Moderator's introduction
Thank you, Valeria. I won't drag things out much either. I'll just introduce the person who's about to speak. Every time we pick a talk topic with him, it's always something new, interesting and unusual. Every time he sends me a topic, I even find myself wondering: "Damn, what will he come up with next time?" Please welcome with applause: Igor Bederov.
Talk
Hello, colleagues. Thanks very much for coming. Glad to see you all at yet another event, an anniversary one this time. How many times now? My fourth time taking part, right? The fourth one, right? Great. So what's on today? In previous years we've talked about Telegram users, Telegram channels, and investigating websites. And indeed, when Dmitry and I were thinking over the topics, we decided, why not take a topic that's partly related to the Mobile Criminalist product line. And we picked a topic that shows us how, using competitive intelligence methods, using OSINT methods, one could track a mobile phone's movements.
Again, using OSINT. I'm not law enforcement, and I'm in no way encroaching on that delicate, mostly unnecessary domain. I'm talking about how you could track mobile phones using open sources of information. Well, here's a brief bio. You can take a photo or not. You'll find me online anyway. First, let's go back a little into the past. And in the past, up until about mid-2018, everything was quite interesting, legal, simple, elementary even, I'd say. Because back then, tracking mobile phones took no effort whatsoever. Let's recall.
How tracking worked before 2018: SMS centers and HLR lookups
Before 2018, well, what was it, 10 years ago, 15 years ago, we had SMS centers. In the SMS centers you could get the LAC and CID, that is, data on the base station's coordinates, practically in real time. So you had to make a few requests on the phone number, a ping SMS, then an HLR lookup, and you got the exact coordinates. A bit later the situation changed somewhat. The mobile operators started returning some kind of code. Instead of the LAC and CID data. But that turned out to be a geographic code too. And you could drive around major cities for a while, collecting codes that were tied to a specific area.
And then, as you got those codes via HLR lookups, you'd tie them to one territory or another as well. But in the end, in April 2018, that Overton window closed. For better or for worse. It survived another year in Ukraine. And, say, in the United States. But gradually it faded away. And the SMS centers, instead of LAC and CID codes, or even unique codes tied to map locations, started returning just their own SMS center's data. Which naturally was no help at all to us in our work. But at the time it certainly had a wow effect. Because back then, we remember countless private detectives advertising "flash" services, call detail records.
They sold all that to their clients. For 10 or 15 thousand rubles, some for 20. Those are all the old days. We did it for 29 kopecks. We got that kind of information. And we didn't need any corrupt connections whatsoever. We got it completely legally, through an equally legal SMS center. Then the question came up. How do we keep getting roughly this kind of information? How do we keep tracking mobile phones? And we concluded: with OSINT methods, the ones we're talking about today.
With access to the phone: parental control and social engineering
You can do it using several approaches. And these approaches split into two categories. Category one: those requiring access to the device itself that we're tracking. And category two: those that don't require it. Let's go through them one by one. If we have access to the mobile phone. Well, we got it one way or another. Got physical access. So what can we install on that phone? We can install parental control software. The simplest and most popular option. Kaspersky, Google's standard app and the like. There are lots of them. They all let you track a child's or an employee's device quite well.
Finally, there are mobile operator services you can subscribe to. If, for example, you monitor your employees, mobile operators can well give you the ability to track, to track their movements, to track relatives' movements. And that's also quite smart, effective and simple. And finally, we have the live location sharing feature. Here we use most of the services we have on our phones. Let's take the simplest example. The Telegram messenger, being blocked in the Russian Federation. You can open Telegram on the target's phone. Start a chat with yourself. Set up continuous sharing of their location to your own phone.
And then delete that chat on the target's phone. Meanwhile the sharing to your device will remain, it persists. And you'll be able to keep monitoring that device's movements. Well, at least until they turn off GPS or reboot the phone. That's as far as getting physical access goes. Here, again, there are all sorts of nuances to getting it.
Of course, there are very experienced people who have Mobile Criminalist. Maybe other software products you use for unlocking. We, of course, don't have that. Even though I used Mobile Criminalist for a while. I love and adore it. But in the field we often can't work with it at all. And even if we're brought in somewhere to give practical help to the police, we work with what we've got. And what have we got? We've got social engineering to unlock the phone. And it tells us that in most cases a person is willing to share their phone password. The "can I borrow your phone for a call" methods always work.
You can always try to watch them enter the password. There's a certain repetitiveness in those passwords, in pattern-lock inputs. There are all kinds of powders, baby talc. There was even a really funny case shown on TV once, where a girl was given Turkish delight to eat and then handed her phone. She tapped around, and naturally the delight left greasy marks on the phone in the spots she pressed to unlock it. And so on. Methods like that are described on Habr in plenty. And you surely know them without me. So let's move on to the next direction.
Without access: digital traces, logging, leaked data
What do you do if you have no physical access to the phone at all? And here too. OSINT says that surveillance is, in principle, possible. Maybe not of the phone itself, but of the whole set of devices and information associated with its owner. Still, what can we do here? First, the obvious social engineering. We have a phone number. We can call that number. And we can ask a question under the cover story of a courier, a flower delivery and the like. Ask when they'll be home. It's something, at least, a way to track. Rough movements or presence at a particular place can be established here.
Then we have a huge number of online services, which we also identify by the mobile phone number. Social networks, Google and Apple accounts, various messengers, and so on. All that social activity which lets us find that golden grain in the huge amount of information a user publishes every day. And that grain can be quite useful. And not all of it is clear to the user. Because something we upload to Google's cloud, almost without noticing, turns out to be tied to Maps. Our numerous reviews, comments. The negativity we dump on, say, shops. And all this information taken together.
And we do a lot of vetting, for example, of people being hired into positions of responsibility; we assess them. Because we pull out their entire digital background, including subscriptions, public messages in chats, channels, communities, walls and so on. And then we analyze it for, say, loyalty. Here we move, let's say, from loyalty to tracking movements, linked addresses, persons and so on. And again we use a neural network on all content the user left on the web. And that lets us build a map of their movements. Their heat map, their connections, ties to particular addresses.
We never fully realize what volume of information we simply spill about ourselves online. And that even goes for some criminals. The second thing that comes up here is the use of various logging tools. Logging means getting a user's digital fingerprint by virtue of them visiting a particular web resource. Logging today makes it possible to obtain not only the IP address and data about the device itself, its browser, the screen resolution, language settings, Java, cookies, Flash files and so on, but in some cases, with extra settings, in the interests of law enforcement, it naturally lets you see the accounts tied to the log, to the device and logged in within the browser, for instance.
They let you see geolocation, in some cases get a photo from the front camera, a voice sample and similar data. But what interests us here is geolocation, so organizing mass messaging via bots, via ad networks, via email campaigns containing logged objects, lets you, to some extent, track a user's movements, their presence at a certain time in a certain area. But this is still, so to speak, a one-sided game. This technology runs on the capabilities of HTML5, the Geolocation API, which is actually already 12 years old. And it lets you fix our location using GPS, Wi-Fi, LBS from cell towers, cellular networks, and finally the IP address.
It does require permission, of course, in most browsers, but on mobile phones that permission is often on by default, which makes it possible to track where they might be. Then, another interesting idea within OSINT research was that, given the huge number of leaked passwords, leaked emails linked to those passwords, it became possible to use the search systems for a lost phone that most operating systems offer us. What do we mostly have? We have iOS from Apple and Android from Google. Both systems let us get access to a lost phone, to its location, if we know two parameters.
The login, that is, the email used to register the account, and the current password. There can't be any two-factor authentication here, simply because there's nowhere to confirm it; your phone is lost. So, knowing those two parameters, the email and the current password, you can get information on where that phone is, provided, of course, that option is enabled in your device's settings. Find my lost phone. In that case, yes, you can quite easily see the phone's location in a given area and track its movements online, which is pretty convenient. I, for one, keep an eye on my daughter that way, bypassing the parental apps that annoy her terribly.
Radio interception, Wi-Fi radars and AirTag trackers
Next point. Every one of our phones and all our smart gadgets constantly broadcast a huge number of signals outward. Just imagine, today we're all hung with phones, smartwatches, smart earbuds, smart rings by now, headsets and things like that. All of these broadcast Bluetooth identifiers, LoRa, MAC addresses, floating around. And all that can be seen by an outside observer. In other words, that outside observer may have a device running, say, WiGLE, nRF, LightBlue, BLE Radar, or other software that detects networks and radio broadcasts from devices like these around them.
And they really can, to some extent, track your movements. Well, the simplest example. Surveillance is under way. Someone follows the target. And to make sure the target doesn't get far away, or to check they're at the address, they can turn on WiGLE and check for a particular device with a particular MAC address in the room, within range of their phone. If we have a grid of such devices, like what they proposed installing in shopping malls a while back, Wi-Fi radars, then using that grid of devices, collecting centralized information from them, we'll be doing the same thing mobile operators do when they track mobile devices moving between their cell towers.
Here we'll see the whole spectrum of the Internet of Things, IoT objects that may move between shopping malls, and, accordingly, record that information. And this is no longer a phone number that can change, this is actual detection of the device by its MAC address, its modem's address.
So we're basically done with that. What else comes up here in terms of interesting elements around surveillance? Over the past year I've had several cases involving the use of trackers, most often AirTags, used to spy on individuals, for a possible attempt, as the victims there claim, on their lives, and other nasty things like that. What's interesting and what's the problem? First, most trackers today are detectable. Modern operating systems, iOS and Android from version 15, detect most trackers around them. If they don't, for example, Apple is tuned to its own maker's trackers, then you can install one piece of software or another on your phone that lets you detect trackers of this kind.
Those software tools are listed here as well. So detecting a tracker is no trouble at all. But what happens when we detect it? We inevitably come to believe we're being followed. Meanwhile, if we take other Apple IoT objects, say, earbuds from that same company, which in exactly the same way, using the device network of that maker, can reveal their location, then here, let's say, there'll be far less suspicion of ongoing surveillance. Finding a lost earbud in no way leads a person to conclude that they're being followed. So it may make sense to use for surveillance not only classic trackers, but also the IoT capabilities that modern IT companies provide us.
And finally, among the things that matter today. We all, of course, understand how the numerous IT corporations are watching us. And marketers, and everyone who today collects without any control our digital fingerprint, collects data on our movements, our interests, information about our purchases, our taxi rides, and scrapes our app data. All that is certainly evil, on one hand. On the other, they make our world a bit more convenient, in their own sense of convenience.
The flip side of this is that the advertising identifier assigned to us in the course of this tracking can also be used by private individuals to carry out that very surveillance on us. So we're no longer just hostages of some IT corporation that, yes, may decide to hand over data on our movements, as Google has done repeatedly, to the police. Now we also have plain private individuals who use a particular way of getting advertising identifier data. And that data can be used to track movements.
ADINT: intelligence from advertising identifiers
This methodology is called ADINT: advertising identifier tracking, intelligence from advertising sources. What does it let you do? It emerged in late 2017 in the depths of the Paul Allen School of Computer Science at the University of Washington, it was very quickly adopted, or picked up, let's say, in our research community. And back in 2019 I had already written my first paper on it. What does it let you do?
Researchers from Washington asked themselves a very good question back in 2017. Say I'm a mobile user. I went to some website. On that website I was shown a banner ad. Then I went to a different site. But that ad started following me across all the other sites. So there's probably some kind of identifier that somehow lets all these external sites pass information about me and my location between them. And in their research they proved that not only users' location and their movements are under control. What's under control is collecting geolocation data about the whole population of users.
Establishing their gender, age, interests, income level, relatives. Establishing connections between users. That is, everything we used to associate with the results of serious analytics on telecom operator data. Today a machine does it all. And ADINT gradually started to take on a more or less definite shape. The first software products appeared, in Israel naturally, that let you use the advertising identifier to set up surveillance. Of course, the data there was enriched with various OSINT methods, and with plain old data leaks, to raise efficiency, to improve how much data gets collected and displayed from users about the target.
In fact, what goes into ADINT as input is even, and this is the key point, we're used to our attacker very often changing phones, changing email addresses, changing phone numbers. Given the position of the IT corporations, they'll ignore all that and keep linking our digital fingerprint, stitching our digital portrait, aiming to ensure that, despite us swapping out all our identifiers, emails, phones, mobile devices, they'll still link us together and give us a single digital advertising identifier. So here we understand, to some extent, that the IT corporations work in the interests of law enforcement, constantly stitching our portrait.
So even if a person has changed their phone, they still have the identifier. Through that identifier they can be found in Yandex, Google and other major IT corporations' systems, and surveillance can be set up. What does this give us? It gives us the ability to build a user's portrait: who they are, what they are, how old, what city they live in, what their interests are, marital status and so on. It gives us the ability to track and monitor their movements, to monitor and uncover their social connections and contacts. It gives us the ability to monitor people's presence at a certain time in a certain area, and this is genuinely frightening: if we open the Yandex Audience service and walk along the line of contact, we'll see how wonderfully both Yandex Audience and the marketing platforms of the mobile operators leak information about the number of devices located in a given area, the number of their actual users, broken down by gender, age and interests, and which cities they came from.
And that already exposes actual troop positions. This is used perfectly for guiding precision weapons, and the cases from the start of this year demonstrate how ADINT was used by Israel to guide weapons and attacks on, in particular, a girls' school. Today it's already being used to deliver spyware, thereby widening the attack vector against the device. So this whole marketing business, this whole uncontrolled data collection, on one hand opens up serious opportunities, and on the other hand creates substantial risks. And in conclusion, it's probably worth saying that it makes sense, at least for us in the Russian Federation, to take care of our own security, our own encryption, because if you compare the capabilities for obtaining and collecting data that our domestic services provide, with those provided by, say, some abstract Google, they're incomparable.
The point of entry is incomparable. You can use operators' marketing services, you can use Yandex Audience completely free of charge, after the simplest registration, or not registering in those services at all. Try doing the same in Google, where you have to take part in ad sales auctions, where you have to get special access to mobile app SDK data, where you have to put down a hefty deposit to get that data and work with it. So Yandex and our telecom operators would do well to take note too, kind and wonderful as they are; maybe it's not such a great idea to dump data like this into practically open access.
My colleagues and I have for several years now been building a free browser based on portable Opera that lets you carry out all sorts of investigations. In Telegram, website investigations, cryptocurrency investigations, 1000+ different OSINT sources in there. It's a browser based on Opera Portable, so it stores all its data inside itself. Inside it has neural networks, inside it has social accounts and messengers. All of it runs, if you like, straight off a flash drive, and stores info on all logs and connections there. Perhaps it'll be secure enough, private and useful in your work. So I'll be grateful for any feedback.
Yes, everyone's taken a photo, right. With that, I thank our esteemed organisers. Happy anniversary, success and prosperity. If anyone's interested, my card is on the screen. Thank you.
Q&A
Igor, thank you very much. Your questions, colleagues, by a raised hand. Yep, I see you, coming, coming, coming. You've climbed so far back.
— Igor Sergeyevich, very glad to see you. An excellent talk, as always. Thank you very much. You've been talking about ADINT for over a year now. Sometimes... And yet nothing changes. My questions are about exactly that. The mobile device used to be covered by technical information protection measures. The mobile device mostly passed through those. Now the mobile device is a full-fledged foreign technical intelligence instrument and falls under measures for countering foreign technical intelligence. In your view, is it necessary to give the mobile device a special legal status, so that we can more effectively carry out measures countering foreign technical intelligence?
So you're proposing we go back to the 2000s, when we got a permit from Gossvyaznadzor to buy a mobile phone?
— Some similar arrangement. Well, you understand it yourself. You've just shown in terms of technical intelligence that it works against us, exerts various economic influence, possibly collects information as a whole. Talking about Palantir and the others, everyone knows that perfectly well. About delivering payloads through advertising and targeted ads, malicious payloads, that is, by companies like Rayzone, Sherlock, Paragon, all of that is also already known.
So this is already a very serious threat in the present day. Especially under the conditions of the special military operation. Although mobile phones were banned, they're actively used on that territory. Palantir created the Maven project, a product for tracking. So it's already tipping over in the public information. That percolation point has already been passed. Is it necessary to create this special status for the mobile device?
Well, I'd agree, and that's probably exactly what all the regulators' actions are saying. Regulators all over the world. If I answer your question as a political scientist, I'd say we are living in the age of... There's the Renaissance, and we have the Age of Return. The Age of Return to the old industrial way of life, when states, state entities, held a monopoly on the means of information and informatisation.
So the most correct thing here, of course, is to create our own alternative software and hardware products out of reach of surveillance from outside.
— Colleagues, more questions. Right, hands over there... Ah, I see one, front row.
— Hello, thank you for the talk. Tell me, please, what are us mere mortals to do? Yes, to avoid ADINT, should we stop using Max, VK and Google? No, first of all, install Max. Absolutely. Naturally. First thing. And on your main phone, too. After that it's recommended, well, at least I ran the experiment myself. I tried to strip out as many Google services and automations as I could. But I'm on Android, I've never used Apple, not once, so I'm on Android, and I stripped out all the services, all the automation tools on my everyday phone. Well, there was a period when I had a really cheap, sluggish old phone, and I cleaned everything off it.
It started flying. That's one. The volume of traffic going through it dropped sharply. At the same time, most of the apps, maps and the rest I installed on it simply as downloaded software and downloaded content. Everything worked, it didn't need a constant network connection, especially relevant during the blocking period. Everything was fast, and the phone got quicker. Think about it. It's probably worth doing. If you're still tied to proprietary services from the big IT corporations, it makes sense to gradually start thinking about resetting those ad identifiers, limiting the ability to track you. Naive as it sounds, there's an option in the settings to limit the constant collection about you.
But that's very naive. And you trust those settings? No, of course I don't. Just like I don't trust Yandex when it says we don't collect this, don't analyze it, and we don't have it. When Yandex needs it, it's all there.
— Colleagues, time for one more question. Igor, tell me, you represent a non-commercial security service, there was something about that at the start? The Coordination Council of Non-State Security Structures. The oldest non-profit organization, an advisory body of NGOs in the security field. Doesn't it bother you that you take on law enforcement functions? That's one. Functions that aren't yours. Second. If you're doing, like our colleagues the day before, they said openly: we're a commercial outfit, we collect information about certain individuals, which we then pass on to police officers. So their status is highly questionable, to put it mildly.
And your status here also raises a lot of questions. Have you thought about it? Collecting personal data, there are draconian laws for the legitimate organizations that collect it. And you're collecting it illegally on top.
— Well, it's very debatable that I'm collecting illegally, because it's sitting in the open. Of course, automated processing of even quasi-personal data is questionable here. But on the other hand, answering the question as posed, which, rephrased, is basically "what the hell am I doing here", it goes like this: first of all, I do a great deal of academic work. I have academic papers that were written at the academies of the Investigative Committee, at the Interior Ministry Management Academy, including on topics related to ADINT. So I do practical work here and run research and R&D projects in this field. I work with specialized technical educational institutions, under dual subordination, both to the agency and to the Ministry of Digital Development, where we also produce academic work and teach students and police officers.
So a priori I have to be up to speed on what I'm teaching them. Second point. When reasoned requests come in from them, naturally, I can also apply the practice developed in the course of the academic work, and provide them with that kind of service. Do I do any of this on private commissions? I do. But what I do will always be tied to compliance with the requirements, first and foremost, of the personal data law. We don't violate it. I have almost no doubt about that. Second point. It will be based on the fact that our client has a case file under review, and within the scope of that case file a law enforcement body will approach us.
— Thank you. Colleagues, I see hands, but unfortunately, because of a slight slip in the schedule, there's no time for questions now. So, Igor, thank you very much. Let's send him off with a round of applause. But Igor is with us in the hall today. You'll have a chance to come up and talk with him privately.