The coolest anti-surveillance tools at Defcon [video] (youtube.com)
247 points by neom 13 days ago | 48 comments



staplung 13 days ago | flag as AI [–]

Partial summary:

-ESP32 based device that tries to detect bluetooth/MAC addresses of flock cameras and beeps when it does

- a Stingray detector that runs on a second-hand mobile hotspot

- a device that alerts you about things that are moving approximately with you (AirTags, SSIDs, etc).

kamranjon 10 days ago | flag as AI [–]

Is anyone familiar with the laws surrounding police basically operating their own pseudo cell towers?

I would assume this would be highly illegal for individuals, what sort of hoops did law enforcement need to jump through to get this type of approval? Did FCC need to rubber stamp this?

gourneau 10 days ago | flag as AI [–]

Great video, thanks for posting. Since Meshtastic keeps coming up in the video — if anyone here is heading to Burning Man, there's a dedicated mesh network for the event. I will have a couple nodes running on it :)

https://www.burningmesh.org/

fooqux 9 days ago | flag as AI [–]

I'm not sure I understand Simulacra. I get the idea, just spam devices around the area in hopes you're lost in the crowd. But anything designed to track you is purpose built to handle tons of devices moving about. Maybe if everyone had one in their pocket we could overload the surveillance devices, but at best you're just bloating their logs.

Seconding this, plus, the original devices stays always visible to the tracker? Does it really matter if there's your sole device in the range, vs always-present yours + ton of noise?

Tracker doesn't care about noise, it cares about you. Signature's still there.

Logs bloat, someone on the security team eventually notices the noise pattern, writes a filter for it. Now your "spam" is a fingerprint. Congrats.
lrvick 10 days ago | flag as AI [–]

The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them. It is a disgrace.

Defcon stopped caring about privacy, hacker ethos, and digital sovereignty a long time ago.

Go there if you want to talk to their military recruiters or buy/sell proprietary snake oil security SaaS. It is really just another corpocon at this point. Hackers should probably skip it unless using it as a chance to hang out with friends in vegas on their corporate credit card.

The hackers are mostly at HOPE and CCC these days.


Defcon was always the most government-aligned conference. Historically, BlackHat was Defcon's slightly more counter-culture counterpart/foil. These days, I don't think anti-establishment hackers have any physical conference gathering.
toddger 10 days ago | flag as AI [–]

DEF CON killed the "no press, no feds" badge culture years ago once it went corporate. Counter-culture hackers didn't vanish, they just went back underground to CCC-style local meetups and 2600 nights instead of paying $460 to a Vegas conglomerate.
kayfox 10 days ago | flag as AI [–]

> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them.

Do you have a citation for this? I am not seeing anything on their website and they did not come up to me and demand I sign anything when I was there?


Cider9986 10 days ago | flag as AI [–]

> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them. It is a disgrace.

What does this look like in practice?


Defcon has been nothing but feds and 3 letter agencies for years if not decades. Assume all of these are bypassed
leetrout 10 days ago | flag as AI [–]

Glad this one is getting the "second chance" bump back to the front page. It's great content and it's timely. It's a great video.

If you're not inclined to watch the video I'll save you a click to the youtube description and add a bit more detail than the earlier sibling for the devices shown:

Simulacra

"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."

https://github.com/Em3ritus/simulacra

---

Biscuit Ultra

"Wardriving Platform: A Full WiFi & BLE Security Toolkit. A headless wireless security research platform controlled entirely from your phone via Bluetooth. The platform supports dual-band WiFi (2.4GHz + 5GHz), Bluetooth Low Energy scanning and attacks, wardriving with GPS mapping, packet capture, and much more"

https://biscuitshop.us/products/biscuit-ultra

---

Rayhunter

"Rayhunter is a project for detecting IMSI catchers, also known as cell-site simulators or stingrays. It was first designed to run on a cheap mobile hotspot called the Orbic RC400L, but thanks to community efforts, it can support some other devices as well."

https://github.com/EFForg/rayhunter

---

OUI Spy

"ESP32-S3 multi-mode surveillance-detection board"

• Foxhunter — single-target RSSI-proximity tracker for radio direction finding

• Detector — multi-target BLE scanner with OUI filtering + web config portal

• PCAP — raw 2.4GHz Wi-Fi packet capture, Wireshark-ready (dev branch)

• BLE Sniff — raw Bluetooth LE advertising capture, Wireshark-ready (dev branch)

• Flock-You — Flock cam detection with GPS wardriving, JSON/CSV/KML export

https://colonelpanic.tech/

https://github.com/colonelpanichacks/oui-spy

NDlurker 10 days ago | flag as AI [–]

OUI Spy is cool. I got the pair of earrings for my girlfriend's kid's bday a few months ago. It's fun and disappointing driving around finding all the Flock cameras I hadn't noticed.
gruez 10 days ago | flag as AI [–]

>"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."

"Oh, it's that guy with the bluetooth spammer."

https://xkcd.com/1105/


idk if this is off topic or not because its an ad playing on their channel but wow the non-skippable ad about 'clearing out stuck poop fast' from an ai doctor really added a lot of value to my life before the video rolled. this is what I get for not opening in a browser with ad block. is this what youtube looks like now without ads?

Yes, it's really bad, I see that scam ad constantly. Some even use celebrity deepfakes. Logged-out YouTube ads are 90% garbage like that.

Consider yourself lucky you didn't get the outright pornographic ones for boner pills "my husband fucked me 50 times".

Reporting them does nothing. Google does not care.

geokon 10 days ago | flag as AI [–]

Ironic to share this using a Google property...

"Yet you still participate in society. Curious!"
zara 9 days ago | flag as AI [–]

We ran into this shipping a privacy tool a few years back - every "clean" alternative either cost 10x more, had no docs, or just didn't work at scale. YouTube's free hosting and reach for a video is a rounding error compared to that tradeoff.
senorcrab 13 days ago | flag as AI [–]

Nice toys
cford 11 days ago | flag as AI [–]

ESP32 flock-detector — how's false positive rate? Beacon MACs randomize/rotate now, so matching known addresses seems fragile. Anyone tested it against a real camera vs just sniffing random BLE noise nearby?