Submind YouTube summaries
Thumbnail for DEF CON 34 - ESP32 as counter-surveillance platform - Cybertiger, Colonel Panic, The Wrew

DEF CON 34 - ESP32 as counter-surveillance platform - Cybertiger, Colonel Panic, The Wrew

Watch on YouTube

Video summary

The speakers, Cyber Tiger from the Electronic Frontier Foundation and Colonel Panic, present a compelling argument against the expanding surveillance state, which they describe as an economic and technological arms race favoring law enforcement and corporate interests. They highlight how ubiquitous technologies like License Plate Readers (ALPRs), body cameras, drones, and cell site simulators are being deployed to monitor citizens' movements, often with bipartisan support from political elites. The core of their presentation is the concept of "economic warfare" in the context of privacy: while police agencies spend millions on sophisticated surveillance equipment, individuals can build effective counter-surveillance tools for a fraction of the cost. By leveraging cheap hardware like the ESP32 microcontroller, which costs around six dollars, citizens can create networks of detectors that rival or exceed the capabilities of expensive professional gear, thereby leveling the playing field and making privacy accessible to everyone rather than just the wealthy or highly trained. To combat this pervasive monitoring, the presenters introduce specific open-source projects designed to detect and map surveillance devices. Colonel Panic showcases "OUI Spy," a simple device consisting of an ESP32 and a buzzer that alerts users when they approach law enforcement equipment by detecting static Bluetooth addresses or Wi-Fi signatures from body cameras and drones. He also discusses tools like "Flock U" for identifying specific license plate reader networks and "Sky Spy" for decoding drone remote IDs. The talk emphasizes that these devices are not just passive sensors but active community resources; users can build their own versions, integrate them into mesh networks to share data across neighborhoods, or even sew detection patches onto clothing. This DIY approach democratizes technical countermeasures (TSCM), allowing ordinary people to "snoop under" the surveillance apparatus as it snoops on them, effectively turning everyday citizens into a distributed intelligence network that can track police movements and identify unauthorized drone flights in real-time. The presentation concludes with a strong call to action for the community to continue developing these tools despite the constant "cat-and-mouse" game where surveillance vendors update their hardware to evade detection. The speakers address various technical challenges, such as dealing with devices that switch to cellular networks or use 5GHz frequencies, and propose solutions like using multiple ESP32 units on different channels or exploring new firmware capabilities. They stress that while the technology evolves, the community's ability to adapt through open-source collaboration is key to maintaining privacy rights. Ultimately, they frame counter-surveillance not merely as a technical hobby but as a necessary defense of civil liberties, encouraging everyone from grandfathers to golfers to engage in this fight by building, sharing, and improving these low-cost detection tools to ensure that the surveillance state does not boil the frog of democracy unnoticed.
Read the full video transcript
Good morning, Defcon. Uh, coming up next, we've got a really exciting talk about the SP32. I got to watch them run over in the green room right before this. It is great. I'm excited to watch it. Um, to my left is Cyber Tiger and Colonel Panic. Unfortunately, the Rue wasn't able to be here today, but please help me welcome Cyber Tiger and Colonel Panic. >> [applause] >> How y'all doing this morning? Thanks for coming out to our talk about counter surveillance. Uh feel free to shout or dance around or do whatever so we don't feel like we're talking to a [ __ ] Zoom call. >> That's right. Yes. That's what I wanted to hear. Thank you so much. Uh I am Cyber Tiger. I'm a senior staff technologist at EFF. I created helped helped create Ray Hunter. tried reverse malware sometimes. I distribute terrible memes and I sometimes wear a tiger suit. And uh this is my colleague Colonel Panic. >> I am Colonel Panic. I work at an allegedly work at an undisclosed malware research company. I am the creator of OUI Spy or Wi Spy as people have aptly named it. Mesh Detect and Dynamic Vision Assist which is which is assistive technologies for visually impaired folks. [applause] This is the crowd feedback here is amazing. I was really worried about that, but y'all are awesome. Uh, unfortunately, uh, our third speaker, the Rue, could not be here with us today. He had a family emergency to deal with. Uh, so he's at home dealing with that, but we're going to go on without him because the show must go on. So, we're here today to talk about the ESP32. ESP32 is a really awesome little system on a chip or compute module. Uh, it runs free realtime operating system. Uh, but it's very, you're programming very close to the middle. It's got a lot of really awesome features in it uh that you might expect from a modern computer like Wi-Fi 2 GHz or 5 GHz depending on your model, Bluetooth. Uh it's got a dual core processor uh so it can't wrap but it can do two things at once. Um and that's really cool. It's got an Arduino like interface. You can program it in Arduino ID. You can use C, C++, MicroPython, Lua or Rust if you're a hipster like me. Um and it's really cheap. These things cost about six bucks, so they're really easy to get involved with and start prototyping on. But we're not just here to talk about fun hardware. I'm also here to bum you out because I'm from the EFF. [laughter] And we're going to talk about surveillance. ALPRs like Flock and Axon are invading our cities, spying on us as we go about our lives, driving down our streets, spying on mothers dropping their kids off at school, spying on people going to the grocery store, going to church, going to the parks and libraries, following us whether we're doing crimes or not all the time and storing that data for future use. Body cameras and axon like axon cameras are on every cop car and on every cop's vest watching us at our worst moments and often not being turned on when cops are at their worst moments. being plugged into license plate readers, being plugged into facial recognition, and generally expanding the surveillance state. Drones spying on us in our backyards and in our homes as we engage in public life and do constitutionally protected activities like protests and exercising our free speech. robot dogs and other police robots, often equipped with surveillance equipment and also maybe even weapons, tasers or other things to go in there and harm people without putting law enforcement at harm. And cell site simulators, MC catchers, things to track our phones, find our location, spy on our calls and text messages, and generally invade our lives to an even greater degree. And the surveillance industry is growing. [laughter] It's a good meme. The surveillance industry is growing. There are companies like Palunteer and Flock are are seeing their stock shoot up. Well, not Flock, but Palanteer is seeing their stock shoot up. Uh and and our president is investing in surveillance tech along with his cronies. They're not just buying this technology. They're also owners of the part owners of these companies. They're investing heavily and guys like Peter Teal and other CEOs of these companies are padding around with the current administration. ISIS's budget has tripled in the last year and this has let them spend tens of millions of dollars on new surveillance equipment. all of these things that I just mentioned. They're signing huge contracts and using this to be a domestic military force and build a domestic intelligence agency that has a ideological goal of spying on anyone who opposes this administration and who opposes what they're doing. Surveillance has bipartisan support from the Epstein class. They love it. The ruling class and the billionaire class loves this [ __ ] They wanted to they want to make us boiling frogs and rise the temperature of surveillance so subtly that we don't notice until it's too late and we can't do [ __ ] about it. But surveillance has bipartisan opposition from almost everyone else. >> Yeah, it's great. It's an across the aisle issue. It's getting people on the same team. Doesn't matter if you're right-wing, leftwing, anarchist, socialist, communist, libertarian, whatever. Everyone [ __ ] hates this [ __ ] >> And AI is making it worse. AI companies are summarizing all this data, finding needles and hay stacks, supercharging fac, and oftentimes finding crimes that aren't there, hallucinating, overpolicing already overpoliced places. predictive policing making thought crime a reality. >> Heard this somewhere before. >> Uh these people these people think that they they they they want to invent the Torment Nexus, right? They think that 1984 is an instruction manual. Uh and we can push back on that. One guy, shout out to the Torment Nexus, but we're hackers. We're not just going to settle for surveillance. We're going to do some [ __ ] counter surveillance. [applause] >> In the words of my hero, Lord Nikon, >> snoop onto them as they snoop onto us. >> So, [laughter] there's a really amazing talk at Defcon 31 from a gentleman called Null Agent. and uh he on stage said, "I was sitting around really pissed off about surveillance and cops and uh I thought what would Lord Nikon do?" Well, Lord Nikon would snoop under them as they snoop under us. So, null agent gave this awesome talk at Defcon 31. If you missed it, this is very inspirational for us. Um he talked about how he realized that he could track Axon devices based on their static Bluetooth addresses. Um, it turns out that all the Axon devices, the body cameras, smart holsters uh, and other police uh, other law uh, other technologies in their cars and on their person are all chatting with each other and with a command and control box and they're constantly broadcasting their Bluetooth address. You can track that Bluetooth address and see where cops are going in your city or maybe see if cops are nearby or approaching your house. and he built this really awesome little war driving tool called RF Party to specifically map out where let people map out where cops are in, you know, uh uh some sort of in some sort of fashion and look back on that data and do a little bit of counter surveillance and we thought that was really cool and it's a really awesome example of uh technical counter surveillance that is easy to do. This is TSCM stands for technical surveillance countermeasures. And this is the [ __ ] that spies use to find hidden cameras, hidden mics, etc. Things like spectrum analyzers, nonlinear junction detectors, high-end software defined radios. This is all really cool tech, but it's all really expensive. This stuff can cost thousands of dollars and it's hard to use, right? Unless you're trained in this, uh, you might not be able to use this stuff, right? But this stuff is for finding hidden surveillance and we're not trying to find hidden surveillance. But moreover, counter surveillance shouldn't need to be expensive and technical. We can make counter surveillance cheap and accessible. Privacy is a human right. Privacy is for everyone. And it shouldn't just be for the rich. [applause and cheering] And it shouldn't and it shouldn't just be for hackers. Anti surveillance is for us all because we don't all need to be cam girls for the surveillance state. But this talk is all [laughter] this talk is also about economic warfare. And uh I'm not in the military. The colonel, despite his rank, also not in the military. >> Not in the military. >> Um hopefully no one will shout stolen valor. Uh >> stolen valor. Um, but there's a a military which is if I send out my $600 drone and you send out a $6 million missile to shoot down my $600 drone, well, even though I've lost my drone, I've still won cuz I've spent a hell of a lot less money than you and I can keep spending less money. Uh, I can build drones faster than you can build $6 million missiles. We can do the same thing with surveillance. Uh, so for example, at EFF, we built this tool called Ray Hunter. Uh, yeah. >> Yep. [applause] I'm not going to talk too much about Ray Hunter because I already talked about that last year, but uh, it's a tool to detect MC catchers. It's free and open- source software which runs on cheap hardware. These devices you can get for 20 to 40 bucks on eBay or you used to be able to. Uh we've used it globally to find real MC catchers in the wild and we've been able to have thousands of people all over the globe helping us do adversarial reverse engineering on tools which were previously completely opaque and uh really I mean not completely opaque a lot of researchers knew how these work but we've been able to prove how they work um and get data on how often they're being used um and The economics are really on our side here, right? Ray Hunter costs about $20, but current MC catchers to buy the truck with all the equipment in it and the fold support package go for about a million. This is a $50,000 to $1 spending ratio. For every for every $50,000 your city is spending, you can spend $1 to counter that. And that's an awesome ratio. But MC catchers are just one type of surveillance. And we're all really mad about flock right now. Las Vegas Metro spent $4.37 million of some billionaire's money who donated specifically for this purpose to buy 211 flot cameras to put up all around this city. You could detect all of these for one $6 ESP32. Or you could pair an ESP32 with each one of these and do stuff [laughter] for about $850 cost of less than the cost of a new iPhone. That's a really good ratio. Shutting down a billionaire's $4.37 million project for $850. I like them odds. [laughter] So, what kinds of [laughter] I just get up and talk to politics. So, what kinds of things can we do with the ESP32? Uh, I'm really glad you asked. And this is where we were going to transition to the RU. Uh, but since he couldn't be here, I'll just list some of the things. One of the awesome things about ESP32 is that it's really easy to program for. You can you can port stuff over from other projects super easily. Uh, Void Mantis OS was a uh new firmware for the exploiters hacker pager. Uh, and we were he was really quickly able to port Sky Spy, We Spy, Fox Hunting. I wrote a password generator, um, axon detector and other things. It's [snorts] super easy to bring this stuff over and and it's really easy. It's a fun and easy way I to get involved with hardware hacking and starting to write close to the middle and starting to think about the sorts of things you can do, right? You can do war driving apps, RF anal RF analysis. I was going to say analyzation. [laughter] >> That's not a word. Now, >> uh, and these are so cheap, right? You can build networks of these. You could you could for $6, these could be throwies, right? You can give one of you you could give these out as Halloween candy, right? Uh, they're really that cheap. [laughter] >> Worse. >> Don't put it within the candy. >> Yeah. No, don't put raise [laughter] >> Check your children's Halloween candy. There may be ESP32s hiding in the Snickers. [laughter] >> New meme just dropped. Yeah. Uh, but without further ado, I want to introduce you all to somebody who's actually working on this stuff. My colleague, Colonel Panic. >> Thank you. [applause] It is very nice to be here with you all. My name is allegedly Colonel Panic. I am the creator of the OUI or Wii Spy. Uh, this is just an ESP32 with a buzzer. As you can see, the wiring's right on there. So you guys can rip it off if you'd like. I also made the mesh detect. This is something that will extend your detections over mesh network. So you can have, you know, sensor networks going over mesh. Like let's say you want to detect a certain OUI at the end of your driveway, you can have it report back to you. I like cheap things in DIY. Spent most of my life very poor, so I need an ESP32 instead of an expensive SDR. And I want to make these things available uh for everyone to use. I sell mine online, but it's more I'm selling my art. You can make this for less than $10. Of course, the art, you know, I like I like metal art patches. I made the patch uh to to go on your battle jacket, and it's just an OUI spy that does the exact same thing with clear PCB. You can sew it onto your jacket and have a detection mechanism on your clothing. Uh, it's really hard to solder. You will melt that if you touch the soldering iron to it. So, that's been really fun. [laughter] New techniques. New new techniques. Uh, SDR and detection can be expensive. Uh, you can, you know, hack hack RFS on the cheaper end, but still not as cheap as a $7, $6 ESP32. >> Not everyone can afford a B210, and that should be okay. You should still be able to do RF research. >> Yep. And it's becoming more and more accessible now uh with microcontrollers. So it shouldn't be a luxury. It shouldn't just be for the rich. Everybody should be able to do this. If they're going to watch us, we can watch back detection for less than the price of a domestic beer on the strip. You don't even need a bu [laughter] you don't even need a buzzer really. Uh you can plug this thing in and into an API and do the same thing. So they make affordable projects cheap and easy for makers. This on the left is Xiao Expp32. Uh these are the really cheap ones and they're really small. That's what I use for my boards, but also getting into this stuff. If you want to start prototyping stuff, M5 stack is really great because maybe you don't know how to solder. They have Grove ports that you can just plug sensors in and extend this. So, if you you could even make uh the same device that I'm using on one of these and have haptic feedback, uh alarms, you can push it to the cloud, whatever you want to do to to take take these detections and uh and categorize them and save them for later. So, this all comes from war driving uh and war driving community. Uh shout out to the wiggle folks and of course kismet folks, too. [applause] [cheering] Definitely check out Wiggle. If you've got a phone, you can put it on there and rock some war driving. But it it comes from war driving and then becoming aware of surveillance and how pervasive it is. And it's easy to just forget about it because it's so homogenized and blending in with the environment, but it's very pervasive. So, the OUI spy works all passive, of course, because that's the legal way to detect things. Uh you not legal advice from the EFF [laughter] or me either. do your own research. So, it's all passive. You're you're looking at BLE and Wi-Fi uh and mostly OUI detection and then of course drone remote ID decoding and uh mapping and and alerts. So, the OUI or we spy can also take a drone remote ID, decode it, and you can get the buzzer to tell you when a drone is flying near you or you can hook it into the API and you can map the drone and the pilot in real time. It's unfortunate the remote ID is that insecure that you can track like this, but it's there. We're going to we're going to pick it up. We're going to look at it. And it's really good to watch surveillance drones. Once you start to really look at this, you'll notice who the most frequent flyers are. If it's not you, it's probably someone who's very official. Uh OUIP firmware. We got the detector. I made this so that it will just you can put an OUI in it. uh it's the first six characters of a MAC address that identify the manufacturer and what now MAC randomization is of course a thing. So we'll be digging deeper into the Bluetooth stack. Uh so it really just lets you put in an OUI and then when you approach this OUI or it approaches you this device you get an alert with your buzzer. So it's great for body cams for instance. Uh Skyspy that's the drone detection and remote ID decoding. And then of course Flock U. Uh this has gone through many iterations, but uh this is when I was war driving and started to become aware that flock cameras were everywhere and no one in my town really knew about it yet. So I wanted to make something that would help people be more aware. And this eventually carried us to our city council and speaking events with Ben Jordan and mayoral candidates to try to get flock cameras out of our city. Didn't work right away, but it will eventually. And then of course uh the fox hunting. Um, it is a fox hunter that that allows you to target it and find a device with a directional antenna. So, if you have an OUI spy, you can plug a directional antenna in it, cheap PCB printed directional antenna, and if you put your target device in it, you can turn a circle until the frequency of the beep increases and then walk a direct line once you find the highest frequency point and you can find the device. Pretty cheap to do. drones, body cams, and flock. Oh my. So, the remote ID and mapping. This is just an example of the Sky Spy API. Um, we've had in my town one of these running for over 6 months, and we're just saving all the data to take a peek at later. But, uh, it, like I said before, it it will map the both the pilot and the drone in near real time, and you can look up the FAA remote ID and find out what model the drone is. So if you see something like a Matrice 3 thermal, you might think, why is there a thermal drone flying over? It's probably the police. So FlockU got really popular. I could not believe it. Uh my GitHub repo blew up and people started uh forking this and making their own and porting it over to other devices like uh the Ruse stuff. And I mean there's probably folks out here that have probably ported to their device. Uh I had to solder over a thousand of these by hand. uh when this first dropped because I did not have assembly yet and I am so thankful for that now. So, Flock actually has an API you can use to incorporate things like GPS and saving uh your detections, but uh also if you if you don't want to use the API, you can have it beep when you drive by a flock cam uh and or you can hook it up to the API, add GPS and map and then save it. You can also it saves detections and spiffs. So you can take it off the little file system on the ESP32 and you can dump it back into your API eventually. You can make your own. It's open source. This thing is literally just an ESP32 and a buzzer. That's under 10 bucks. If you look at that schematic of that board that I made is art. You can just make this. Just rip it off. Make it yourself. I'd be happy if that happened. All you need is an ESP32 and a buzzer. And that's a 3volt passive buzzer. Super cheap. Super cheap. I can attest the buzzer is optional. >> Yeah, it's a it gets annoying. I took a road trip and I was like testing the body cam detection. I was like, I don't want to know anymore how many of these are around me. [laughter] So, as it turns out, it's decent, really good for cryptography. And >> yeah. Yeah. So, there's a lot of there's a lot of future directions we can take this, right? Um, it turns out ESP32 can also do some fun cryptography stuff. Um, I wrote a password generator app for it because it has the feature of giving you true random numbers. Uh, and I'm not a cryptographer. Please don't take this as a fact. But the manual says that it can give you true randomness based on the noise floor of Bluetooth and uh, Wi-Fi. So, you can do some really cool stuff with that. And I think if if some cryptographer can verify that's true, you can do some really cool stuff uh, building on top of that. Um, and uh, we can also do stuff with the C5 with 5 gigahertz. You can >> do uh, 5 gigahertz Wi-Fi or you can also start to look at uh, trying to use 5G to decode remote ID for drones like parrot drones. I haven't gotten a detection of a parrot drone yet because I don't believe they're used in my area, but I would love to hear if anybody ever gets one with a with a, you know, micro controller on the 5G Wi-Fi spectrum. And we just want to detect everything. You know, that's what war drivers do. We want to get all the devices. So, [laughter] I'm already working on the V2. It It incorporates GPS, haptic feedback. I'm making an app for it. I just The art is what's holding it back. I got to get that art perfect. [laughter] But, uh, want to put multiple radios on it. So, one manages the app and then you have a radio that is dedicated to detection. And of course, we want clear cases. It's going to have a clear case. We love the [ __ ] clear cases. >> Listen, the 1990s got everything correct aesthetically. Okay, bring back clear cases. [laughter] [applause] Electronics don't have to electronics don't have to look boring or stupid. We can put we can put art on stuff. We can make this [ __ ] look cool. We can make this [ __ ] punk rock, right? Counter surveillance does not need to be boring. It does not. >> What are you going to build? >> Yeah, this is and what so what really inspired me and the the reason I met up with this guy and wanted to do this talk because I think that this this is a really awesome way for people just to get involved, right? A lot of us get paralyzed by inaction, right? We see the horrors around us and we want to do something, but it's it's hard, right? It's hard to find that first thing. And this is a first thing to do, right? It's an easy accessible thing that is achievement anyone can do. And then once you start doing one thing, you start thinking of more things you could do, right? This is propaganda as much as it is uh a tool, right? It's it's the the propaganda of the deed where we inspire people to get out there, do things, start thinking about the surveillance around them and start noticing surveillance around them >> because it is pervasive and if you have a little thing to do, I mean the idea was to to just make people aware and now it's become a full-blown detection tool. We can't stop now though. It takes a community to raise a counter surveillance tool. So we need you guys to war drive and continue to submit data to the project. Did you find a new OUI? Did you find a new way that you know a flot camera is uh trying to change their uh the way that they broadcast something so that they can evade detection? They know about what we're doing and they're going to know more after this talk. So they're going to keep it's like they're going to keep changing it. And so we have to figure out new ways to to find these things in our in our environment. >> So in the words of Zero Cool, hack the planet because they're trashing our rights. >> Hack the planets. >> Hack the planet. >> [applause] >> Thank thanks y'all so much. Uh we have we have uh quite a lot of time for questions. Um and uh you can find us on the social medias here at the following things. Uh of course this uh this work is also you know we we don't stand up here alone right this work is built on the work and camaraderie of so many people. So, especially huge thanks to our families. Uh, huge thanks to the Hackers Town crew. Huge thanks to the of course the EFF staff and members uh that that you know helped fund my work. Um, and uh for Colonel the Wiggle crew, of course, Dlock folks, those DOG war drivers are the best. Uh, Nightcry or Aurora Bor Aurora, I can't even pronounce the word now. Nightcry. At any rate, uh, DZAZ, another homie that, yeah, a goon, no less. Blindster, who taught me how to do PCB design and was kind enough to show me how to do it. Uh, of course, the Hardcat Brigade who have been kind to me over the years. All war drivers, Gain who did it. I don't know if you've checked this guy, but he found a lot of vulnerabilities that Flock ignored for some time. So, it's really if check out his talk if you haven't already seen it. Uh for me, Hackblock, who brought me up in uh DC 415, my hometown, >> and of course my hometown hacker crew in Asheville, North Carolina, the Dirty South Hackers. Thanks y'all. [applause] >> If you do have questions, we have a microphone here. You can come up and shout them out. We got at least 10 to 15 minutes. Or if you don't have questions, we'll just leave the stage. Um, >> take >> hand it over. >> I >> Yeah, hold. I can come over here. >> When you collect all this >> No, no, take the microphone. >> When you collect this data, what's your favorite way to store and analyze it? >> Ah, >> yep. >> It comes across in JSON, so we store it. But I think the real thing to do is get something in Warrive and look for PECAPS because these things are going to constantly change. Uh, you know, something like uh Wiggle would be good, but you can actually get PECAPS on an ESP32. So, uh, >> I end up making this stuff and end up doing a lot of work working on it. So, I'm not storing it. So, that's a question for what are you where are you what are you going to do with it? You store it. You figure out what you're going to do with it, how you can analyze it. It's a >> Anybody can do it. But uh yeah, I mean there's there there are exactly there are projects like Wiggle where people can upload this, right? Like this this data should be available to the community overall, right? And and we're probably not going to build that, but you all could certainly build that, right? We can build amazing maps. We can build you all can build amazing maps. You all can build amazing visual propaganda, right? And and start doing this and start like crowdsourcing this research, right? Like even just upload it to your GitHubs, right? Put it on paste bins. I don't care. Right. The important thing is to this a deep cut. The important thing is to get it out there, right? Um and and get that data out there. You know, um there is there is talk of an interchange format for uh uh you know, publicly available uh uh lists of OUIS and other indicators of surveillance equipment, uh which we're which we're working on with the wiggle crew. So that might that's coming down the line, right? Um but yeah, just just do it. Thank you though. Good question. >> Yeah. >> Have you done any looking into or research on companies like Axis who don't run NRF? And >> there's a problem which is that we can't hear you. >> Is this better? >> No. >> Mike, you [laughter] just come up here. Have you done any research or looking into companies like Axis who don't run uh on RF and only run on PoE? >> I haven't done that research yet, but uh that's a good call out for sure. >> Yeah, we'd love to Yeah, we'd love to know more. Haven't Yeah, we'll chat. >> Yeah, absolutely. >> Okay. Um, what ESP32 would work for all the gigahertz? >> For which one? >> Um, if you're trying to get different frequencies for the drones, for example, on all the gigahertz and like the ESPs, they work on different >> Oh, yeah. >> Work best for that. >> The ESP32C5 is what'll get you 5 GHz and 2.4 GHz. The S3 will just get you 2.4 gigahertz, which is still good enough for a lot of things, but I know you've run into limitations with that. >> Yeah, the great thing about the S3 is it has a dual core, too. So, you could do both Bluetooth and Wi-Fi since they're on the same wavelength. You can do them both at the same time. But, uh, yeah, taking it's never going to find FPV with this. You know, you're going to need more equipment, SDR equipment for that. But you have for remote ID decoding. Uh I generally use the S3, but if you're looking for five uh 5G Wi-Fi, try C5. And it's Xiao. Uh seed Studio Xiao is the the ones that I use. Xiao. >> Oh, got one. >> So kind of a question, kind of an idea to bounce. What about making a version of these? What about making a version of these as an almost enduser awareness device like that people that you could like distribute to people to like keep in their cars to like uh like could like could you make almost a firmware to put on these to like distribute in for people in their cars to get more people aware of? >> Yeah. uh what how many times they're passing by uh flock reader like flock cameras. >> Yeah, I mean I think that's kind of what it's already doing, right? If I may speak on your behalf, I keep mine I keep one in my car and constantly scare the [ __ ] out of myself and my wife uh because we forget it's in there and then we start the car and it goes [clears throat] and [ __ ] what? Uh so yeah, I mean that's >> not a pleasant sounding buzzer, you know? It's really not. Uh but no I I mean yeah that's that's that is kind of already and that is kind of I think already one of the potential uses for it certainly how I use it. Um, and if you if you think that there are there's like a better form factor and it could be better, I honestly like please build it like like or you know come come hang out and show you know >> Yeah. Yeah. >> Tell us what you want because Yeah. Absolutely. Like this is all open source, right? And and remix, reuse, create, right? It's all it's all there for the for the doing. So yeah, it's like when I made it and I never thought it would go beyond niche hackers, so I made it a little hacky, you know? So, with the next version, we're going to keep adding things to make it easy for just the average user to get into, you know, so you don't An app would be very helpful or things that just make it easy to use. >> It's there's nothing like building a tool for yourself and then finding out that everyone really likes it and find and finds it super fun. But also, there's the problem of like what's easy for people who live in the terminal to use, right? Is it necessarily it doesn't always occur to us that that's not exactly easy for somebody else to use, right? We learn that through user feedback. [laughter] And so I think yeah like uh you know finding finding finding that out and finding like I said accessibility is a big is a feature here right it's a big thing we want and so like yeah finding ways to make this stuff more accessible you know with apps and gooies make it easier to use right that's what we want because we want we want grandpas doing this right we want we want people who main hobby is golf right I don't I don't need you don't need to be a hacker for this stuff we don't want you to have to be a hacker for this stuff >> and if you do happen to get a hold of one of these and you need help, please hit me up. I I will email you back. Do not email EFF. Not everybody at once, at least. [laughter] >> Uh, thanks. Um, so I've been driving around in my car with one of these, just like you were talking about, and I get mystified when I hear the little buzzer goh, and I don't see anything that that obviously corresponds to what looks like a camera device. I don't know what's going on, and I'm not sure how to correlate. I also don't see the same devices on the deflock maps. So like there's a discordance and if I go to places where I think there is DLOC, I also don't get I don't don't hear the device say anything. So I'm kind of mystified. I'm hearing it places I don't expect it and I you know I'm not hearing places where I would expect it. >> Which firmware are you running out of curiosity? The Bluetooth is kind of I would say go get the the newest firmware at Reashlash because we've done a lot of work, not just me, other folks that have discovered things and we implemented it, but the Wi-Fi is the best way now. So, it it uses permiscuous so that it can pull down data from probe requests and wild card probes and things like that. But, uh definitely flash that newest firmware. I pro probably shipped it to you with the old firmware. So, uh, use platform IO or I can make a web flasher or something and and if you find something, please let me know. >> There's there's, uh, I mean, I think one of the things that I've found as as a user of it is is and I I think that you've talked to me about is like the the some of the newer flocks are on 5 GHz, right? And they're they're >> they have cell uh some of them have cell connections. I think >> some of them have cell connections, right? And we were like talking for a bit about if we could use Ray Hunter to have when we can't. Um, but like yeah, there are there are it's a bit of a cat-and- mouse game, right? And some of these some of these just aren't detectable with the C3, with the S3, right? And we're going to we're going to need to think about new ways to detect these. On the on the other hand, sometimes I detect these cameras from like two blocks away, right? And and so like this is where you can like switch over to fox hunting, right? Or you can uh uh you know, just start circling around. Um but yeah, you might you might detect it from very far away sometimes, right? And uh might need to might need to to do a little more looking, but yeah, I love the headgear here. >> Sweet. Throwing out everything and seeing what sticks, too. So, they're going to be changing everything. So, we need community help to continue with this detection to make it actually really accurate and reduce false positives as well. >> Well, thank you for queuing me up so well for this question. Um really about the cat-and- mouse game. Like you said, as we're sharing this information, they're going to be updating their techniques. Um, static Bluetooth addresses seem like one of the easiest things to go. So, I'm curious where where you see that going next. Are we going to be collecting like characteristic and service UYU IDs? >> That's exactly it. We're going to look for that in the advertise. We're look for the manufacturer data and then we're just keep digging to the Bluetooth stack passively because we don't want to touch it. >> Yeah. >> Yeah. There's a lot in Bluetooth you can nab and you can make a fingerprint. So, when I stop having to make these things in soldering all the time, I'm going to continue the work. So more more uh assembly but if you find something please let us know like shoot me an email uh if a new technique we can make it happen. >> Love to yeah catalog some and send them to you. Um other question u state detection thinking specifically about body cameras. Have you looked into or do they emit characteristics that tell you that they're on or off? That seems like a useful bit of information to surface >> there. So, someone released an exploit uh months back that will turn the camera on any body cam via a insecure Bluetooth service. So, I'm guessing that you could probably find if it were on and off via that, but I have not dug into that yet. >> Please consult with your lawyer before doing that. [laughter] >> If you start touching things, it crosses a line. So, >> for me, yeah. >> Thank you guys so much. Love what you're doing. >> Thank you. Hello, I've been listening to you and I've been wondering why uh didn't you use uh one of the existing platform for SP32 like a carpenter or something like that. It's have anything that you need? Uh are you thinking about porting those firmers for those devices? Yes, I think I did a drone detection port for uh M5 Stack Core S3 and it has haptic feedback and it'll show you the remote ID on screen. In my V2, I stayed away from screens because I personally will break them off and uh I I won't end up using the thing. So, I made an app, but >> it's hard to have a screen in a mosh pit. >> The card is awesome and they're making the their new one that's like >> Yeah. And it's got you has Linux on it, but you could probably do a lot with that. But yeah, you I'm going to port and people have ported them to other devices, too. So my code is all open source. If you want to port it, too, go for it. It's all you. >> The new one with the Raspberry >> the new one with the Raspberry Pi on board h get a new advantage because you can use all those USB SDR sticks. >> Yeah. with mostly extends the range of detection >> far beyond only the Bluetooth and Wi-Fi. >> Yeah, that's a great that's a great thing. Yeah. >> And then and and I'll I'll speak on behalf of Colonel Panic, right? Like I mean, part of the reason to make your own stuff is to make it look cool, right? Uh uh you know, make it make it make it punk rock and make it your and you know, do the DIY thing. Make it cheap, right? Uh uh make it something that someone can just buy and plug in, right? I suppose I haven't know that. So, but but yeah, easy to port, right? And yeah, port it to your favorite platform. Yes, >> M5 stack is a great one for that too because it has everything in there already. >> Another another question. Um, have you seen these cameras start to move away from Bluetooth and Wi-Fi pros and only on um cellular networks? And um have you seen that they uh ones that do use cellular networks are on the first responder network? >> I haven't dug into that one enough yet, but I I can say that they are they definitely stop using as much Bluetooth. I'm sure there are ones out there that still do because I mean half these things are still in like factory mode, you know, like people don't know how to set them up and and they tend to be very insecure. So, >> it's a cat and mouse game for sure. Um, but like I mean I can tell you that a lot of the stuff that goes over cellular is not encrypted or authenticated and is very very uh uh easy to spot if you can listen to that frequency. So like if there are like ESP32 can't listen to that frequency, right? But if there are cheap ways to listen to those frequencies, right? uh pending a full legal investigation. Like that's that's a place where I could the lawyer in my mind is screaming at me right now. [laughter] Uh that's a that's a you know that's a that's a direction to go in for sure. >> Last question. Have you done or looked into anything with uh signal trace? >> I'm I am very concerned about signal trace um and and ramping up you know what I'm what I'm going to do about it. But so signal trace for those of you who don't know is the add-on for add-on for flot cameras I want to say uh that that is or it's a it's a separate company I can't remember what but the >> war driving is Leonardo yeah they're war >> America government war drive you [laughter] >> yakov uh uh yeah so so for those they're they're war driving you they're basically building a RF fingerprint of your Bluetooth and Wi-Fi devices and using this to identify the individuals in cars, to identify when people go into new cars, to identify you when you're walking or biking or or using other modes of transportation, right? So, it's just another another form of surveillance. And yeah, I know I know the guy who asked the question is thinking about ways to counter that. I'm uh you know, at EFF, we're thinking about all of the legal and activist strategies we can do around that. I'm thinking about what we can do on the tech side. But yeah, it's it's top of mind for sure, man. Well, you have to become a lite and not carry a device with you or have a car. [laughter] >> Simply don't participate in society and you'll have nothing to hide and therefore nothing to fear. [laughter] >> There perhaps another version of this where it you can then start broadcasting sort of a random or a you know war radio signals that might disturb their data that they're collecting for the ones that are war driving us >> like poisoning the well. Yeah, I'm sure somebody's doing that, but uh >> you could do it if you wanted to. >> Yeah, >> legally ambiguous. Yay name. >> But my question is if you're doing it, will they then be able to to use AI to find the you know signal in the noise too? So flooding it. That's very interesting. You know, >> I mean we are at least making it more expensive at that point, right? >> Exactly. >> Imposed cost. >> Yes, exactly. Imposed cost like we were saying earlier. >> All right, I think we got time for like one more question. All right, we got one one coming up. >> All right. >> You can also find us after this. Sorry. Yeah. >> Uh, is there a way to use multiple like ESP 32C5s example to have a cluster of >> Yeah, I'm glad you asked. There's a thing called ESP now that you can use to have them wirelessly transmit to each other and it doesn't interfere with the Wi-Fi or Bluetooth stack. So you could, for example, have 12 of these things, one on each channel. If you can get enough amperage to the damn thing, you can not have to hop channels and you can grab more data as you drive around and get way better reward driving than if you had one SDR that's hopping around on channels. So, it's not hard to do. I have some firmware for it that I'm testing. I'll probably put out at some point, but yeah, it's looks pretty janky. You just plug a bunch of USBs in and hang them over your uh rearview mirror. [laughter] All right. Thanks y'all so much for coming out. Hack the planet. >> Thank you very much. [applause] >> [music]