[00:50.830 --> 00:51.390] Sunday. [00:52.170 --> 00:53.630] You made it to Sunday. [00:54.810 --> 00:56.410] Good program today, right? [00:56.670 --> 00:57.970] A lot of good stuff going on. [00:58.870 --> 00:59.630] Thank you. [01:00.050 --> 01:00.510] Thank you. [01:05.270 --> 01:06.510] You're still here. [01:06.730 --> 01:10.630] Sleep deprivation has set in pretty thoroughly at this point. [01:10.910 --> 01:14.930] Might be a little bit of a hangover experience for those staying off campus. [01:16.270 --> 01:18.110] Be careful with that. [01:18.830 --> 01:20.050] So welcome to Sunday. [01:20.210 --> 01:21.890] This is the third day of A New HOPE. [01:22.170 --> 01:24.890] We're going to have a closing ceremony at 6 p.m. [01:25.410 --> 01:30.750] And following the closing ceremony, we'll do a lot of thank yous and sort of a little summary of some of the stuff that happened. [01:31.350 --> 01:33.890] There's going to be a band starting right out here. [01:34.270 --> 01:35.010] Samba band. [01:35.210 --> 01:36.390] They're going to do a little processional. [01:36.610 --> 01:37.930] Maybe wind out out front. [01:38.090 --> 01:40.510] Have a little bit of a block party atmosphere. [01:40.730 --> 01:44.350] So if you're thinking of leaving early, think of sticking around until then. [01:44.350 --> 01:50.490] And after the closing ceremony and block party thing, or actually even during it, there'll be a lot of cleanup. [01:50.790 --> 01:52.090] A lot of volunteers are needed. [01:52.250 --> 01:56.130] We have some fairly heavy equipment that needs to be moved from a little theater up to our loading dock. [01:56.310 --> 01:57.430] Getting ready for the trucks. [01:57.510 --> 01:58.530] Taking down signs. [01:58.730 --> 01:59.510] Folding tables. [02:00.090 --> 02:00.770] Stuff like that. [02:00.930 --> 02:04.130] So please do consider sticking around for a little bit because we can really use that help. [02:04.130 --> 02:09.950] And as I think you've heard at this point, A New HOPE, the HOPE series of conferences, entirely volunteer driven. [02:10.170 --> 02:11.530] And we get a lot out of this. [02:11.730 --> 02:15.150] And if you've been volunteering, you know that you're getting a lot out of that experience. [02:15.170 --> 02:17.470] And if you haven't yet, you still have the opportunity. [02:17.750 --> 02:20.310] In fact, you have the opportunity going into tomorrow morning. [02:20.310 --> 02:22.350] Because we've got to load up all those big trucks. [02:22.350 --> 02:25.490] So if you have opportunity to help with that, that would be great. [02:25.710 --> 02:29.890] You've seen on the rotating screen, we have some good stuff going on in the fourth track. [02:29.930 --> 02:32.470] So if you're not sure what to do after this, take a look at the wiki. [02:32.650 --> 02:35.850] And see what's happening in the coffee house, as well as workshops. [02:36.170 --> 02:37.010] Other talks. [02:37.250 --> 02:38.150] Capture the flag. [02:38.410 --> 02:39.210] Talking to vendors. [02:39.650 --> 02:40.690] All kinds of great stuff. [02:40.970 --> 02:44.350] So without further ado, let's welcome Lucas. [02:44.530 --> 02:48.470] And we're going to hear all about conducting electronic warfare on a budget. [02:58.990 --> 03:04.410] Hi, and welcome to conducting electronic warfare on a budget of $15 or less. [03:04.930 --> 03:13.970] So you are constantly being irradiated by a plethora of gadgets and gizmos that are firing photons at you from every direction passing through your body. [03:14.430 --> 03:17.970] So today, we're going to try and figure out how to read those airwaves. [03:18.890 --> 03:26.970] I'm Lucas Rooyakkers, and I have a background in physics and have worked as a satellite engineer at a space Internet company, not Elon Musk's. [03:27.350 --> 03:34.490] And also come from a military background, and I'm going back to school to do more satellite stuff. [03:34.770 --> 03:43.290] So I've been informed that due to supply shortages as of late, some of the equipment I want, or that I demonstrate here, is no longer available at $15. [03:43.750 --> 03:47.390] And so this talk really ought to be $50 or so. [03:47.570 --> 03:47.890] Sorry. [03:48.810 --> 03:51.950] So this lesson will be broken down into three main parts. [03:52.210 --> 03:58.450] And by the end of this presentation, you will know what radios are and how they work, though this will be a review for many of you. [03:58.870 --> 04:03.150] You will know and understand the tenets of electronic warfare and their practical applications. [04:03.970 --> 04:09.350] So countermeasures against them, counter countermeasures against those countermeasures, and so on. [04:09.350 --> 04:13.690] This quickly becomes an unending game of cat and mouse, as you will see. [04:14.110 --> 04:25.070] You will also learn how to apply these principles to your everyday life to use software-defined radio platforms to listen to all of those radio waves that are constantly irradiating you. [04:25.710 --> 04:28.850] So, first off, what is a radio? [04:30.290 --> 04:32.230] So, uh, nice. [04:33.390 --> 04:38.170] Depicted on here, every photo on this page is radio, in fact. [04:38.430 --> 04:44.910] So, starting from the top left, we have walkie-talkies that use the family radio service band. [04:45.490 --> 04:48.110] Larger, there's a larger dish beside that. [04:49.390 --> 04:56.110] Underneath there, on the tower, are cell phone antennas, the long, white, rectangular ones that you see, that provides cell phone service. [04:56.890 --> 05:01.530] And correspondingly, inside of your phone, is the antenna that communicates with that cell phone tower. [05:01.850 --> 05:10.090] I've also included an old FM dial, a more military-looking radio, and a satellite, because they have radios too. [05:10.370 --> 05:18.750] At the bottom, there's a block diagram that shows you how, when a signal goes into the radio, how it's processed and turned into something intelligible. [05:19.710 --> 05:24.150] I've also included on this a magnet and a piece of copper wire. [05:24.770 --> 05:37.530] Now, the reason for this is, from Maxwell's equations in the laws of physics, we know that if you move a wire around, or, correction, if you move a magnet around, it will generate an EM current. [05:37.530 --> 05:44.050] So, if you jostle a magnet at a given frequency, you will be generating EM radiation and photons at that frequency. [05:44.050 --> 05:45.690] Just extremely low power. [05:46.450 --> 05:59.530] Similarly, if you have a piece of wire, and you're in a magnetic field, say, the magnetic field of the Earth that we experience, and start shaking that wire around, you will also induce a current in the wire and generate radio waves, no matter how small. [06:00.250 --> 06:02.130] So, everything on here is a radio. [06:02.410 --> 06:11.090] To sum that up, a radio is just a piece of wire with an oscillating current, or an alternating current going back and forth, jostling radio waves out of it. [06:11.090 --> 06:17.950] These can be analog or digital, and the two main antenna types that we need to concern ourselves with today are directed and undirected ones. [06:18.610 --> 06:28.990] Directed antennae points their field only at a particular angle, and have a farther reach, versus undirected or unidirectional antennae, spam it everywhere, but their range is lower. [06:29.590 --> 06:35.110] So, going over the radio spectrum briefly, here it is sorted by frequency, from high to low. [06:35.810 --> 06:45.170] The general characteristics you need to know is, a lower frequency means longer waves, which means more penetration through services, but less data throughput. [06:45.610 --> 06:54.790] And higher frequency means shorter radio waves, which means you can send a lot more data on them, but it has less penetration and range. [06:57.030 --> 07:04.510] So, my government divvies up the radio spectrum, according to this chart here. [07:04.510 --> 07:11.150] So, we've got, starting from very low frequencies at the top, going all the way up to very high frequencies at the bottom. [07:11.290 --> 07:14.070] This is the usages that are allocated there. [07:14.290 --> 07:16.590] I've decided to highlight some of those bands. [07:16.970 --> 07:22.430] So, in the low frequency in the HF range, there's the National Research Council time signal. [07:22.430 --> 07:39.250] So, this signal is sent out by government stations, to update the clocks of various autonomous and remote radio things, that need to have their clocks updated, because they don't have Internet connections or something. [07:40.090 --> 07:45.170] Also higher up here in the VHF range, is the FM radio band highlighted, fairly large. [07:45.450 --> 07:49.370] Going up in the FRS band, that's the family radio service. [07:49.370 --> 07:52.590] So, any walkie-talkie that you buy will be in this band. [07:53.230 --> 07:58.910] Going up, there's the old cellular one highlighted, as well as 2.4 and 5 gigahertz Wi-Fi. [07:59.750 --> 08:08.450] And at the top there, I've also highlighted the KU band, which is used in satellite communications, due to its extremely high data throughput. [08:09.610 --> 08:16.870] So, here is that spectrum broken again, showing you the frequency and the wavelength for the different spectrums. [08:16.870 --> 08:20.010] So, the frequency determines the wavelength. [08:20.430 --> 08:24.070] And this comes from the math equation, the physics equation you see on the board. [08:24.390 --> 08:30.130] Where the frequency times the wavelength of any given radio wave, must always be equal to the speed of light. [08:30.730 --> 08:33.410] So, the frequency fixes the wavelength. [08:33.770 --> 08:38.010] But the wavelength tells you how long of an antenna you'll need to receive that signal. [08:38.530 --> 08:42.130] So, the ideal antenna is usually the size of the wavelength. [08:42.130 --> 08:47.990] But barring that, you want it to be half the size or a quarter the size and so on. [08:48.890 --> 08:51.390] So this isn't just a physics equation. [08:51.570 --> 09:04.950] It's actually practical for soldiers in the field who are often deployed on an operation given several mission-specific frequencies at the beginning and one general-purpose antenna that works broadly for a wide range of frequencies. [09:04.950 --> 09:13.230] However, in the field, oftentimes those don't work so well and you need to create your own antenna in order to receive the signal better. [09:13.450 --> 09:26.130] So then that process requires literally just cutting coax cable, rearranging the equation from the previous page and figuring out what antenna you need strapping in a tree, referred to as field expedient antennae. [09:26.870 --> 09:28.730] So that covers what is a radio. [09:29.010 --> 09:32.670] Now we'll move on to electronic warfare, part two. [09:32.670 --> 09:37.730] Note, this picture is not an accurate depiction of modern electronic warfare. [09:39.390 --> 09:46.370] So, the tenets of EW invert the traditional CIA triad of information security. [09:46.650 --> 09:56.270] So instead of maintaining the confidentiality, integrity, availability of messages, we instead seek to deny service, exploit, and employ deception against our adversaries. [09:56.270 --> 10:03.310] So, the doctrine of electronic warfare can be broken down into three primary branches. [10:03.650 --> 10:11.770] Electronic protection, which we'll start with, focuses on things like encryption and protecting your forces from enemy EW capabilities. [10:11.770 --> 10:22.390] EW attack seeks to disrupt and deny the usage of the electromagnetic spectrum by adversarial forces using jamming or directed energy weapons and the like. [10:22.830 --> 10:34.530] EW support is a far more intelligence-based focus, where you try and gather everything that you can, every bit of info that you can, based on all of the enemy radio traffic that you can pick up. [10:35.370 --> 10:36.770] So, why is this important? [10:36.990 --> 10:38.810] Because communication matters. [10:39.190 --> 10:44.790] If a battlefield commander cannot communicate with their troops, they have a series of functionally independent armies. [10:45.090 --> 10:56.390] If subordinate units cannot communicate with their superiors, then they are unable to see the larger picture, which can result in drops of morale and inability to act as a cohesive and coordinated organization. [10:56.390 --> 11:01.850] Throughout history, many a battle has been lost as a direct result of severed communication lines. [11:02.430 --> 11:07.710] And the modern battlefield is chock-full of communication systems to exploit. [11:08.130 --> 11:18.110] So, for the rest of this talk, we'll be starting to focus on the measures and countermeasures and counter-countermeasures, starting with two basic questions. [11:18.410 --> 11:23.430] How can we listen to other people's conversations, and how can we stop them from doing that to us? [11:24.650 --> 11:30.570] To start off, the first thing you want to do is encrypt your traffic so that they can't hear it. [11:30.910 --> 11:36.990] This works much the same as cryptography does in other information security systems that you've seen. [11:37.850 --> 11:44.450] But as a historical side note, I would like to bring up the first form of radio encryption that was employed. [11:45.730 --> 11:47.230] So, scrambling the airwaves. [11:47.330 --> 11:48.450] You may have heard of this before. [11:48.450 --> 11:57.110] In this picture, the human voice spectrum, so this is audio waves, not radio waves, goes from 300 hertz to 3 kilohertz. [11:57.710 --> 12:06.730] And in order to hide the traffic from people who had regular radios, what they would do is just invert the powers of all of the different frequencies. [12:06.730 --> 12:11.490] So, if you had a signal that looked like this, you just literally flip them around a middle axis. [12:12.930 --> 12:17.650] This sounds like demonic hissing if you are listening to it on a normal radio. [12:17.950 --> 12:26.250] However, this is, of course, insecure as you only need to know three or so parameters in order to undo most types of voice inversion. [12:26.250 --> 12:35.510] So, modern radio encryption works by generally distributing keys at a facility beforehand on all of the radios. [12:36.070 --> 12:42.070] And then they can be sent out into the field and crypto material can be updated over the air afterwards. [12:43.650 --> 12:45.510] So, now we've done it. [12:45.770 --> 12:51.850] We've encrypted our traffic and we can freely and openly communicate securely without anyone else hearing us. [12:53.610 --> 12:57.230] But, now we're going to get to our first electronic attack method. [12:57.650 --> 12:58.810] So, jamming. [12:58.990 --> 13:04.410] This is equivalent to screaming at people who are trying to have a conversation so they can't hear you. [13:05.370 --> 13:15.290] So, on the left here, we can see an unjammed signal which has a nice beautiful waveform with all kinds of crisp and rich substructure. [13:15.510 --> 13:17.190] And just visible peaks. [13:17.410 --> 13:20.870] And on the left, we have that same signal but being jammed. [13:20.870 --> 13:23.550] So, there's a lot to learn from these two diagrams. [13:23.750 --> 13:27.230] The first being that jamming can only occur at a particular frequency. [13:27.610 --> 13:33.290] You must know the frequency that you want to jam and that your adversary is likely to use in order for this to work. [13:33.610 --> 13:37.790] You can't just broadly dump energy... you can't broadly dump energy all throughout the spectrum. [13:38.030 --> 13:39.090] It won't work so well. [13:39.750 --> 13:45.450] And also, so as a result of that, the noise floors on the sides of these graphs go back down to zero. [13:47.370 --> 13:53.510] So, here's another analogy I love to describe jamming and why just dumping energy works. [13:53.730 --> 13:58.370] It's kind of like driving home on your commute if you drive home towards the sunset. [13:58.690 --> 14:02.390] It's very hard to see when you're driving towards the sun like that and there's lots of glare. [14:02.390 --> 14:10.050] And this might not make sense at first because you might think, oh, but if you're adding more light to the situation, shouldn't you be able to see more better? [14:10.290 --> 14:17.750] But all of that light blocks it out as noise effectively and the glare prevents you from seeing even though things are more illuminated. [14:18.370 --> 14:24.790] I like this analogy because from a physics perspective, it's completely indistinguishable from actual radio jamming. [14:24.950 --> 14:32.510] Given that your eyes are radio antennae that pick up only frequencies in a certain band that we refer to as the visible range. [14:34.370 --> 14:35.730] So, broad jamming. [14:35.950 --> 14:40.830] So, you have to do a bit of research beforehand of knowing your enemy frequencies in order to employ in jamming. [14:41.710 --> 14:49.830] But you probably just don't want to jam the radio network as a whole because then the adversary will simply change frequencies and you have to keep doing that. [14:50.810 --> 14:55.430] Then that also alerts them to the presence of EW attack in the region. [14:55.910 --> 15:03.070] So, a more effective method is to use directional jamming to only break certain key links if you can figure out what those are. [15:03.070 --> 15:14.770] So, this basically will just look more like an individual's radio broke rather than them being alerted that the entire spectrum is being jammed. [15:14.930 --> 15:18.890] And can be turned on during critical times to your advantage. [15:20.130 --> 15:23.670] So, we've encrypted our comms so now no one can read them. [15:23.870 --> 15:27.350] And now we can also selectively jam our enemies to our advantage. [15:27.730 --> 15:30.650] But unfortunately, they can jam us. [15:32.570 --> 15:34.230] So, how do we deal with that? [15:34.670 --> 15:35.730] Direction-finding antenna. [15:36.050 --> 15:40.130] If we can... when someone... like I said, this is like screaming over people's conversations. [15:40.430 --> 15:44.190] So, if you can just hear where that's coming from, you can send a missile that way. [15:44.390 --> 15:45.550] And now the jamming is dealt with. [15:46.470 --> 15:49.010] So, this is done with direction-finding antenna. [15:50.210 --> 15:53.050] Using one direction-finding antenna, you can find what direction they are. [15:53.170 --> 15:55.830] With two or more, you can start to triangulate them as in this photo. [15:57.730 --> 16:00.330] And here's a brief overview of how these antennae work. [16:00.330 --> 16:04.030] Because a regular piece of wire has no idea where the signal is coming from. [16:04.210 --> 16:07.750] It can only determine the relative strength given how directed it is. [16:08.370 --> 16:13.430] So, directional antennae will generally have a series of antennae in a circle that are directed. [16:13.670 --> 16:16.930] And just calculate the relative signal strength based on that. [16:17.490 --> 16:19.930] So, giving you the direction of transmission. [16:20.350 --> 16:23.650] So, now we can talk with encrypted comms and they can't understand us. [16:23.650 --> 16:25.710] We can jam them and they can jam us. [16:25.870 --> 16:28.330] But if they do jam us, we can find out where they are. [16:28.930 --> 16:33.950] How do we prevent the adversaries from finding out where we are? [16:35.710 --> 16:39.890] Well, don't stay on the same frequency and change it hundreds of times per second. [16:39.890 --> 16:47.370] So, this works against a variety of attacks including jamming, detection generally, and direction finding. [16:47.670 --> 16:56.570] How this works is pre-shared keys are distributed on the radios that are plugged into a stifer that just generates the list of frequencies that you want. [16:56.690 --> 16:59.610] And there's some time synchronization stuff I don't fully understand. [16:59.610 --> 17:08.130] This is used also in civilian applications lots and things like CDMA or Code Division Multiplex Accessing. [17:08.270 --> 17:16.010] Long acronym, but it is used in Bluetooth to help your Bluetooth devices alternate which frequencies they are using and lower interference with that. [17:16.890 --> 17:19.070] So, why does this work so well? [17:19.390 --> 17:24.250] One principle is that a radio can only ever be tuned to a single frequency at a time. [17:24.250 --> 17:32.170] So, if you're searching for enemy frequencies, then you will generally sweep starting from high to low, tuning your radio up and trying to catch bits. [17:32.370 --> 17:39.650] But if you're sweeping in a pattern like this and they're dotting around everywhere, the odds that you'll intercept any traffic become increasingly low. [17:39.890 --> 17:42.390] And even if they do, it's encrypted, so that's good. [17:43.270 --> 17:50.510] So, we've encrypted our comms, we can jam them, direction find the enemies, and we're now frequency hopping to hide our own signal. [17:50.510 --> 17:54.530] But let's suppose that the adversaries are also doing the same. [17:55.210 --> 18:00.750] What analysis can be done on those tiny bits of encrypted radio traffic that we do catch? [18:02.730 --> 18:03.690] All kinds. [18:04.110 --> 18:11.890] One hot area of research focuses on the rising edge curves of the radios. [18:12.070 --> 18:16.790] So, when a radio starts up, that process is depicted in this diagram here. [18:16.790 --> 18:27.050] On the left, the RF level is at the noise floor, and as the oscillator turns on, we have this rising edge curve before reaching the reference level, sending its signal, and then turning off. [18:27.530 --> 18:35.170] When the oscillator starts turning on, there are all kinds of features of this curve that are very unique to the individual transmitter. [18:35.170 --> 18:43.190] And putting this into things like machine learning and doing other analysis can allow you to uniquely identify transmitters. [18:43.330 --> 18:50.650] So, you can figure out, is this one guy driving around generating the traffic of a convoy, or is this a bunch of unique radio units? [18:51.130 --> 18:57.130] This process essentially measures the engineering tolerances on the manufacturing process of the radio. [18:57.130 --> 19:05.050] Because you can often, just with radios that are produced on the same manufacturing line, you can uniquely identify which transmitter is which. [19:05.510 --> 19:07.710] So, there is still quite a bit of information. [19:07.710 --> 19:13.530] Even if you can't get the content of the message, you can at least figure out things like who's transmitting and where are they moving. [19:14.730 --> 19:18.070] So, let's say we want to prevent this from happening at all. [19:18.230 --> 19:23.170] How can we prevent the enemy from even getting these tiny little blips of our encrypted traffic? [19:23.170 --> 19:26.910] Well, the answer is to simply wish upon a shooting star. [19:27.430 --> 19:27.750] Really. [19:28.790 --> 19:45.570] So, meteor burst comms, probably one of my favorite esoteric radio communication methods, involves waiting for a meteor to come streaming down through the atmosphere, heating up and leaving in its wake a large pile of ions, leaving the atmosphere electrically charged in that region. [19:46.150 --> 20:02.250] So, radio signals from someone who's just waiting for shooting stars to fall can be bounced off of this layer, at which point the signal goes up from transmitter to the meteor to the receiver, and very low chance of interception in between. [20:02.790 --> 20:14.690] This is primarily used by remote science stations, where they're just sending back info autonomously, or by operators who are working in places they really don't want to transmit. [20:15.350 --> 20:20.850] For as many of you may know, this principle can be generalized to give us HF radio. [20:20.850 --> 20:34.330] So, the sun streaming down all of its energy onto our planet rips at a certain layer in the atmosphere all of the electrons off of their creating ions in what we call the ionosphere. [20:34.630 --> 20:42.670] This changes its characteristics and shape throughout the day, depending on how hot the sun is and different things about solar weather. [20:42.670 --> 20:57.530] But the basic principle is that you can, if you know your frequency and where you're trying to reach, you can bounce a signal right off of the ionosphere, and it'll go back down and reflect around the Earth several times generally, allowing for worldwide communications via radio. [20:58.850 --> 21:02.210] The problem with this include skip zones, as depicted here. [21:02.390 --> 21:08.050] So, when the signal's going up and bouncing down, there will be skip zones where it's not easy to pick up. [21:08.050 --> 21:17.650] This makes HF communications quite tricky, and I always found it to be a bit of a black magic from my perspective to get all of this stuff right. [21:18.630 --> 21:23.370] But the principle of HF radio can also be applied to radar. [21:23.370 --> 21:33.350] So, instead of, for communications, you send a signal which bounces off of the ionosphere and over the horizon, and when it comes back, you measure the difference. [21:33.570 --> 21:42.670] And if you're doing this for long enough, you can see that aircraft, the aircraft will create particular shadows in these images, allowing you to detect. [21:42.870 --> 21:48.970] This is how certain NORAD systems and stuff work to detect planes over the horizon. [21:48.970 --> 21:58.610] This particular photo is of the Duga radio installation for over the horizon radar in Russia, close to Chernobyl. [21:58.810 --> 22:01.810] I included two photos of it because it looks really fun to climb. [22:02.910 --> 22:06.810] So, why haven't I brought up SATCOMs yet? [22:07.190 --> 22:16.510] Because satellites can, of course, pass overhead directly every 50 minutes and give you high bandwidth and transmission and can discreetly get data around. [22:16.510 --> 22:23.850] Plus, the military created GPS and employs satellites all throughout its operations for communication purposes. [22:24.330 --> 22:31.550] However, there are lots of reasons that a military would want to maintain their high-frequency radio capabilities. [22:31.930 --> 22:34.510] And one of them is Kessler syndrome. [22:35.310 --> 22:40.290] The rundown, if one tiny screw hits a satellite, it explodes into 50 pieces. [22:40.510 --> 22:44.990] Those 50 pieces hit another 50 satellites, which explode into 50 more pieces each. [22:44.990 --> 22:52.350] The end result is that the exosphere becomes a spinning maelstrom of space junk that entombs us in a casket of jagged metal for decades. [22:53.270 --> 22:57.090] And this photo here is provided by the European Space Agency. [22:57.310 --> 23:03.050] And this shows every single piece of space junk that they are tracking that is greater than one millimeter in size. [23:03.710 --> 23:07.790] So, there are reasons that you would want to maintain capabilities other than SATCOMs. [23:07.790 --> 23:19.350] Now, going into more esoteric communications methods, bringing up extremely low-frequency communications, which are often used to talk to submarines. [23:19.910 --> 23:23.510] So, I've included a little clip of that chart from the first page. [23:23.630 --> 23:32.810] So, if you look, that VLF, very low-frequency, and ELF, extremely low-frequency, have very, very long antennae. [23:32.810 --> 23:37.130] So, setting up the antennae on the ground is fairly easy. [23:37.310 --> 23:42.330] You just string a wire that's multiple kilometers long and pump an ungodly amount of power into it. [23:42.770 --> 23:51.010] Now, on the receiving end, the submarines, what they do is trail a cable behind them with a buoy that you can see depicted there. [23:51.010 --> 23:55.310] And then, that generally is designed so that it isn't picked up by sonar. [23:55.810 --> 24:04.830] And since the submarines themselves can't transmit well, that is basically used as a signal for, hey, come up to an area where we can talk to you better. [24:05.490 --> 24:12.250] These, of course, being low-frequency, have an extraordinarily low data rate, often measured in BAUD. [24:13.170 --> 24:19.550] One bonus method for encrypted, for discrete radio communications is number stations. [24:20.090 --> 24:30.810] So, numbers, this is when a governmental organization will set up a radio tower that is audible, and you can pick up the signal from other countries and other places. [24:31.070 --> 24:38.830] And the only thing being broadcast is usually someone reading numbers, very creepily in a voice, 24-7 for hours. [24:38.830 --> 24:42.010] And these numbers are random, mostly, maybe. [24:43.290 --> 24:53.730] But in the host country, the clandestine operatives will be given a codebook and told, start listening to the radio at these times, 10 a.m. [24:53.830 --> 24:54.550] on Tuesday mornings. [24:54.730 --> 25:01.010] Start just writing down the numbers, and then look that up in your codebook, and they would distribute messages that way before the Internet. [25:01.970 --> 25:04.010] So, that brings us to the end of part two. [25:04.170 --> 25:07.570] And for part three, we will start talking about software-defined radio. [25:07.570 --> 25:08.950] Here are a bunch of them. [25:09.150 --> 25:11.990] I know many of you in the audience have these toys at home. [25:13.030 --> 25:20.730] But these are commercially available ones, and the one in the bottom right is a few thousand times more expensive, but still in SDR. [25:21.690 --> 25:23.090] What is a software-defined radio? [25:23.810 --> 25:29.010] It differs from a regular radio, as a regular radio has custom-built circuitry for its task. [25:29.170 --> 25:32.410] An FM radio will have the FM modulator built in the circuitry. [25:32.410 --> 25:40.250] However, an SDR will just receive the signal, and you write a computer program that allows you to simulate all of that circuitry. [25:40.430 --> 25:46.410] So, although it's more inefficient from an energy perspective, the reprogrammability is very useful. [25:46.950 --> 25:51.030] On the left is just that radio block diagram from the first page, showing you... [25:51.030 --> 25:52.750] I think that's an FM modulator. [25:53.010 --> 26:05.230] And then on the right is a GNU radio block diagram, where GNU radio is a program that allows you to essentially build these RF circuits by putting all of the blocks together as software. [26:06.530 --> 26:08.850] The SDR, I'm going to recommend. [26:09.010 --> 26:12.770] I've heard that the prices have changed recently due to supply chain shortage and other corona issues. [26:13.690 --> 26:23.090] This is a software-defined radio that's extremely cheap, extremely accessible, and has such a good range of frequencies out of the start. [26:23.710 --> 26:26.790] 500 kilohertz, just can't quite get to Wi-Fi. [26:27.030 --> 26:30.790] But you can go even lower or higher if you have an up-or-down converter. [26:30.790 --> 26:32.990] Another popular one is the Ham-It-Up. [26:33.930 --> 26:46.730] This was made by a TV tuner, and I'm fairly certain that the guys just bought the factory where this TV tuner was being made, and then altered the design until... and then just, yeah, started just producing there, just bought the factory. [26:47.450 --> 26:54.250] So this is great, because this is, like, really the first entry in, like, the actual real budget software-defined radio world. [26:54.410 --> 26:56.770] Because before this, you would have had to spend thousands of dollars... [26:56.770 --> 27:01.410] or you would have had to get your employer to spend thousands of dollars on a USRP that you can maybe take home sometimes. [27:02.570 --> 27:05.250] So there are many, many things that are within that. [27:05.490 --> 27:06.970] Even though it's banned, it's fairly limited. [27:07.130 --> 27:09.310] There's all kinds of stuff that you can listen to. [27:09.510 --> 27:11.170] This is a very plug-and-play thing. [27:11.350 --> 27:11.910] You can... [27:11.910 --> 27:15.810] Once you get all the installing and drivers done, you can just start listening to signals. [27:16.310 --> 27:22.310] So, going over some of those, airplanes have a lot of antennae on them, too. [27:23.310 --> 27:27.750] The Boeing 747 has over 40 antennae on it. [27:27.870 --> 27:31.690] Not all of them are listed on here, because there are some duplicates and other ones. [27:32.850 --> 27:35.730] So, what signals can we pick up from an airplane? [27:37.170 --> 27:38.770] ADS and B is the first one. [27:38.870 --> 27:41.470] This stands for the Automatic Dependent Surveillance Broadcast. [27:41.470 --> 27:45.890] It is broadcast at 1090 megahertz, and this gives you the GPS coordinates of planes. [27:46.350 --> 27:50.350] Just so that they don't crash into each other, and the air traffic controllers know what's going on. [27:50.870 --> 27:55.270] But, fortunately, with all this data, if you live close enough to an airport, you can just plot it into a map. [27:55.410 --> 27:58.670] There exists many, myriad programs to do so. [27:58.810 --> 28:10.950] And one of my favorite websites and community radio projects for this is the Dictator Tractor, where they just track the ADSB info of known planes of dictators to just find out what they're up to in the world. [28:11.910 --> 28:17.610] Also from planes are pilot text messages, also referred to as the Aircraft Communication Addressing and Reporting System. [28:17.990 --> 28:25.570] This is mostly routine, boring stuff, but there's all kinds of interesting special requests that you can hear. [28:25.670 --> 28:32.490] For example, special requests from particularly pernicious celebrities onboard an airplane, and other local drama unfolding at the terminal. [28:33.490 --> 28:39.270] Here are some ACARS demodulator programs that you can just get the output from. [28:39.950 --> 28:43.430] AIS works like ADS and B, but is for boats. [28:43.670 --> 28:51.430] So all boats over a certain size require the automatic identification system tags, even if they don't actually have them. [28:51.610 --> 28:55.850] This allows you to map out fishing fleets and the like on maps very similar to the planes. [28:57.390 --> 29:01.350] Pager messages are very fun, very diverse in what you'll see. [29:01.350 --> 29:08.290] The protocols here are the old classic one is called POCSAG, but there's other protocols like flex and tap. [29:09.070 --> 29:18.670] This you'll get all kinds of alarms from automated security systems, fire alarms for volunteer firefighters, pager messages for doctors and other medical staff, etc. [29:18.670 --> 29:22.330] There is a wide variety of things that still use pagers. [29:22.630 --> 29:23.090] It's very wonderful. [29:24.250 --> 29:29.870] If none of this stuff on Earth is your thing, you can also use this $15 SDR to do radio astronomy. [29:30.410 --> 29:39.970] Although it did require the building for the creator of this, they had to build that horde antenna that you see on the left in order to listen to the astronomy stuff. [29:39.970 --> 29:47.290] They were able to, with the $15 SDR, pick up the 21 centimeter hydrogen line from the center of the Milky Way galaxy with them. [29:48.150 --> 29:53.650] So, if space isn't your thing, and hacking is, you can also turn it into an IMSI catcher. [29:54.110 --> 30:02.610] Which, as many of you are familiar with, is the device that stimulates the cell phone tower, man in the middle, essentially, to read your text messages. [30:03.690 --> 30:12.090] If you download this GitHub repo that's linked here, this will allow you to track the cell phones in your area and see who's coming and going and when and where. [30:12.590 --> 30:18.850] However, in order to decrypt text messages such as your own, you do have to extract the key from your phone and put it into the program. [30:19.090 --> 30:20.190] It's a bit of a hassle. [30:21.050 --> 30:26.650] So, moving away from traditional hacking to more government-y concerns. [30:27.450 --> 30:34.910] TEMPEST is an acronym that stands for Telecommunications and Electronic Materials Protected from Emanating Spurious Transmissions. [30:34.910 --> 30:45.370] What this is saying is, as I mentioned before, a magnet moving or a wire moving, relative to a magnetic field, is a radio and will generate a current. [30:45.550 --> 30:50.310] So, all of the wires coming out in and out of your computer, all of the... [30:50.310 --> 30:55.670] Even your monitor oscillating at 60 Hz or 120 Hz refresh rate, is also a radio. [30:56.190 --> 31:04.170] So, a good hacking question is, what can be learned from someone's computer by just putting a radio next to it? [31:04.170 --> 31:05.950] The answer is a lot. [31:06.530 --> 31:23.370] As Tempest is also the name of this person's GitHub repo, where they show these principles with the RTL-SDR here, hooked up to that monitor with the checker backgrounds, and then the antenna in the long on the back there behind it. [31:23.370 --> 31:32.550] On the left screen is the signal, the reconstructed monitor output from the SDR's received signal. [31:32.790 --> 31:38.990] So, as you can see, you can now, with an SDR, find out what someone's monitor is saying. [31:39.170 --> 31:44.590] And also kind of scary, given that essentially your monitor is also radiating what you see on the screen behind it. [31:46.110 --> 31:48.210] So, you can also do badge reading. [31:48.450 --> 31:51.510] This example was taken by... from an Edis research. [31:52.810 --> 31:57.350] This one, you'll need a USRP or something more expensive in order to do. [31:57.590 --> 32:03.510] But you can read badges and potentially play them back and intercept badge keys. [32:04.490 --> 32:07.930] But in order to do that, in order to do playback, we have to transmit. [32:07.930 --> 32:10.870] And this is where it gets expensive. [32:11.250 --> 32:19.530] So, even for... the RTL-SDR is great because the next higher options start to just go up in price, although they do have transmit capabilities. [32:20.390 --> 32:30.350] So, instead of pointing you towards those, which I'm sure that anyone interested in SDRs can research in the run time, I will instead show you the cheap way. [32:31.050 --> 32:41.870] This is another GitHub repo called Raspberry Pi TX that allows you to use the GPIO pin to send signals from 5 kHz to 1.5 GHz. [32:42.270 --> 32:58.830] However, this is extremely not a good idea to necessarily do without a bandpass filter and other precautions to make sure that you're not transmitting illegally, as it does spread a lot of energy all over the spectrum, despite its short range. [32:59.070 --> 33:05.610] There are lots of fun applications for this, including sending images over the spectrogram, as in the picture on the right there. [33:06.150 --> 33:13.650] And, personally, I use it for... my nephews just like taking over the FM radio to say stuff to their parents whenever I go home. [33:14.190 --> 33:18.930] So, the SDR software you can use, there is a plethora of that. [33:19.190 --> 33:23.250] I've included just one screenshot of one that I like called Cubic SDR. [33:24.150 --> 33:26.190] And they all basically look like this. [33:26.570 --> 33:28.990] Different combinations of waterfall diagrams. [33:29.350 --> 33:32.090] And they all often have different built-in demodulators. [33:32.270 --> 33:34.970] And they allow you to just start exploring the spectrum. [33:35.150 --> 33:40.950] It's great to just download all of these and any of them, and just start seeing what signals you can find. [33:41.590 --> 33:46.590] Also, another good mention is the Universal Radio Hacker Resource. [33:46.590 --> 33:50.090] So, that is an application that launched recently that allows you to... [33:50.090 --> 33:58.510] If you don't know the protocol of a message, you can start to figure it out and decode the protocol and write your own disector for it, essentially. [33:59.230 --> 34:04.750] So, that... these... all of the other programs are generally just more... [34:04.750 --> 34:06.530] just straight receiving programs. [34:07.110 --> 34:08.830] So, any questions? [34:24.790 --> 34:26.570] There's a nice microphone back there. [34:26.770 --> 34:27.450] Good lighting too. [34:30.760 --> 34:31.680] No questions? [34:31.960 --> 34:32.740] Explained everything good. [34:32.880 --> 34:33.050] Nice. [34:44.680 --> 34:46.500] Not that I would ever do this. [34:46.640 --> 34:56.860] But, is there a way to hear what's happening on an encrypted digital P25 system? [34:58.160 --> 34:59.620] Not that you would know that. [35:01.220 --> 35:02.160] Sorry, P25. [35:02.520 --> 35:04.440] I forget which protocol. [35:04.580 --> 35:05.420] I know I've seen that before. [35:05.560 --> 35:08.480] Is that related to DMR or no? [35:08.960 --> 35:10.140] Yeah, yeah. [35:11.040 --> 35:12.260] That's like a Motorola one? [35:12.680 --> 35:15.220] Yeah, unfortunately I don't have enough knowledge about that specifically. [35:15.800 --> 35:16.120] Thank you. [35:19.160 --> 35:27.380] I just want to say that there's another SDR called HackRF and there's a standalone, like a unit that makes it standalone called the Portapack. [35:27.540 --> 35:31.200] And apparently a bunch of Chinese knockoffs came out and they're really cheap. [35:31.440 --> 35:32.920] They come with everything together. [35:33.140 --> 35:35.060] Like you can buy on like AliExpress or something. [35:35.360 --> 35:38.280] So if somebody wants to mess with like... and that transmits as well. [35:38.520 --> 35:39.520] But it's Simplex. [35:39.720 --> 35:42.060] So it's... you can't transmit and receive simultaneously. [35:44.460 --> 35:45.220] Well, yes. [35:45.860 --> 35:47.320] Excellent suggestion, please. [35:47.540 --> 35:49.080] Sorry, what was the name of it again? [35:49.240 --> 35:51.020] You said it's a new HackRF. [35:51.260 --> 35:52.840] HackRF, but don't look for HackRF. [35:52.920 --> 35:53.840] Look for Portapack. [35:54.120 --> 35:55.740] P-O-R-T-A. [35:56.140 --> 35:56.560] Pack. [35:56.840 --> 35:58.000] P-A-C-K is one word. [35:58.800 --> 36:10.800] And the ones on like AliExpress, if it says that it comes already in the case, that means it must already come with the HackRF SDR and usually with batteries already pre-built. [36:11.040 --> 36:16.080] And it's insanely cheap considering that individually it will cost around 500 bucks. [36:16.260 --> 36:20.900] But online is the cheap Chinese knockoffs, which it's an open source design. [36:20.900 --> 36:22.960] So it's virtually the same. [36:23.240 --> 36:26.820] It's like it's under 200 bucks, which is insanely like... [36:26.840 --> 36:27.520] a lower price. [36:27.840 --> 36:31.120] So this is what I love, is that this world just keeps getting better and better. [36:31.380 --> 36:35.300] Before, doing this hobby would have been extremely expensive, for example, 30 years ago. [36:35.400 --> 36:38.300] But as time goes on, we keep getting cheaper and cheaper and more fun toys. [36:38.940 --> 36:39.220] Sorry. [36:40.080 --> 36:40.520] Yeah. [36:40.680 --> 36:42.060] Are you familiar with the Flipper Zero? [36:42.500 --> 36:43.880] And if so, what's your take on it? [36:44.000 --> 36:44.100] Yeah. [36:44.320 --> 36:44.620] Yes. [36:44.620 --> 36:48.260] I've seen people running around with those in the hardware workshop. [36:48.900 --> 36:50.620] There'll be tons of radio stuff there. [36:51.120 --> 36:51.460] Yeah. [36:51.560 --> 36:57.580] Lots of the radios I showed on this presentation, people have these set up if you guys go to the hardware area. [36:57.720 --> 36:59.580] And I'm sure they'll be very happy to show you. [37:00.480 --> 37:00.920] Hi. [37:00.920 --> 37:02.380] I like silly stories. [37:02.380 --> 37:08.280] So I was curious, what is the weirdest or most unexpected thing you found that you are comfortable telling us about? [37:08.940 --> 37:09.300] Pardon? [37:11.520 --> 37:11.880] Found? [37:12.200 --> 37:12.280] Sorry? [37:12.620 --> 37:15.220] Like, listened to or heard or discovered? [37:16.140 --> 37:19.640] Honestly, just doing... setting up HF is just awesome. [37:19.780 --> 37:22.200] Like, when you're trying to set up that and, like, communicate with someone. [37:22.540 --> 37:24.220] Because then you, like, wind up hearing... [37:24.220 --> 37:28.540] Well, like, I always wondered, how come HF is sort of, like, hard for the military, it seems? [37:28.600 --> 37:29.840] But then all the ham people have it easy. [37:30.020 --> 37:30.100] Cool. [37:30.160 --> 37:33.960] Because I think, like, they're just, like, largely talking to, like, kind of anyone they can. [37:33.960 --> 37:38.100] So, like, when you pick up all of those stray signals, like, Singaporean fishermen and stuff, that's great. [37:38.480 --> 37:39.180] So, yeah. [37:39.360 --> 37:41.420] Definitely all the random HF traffic. [37:42.140 --> 37:45.820] Which is great, because that traffic anyone can listen to if you just set the antenna up. [37:47.400 --> 37:49.580] Quick question on just a practical application. [37:49.580 --> 38:08.140] You did cover all the things involved, but with, say, a 27 megahertz remote control car signal, what would you use to decode that or figure out what they're using as far as the signal goes and then possibly use something generic to reproduce it? [38:09.360 --> 38:17.360] So, my preferred toolkit for demodulating signals and, like, figuring out their protocols and stuff is definitely universal radio hacker. [38:18.200 --> 38:22.000] But in terms of the SDR, just, like, whatever one I have on hand that works best. [38:22.180 --> 38:29.020] Like, you know, if you start getting higher sampling rates and stuff, that obviously helps your case a lot more and, like, more expensive ones. [38:29.160 --> 38:31.540] But often we are budget constrained. [38:33.120 --> 38:34.660] Thank you for sharing today. [38:34.660 --> 38:39.200] I thought your talk was extremely riveting and constantly moving. [38:39.200 --> 38:42.180] I was struggling to keep up a bit, but I loved it. [38:42.280 --> 38:44.300] And your teaching method is really great. [38:44.300 --> 38:50.300] Do you have a YouTube channel, Instagram, or anything where I can get more information from you because I like your teaching style? [38:51.920 --> 38:52.680] No, actually. [38:54.260 --> 38:58.600] How can we reach out to you for questions or further stuff, or are you just invisible? [38:59.400 --> 38:59.920] Oh, geez. [39:00.220 --> 39:01.180] Yeah, is my email on here? [39:01.300 --> 39:01.720] Yeah, I don't know. [39:01.760 --> 39:02.660] You can probably email me. [39:02.800 --> 39:06.460] Or if you, like, Google my name, I'm super, like, unique last name. [39:06.780 --> 39:10.620] So, it's, like, there's, like, random Arch Linux commits and stuff that have my email. [39:12.160 --> 39:12.540] Right. [39:12.540 --> 39:13.680] I guess I can put that up. [39:14.380 --> 39:15.200] Yeah, well, thank you. [39:20.180 --> 39:25.500] You talked about putting a bandpass filter on the output radio of a Raspberry Pi. [39:26.140 --> 39:28.040] Can you say more about how you actually do that? [39:28.840 --> 39:29.180] Pardon? [39:30.700 --> 39:35.240] You talked about a bandpass filter for the radio output with the Raspberry Pi. [39:35.660 --> 39:36.760] If I caught that right? [39:37.800 --> 39:46.880] Yeah, sorry, I was saying, or, sorry, what I meant to say was you shouldn't operate it without a bandpass filter due to the spectrum linkage. [39:47.040 --> 39:55.320] Whether or not that's, like, feasible to add on to the radio and whether or not using a Raspberry Pi as a radio is legal. [39:56.160 --> 39:57.900] You have to check your local regulations. [40:00.940 --> 40:10.500] But the range of it is, like, if you're broadcasting in the ISM bands and, like, you're doing something to filter out the frequencies, like, the range of it's, like, 10 centimeters, so it's, like, not super powerful anyways. [40:11.260 --> 40:13.640] Yeah, sorry, that doesn't answer your question. [40:23.020 --> 40:28.260] Well, so, people in North America will say, yeah, like, Roy Akers or Rue Akers. [40:28.720 --> 40:29.300] Either's fine. [40:29.500 --> 40:30.920] I'm, what, Goddard's Law? [40:31.120 --> 40:34.480] Be conservative in what you send, permissive in what you accept. [40:34.680 --> 40:35.200] Ah, just whatever. [40:35.600 --> 40:36.900] If it's obvious, you're referring to me. [40:43.210 --> 40:43.610] Cool. [40:43.830 --> 40:44.710] Well, thank you so much. [40:44.930 --> 40:45.410] Thank you.