DEF CON 34 - ESP32 as counter-surveillance platform - Cybertiger, Colonel Panic, The Wrew
Watch on YouTubeVideo summary
The speakers, Cyber Tiger from the Electronic Frontier Foundation and Colonel Panic, present a compelling argument against the expanding surveillance state, which they describe as an economic and technological arms race favoring law enforcement and corporate interests. They highlight how ubiquitous technologies like License Plate Readers (ALPRs), body cameras, drones, and cell site simulators are being deployed to monitor citizens' movements, often with bipartisan support from political elites. The core of their presentation is the concept of "economic warfare" in the context of privacy: while police agencies spend millions on sophisticated surveillance equipment, individuals can build effective counter-surveillance tools for a fraction of the cost. By leveraging cheap hardware like the ESP32 microcontroller, which costs around six dollars, citizens can create networks of detectors that rival or exceed the capabilities of expensive professional gear, thereby leveling the playing field and making privacy accessible to everyone rather than just the wealthy or highly trained.
To combat this pervasive monitoring, the presenters introduce specific open-source projects designed to detect and map surveillance devices. Colonel Panic showcases "OUI Spy," a simple device consisting of an ESP32 and a buzzer that alerts users when they approach law enforcement equipment by detecting static Bluetooth addresses or Wi-Fi signatures from body cameras and drones. He also discusses tools like "Flock U" for identifying specific license plate reader networks and "Sky Spy" for decoding drone remote IDs. The talk emphasizes that these devices are not just passive sensors but active community resources; users can build their own versions, integrate them into mesh networks to share data across neighborhoods, or even sew detection patches onto clothing. This DIY approach democratizes technical countermeasures (TSCM), allowing ordinary people to "snoop under" the surveillance apparatus as it snoops on them, effectively turning everyday citizens into a distributed intelligence network that can track police movements and identify unauthorized drone flights in real-time.
The presentation concludes with a strong call to action for the community to continue developing these tools despite the constant "cat-and-mouse" game where surveillance vendors update their hardware to evade detection. The speakers address various technical challenges, such as dealing with devices that switch to cellular networks or use 5GHz frequencies, and propose solutions like using multiple ESP32 units on different channels or exploring new firmware capabilities. They stress that while the technology evolves, the community's ability to adapt through open-source collaboration is key to maintaining privacy rights. Ultimately, they frame counter-surveillance not merely as a technical hobby but as a necessary defense of civil liberties, encouraging everyone from grandfathers to golfers to engage in this fight by building, sharing, and improving these low-cost detection tools to ensure that the surveillance state does not boil the frog of democracy unnoticed.
Read the full video transcript
Good morning, Defcon. Uh, coming up
next, we've got a really exciting talk
about the SP32. I got to watch them run
over in the green room right before
this. It is great. I'm excited to watch
it. Um, to my left is Cyber Tiger and
Colonel Panic. Unfortunately, the Rue
wasn't able to be here today, but please
help me welcome Cyber Tiger and Colonel
Panic.
>> [applause]
>> How y'all doing this morning? Thanks for
coming out to our talk about counter
surveillance. Uh feel free to shout or
dance around or do whatever so we don't
feel like we're talking to a [ __ ]
Zoom call.
>> That's right. Yes. That's what I wanted
to hear. Thank you so much. Uh I am
Cyber Tiger. I'm a senior staff
technologist at EFF. I created helped
helped create Ray Hunter. tried reverse
malware sometimes. I distribute terrible
memes and I sometimes wear a tiger suit.
And uh this is my colleague Colonel
Panic.
>> I am Colonel Panic. I work at an
allegedly work at an undisclosed malware
research company. I am the creator of
OUI Spy or Wi Spy as people have aptly
named it. Mesh Detect and Dynamic Vision
Assist which is which is assistive
technologies for visually impaired
folks.
[applause]
This is the crowd feedback here is
amazing. I was really worried about
that, but y'all are awesome. Uh,
unfortunately, uh, our third speaker,
the Rue, could not be here with us
today. He had a family emergency to deal
with. Uh, so he's at home dealing with
that, but we're going to go on without
him because the show must go on. So,
we're here today to talk about the
ESP32.
ESP32 is a really awesome little system
on a chip or compute module. Uh, it runs
free realtime operating system. Uh, but
it's very, you're programming very close
to the middle. It's got a lot of really
awesome features in it uh that you might
expect from a modern computer like Wi-Fi
2 GHz or 5 GHz depending on your model,
Bluetooth. Uh it's got a dual core
processor uh so it can't wrap but it can
do two things at once. Um and that's
really cool. It's got an Arduino like
interface. You can program it in Arduino
ID. You can use C, C++, MicroPython, Lua
or Rust if you're a hipster like me. Um
and it's really cheap. These things cost
about six bucks, so they're really easy
to get involved with and start
prototyping on.
But we're not just here to talk about
fun hardware. I'm also here to bum you
out because I'm from the EFF. [laughter]
And we're going to talk about
surveillance.
ALPRs like Flock and Axon are invading
our cities, spying on us as we go about
our lives, driving down our streets,
spying on mothers dropping their kids
off at school, spying on people going to
the grocery store, going to church,
going to the parks and libraries,
following us whether we're doing crimes
or not all the time and storing that
data for future use.
Body cameras and axon like axon cameras
are on every cop car and on every cop's
vest watching us at our worst moments
and often not being turned on when cops
are at their worst moments. being
plugged into license plate readers,
being plugged into facial recognition,
and generally expanding the surveillance
state.
Drones spying on us in our backyards and
in our homes as we engage in public life
and do constitutionally protected
activities like protests and exercising
our free speech.
robot dogs and other police robots,
often equipped with surveillance
equipment and also maybe even weapons,
tasers or other things to go in there
and harm people without putting law
enforcement at harm. And cell site
simulators, MC catchers, things to track
our phones, find our location, spy on
our calls and text messages, and
generally invade our lives to an even
greater degree.
And the surveillance industry is
growing. [laughter]
It's a good meme. The surveillance
industry is growing. There are companies
like Palunteer and Flock are are seeing
their stock shoot up. Well, not Flock,
but Palanteer is seeing their stock
shoot up. Uh and and our president is
investing in surveillance tech along
with his cronies. They're not just
buying this technology. They're also
owners of the part owners of these
companies. They're investing heavily and
guys like Peter Teal and other CEOs of
these companies are padding around with
the current administration.
ISIS's budget has tripled in the last
year and this has let them spend tens of
millions of dollars on new surveillance
equipment. all of these things that I
just mentioned. They're signing huge
contracts and using this to be a
domestic military force and build a
domestic intelligence agency that has a
ideological goal of spying on anyone who
opposes this administration and who
opposes what they're doing. Surveillance
has bipartisan support from the Epstein
class. They love it. The ruling class
and the billionaire class loves this
[ __ ] They wanted to they want to
make us boiling frogs and rise the
temperature of surveillance so subtly
that we don't notice until it's too late
and we can't do [ __ ] about it. But
surveillance has bipartisan opposition
from almost everyone else.
>> Yeah, it's great. It's an across the
aisle issue. It's getting people on the
same team. Doesn't matter if you're
right-wing, leftwing, anarchist,
socialist, communist, libertarian,
whatever. Everyone [ __ ] hates this
[ __ ]
>> And AI is making it worse. AI companies
are summarizing all this data, finding
needles and hay stacks, supercharging
fac,
and oftentimes finding crimes that
aren't there, hallucinating,
overpolicing already overpoliced places.
predictive policing
making thought crime a reality.
>> Heard this somewhere before.
>> Uh these people these people think that
they they they they want to invent the
Torment Nexus, right? They think that
1984 is an instruction manual. Uh and we
can push back on that.
One guy, shout out to the Torment Nexus,
but we're hackers. We're not just going
to settle for surveillance. We're going
to do some [ __ ] counter surveillance.
[applause]
>> In the words of my hero, Lord Nikon,
>> snoop onto them as they snoop onto us.
>> So, [laughter]
there's a really amazing talk at Defcon
31 from a gentleman called Null Agent.
and uh he on stage said, "I was sitting
around really pissed off about
surveillance and cops and uh I thought
what would Lord Nikon do?" Well, Lord
Nikon would snoop under them as they
snoop under us. So, null agent gave this
awesome talk at Defcon 31. If you missed
it, this is very inspirational for us.
Um he talked about how he realized that
he could track Axon devices based on
their static Bluetooth addresses. Um, it
turns out that all the Axon devices, the
body cameras, smart holsters uh, and
other police uh, other law uh, other
technologies in their cars and on their
person are all chatting with each other
and with a command and control box and
they're constantly broadcasting their
Bluetooth address. You can track that
Bluetooth address and see where cops are
going in your city or maybe see if cops
are nearby or approaching your house.
and he built this really awesome little
war driving tool called RF Party to
specifically map out where let people
map out where cops are in, you know, uh
uh some sort of in some sort of fashion
and look back on that data and do a
little bit of counter surveillance and
we thought that was really cool and it's
a really awesome example of uh technical
counter surveillance that is easy to do.
This is TSCM stands for technical
surveillance countermeasures. And this
is the [ __ ] that spies use to find
hidden cameras, hidden mics, etc. Things
like spectrum analyzers, nonlinear
junction detectors, high-end software
defined radios. This is all really cool
tech, but it's all really expensive.
This stuff can cost thousands of dollars
and it's hard to use, right? Unless
you're trained in this, uh, you might
not be able to use this stuff, right?
But this stuff is for finding hidden
surveillance and we're not trying to
find hidden surveillance.
But moreover, counter surveillance
shouldn't need to be expensive and
technical. We can make counter
surveillance cheap and accessible.
Privacy is a human right. Privacy is for
everyone. And it shouldn't just be for
the rich. [applause and cheering]
And it shouldn't and it shouldn't just
be for hackers. Anti surveillance is for
us all because we don't all need to be
cam girls for the surveillance state.
But this talk is all [laughter]
this talk is also about economic
warfare. And uh I'm not in the military.
The colonel, despite his rank, also not
in the military.
>> Not in the military.
>> Um hopefully no one will shout stolen
valor. Uh
>> stolen valor. Um, but there's a a
military which is if I send out my $600
drone and you send out a $6 million
missile to shoot down my $600 drone,
well, even though I've lost my drone,
I've still won cuz I've spent a hell of
a lot less money than you and I can keep
spending less money. Uh, I can build
drones faster than you can build $6
million missiles. We can do the same
thing with surveillance. Uh, so for
example, at EFF, we built this tool
called Ray Hunter. Uh, yeah.
>> Yep.
[applause]
I'm not going to talk too much about Ray
Hunter because I already talked about
that last year, but uh, it's a tool to
detect MC catchers. It's free and open-
source software which runs on cheap
hardware. These devices you can get for
20 to 40 bucks on eBay or you used to be
able to. Uh we've used it globally to
find real MC catchers in the wild and
we've been able to have thousands of
people all over the globe helping us do
adversarial reverse engineering on tools
which were previously completely opaque
and uh really I mean not completely
opaque a lot of researchers knew how
these work but we've been able to prove
how they work um and get data on how
often they're being used um and
The economics are really on our side
here, right? Ray Hunter costs about $20,
but current MC catchers to buy the truck
with all the equipment in it and the
fold support package go for about a
million. This is a $50,000 to $1
spending ratio. For every for every
$50,000 your city is spending, you can
spend $1 to counter that. And that's an
awesome ratio. But MC catchers are just
one type of surveillance. And we're all
really mad about flock right now. Las
Vegas Metro spent $4.37 million of some
billionaire's money who donated
specifically for this purpose to buy 211
flot cameras to put up all around this
city. You could detect all of these for
one $6 ESP32.
Or you could pair an ESP32 with each one
of these and do stuff [laughter]
for about $850
cost of less than the cost of a new
iPhone.
That's a really good ratio. Shutting
down a billionaire's $4.37 million
project for $850. I like them odds.
[laughter]
So, what kinds of
[laughter]
I just get up and talk to politics.
So, what kinds of things can we do with
the ESP32? Uh, I'm really glad you
asked. And this is where we were going
to transition to the RU. Uh, but since
he couldn't be here, I'll just list some
of the things. One of the awesome things
about ESP32 is that it's really easy to
program for. You can you can port stuff
over from other projects super easily.
Uh, Void Mantis OS was a uh new firmware
for the exploiters hacker pager. Uh, and
we were he was really quickly able to
port Sky Spy, We Spy, Fox Hunting. I
wrote a password generator, um, axon
detector and other things. It's [snorts]
super easy to bring this stuff over and
and it's really easy. It's a fun and
easy way I to get involved with hardware
hacking and starting to write close to
the middle and starting to think about
the sorts of things you can do, right?
You can do war driving apps, RF anal
RF analysis. I was going to say
analyzation. [laughter]
>> That's not a word. Now,
>> uh, and these are so cheap, right? You
can build networks of these. You could
you could for $6, these could be
throwies, right? You can give one of you
you could give these out as Halloween
candy, right? Uh, they're really that
cheap. [laughter]
>> Worse.
>> Don't put it within the candy.
>> Yeah. No, don't put raise [laughter]
>> Check your children's Halloween candy.
There may be ESP32s hiding in the
Snickers. [laughter]
>> New meme just dropped. Yeah.
Uh, but without further ado, I want to
introduce you all to somebody who's
actually working on this stuff. My
colleague, Colonel Panic.
>> Thank you. [applause]
It is very nice to be here with you all.
My name is allegedly Colonel Panic. I am
the creator of the OUI or Wii Spy.
Uh, this is just an ESP32 with a buzzer.
As you can see, the wiring's right on
there. So you guys can rip it off if
you'd like.
I also made the mesh detect. This is
something that will extend your
detections over mesh network. So you can
have, you know, sensor networks going
over mesh. Like let's say you want to
detect a certain OUI at the end of your
driveway, you can have it report back to
you.
I like cheap things in DIY.
Spent most of my life very poor, so I
need an ESP32 instead of an expensive
SDR. And I want to make these things
available uh for everyone to use. I sell
mine online, but it's more I'm selling
my art. You can make this for less than
$10.
Of course, the art, you know, I like I
like metal art patches. I made the patch
uh to to go on your battle jacket, and
it's just an OUI spy that does the exact
same thing with clear PCB. You can sew
it onto your jacket and have a detection
mechanism on your clothing.
Uh, it's really hard to solder. You will
melt that if you touch the soldering
iron to it. So, that's been really fun.
[laughter]
New techniques. New new techniques.
Uh, SDR and detection can be expensive.
Uh, you can, you know, hack hack RFS on
the cheaper end, but still not as cheap
as a $7, $6 ESP32.
>> Not everyone can afford a B210, and that
should be okay. You should still be able
to do RF research.
>> Yep. And it's becoming more and more
accessible now uh with microcontrollers.
So it shouldn't be a luxury. It
shouldn't just be for the rich.
Everybody should be able to do this. If
they're going to watch us, we can watch
back detection for less than the price
of a domestic beer on the strip. You
don't even need a bu [laughter]
you don't even need a buzzer really. Uh
you can plug this thing in and into an
API and do the same thing.
So they make affordable projects cheap
and easy for makers. This on the left is
Xiao Expp32.
Uh these are the really cheap ones and
they're really small. That's what I use
for my boards, but also getting into
this stuff. If you want to start
prototyping stuff, M5 stack is really
great because maybe you don't know how
to solder. They have Grove ports that
you can just plug sensors in and extend
this. So, if you you could even make uh
the same device that I'm using on one of
these and have haptic feedback, uh
alarms, you can push it to the cloud,
whatever you want to do to to take take
these detections and uh and categorize
them and save them for later.
So, this all comes from war driving uh
and war driving community. Uh shout out
to the wiggle folks and of course kismet
folks, too. [applause]
[cheering]
Definitely check out Wiggle. If you've
got a phone, you can put it on there and
rock some war driving. But it it comes
from war driving and then becoming aware
of surveillance and how pervasive it is.
And it's easy to just forget about it
because it's so homogenized and blending
in with the environment, but it's very
pervasive.
So, the OUI spy works all passive, of
course, because that's the legal way to
detect things. Uh you not legal advice
from the EFF [laughter]
or me either. do your own research. So,
it's all passive. You're you're looking
at BLE and Wi-Fi uh and mostly OUI
detection and then of course drone
remote ID decoding and uh mapping and
and alerts. So, the OUI or we spy can
also take a drone remote ID, decode it,
and you can get the buzzer to tell you
when a drone is flying near you or you
can hook it into the API and you can map
the drone and the pilot in real time.
It's unfortunate the remote ID is that
insecure that you can track like this,
but it's there. We're going to we're
going to pick it up. We're going to look
at it. And it's really good to watch
surveillance drones. Once you start to
really look at this, you'll notice who
the most frequent flyers are. If it's
not you, it's probably someone who's
very official.
Uh OUIP firmware. We got the detector. I
made this so that it will just you can
put an OUI in it. uh it's the first six
characters of a MAC address that
identify the manufacturer and what now
MAC randomization is of course a thing.
So we'll be digging deeper into the
Bluetooth stack. Uh so it really just
lets you put in an OUI and then when you
approach this OUI or it approaches you
this device you get an alert with your
buzzer. So it's great for body cams for
instance. Uh Skyspy that's the drone
detection and remote ID decoding. And
then of course Flock U. Uh this has gone
through many iterations, but uh this is
when I was war driving and started to
become aware that flock cameras were
everywhere and no one in my town really
knew about it yet. So I wanted to make
something that would help people be more
aware. And this eventually carried us to
our city council and speaking events
with Ben Jordan and mayoral candidates
to try to get flock cameras out of our
city. Didn't work right away, but it
will eventually. And then of course uh
the fox hunting. Um, it is a fox hunter
that that allows you to target it and
find a device with a directional
antenna. So, if you have an OUI spy, you
can plug a directional antenna in it,
cheap PCB printed directional antenna,
and if you put your target device in it,
you can turn a circle until the
frequency of the beep increases and then
walk a direct line once you find the
highest frequency point and you can find
the device.
Pretty cheap to do. drones, body cams,
and flock. Oh my.
So, the remote ID and mapping. This is
just an example of the Sky Spy API. Um,
we've had in my town one of these
running for over 6 months, and we're
just saving all the data to take a peek
at later. But, uh, it, like I said
before, it it will map the both the
pilot and the drone in near real time,
and you can look up the FAA remote ID
and find out what model the drone is. So
if you see something like a Matrice 3
thermal, you might think, why is there a
thermal drone flying over? It's probably
the police.
So FlockU got really popular. I could
not believe it. Uh my GitHub repo blew
up and people started uh forking this
and making their own and porting it over
to other devices like uh the Ruse stuff.
And I mean there's probably folks out
here that have probably ported to their
device. Uh I had to solder over a
thousand of these by hand. uh when this
first dropped because I did not have
assembly yet and I am so thankful for
that now.
So, Flock actually has an API you can
use to incorporate things like GPS and
saving uh your detections, but uh also
if you if you don't want to use the API,
you can have it beep when you drive by a
flock cam uh and or you can hook it up
to the API, add GPS and map and then
save it. You can also it saves
detections and spiffs. So you can take
it off the little file system on the
ESP32
and you can dump it back into your API
eventually.
You can make your own. It's open source.
This thing is literally just an ESP32
and a buzzer. That's under 10 bucks. If
you look at that schematic of that board
that I made is art. You can just make
this. Just rip it off. Make it yourself.
I'd be happy if that happened. All you
need is an ESP32 and a buzzer. And
that's a 3volt passive buzzer. Super
cheap. Super cheap. I can attest the
buzzer is optional.
>> Yeah, it's a it gets annoying. I took a
road trip and I was like testing the
body cam detection. I was like, I don't
want to know anymore how many of these
are around me. [laughter]
So, as it turns out, it's decent, really
good for cryptography. And
>> yeah. Yeah. So, there's a lot of there's
a lot of future directions we can take
this, right? Um, it turns out ESP32 can
also do some fun cryptography stuff.
Um, I wrote a password generator app for
it because it has the feature of giving
you true random numbers. Uh, and I'm not
a cryptographer. Please don't take this
as a fact. But the manual says that it
can give you true randomness based on
the noise floor of Bluetooth and uh,
Wi-Fi. So, you can do some really cool
stuff with that. And I think if if some
cryptographer can verify that's true,
you can do some really cool stuff uh,
building on top of that. Um, and uh, we
can also do stuff with the C5 with 5
gigahertz.
You can
>> do uh, 5 gigahertz Wi-Fi or you can also
start to look at uh, trying to use 5G to
decode remote ID for drones like parrot
drones. I haven't gotten a detection of
a parrot drone yet because I don't
believe they're used in my area, but I
would love to hear if anybody ever gets
one with a with a, you know, micro
controller on the 5G Wi-Fi spectrum. And
we just want to detect everything. You
know, that's what war drivers do. We
want to get all the devices.
So, [laughter] I'm already working on
the V2. It It incorporates GPS, haptic
feedback. I'm making an app for it. I
just The art is what's holding it back.
I got to get that art perfect.
[laughter]
But, uh, want to put multiple radios on
it. So, one manages the app and then you
have a radio that is dedicated to
detection. And of course, we want clear
cases. It's going to have a clear case.
We love the [ __ ] clear cases.
>> Listen, the 1990s got everything correct
aesthetically. Okay, bring back clear
cases. [laughter]
[applause]
Electronics don't have to
electronics don't have to look boring or
stupid. We can put we can put art on
stuff. We can make this [ __ ] look cool.
We can make this [ __ ] punk rock, right?
Counter surveillance does not need to be
boring. It does not.
>> What are you going to build?
>> Yeah, this is and what so what really
inspired me and the the reason I met up
with this guy and wanted to do this talk
because I think that this this is a
really awesome way for people just to
get involved, right? A lot of us get
paralyzed by inaction, right? We see the
horrors around us and we want to do
something, but it's it's hard, right?
It's hard to find that first thing. And
this is a first thing to do, right? It's
an easy accessible thing that is
achievement anyone can do. And then once
you start doing one thing, you start
thinking of more things you could do,
right? This is propaganda as much as it
is uh a tool, right? It's it's the the
propaganda of the deed where we inspire
people to get out there, do things,
start thinking about the surveillance
around them and start noticing
surveillance around them
>> because it is pervasive and if you have
a little thing to do, I mean the idea
was to to just make people aware and now
it's become a full-blown detection tool.
We can't stop now though. It takes a
community to raise a counter
surveillance tool. So we need you guys
to war drive and continue to submit data
to the project. Did you find a new OUI?
Did you find a new way that you know a
flot camera is uh trying to change their
uh the way that they broadcast something
so that they can evade detection? They
know about what we're doing and they're
going to know more after this talk. So
they're going to keep it's like they're
going to keep changing it. And so we
have to figure out new ways to to find
these things in our in our environment.
>> So in the words of Zero Cool, hack the
planet because they're trashing our
rights.
>> Hack the planets.
>> Hack the planet.
>> [applause]
>> Thank
thanks y'all so much. Uh we have we have
uh quite a lot of time for questions. Um
and uh you can find us on the social
medias here at the following things. Uh
of course this uh this work is also you
know we we don't stand up here alone
right this work is built on the work and
camaraderie of so many people. So,
especially huge thanks to our families.
Uh, huge thanks to the Hackers Town
crew. Huge thanks to the of course the
EFF staff and members uh that that you
know helped fund my work. Um, and uh for
Colonel the Wiggle crew, of course,
Dlock folks, those DOG war drivers are
the best. Uh, Nightcry or Aurora Bor
Aurora, I can't even pronounce the word
now. Nightcry. At any rate, uh, DZAZ,
another homie that, yeah, a goon, no
less. Blindster, who taught me how to do
PCB design and was kind enough to show
me how to do it. Uh, of course, the
Hardcat Brigade who have been kind to me
over the years. All war drivers, Gain
who did it. I don't know if you've
checked this guy, but he found a lot of
vulnerabilities that Flock ignored for
some time. So, it's really if check out
his talk if you haven't already seen it.
Uh for me, Hackblock, who brought me up
in uh DC 415, my hometown,
>> and of course my hometown hacker crew in
Asheville, North Carolina, the Dirty
South Hackers.
Thanks y'all. [applause]
>> If you do have questions, we have a
microphone here. You can come up and
shout them out. We got at least 10 to 15
minutes. Or if you don't have questions,
we'll just leave the stage. Um,
>> take
>> hand it over.
>> I
>> Yeah, hold. I can come over here.
>> When you collect all this
>> No, no, take the microphone.
>> When you collect this data, what's your
favorite way to store and analyze it?
>> Ah,
>> yep.
>> It comes across in JSON, so we store it.
But I think the real thing to do is get
something in Warrive and look for PECAPS
because these things are going to
constantly change. Uh, you know,
something like uh Wiggle would be good,
but you can actually get PECAPS on an
ESP32. So, uh,
>> I end up making this stuff and end up
doing a lot of work working on it. So,
I'm not storing it. So, that's a
question for what are you where are you
what are you going to do with it? You
store it. You figure out what you're
going to do with it, how you can analyze
it. It's a
>> Anybody can do it. But uh yeah, I mean
there's there there are exactly there
are projects like Wiggle where people
can upload this, right? Like this this
data should be available to the
community overall, right? And and we're
probably not going to build that, but
you all could certainly build that,
right? We can build amazing maps. We can
build you all can build amazing maps.
You all can build amazing visual
propaganda, right? And and start doing
this and start like crowdsourcing this
research, right? Like even just upload
it to your GitHubs, right? Put it on
paste bins. I don't care. Right. The
important thing is to this a deep cut.
The important thing is to get it out
there, right? Um and and get that data
out there. You know, um there is there
is talk of an interchange format for uh
uh you know, publicly available uh uh
lists of OUIS and other indicators of
surveillance equipment, uh which we're
which we're working on with the wiggle
crew. So that might that's coming down
the line, right? Um but yeah, just just
do it.
Thank you though. Good question.
>> Yeah.
>> Have you done any looking into or
research on companies like Axis who
don't run NRF? And
>> there's a problem which is that we can't
hear you.
>> Is this better?
>> No.
>> Mike, you [laughter]
just come up here.
Have you done any research or looking
into companies like Axis who don't run
uh on RF and only run on PoE?
>> I haven't done that research yet, but uh
that's a good call out for sure.
>> Yeah, we'd love to Yeah, we'd love to
know more. Haven't Yeah, we'll chat.
>> Yeah, absolutely.
>> Okay.
Um, what ESP32 would work for all the
gigahertz?
>> For which one?
>> Um, if you're trying to get different
frequencies for the drones, for example,
on all the gigahertz and like the ESPs,
they work on different
>> Oh, yeah.
>> Work best for that.
>> The ESP32C5
is what'll get you 5 GHz and 2.4 GHz.
The S3 will just get you 2.4 gigahertz,
which is still good enough for a lot of
things, but I know you've run into
limitations with that.
>> Yeah, the great thing about the S3 is it
has a dual core, too. So, you could do
both Bluetooth and Wi-Fi since they're
on the same wavelength. You can do them
both at the same time. But, uh, yeah,
taking it's never going to find FPV with
this. You know, you're going to need
more equipment, SDR equipment for that.
But you have for remote ID decoding. Uh
I generally use the S3, but if you're
looking for five uh 5G Wi-Fi, try C5.
And it's Xiao. Uh seed Studio Xiao is
the the ones that I use. Xiao.
>> Oh, got one.
>> So kind of a question, kind of an idea
to bounce. What about making a version
of these? What about making a version of
these as an almost enduser awareness
device like that people that you could
like distribute to people to like keep
in their cars to like
uh like could like could you make almost
a firmware to put on these to like
distribute in for people in their cars
to get more people aware of?
>> Yeah.
uh what how many times they're passing
by uh flock reader like flock cameras.
>> Yeah, I mean I think that's kind of what
it's already doing, right? If I may
speak on your behalf, I keep mine I keep
one in my car and constantly scare the
[ __ ] out of myself and my wife uh
because we forget it's in there and then
we start the car and it goes
[clears throat] and [ __ ] what? Uh so
yeah, I mean that's
>> not a pleasant sounding buzzer, you
know? It's really not. Uh but no I I
mean yeah that's that's that is kind of
already and that is kind of I think
already one of the potential uses for it
certainly how I use it. Um, and if you
if you think that there are there's like
a better form factor and it could be
better, I honestly like please build it
like like or you know come come hang out
and show you know
>> Yeah. Yeah.
>> Tell us what you want because Yeah.
Absolutely. Like this is all open
source, right? And and remix, reuse,
create, right? It's all it's all there
for the for the doing. So yeah, it's
like when I made it and I never thought
it would go beyond niche hackers, so I
made it a little hacky, you know? So,
with the next version, we're going to
keep adding things to make it easy for
just the average user to get into, you
know, so you don't An app would be very
helpful or things that just make it easy
to use.
>> It's there's nothing like building a
tool for yourself and then finding out
that everyone really likes it and find
and finds it super fun. But also,
there's the problem of like what's easy
for people who live in the terminal to
use, right? Is it necessarily it doesn't
always occur to us that that's not
exactly easy for somebody else to use,
right? We learn that through user
feedback. [laughter]
And so I think yeah like uh you know
finding finding finding that out and
finding like I said accessibility is a
big is a feature here right it's a big
thing we want and so like yeah finding
ways to make this stuff more accessible
you know with apps and gooies make it
easier to use right that's what we want
because we want we want grandpas doing
this right we want we want people who
main hobby is golf right I don't I don't
need you don't need to be a hacker for
this stuff we don't want you to have to
be a hacker for this stuff
>> and if you do happen to get a hold of
one of these and you need help, please
hit me up. I I will email you back.
Do not email EFF.
Not everybody at once, at least.
[laughter]
>> Uh, thanks. Um, so I've been driving
around in my car with one of these, just
like you were talking about, and I get
mystified when I hear the little buzzer
goh, and I don't see anything that that
obviously corresponds to what looks like
a camera device.
I don't know what's going on, and I'm
not sure how to correlate. I also don't
see the same devices on the deflock
maps. So like there's a discordance and
if I go to places where I think there is
DLOC, I also don't get I don't don't
hear the device say anything. So I'm
kind of mystified. I'm hearing it places
I don't expect it and I you know I'm not
hearing places where I would expect it.
>> Which firmware are you running out of
curiosity? The Bluetooth is kind of I
would say go get the the newest firmware
at Reashlash because we've done a lot of
work, not just me, other folks that have
discovered things and we implemented it,
but the Wi-Fi is the best way now. So,
it it uses permiscuous so that it can
pull down data from probe requests and
wild card probes and things like that.
But, uh definitely flash that newest
firmware. I pro probably shipped it to
you with the old firmware. So, uh, use
platform IO or I can make a web flasher
or something and and if you find
something, please let me know.
>> There's there's, uh, I mean, I think one
of the things that I've found as as a
user of it is is and I I think that
you've talked to me about is like the
the some of the newer flocks are on 5
GHz, right? And they're they're
>> they have cell uh some of them have cell
connections. I think
>> some of them have cell connections,
right? And we were like talking for a
bit about if we could use Ray Hunter to
have when we can't. Um, but like yeah,
there are there are it's a bit of a
cat-and- mouse game, right? And some of
these some of these just aren't
detectable with the C3, with the S3,
right? And we're going to we're going to
need to think about new ways to detect
these. On the on the other hand,
sometimes I detect these cameras from
like two blocks away, right? And and so
like
this is where you can like switch over
to fox hunting, right? Or you can uh uh
you know, just start circling around. Um
but yeah, you might you might detect it
from very far away sometimes, right? And
uh might need to might need to to do a
little more looking, but yeah, I love
the headgear here.
>> Sweet. Throwing out everything and
seeing what sticks, too. So, they're
going to be changing everything. So, we
need community help to continue with
this detection to make it actually
really accurate and reduce false
positives as well.
>> Well, thank you for queuing me up so
well for this question. Um really about
the cat-and- mouse game. Like you said,
as we're sharing this information,
they're going to be updating their
techniques. Um, static Bluetooth
addresses seem like one of the easiest
things to go. So, I'm curious where
where you see that going next. Are we
going to be collecting like
characteristic and service UYU IDs?
>> That's exactly it. We're going to look
for that in the advertise. We're look
for the manufacturer data and then we're
just keep digging to the Bluetooth stack
passively because we don't want to touch
it.
>> Yeah.
>> Yeah. There's a lot in Bluetooth you can
nab and you can make a fingerprint. So,
when I stop having to make these things
in soldering all the time, I'm going to
continue the work. So more more uh
assembly but if you find something
please let us know like shoot me an
email uh if a new technique we can make
it happen.
>> Love to yeah catalog some and send them
to you. Um other question u state
detection thinking specifically about
body cameras. Have you looked into or do
they emit characteristics that tell you
that they're on or off? That seems like
a useful bit of information to surface
>> there. So, someone released an exploit
uh months back that will turn the camera
on any body cam via a insecure Bluetooth
service. So, I'm guessing that you could
probably find if it were on and off via
that, but I have not dug into that yet.
>> Please consult with your lawyer before
doing that. [laughter]
>> If you start touching things, it crosses
a line. So,
>> for me, yeah.
>> Thank you guys so much. Love what you're
doing.
>> Thank you.
Hello, I've been listening to you and
I've been wondering why uh didn't you
use uh one of the existing platform for
SP32
like a carpenter or something like that.
It's have anything that you need? Uh are
you thinking about porting those firmers
for those devices? Yes, I think I did a
drone detection port for uh M5 Stack
Core S3 and it has haptic feedback and
it'll show you the remote ID on screen.
In my V2, I stayed away from screens
because I personally will break them off
and uh I I won't end up using the thing.
So, I made an app, but
>> it's hard to have a screen in a mosh
pit.
>> The card is awesome and they're making
the their new one that's like
>> Yeah. And it's got you has Linux on it,
but you could probably do a lot with
that. But yeah, you I'm going to port
and people have ported them to other
devices, too. So my code is all open
source. If you want to port it, too, go
for it. It's all you.
>> The new one with the Raspberry
>> the new one with the Raspberry Pi on
board h get a new advantage because you
can use all those USB SDR sticks.
>> Yeah. with mostly extends the range of
detection
>> far beyond only the Bluetooth and Wi-Fi.
>> Yeah, that's a great that's a great
thing. Yeah.
>> And then and and I'll I'll speak on
behalf of Colonel Panic, right? Like I
mean, part of the reason to make your
own stuff is to make it look cool,
right? Uh uh you know, make it make it
make it punk rock and make it your and
you know, do the DIY thing. Make it
cheap, right? Uh uh make it something
that someone can just buy and plug in,
right? I suppose I haven't know that.
So, but but yeah, easy to port, right?
And yeah, port it to your favorite
platform. Yes,
>> M5 stack is a great one for that too
because it has everything in there
already.
>> Another another question. Um, have you
seen these cameras start to move away
from Bluetooth and Wi-Fi pros and only
on um cellular networks? And
um have you seen that they uh ones that
do use cellular networks are on the
first responder network?
>> I haven't dug into that one enough yet,
but I I can say that they are they
definitely stop using as much Bluetooth.
I'm sure there are ones out there that
still do because I mean half these
things are still in like factory mode,
you know, like people don't know how to
set them up and and they tend to be very
insecure. So,
>> it's a cat and mouse game for sure. Um,
but like I mean I can tell you that a
lot of the stuff that goes over cellular
is not encrypted or authenticated and is
very very uh uh easy to spot if you can
listen to that frequency. So like if
there are like ESP32 can't listen to
that frequency, right? But if there are
cheap ways to listen to those
frequencies, right? uh pending a full
legal investigation. Like that's that's
a place where I could the lawyer in my
mind is screaming at me right now.
[laughter]
Uh that's a that's a you know that's a
that's a direction to go in for sure.
>> Last question. Have you done or looked
into anything with uh signal trace?
>> I'm I am very concerned about signal
trace um and and ramping up you know
what I'm what I'm going to do about it.
But so signal trace for those of you who
don't know is the add-on for add-on for
flot cameras I want to say uh that that
is or it's a it's a separate company I
can't remember what but the
>> war driving is Leonardo yeah they're war
>> America government war drive you
[laughter]
>> yakov uh
uh yeah so so for those they're they're
war driving you they're basically
building a RF fingerprint of your
Bluetooth and Wi-Fi devices and using
this to identify the individuals in
cars, to identify when people go into
new cars, to identify you when you're
walking or biking or or using other
modes of transportation, right? So, it's
just another another form of
surveillance. And yeah, I know I know
the guy who asked the question is
thinking about ways to counter that. I'm
uh you know, at EFF, we're thinking
about all of the legal and activist
strategies we can do around that. I'm
thinking about what we can do on the
tech side. But yeah, it's it's top of
mind for sure, man. Well, you have to
become a lite and not carry a device
with you or have a car. [laughter]
>> Simply don't participate in society and
you'll have nothing to hide and
therefore nothing to fear. [laughter]
>> There perhaps another version of this
where it you can then start broadcasting
sort of a random or a you know war radio
signals that might disturb their data
that they're collecting for the ones
that are war driving us
>> like poisoning the well. Yeah, I'm sure
somebody's doing that, but uh
>> you could do it if you wanted to.
>> Yeah,
>> legally ambiguous. Yay name.
>> But my question is if you're doing it,
will they then be able to to use AI to
find the you know signal in the noise
too? So flooding it. That's very
interesting. You know,
>> I mean we are at least making it more
expensive at that point, right?
>> Exactly.
>> Imposed cost.
>> Yes, exactly. Imposed cost like we were
saying earlier.
>> All right, I think we got time for like
one more question.
All right, we got one one coming up.
>> All right.
>> You can also find us after this. Sorry.
Yeah.
>> Uh, is there a way to use multiple like
ESP 32C5s
example to
have a cluster of
>> Yeah, I'm glad you asked. There's a
thing called ESP now that you can use to
have them wirelessly transmit to each
other and it doesn't interfere with the
Wi-Fi or Bluetooth stack. So you could,
for example, have 12 of these things,
one on each channel. If you can get
enough amperage to the damn thing, you
can not have to hop channels and you can
grab more data as you drive around and
get way better reward driving than if
you had one SDR that's hopping around on
channels. So,
it's not hard to do. I have some
firmware for it that I'm testing. I'll
probably put out at some point, but
yeah, it's looks pretty janky. You just
plug a bunch of USBs in and hang them
over your uh rearview mirror. [laughter]
All
right. Thanks y'all so much for coming
out. Hack the planet.
>> Thank you very much. [applause]
>> [music]