't perceptible by humans and recreate it as something that is much smaller but looks the same to human senses.

      MPEG is perceptual encoding. The imperceptible would be lost by design, not because they were trying to ensure privacy but simply as a side effect of the design.

      Yes, they could easily design cameras that could use stenography to encode data in the mpeg stream that would survive, but that isn't what we're discussing. We're discussing power line noise making its way through the entire system and being used to ID a recordings location.

      Even so, assuming an analog recording, I'm still inclined to believe it would rarely work just based on modern electronics having so much built in power supply conversions and filtering. Digital ballasts for example are going to make it hard to see fluctuations in lighting.

      --
      Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
  3. Sounds Plausible by Anonymous Coward · · Score: 1

    The skeptics are creating a straw man by framing the issue as whether the NSA could do it reliably, consistently, and at all locations. And then tear it down by saying it's too far fetched. Well, d'uh. But that's the typical response for anybody who doesn't actually study and understand how attacks work in real-life, and how you leverage multiple pieces of evidence to zero in on an answer.

    The supposed informer said that they could do it even faster if the informant was taped at a known location (that is, one of a set of locations already known to be the site of taping). That suggests that they can in fact use ENF to help pinpoint location, in tandem with a bunch of other information. And of course could use ENF to to help verify locations by measuring ENF of suspected locations.

    So, sounds entirely plausible. Heck, if Google (and other companies) can send trucks around the country to scan WiFi, why couldn't the NSA do something similar for ENF? We don't say that Google's WiFi database is impossible simply because they can't be 100% certain that a particular MAC address is still (or ever was) definitely associated with a particular street address. We intuitively accept the limit accuracy, precision, and general reliability of such methods without discounting the value altogether.

    1. Re: Sounds Plausible by Anonymous Coward · · Score: 2, Interesting

      To the paranoid, this sounds like a cover. When the magician says he can pull a rabbit out of your ear with his right hand, look to his left hand; when the NSA says/leaks that they can locate you by electric hum, they probably found an easier shortcut (something embedded in the camera?) and want you to go looking elsewhere so you don't find it. Remember, the NSA claims magic but practices sidechannel attacks that make it look like they know magic.

  4. Well, sort of. by waddgodd · · Score: 1, Informative

    Tracking someone through landlines has been a Thing for many years now. Ever hear of a "lock and trace"? You can SORT OF do the same thing for power, by embedding a signal in a given substation. It's nontrivial, and it's horribly complicated, but it IS feasable. As for the "hum" thing, that's just standard TEMPEST, been a Thing now for going on thirty years, where you can fingerprint electronics via EM signatures and you can read those EM signatures via physical phenomena including audio hums and induced currents in surrounding circuits. This is why the LASER mike was actually developed, not for actual sounds (standard shotgun mikes do wonders there, because the glass reresonates sound just fine), but to get a good frequency signature on TEMPEST EM leakage. So, in sum, they're not specifically taking a van out and following lines to see what location an interviewee is at, but a lot of that is that they don't really need to because they can get all the information they need through older technologies that approximate the capabilities

    --
    Just because you're paranoid doesn't mean they aren't out to get you
    1. Re:Well, sort of. by Anonymous Coward · · Score: 1

      If someone has not yet called bullshit, allow me.

    2. Re:Well, sort of. by phantomfive · · Score: 2, Insightful

      You can SORT OF do the same thing for power, by embedding a signal in a given substation.

      So, I came here to ask, "Why is this on Slashdot? Don't we all realize that isn't possible?"
      Then I came here and saw this, and that it was moderated up. Oh well.

      --
      "First they came for the slanderers and i said nothing."
    3. Re:Well, sort of. by Shoten · · Score: 5, Interesting

      Tracking someone through landlines has been a Thing for many years now. Ever hear of a "lock and trace"? You can SORT OF do the same thing for power, by embedding a signal in a given substation. It's nontrivial, and it's horribly complicated, but it IS feasable. As for the "hum" thing, that's just standard TEMPEST, been a Thing now for going on thirty years, where you can fingerprint electronics via EM signatures and you can read those EM signatures via physical phenomena including audio hums and induced currents in surrounding circuits. This is why the LASER mike was actually developed, not for actual sounds (standard shotgun mikes do wonders there, because the glass reresonates sound just fine), but to get a good frequency signature on TEMPEST EM leakage. So, in sum, they're not specifically taking a van out and following lines to see what location an interviewee is at, but a lot of that is that they don't really need to because they can get all the information they need through older technologies that approximate the capabilities

      HUGE problem with this theory.

      The power grid operates on incredibly tight tolerances with regard to frequency. Additionally, within that margin (which is the same, everywhere, within a certain grid...and by grid, I mean, like "The United States" or "Great Britain") there is a small degree of variation that is the same for that grid and all that are built using the same equipment...which is a significantly humongous population.

      Imagine a metropolitan area like, say, San Antonio. San Antonio has several power stations that service its region. Each generation turbine produces what's known as "three-phase power," which is kind of like TDMA for AC electricity. Those three phases get broken out and separated into three outputs that then go into a substation and transformers, then out on the grid. The three phases equally and perfectly distribute around the 360-degree rotation of the "exciter," which is basically the generator's key component. If that distribution gets out of whack, power spikes in a really nasty way, and copper vaporizes fast enough that it's actually a detonation.

      But I digress. The point is this: AC power is a waveform, oscillating at 60 Hz. It cannot vary much at all...because within the same grid, everything is interconnected. Every generator is in sync, or has a syncrophasor to re-sync the power coming from it before it hits the grid. Otherwise, you get some power from A and some from B, with waveforms that are out of sync...and the frequency changes in both rate and amplitude, and shit blows up. (Including generators themselves...the "Aurora Vulnerability" that DoE is so batshit scared of is essentially a manifestation of this at the generator itself.)

      So...I've been trying to think of how there could possibly be enough variation to fingerprint someone based on the hum caused by that 60Hz frequency noise. I've been in transmission control centers where they monitor, regulate and occasionally wet themselves over frequency shifts, and I've seen that the amount of variation needed to cause sheer panic is shockingly low..and it rarely ever happens for even a second. And those tolerances have been the same everywhere I've gone.

      So no, it's not at all like TEMPEST. Because if it were, it'd be the equivalent of being able to figure which monitor you were looking at by EM emissions...when all the monitors in the country show the exact same thing.

      --

      For your security, this post has been encrypted with ROT-13, twice.
    4. Re:Well, sort of. by russotto · · Score: 1

      But I digress. The point is this: AC power is a waveform, oscillating at 60 Hz. It cannot vary much at all...because within the same grid, everything is interconnected. Every generator is in sync, or has a syncrophasor to re-sync the power coming from it before it hits the grid.

      Sure, the fundamental won't tell you much. There's a lot of other crap on the power lines though, and that might give you a signature of the location.

    5. Re:Well, sort of. by the+eric+conspiracy · · Score: 1

      The other crap in the lines is noise. It's insane to imagine that you could reliably extract any reliable information from it.

    6. Re:Well, sort of. by jenningsthecat · · Score: 1

      HUGE problem with this theory.

      The power grid operates on incredibly tight tolerances with regard to frequency...

      FTA: "It found fundamental differences in the structure of the harmonics of the 50 Hz which could be detected because Total Harmonic Distortion was strongly affected by local factors and had as a result little geographical consistency."

      Not that any of this is likely to matter. Even if they had a unique spectrum capture of a specific location at a specific time for comparison purposes, turning one computer on, (or off), would totally change the harmonic signature appearing on the local wiring, thereby making the reference capture useless. And a vacuum cleaner running would really mess things up.

      For anyone worried about this, running a randomly-swept audio generator through a frequency range of, say, 20 to 150 Hz, and injecting the signal into the audio capture at a level that is just audible without being too annoying, should seriously reduce any chances of the 'power line signature' being traced.

      Now if someone is actually injecting a unique signal into the grid for a defined geographic area, countermeasures would be more involved. Recording in a very good Faraday cage, using battery power only, with no cables entering the Faraday cage from outside, would probably thwart any such attempts at tracking. The sweep-generator technique mentioned above would provide additional insurance. But now we're very far into tin-foil-hat territory.

      --
      'The Economy' is a giant Ponzi scheme whose most pitiable suckers are the youngest among us and the yet-unborn.
    7. Re:Well, sort of. by pipedwho · · Score: 3, Interesting

      There's also the off-peak hot water signals that are modulated on the line (at around 1kHz) in some places. Those signals are generated at the local substation. Their purpose is to activate various hot-water systems to load balance the area's power use. Where the final goal is to minimise the peak usage during 'peak' periods of use.

      It is conceivable that if an 'interview' is made when that type of noise appears on the line, and that an accurate time reference is available, it may be possible to use this to narrow down the search region.

      Still not going to pin-point a location, but could definitely narrow it down far better than just using the 60Hz line frequency. Which is far too narrow band to provide any useful information beyond what country you're in.

    8. Re:Well, sort of. by Baloroth · · Score: 2

      It may be just noise, but is it different noise between different power lines (and if so, consistently different)? If so, it's a fingerprint. Noise can be information if you're looking for a specific kind of noise. Not all noise is identical, and if you can fingerprint that noise, you can use it to determined the source.

      Granted, that's a pretty big "if". I have no idea if powerline noise is consistent enough to be fingerprinted, different enough for a useful comparison, or strong enough to be picked up by standard recording devices. But it could be possible, in theory.

      --
      "None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
    9. Re:Well, sort of. by DeSigna · · Score: 2

      But I digress. The point is this: AC power is a waveform, oscillating at 60 Hz. It cannot vary much at all...because within the same grid, everything is interconnected. Every generator is in sync, or has a syncrophasor to re-sync the power coming from it before it hits the grid. Otherwise, you get some power from A and some from B, with waveforms that are out of sync...and the frequency changes in both rate and amplitude, and shit blows up.

      You may wish to engage in a quick review of:

      And numerous other examples of various subcarriers being successfully overlaid on the 50/60Hz power waveform. When used for data transmission, BPL technologies (while commonly deployed in short-range scenarios due to EMI problems), can deliver hundreds of megabits, up to multiple gigabits of bandwidth over tens of KMs - this was deployed and trialled for wide-coverage broadband delivery in Australia. These capabilities would indicate we already have consumer technology which can work through the noise to transmit and receive such a high-precision signal on a shared medium, and which would not create the chaos described.

      I'm not disagreeing with this being highly unlikely as a useful tool for tracking without a lot of infrastructure, but the power networks are in no way clean or perfectly in sync. Phases are locked (or the generators will get yanked into line, potentially disastrously), but beyond mechanical low-frequency synchronisation at the production end, there's a lot of noise and variation. I've personally seen several scenarios, mostly large industrial estates, which vary very significantly in voltage and frequency (both over 20%) depending on time of day and resultant grid load. IT gear doesn't agree with this and requires heavy duty power conditioning.

    10. Re:Well, sort of. by angel'o'sphere · · Score: 1

      That Laser story of your parent is nonsense ofc.
      You are right that the whole grid is synched at 50Hz/60Hz.
      Nevertheless it is fluctuating locally +/- 1Hz as soon as a heavy demand (or simply high inductive) consumer gets switched on or switched off.

      --
      Cost free eBook I read (by iBook/Kobo/Amazon/ObookO/Gutenberg etc.): "The Green Odyssey" by Philip Jose Farmer.
    11. Re:Well, sort of. by bluegutang · · Score: 1

      Interesting story: I once took a plug-in alarm clock to Europe. My first day there, I used it with a plug adapter. I overslept the next morning, and soon realized that the clock was running slow by several hours per day! Apparently its entire timing mechanism was based on the 60Hz of the grid, and where I was the frequency was 50Hz, so the clock ran slow by exactly that proportion.

    12. Re:Well, sort of. by AmiMoJo · · Score: 2

      I've been in transmission control centers where they monitor, regulate and occasionally wet themselves over frequency shifts, and I've seen that the amount of variation needed to cause sheer panic is shockingly low..and it rarely ever happens for even a second.

      You answered your own question. There are tiny variations at the local substation level, fractions of 1Hz and fractions of a volt. All that is monitored and recorded, second by second. The pattern of tiny variations over time, small as they might be, can be picked out of the mains hum on the recording and matched up to the data on file. Maybe not in real-time yet, but certainly after the fact.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    13. Re:Well, sort of. by Ungrounded+Lightning · · Score: 1

      I've been trying to think of how there could possibly be enough variation to fingerprint someone based on the hum caused by that 60Hz frequency noise. I've been in transmission control centers where they monitor, regulate and occasionally wet themselves over frequency shifts, and I've seen that the amount of variation needed to cause sheer panic is shockingly low..and it rarely ever happens for even a second. And those tolerances have been the same everywhere I've gone.

      The frequency is synchronized across the whole grid.

      The phase shifts, due to several factors (which way the power is going on the lines (treated as signal transmission lines), power factors of loads switching on and off, etc.) Much of this shiftig is local (motors on your transformer starting and stopping, etc.). Some of it is regional (for starters: the average across a distribution block of all those motor loads switching).

      The combining of the varioius contributibutions to the phase offset is essentially linear. So if you have a recording system that is including power line hum and sufficiently stable on a tens-of-seconds time scale, the phase can be extracted and correlated with a recording from a nearby part of the grid. The closer they are (in electrical term), the stronger the correlation.

      I could imagine the NSA recording this phase signal from one or several places in each city or rural region and archiving it, then using a cross-correlation against such a signal extracted from a recording. The amount of data to be stored and processed would be pretty small and a hit would stand out like a beacon.

      First run against a national average (or several regional signals) to get enough of a hit to identiy the time of the recording. Then run against that time segment of the whole database of local samples to get a rough location. (With enough samples this should get you down to a "which cell tower" level.) Then see what suitable recording studios are in the identified region and look for other clues.

      Possible countermeasures:
        - Notch-filter out the power line frequency and its first few harmonics.
        - Bandpass filter out the low part of the audio.
        - Add in a small amount of hum of your own, with a pseudo-random phase jitter (and still more phase jitter on the harmonics). Be sure to use a set of pseudo-random generator that they won't be able to identify and cancel out - like by using several of them to continuously adjust the amount of phase noise added and such.
        - Jitter the sampling rate.
        - Re-record it with deliberate injection of a larger amount of real power line hum at a different time and location, before releasing the recording. B-)

      Identifying edits in a recording consists of lookinf for a gross jump in the phase of the hum. Identifying the recording location from the pattern of small phase shifts (and other artifacts) in the power line signal is a much signal to find in a much larger amount of noise. I'm not convinced yet how doable it is. But with the above description of what I think they're doing, I expect a bunch of slashdotters will soon be playing with their audio cards, hacking up code to analyze recordings. B-)

      --
      Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    14. Re:Well, sort of. by budgenator · · Score: 1

      Powerline Electricity has a wavelength of 6000 Km, which means that it's highly likely that even without loads connected to the grid, the constructive and destructive interferences of the different generators which is very likely to be analysable to produce a geographic area within a knowable error radius. Start adding in unique charecteristics like dead-spots in the generator's comutators, odd harmonics caused by the unique differences in how the stators are wound and even the number of stators used, and we're getting to the question of whether is works in reality or just in theory, and if it does, does it work better and easier than other methods.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    15. Re:Well, sort of. by Shoten · · Score: 1

      Noise? Or the encrypted output of a signal generator? Prove it.

      Spend some time in a DMS operations center of a power company. They watch for noise too...noise is variation in that waveform, and a sign that something somewhere (a transformer, for example) is in distress. A power company would notice noise on their lines like the phone company would notice Rick Astley playing instead of a dial tone on their landlines.

      --

      For your security, this post has been encrypted with ROT-13, twice.
    16. Re:Well, sort of. by waddgodd · · Score: 1

      Wow, lots of flapping e-peens here. Please note I specificaly mentioned at the SUBSTATION for a reason. Anyone that thinks that a substation has anything at all to do with generation, please go away: while there CAN be generators at substations, if one's in use at the substation, the chances of there being enough current to do a TV interview anywhere within the substation's reach are vanishingly small, they typically call times when substation generators are active "brownouts". One of the bits of equipment at a substation, however, IS an isolation transformer, specificaly designed so asynchronicities induced downstream of the substation don't propagate back up the line to the generators and blow them out, even if an embedded signal had to be such a gross change that it affected the base 60 Hz signal (if you're dealing with 50 Hz power, again, go away, because all 50 Hz operators also have their own intelligence agencies that are decidedly NOT the NSA). Typically, you won't see even a need for that with embedded signals that are extreme-order harmonics of the base 60 Hz (6 kHz is an off-the-cuff example), which is what the entire point of an embedded signal IS: a signal that doesn't effect the existing signal in any negative fashion (you're still going to want the embedded signal to not travel upstream though, so you can actually use differing embeded signals for different substations, or the whole "locate the mook" thing falls prety flat, you already know to within a 20-block area if you can figure out which specific substation to inject the signal to)

      I should apologize for one bit here: I really should have inserted a paragraph break before the "As for the hum..", apparently many of the flapping e-peens thought that TEMPEST was somehow interconnected with the inserted signal (it's not). There's an entire career path in the US Navy dedicated to the fact that individual electronic devices react in increasingly individual ways to data (EWs, if you must know) as they get older, and with multiple devices in the area to get signatures from, you can easily determine which devices are being used and from that and a general knowledge of where the devices may be, you can get a location on them. In fact, NCIS ACTUALLY PORTRAYS AN EW SPECIALIST, it's literally on your TV every week. So while TEMPEST can't really be used in real-time (well, it can, but a SLQ-25 isn't really manportable), it can certainly tell you if you have the right spot

      --
      Just because you're paranoid doesn't mean they aren't out to get you
  5. I doubt it by epyT-R · · Score: 1

    Lossy digital compression and processing filter this out. This is especially true on consumer electronics used today. If people were still using all analog AC powered equipment, maybe.

    1. Re:I doubt it by mysidia · · Score: 1

      Lossy digital compression and processing filter this out. This is especially true on consumer electronics used today.

      In theory. There's no such thing as a perfect filter, though.

      You're not guaranteed that lossy compression render the signals completely unusable for the purpose investigators would be interested in.

      Theories one way or the other are pointless, until people start looking with the best analysis tools to see if videos usually contain such signals in some form or another or not.

      I mean.... I have a theory that Internet Explorer has no zero day vulnerabilities left to be found, since none are known, but, some day, that will probably be shown to have not been such a great theory.

  6. Re:Interesting... by Ol+Olsoc · · Score: 2

    Or I could be talking out of my ass.

    As long as there's no hum signature, you should be okay.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  7. doubtful by LoRdTAW · · Score: 1

    They would have to have data recorded 24/7 about load distribution throughout the entire country. And if the person leaves the country to rendezvous with a reporter? Are they recording the electrical loads in Mexico? Brazil? Poland?

    Perhaps they are monitoring EMF using receivers around the country, recording them and using triangulation. But how does this help them? If I blow the whistle to a reporter I am not doing it in my home town. Most people would go somewhere else to a neutral location. So then the tape surfaces weeks or months later and the NSA or whoever triangulated the location to a parking lot without any surveillance. They could do some old fashioned sleuthing but hopefully a whistle blower will try to cover their tracks.

  8. Sounds like fiction by John.Banister · · Score: 1

    I thought that was just the proactively homicidal NSA computer from John Varley's 1984 novella, Press Enter

  9. Almost no-tech method by JimSadler · · Score: 1

    Assuming that an individual can be located within a moderate sized population area then one might find him simply by the size of his electric bill in the past. For example if he usually has had an electric expense of $75. plus or minus six dollars then the size of the homes needed to be looked at drops to a few unless his electric use is smack in the center of the bell curve. In a suburb with 7,000 homes maybe only 70 have a typical electric bill of $75. dollars. Also time of day for electric demand might further narrow the search. We might find his hourly, historic power bill and study only the homes that follow a similar time pattern. Then we have past mode of payment, regardless of the name used. He might have a habit of always paying cash or always using a money order for example. If we find a home that matches all of the above past habits then we would have him cold rather easily. Another little trick is to look at people who pay power bills but have no driver's license or do not own a car. Bad guys know all too well that most people who do not drive will never interact with a cop whereas all drivers end up talking to a cop even if someone only dents their fender. Investigate just a bit and finding people can be rather easy.

  10. Misread that by PPH · · Score: 1

    used to prove video and audio screams have not been tampered with

    I thought this was going to something involving power lines, clamps and testicles. Never mind.

    --
    Have gnu, will travel.
  11. What about if they inject signal? by manu0601 · · Score: 1

    TFA says it would be difficult to tap every transformer to get the data, but what about if the NSA is able to inject signal they can recognize later?

    1. Re:What about if they inject signal? by Ghaoth · · Score: 1

      Hmmm...Inject a different signal into every grid in every country on every planet. That would only localise the location to a grid, getting a location of a house, or even a suburb, would require a mind boggling stretch of the imagination. As has been said, battery operated camera, data compression and frequency limited microphones are just a few of the problems. It doesn't matter what ENF/FFT analysis is employed, you can't extract information from nothing. Once a signal is too far down in the noise level it cannot be reconstructed with any degree of fidelity. However, on positive note, I do see a Hollywood movie coming out of this.

      --
      Nos Morituri te salutamus
    2. Re:What about if they inject signal? by AHuxley · · Score: 1

      Ripple control like over a grid?
      http://en.wikipedia.org/wiki/L...
      http://en.wikipedia.org/wiki/Z...
      A few nations use that. If tame staff let you can dial in tiny changes and know what your looking for?

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:What about if they inject signal? by AHuxley · · Score: 1

      Yes re 'They compare sources. I bet it's literally that academic."
      A hum list from firms based in say Brazil, South Africa, Spain, Italy, Germany, Japan, Russia i.e. exports that that find a new role in another part of the world.
      Whats working, how many are running, how many shifts, what the power needs are. Look for staff who might want/need cash....

      --
      Domestic spying is now "Benign Information Gathering"
  12. Information collection via power lines from PC's by Trachman · · Score: 1

    Information collection via power lines has been developed a long time ago against hard to reach targets, such as, for example adversary's strategic forces (icbm), nuclear plants and warehouse, headquarters and other similar high value targets. Many times such objects are disconnected from internet (but have local computers) and if such targeted computers are using electricity, then they can be targeted. If you remember, a while ago, there was DSL internet delivered via power lines. Be sure that such internet delivered via power lines is one additional avenue, a tool, in NSA's toolbox. One of many

  13. Being wrong doesn't mean the NSA doesn't believe by Anonymous Coward · · Score: 1

    Many times in business and ever more often in government circles the belief that something works is more important than the truth. The truth normally being ... seriously, what ever made you think that might work? Did you skip all of physics? The truth is most likely that some NDA droid convinced some useless government drone that this might work. Said drone then told his, laughably called such, superiors and they increased the possible results from slim to 99% certain. Typical up scaling of the results by management to get funding for a project that most likely should have died. But, what else are you going to do while you wait for Utah to survive a power cycle?

  14. lol by Charliemopps · · Score: 1

    Ok, a few years ago I would have also said it was impossible. But now that I know the lengths they'll go to for information that's not even helpful to them... Give me a unlimited budget and complete legal immunity? Yea, I could do it. It would be pretty unconventional, and break tons of laws, but I bet I could get it to work.

    I think my first wild guess would be, start buying up power transformer producers. I bet there's only a few in the world. Figure out how to make that hum unique in a way most people wouldn't notice. Treat it like a serial number. Since you sell every transformer, that would include the ones in video cameras. The hum would get encoded in the video. The hum would also interact with the local power in the home or whatever. They've already proved you can use home wiring as an antenna. So yea, far fetched but again, given an infinite budget? Totally doable.

  15. Better idea by MonsterMasher · · Score: 1

    Modulate the power frequency in a cycling and distinguishable patters, different 'sections' and the number and size determine resolution, and .. wait until they match.
    Isn't this already used? Seems natural. Or some variation of this.

  16. Re:Better idea (50Hz timing detected in cell?) by MonsterMasher · · Score: 1

    Oh, would anyone happen to know the cell encoding .. if it somehow communicates the timing of such built in, or a time code when last detected..?
    Perhaps such is already implemented and see-able in the deep code.

  17. Re:Hmmm. by Z00L00K · · Score: 1

    The electric noise would only be useful for a very rough approximation of where someone is located and largely depend on interference on the grid. At best you may find the county or town where someone is located, but it won't necessarily be conclusive since it's important to also match that to the correct time slot.

    The noise brought in as location information in CSI etc. is often depending on more distinct noises that are well-known. A subway station has one set of specific noises, a harbor has a different set. Sometimes among the general noises there are some distinct parts that can help pinpointing.

    But if someone records the noises of an out of place location and then use that as a background then it will throw investigation off track. It's impossible to realize straight away that a certain noise is good or misleading unless a repetitive pattern is heard because the noise is looped.

    --
    If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
  18. Re:It depends on how you look at it. by Z00L00K · · Score: 1

    Add to it the arcing that occurs from bad insulators on the grid - sometimes they cause a lot of RFI - and they are local. Just go out and listen to a high voltage power line when the weather is humid - there's usually a buzzing on the line caused by surface currents on the insulators.

    --
    If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
  19. Re:Easy to get around.... by camperdave · · Score: 1

    Some recording studios have done this to clean up their power.

    Why wouldn't they just run DC?

    --
    When our name is on the back of your car, we're behind you all the way!
  20. Easily countered in any case by Karmashock · · Score: 1

    All this weird stuff relies on the subject being unaware of it.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
  21. Re:Yes, even video and digital photos are modulate by gl4ss · · Score: 1

    I would think analog to be better for this than digital that gets run through filters before the data gets saved to disk as a single frame(analog being continuous feed giving them more to work with within a single frame.

    telephone codecs etc would also just filter this out.

    and hey, this doesn't really help one bit to catch some guy sitting inside a cave running their own generator. or someone who just runs it through some filters to improve quality.

    though, that being said, I have no doubt that there's a few consultants selling technology to do this to NSA. being usable for anything in the real world or not being entirely different point..

    --
    world was created 5 seconds before this post as it is.
  22. Not location but time by Gonoff · · Score: 1

    I think I saw this on the Discovery channel a couple of years ago.

    An AC grid does not keep perfect time. It will vary by a few hundredths of a HZ when certain things happen, like increased load during commercials, dropped load as people go to work and even when wind speed suddenly increases making the wind turbines contribute more.
    All these things make a unique time signature for that mains hum on any given power grid. If you have a nationwide grid, as found in most developed countries, this is the same everywhere but if you are on just a regional one, that will narrow it down for the spooks and they will know you are in that particular region too.

    --
    I'll see your Constitution and raise you a Queen.
  23. Needn't be done on the power company's premisis. by Ungrounded+Lightning · · Score: 1

    How hard would it be to send signals from the power plant or substations across different parts of the grid creating a signature that could be detected in recorded hums?

    It wouldn't have to come from the substations. It could be injected at any power feed (though the higher-capacity feed the better). B-b

    It might also drive the power company nuts - especially if it was close to the line frequency, because that would look like a large and rapidly varying power factor.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  24. Re:It could be done by amxcoder · · Score: 1

    The way I've seen the DEA track down grow-ops, is to use a helicopter outfitted with FLIR and fly over neighborhoods at night. The houses with decent sized grow operations lit up 'like a Christmas tree' compared to other houses around them. The heat from the lights would transfer through the windows, and exhaust vents of the house.

    The other method that I've heard is that people with very high power usage or big power fluctuations at set times per day get flagged for further scrutiny. They basically use information about a residence's power usage over the course of a given time to help look for patterns that might indicate a grow operation is occurring (probably based on information they have from known grow locations)

    I've always heard the cable company claims of the mystery van that roamed the city streets and could detect whether a house was stealing cable/pay-per-view or not. I find that a little unrealistic as well. Later in life, I heard another explanation that made more sense, which was related to putting advertising out on channels that required subscription (like PPV), and seeing who called in for information/contests/etc. and comparing caller information with their paying subscriber list. This seems way more feasible, possible, cheaper, and realistic than the "mystery vans". This method is similar to how cops get some people in mass to show up to be arrested, they call them all and tell them they won something (cash, TV, or whatever), and to come down to X address to pick it up, and they have police there waiting to arrest. I've seen on TV them able to arrest 25-50 people that they wanted for back-child support without having to locate and apprehend each person individually.

  25. Chrono-location via mains hum by illtud · · Score: 1

    There was BBC story a couple of years ago about the Met police in London recording the frequency of UK mains so that they can analyse the mains hum from recordings and compare the fingerprint against their records to accurately place the recording in time.