Mikael Thalen
@mikaelthalen.bsky.social
3.6K followers 150 following 200 posts
Tech Reporter at Straight Arrow [email protected] [email protected]: mikaelthalen.12
Posts Media Videos Starter Packs
Pinned
mikaelthalen.bsky.social
EXCLUSIVE: A cell-site simulator, commonly referred to as an IMSI-catcher or "Stingray," may have been used at the ICE facility in Portland.

Analysis of cellular signals in the area showed phones receiving abnormal spikes in requests for their unique identifiers. san.com/cc/exclusive...
Exclusive: Fake cellphone tower likely surveilled protesters at Portland ICE facility
Law enforcement officials may have deployed a secretive cellphone surveillance technology last weekend at Portland’s ICE facility.
san.com
mikaelthalen.bsky.social
2G is and 3G are getting phased out and aren't used in much of the country already. Modern Stingrays don't need to downgrade to 2G to work anymore. They have attacks for 3G/4G/5G. But you should disable 2G regardless.
mikaelthalen.bsky.social
It does! I have a phone called a Cape Obscura that rotates all identifiers. Unfortunately it isn't available to the public. But they do have a publicly-available mobile service that will be introducing an IMSI-rotation feature in the near future. cape.co
Cape
Cape is premium wireless coverage with an added layer of personal security. Talk, text, and live with the confidence that you’re protected.
cape.co
Reposted by Mikael Thalen
clancyny.bsky.social
Mikael Thalen's video explainer is the best, simplest explanation that I've ever seen of how these somewhat obscure devices work. Well worth your 2 min. 24 secs.
mikaelthalen.bsky.social
EXCLUSIVE: A cell-site simulator, commonly referred to as an IMSI-catcher or "Stingray," may have been used at the ICE facility in Portland.

Analysis of cellular signals in the area showed phones receiving abnormal spikes in requests for their unique identifiers. san.com/cc/exclusive...
Exclusive: Fake cellphone tower likely surveilled protesters at Portland ICE facility
Law enforcement officials may have deployed a secretive cellphone surveillance technology last weekend at Portland’s ICE facility.
san.com
mikaelthalen.bsky.social
The thread tries to explain it. Let me know if you have any questions!
Reposted by Mikael Thalen
alexbaumhardt.bsky.social
“Although warrants are required to operate cell-site simulators, the devices can be used without judicial authorization in certain circumstances, such as when there is an immediate threat to national security.”
san.com/cc/exclusive...
Exclusive: Fake cellphone tower likely surveilled protesters at Portland ICE facility
Law enforcement officials may have deployed a secretive cellphone surveillance technology last weekend at Portland’s ICE facility.
san.com
mikaelthalen.bsky.social
But the abnormal spikes I saw--outside a federal facility, run by an agency which recently purchased and is known to use cell-site simulators, during a protest, weeks after ICE facilities were placed on high-alert--is important context.
mikaelthalen.bsky.social
I of course cannot definitively say that a cell-site simulator was used or who may have used it.

My analysis merely shows abnormal network behavior consistent with cell-site simulator use.
mikaelthalen.bsky.social
By contrast, outside the ICE facility, I witnessed three separate spikes of 18% in just a one hour window.

Interestingly, I walked 1,500 feet away from the facility and began to see those numbers drop to single digits.

Neither ICE nor DHS responded to inquires I sent regarding my findings.
mikaelthalen.bsky.social
Marlin's researchers conducted 400 hours of analysis across two continents to distinguish how often legitimate towers ask for an IMSI.

They found a median of less than 3%. Across multiple 24-hour long test scans, they rarely saw that percentage reach 10%, & the highest spike they ever saw was 14%.
mikaelthalen.bsky.social
An IMSI is a unique 15-digit code tied to your SIM card that networks use to identify you.

Because your IMSI can be used to track you, cell networks, once they obtain your IMSI, assign you a temporary IMSI, or TMSI, that rotates as you move from tower to tower.
mikaelthalen.bsky.social
I used an academic tool called Marlin last weekend to analyze cellular signals outside the ICE facility in Portland.

Marlin works by detecting the percentage of messages that ask phones at any given moment for their IMSI, or International Mobile Subscriber Identity.
mikaelthalen.bsky.social
EXCLUSIVE: A cell-site simulator, commonly referred to as an IMSI-catcher or "Stingray," may have been used at the ICE facility in Portland.

Analysis of cellular signals in the area showed phones receiving abnormal spikes in requests for their unique identifiers. san.com/cc/exclusive...
Exclusive: Fake cellphone tower likely surveilled protesters at Portland ICE facility
Law enforcement officials may have deployed a secretive cellphone surveillance technology last weekend at Portland’s ICE facility.
san.com
mikaelthalen.bsky.social
I met the OG frog guy in Portland last weekend. Wish I'd chatted more. He's become iconic haha
mikaelthalen.bsky.social
This is so rad. Killer report.
Reposted by Mikael Thalen
agreenberg.bsky.social
For the latest episode of Hacklab, we carried out one of the more fun and stressful hacking experiments of my career: We hacked a casino card shuffler to help me cheat in a game of poker against unsuspecting players in Vegas. www.youtube.com/watch?v=JQ20...
I Cheated At Poker By Hacking A Casino Card Shuffling Machine | Hacklab | WIRED
YouTube video by WIRED
www.youtube.com
Reposted by Mikael Thalen
Reposted by Mikael Thalen
josephcox.bsky.social
New: Apple banned an app that simply archived videos of ICE abuses. Rather than other apps that record ICE official's real-time location, Eyes Up is to "preserve evidence until it can be used in court." Videos from TikTok etc. Every submission manually reviewed

www.404media.co/apple-banned...
Apple Banned an App That Simply Archived Videos of ICE Abuses
Eyes Up's purpose is to "preserve evidence until it can be used in court." But it has been swept up in Apple's crackdown on ICE-spotting apps.
www.404media.co
mikaelthalen.bsky.social
I'm losing count of all the "we're clean on opsec" moments from the admin.
mikaelthalen.bsky.social
Once again clean on opsec.
Reposted by Mikael Thalen
davidho.bsky.social
“People over Papers, a crowdsourcing project that maps sightings of US immigration agents, was taken offline yesterday by Padlet, the collaborative bulletin board platform on which it was built. It’s just the latest ICE-tracking initiative to be pulled by tech platforms in the past few days.”
Another effort to track ICE raids was just taken offline
People over Papers was removed by Padlet, the platform it was built on, yesterday.
www.technologyreview.com