Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
The coolest anti-surveillance tools at Defcon [video] (youtube.com)
231 points by neom 1 day ago | hide | past | favorite | 44 comments
 help



Partial summary:

-ESP32 based device that tries to detect bluetooth/MAC addresses of flock cameras and beeps when it does

- a Stingray detector that runs on a second-hand mobile hotspot

- a device that alerts you about things that are moving approximately with you (AirTags, SSIDs, etc).


The last project is this, it actually does a lot more.

https://github.com/Em3ritus/simulacra


> ESP32 based device that tries to detect bluetooth/MAC addresses of flock cameras and beeps when it does

Is it this thing?

https://simeononsecurity.com/articles/flock-you-detection-pr...



Cool, I like the esp idea but won't you have to walk fairly slowly with a default ESP antenna? High gain might be better.. If you're wearing a cap you may not care as much being seem from above vs from the front. Maybe attach a little windspeed meter to the top of the antenna on your hat too ;)

Sigh, researchers used to publish cutting edge stuff.

That list reads like a fist year lab schedule. lol =3

https://www.youtube.com/watch?v=fBlAMqoJ5BA


Is anyone familiar with the laws surrounding police basically operating their own pseudo cell towers?

I would assume this would be highly illegal for individuals, what sort of hoops did law enforcement need to jump through to get this type of approval? Did FCC need to rubber stamp this?


John Oliver did a piece on this a couple of weeks ago. The videos are not widely available outside of the US, but here's a Guardian write-up [0], and in the UK you can get access to the episode via catch-up if you have Sky Atlantic.

TLDR: the police do this whenever they want, pretty much.

[0] https://www.theguardian.com/tv-and-radio/2026/aug/03/john-ol...


In the US, the legality of Flock cameras is complicated. =3

https://www.youtube.com/watch?v=gmnL_Y9CsI0


In general, interfering with a radio link can be hundreds of thousands of dollar fines, and years in prison.

Almost every RF (legal) communication device consumers own will back off broadcasting if it detects collision or interference.

The fact many governments of the past few decades feel entitled to run intelligence campaigns on their own citizens often points to a degenerative despotic trend.

The best plans simply don't require secrecy, and everyone has fun. =3


I'm not sure I understand Simulacra. I get the idea, just spam devices around the area in hopes you're lost in the crowd. But anything designed to track you is purpose built to handle tons of devices moving about. Maybe if everyone had one in their pocket we could overload the surveillance devices, but at best you're just bloating their logs.

Seconding this, plus, the original devices stays always visible to the tracker? Does it really matter if there's your sole device in the range, vs always-present yours + ton of noise?

Defcon has been nothing but feds and 3 letter agencies for years if not decades. Assume all of these are bypassed

Great video, thanks for posting. Since Meshtastic keeps coming up in the video — if anyone here is heading to Burning Man, there's a dedicated mesh network for the event. I will have a couple nodes running on it :)

https://www.burningmesh.org/


Cell phone connectivity was the beginning of the end for burning man.

I'd love to know how it does. One of meshcore's claims is that it scales better than meshtastic. The 900 MHz band is limited and herding cats without a shepherd is a hard problem. Music festivals are a good stress test.

CSS - chirp spread spectrum is used by both, so likely better software

The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them. It is a disgrace.

Defcon stopped caring about privacy, hacker ethos, and digital sovereignty a long time ago.

Go there if you want to talk to their military recruiters or buy/sell proprietary snake oil security SaaS. It is really just another corpocon at this point. Hackers should probably skip it unless using it as a chance to hang out with friends in vegas on their corporate credit card.

The hackers are mostly at HOPE and CCC these days.


Defcon was always the most government-aligned conference. Historically, BlackHat was Defcon's slightly more counter-culture counterpart/foil. These days, I don't think anti-establishment hackers have any physical conference gathering.

BSidesLV is still pretty chill, although it's more focused on cybersecurity professionals than on the hacking side of things.

> These days, I don't think anti-establishment hackers have any physical conference gathering.

HOPE still exists


> These days, I don't think anti-establishment hackers have any physical conference gathering.

Wouldn't you be essentially doxxing yourself by attending?


Privacy centric cons allow paying cash at the door. That is maybe the one thing Defcon still gets right.

Paying cash is nothing compared to all of the cameras installed in and around the location of the con. Which also means nothing towards the hotels definitely not accepting cash unless you're willing to stay at hotel with the working girls and dealers.

Agreed. It is simply the one privacy thing they do right.

I think you got them confused, DEF CON is the more counterculture and Blackhat is the corporate conference.

While I agree that was the original intention, modern DEFCON is just as corpo but for those that cannot afford blackhat. European hacker cons like CCC are now what DEFCON once was rumored to be long ago.

>These days, I don't think anti-establishment hackers have any physical conference gathering.

MoneroKon and Monerotopia.



> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them.

Do you have a citation for this? I am not seeing anything on their website and they did not come up to me and demand I sign anything when I was there?


Last time I was there the only ways to engage with the community were via slack, google groups, github, or discord. All centralized proprietary surveillance capitalism products, and no decentralized/FOSS options.

https://cryptovillage.github.io/ shows nothing has changed.


> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them. It is a disgrace.

What does this look like in practice?


They have a sign similar to the ones at stadiums or events that say recording is in progress and that by being there you agree to be recorded... being here means you agree... not that there is any enforcement but very flocky and thus ironic.

That's not Google though?

You have your choice of salesforce, google, or discord to interact with them.

They even virtue signal with their "crypto means cryptography!" sign without actually promoting tools that let people have control of their own keys.

They do not use or support any privacy preserving comms, and thus, they are just yet another surveillance capitalism marketing village.

I actually encourage Defcon attendees to visit the village with context, as it really is a symbol of everything wrong with privacy advocacy in America, and why we are so so so far behind Europe.


Glad this one is getting the "second chance" bump back to the front page. It's great content and it's timely. It's a great video.

If you're not inclined to watch the video I'll save you a click to the youtube description and add a bit more detail than the earlier sibling for the devices shown:

Simulacra

"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."

https://github.com/Em3ritus/simulacra

---

Biscuit Ultra

"Wardriving Platform: A Full WiFi & BLE Security Toolkit. A headless wireless security research platform controlled entirely from your phone via Bluetooth. The platform supports dual-band WiFi (2.4GHz + 5GHz), Bluetooth Low Energy scanning and attacks, wardriving with GPS mapping, packet capture, and much more"

https://biscuitshop.us/products/biscuit-ultra

---

Rayhunter

"Rayhunter is a project for detecting IMSI catchers, also known as cell-site simulators or stingrays. It was first designed to run on a cheap mobile hotspot called the Orbic RC400L, but thanks to community efforts, it can support some other devices as well."

https://github.com/EFForg/rayhunter

---

OUI Spy

"ESP32-S3 multi-mode surveillance-detection board"

• Foxhunter — single-target RSSI-proximity tracker for radio direction finding

• Detector — multi-target BLE scanner with OUI filtering + web config portal

• PCAP — raw 2.4GHz Wi-Fi packet capture, Wireshark-ready (dev branch)

• BLE Sniff — raw Bluetooth LE advertising capture, Wireshark-ready (dev branch)

• Flock-You — Flock cam detection with GPS wardriving, JSON/CSV/KML export

https://colonelpanic.tech/

https://github.com/colonelpanichacks/oui-spy


OUI Spy is cool. I got the pair of earrings for my girlfriend's kid's bday a few months ago. It's fun and disappointing driving around finding all the Flock cameras I hadn't noticed.

>"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."

"Oh, it's that guy with the bluetooth spammer."

https://xkcd.com/1105/


If they became cheap enough, you could deploy them "permanently" to leave around town. Hang 'em on the same pole the Flock cameras are mounted, or on the ground in one of those hide-a-key things shaped like a rock on the ground near the pole. Just toss one out as you drive by type of situations. It's all solid state, so should be okay being tossed around a bit.

Ironic to share this using a Google property...

"Yet you still participate in society. Curious!"

idk if this is off topic or not because its an ad playing on their channel but wow the non-skippable ad about 'clearing out stuck poop fast' from an ai doctor really added a lot of value to my life before the video rolled. this is what I get for not opening in a browser with ad block. is this what youtube looks like now without ads?

Yes, it's really bad, I see that scam ad constantly. Some even use celebrity deepfakes. Logged-out YouTube ads are 90% garbage like that.

Consider yourself lucky you didn't get the outright pornographic ones for boner pills "my husband fucked me 50 times".

Reporting them does nothing. Google does not care.


Nice toys



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: