[00:01.420 --> 00:06.160] ...right now, mainly because some of Bernie's stuff got stolen, which really sucks. [00:07.020 --> 00:10.980] But we're going to try and do a demonstration anyways. [00:12.360 --> 00:14.560] What we've got going is... I'm Jason Hillyard. [00:14.820 --> 00:16.620] I'm going to be talking about digital cellular. [00:20.300 --> 00:28.400] Mark over there is going to talk about how he explored the Oki-900 and maybe talk about this neat interface he built for it. [00:29.540 --> 00:37.540] Andy here is from Germany, and he seems to be busy ripping apart a GSM phone, which is the new little phone that is used throughout Europe. [00:39.060 --> 00:45.620] And Bernie is trying to set up somebody else's equipment to do his cloning demonstration, correct? [00:46.200 --> 00:46.720] OK. [00:48.740 --> 00:49.520] So here we go. [00:59.480 --> 01:00.180] All right. [01:01.340 --> 01:03.260] Digital cellular is what I'm going to be talking about. [01:06.520 --> 01:10.320] There's going to be new digital cellular systems coming out in the US. [01:10.760 --> 01:12.280] I'm going to be talking about two of them. [01:12.840 --> 01:16.800] One's called CDMA and one's called CDPD. [01:17.580 --> 01:19.260] CDMA is for digital voice. [01:19.620 --> 01:26.340] CDPD is actually a wireless data network that works within the existing analog cellular network. [01:36.040 --> 01:41.580] I'm going to be talking about some of the motivations for digital cellular, why they're building it, why we need it. [01:42.180 --> 01:44.240] I'm going to talk about what CDMA is. [01:44.560 --> 01:46.320] That's Code Division Multiple Access. [01:46.860 --> 01:49.620] And I'm going to talk about what CDPD is, how it works. [01:49.880 --> 01:51.700] That's cellular digital packet data. [01:51.700 --> 02:04.440] And I'm going to talk about some security issues on both those systems, how they do authentication, whether it's possible to monitor those systems, and whether it's possible to do things like cloning. [02:08.920 --> 02:13.920] Probably the main motivation for digital cellular is more channels, higher capacity. [02:13.920 --> 02:15.780] Right now, AMPS is kind of saturated. [02:15.960 --> 02:18.200] AMPS is the analog system in the US today. [02:18.840 --> 02:23.940] In urban areas, all the channels are going to be in use in some cells during like rush hour. [02:26.420 --> 02:31.360] Also, probably most of you know that the security on AMPS really sucks. [02:31.700 --> 02:35.020] It's basically wide open for monitoring and for fraud. [02:36.380 --> 02:38.700] The system wasn't designed for security. [02:38.700 --> 02:41.160] The digital systems that are coming out are. [02:43.160 --> 02:53.220] Digital cellular also allows better voice quality and less things like dropped calls, cleaner handoffs, less static. [02:55.380 --> 03:02.120] And also, wireless data is another thing that some of those service providers are going to want to sell. [03:03.000 --> 03:06.460] They're expecting the wireless data market to really explode in the next few years. [03:13.260 --> 03:13.680] CDMA. [03:14.140 --> 03:18.700] We're going to be looking at the market, who's selling the service, whether it's available. [03:18.840 --> 03:19.600] It's not available now. [03:20.540 --> 03:21.660] Who's making the equipment. [03:22.240 --> 03:23.300] We're going to look at the system. [03:23.460 --> 03:25.460] I'm going to try not to be too technical about it. [03:26.660 --> 03:28.940] Since CDMA is really some pretty hairy stuff. [03:29.840 --> 03:33.780] We're going to look at the authentication and some of the advantages of CDMA. [03:34.500 --> 03:40.080] Oh, I should mention, TDMA is the other digital cellular system for voice in the US. [03:40.080 --> 03:40.980] The other US standard. [03:41.580 --> 03:48.760] I'm not going to talk about TDMA much, but there are some things about TDMA that are exactly the same as CDMA. [03:49.560 --> 03:52.700] Mainly the authentication with CDMA and TDMA is the same. [04:00.460 --> 04:03.580] Here's where they're looking at providing CDMA service. [04:04.560 --> 04:06.860] No one is selling CDMA service yet. [04:07.860 --> 04:14.040] Mainly the major market areas are going to be getting it sometime next year. [04:17.400 --> 04:21.660] And AirTouch, which used to be Pactel, is going to be providing it in Los Angeles, San Diego, Atlanta. [04:22.580 --> 04:25.540] And NYNEX is looking at doing it in New York and Boston. [04:26.780 --> 04:28.380] There are some of the equipment manufacturers. [04:30.100 --> 04:33.220] Motorola is going to be making CDMA base stations. [04:33.220 --> 04:38.480] Qualcomm, which is a company in Southern California, actually invented the CDMA system. [04:38.700 --> 04:44.540] And they license a lot of the technology, mostly chips, for use in CDMA base stations and phones. [04:45.140 --> 04:52.880] And every cell phone manufacturer under the sun has a licensing agreement with Qualcomm for their technology. [04:57.640 --> 04:58.280] Okay. [04:59.240 --> 05:00.880] CDMA is spread spectrum. [05:02.200 --> 05:04.140] Anyone know what spread spectrum is? [05:04.320 --> 05:04.900] How it works? [05:05.260 --> 05:05.920] A couple of people. [05:06.700 --> 05:06.860] Okay. [05:07.700 --> 05:13.620] Spread spectrum was used in military applications for security, things like that. [05:15.300 --> 05:19.940] What it allows you to do is basically, it's a really wide band transmission. [05:22.480 --> 05:27.460] It allows you to obscure the signal. [05:28.000 --> 05:38.780] And it's well suited for cellular applications because the advantage is a lot more channels than the analog system. [05:40.080 --> 05:42.940] I guess one example you can give is like this. [05:43.480 --> 05:49.400] With AMPS, the analog system now, it's like two people in a room having a conversation. [05:49.400 --> 05:51.840] That's what the communication is like on the system. [05:52.320 --> 05:57.560] With CDMA, the time division system, it'd be like three conversations going on at the same time. [05:57.820 --> 05:59.100] Or not at the same time, excuse me. [05:59.180 --> 06:01.820] Three conversations going on, but everyone speaks at different times. [06:01.980 --> 06:03.040] They all learn from time slot. [06:04.000 --> 06:08.640] With CDMA, it'd be more like ten different conversations in the room. [06:09.380 --> 06:12.040] Everyone's speaking at the same time, but it's all different languages. [06:12.040 --> 06:16.800] So you can figure out who is speaking because you know the other person's language. [06:19.420 --> 06:22.840] A CDMA channel is 1.23 MHz wide. [06:23.240 --> 06:25.900] You are not going to be able to pick that up on your RadioShack scanner. [06:26.640 --> 06:31.840] And there are 64 channels in that 1.23 MHz. [06:31.860 --> 06:36.660] That includes both voice channels and access and paging channels. [06:38.500 --> 06:40.260] So how do they do this digital voice? [06:40.480 --> 06:42.540] Well, the trick is to get the bitrate low. [06:43.380 --> 06:47.700] To do that, you need a sophisticated compression algorithm. [06:48.260 --> 06:51.800] And what they use is called a vocoder, which is a voice encoder decoder. [06:52.880 --> 07:02.860] The one that's used at CDMA is a variable rate from 2.4 kbps to 9.6 kbps. [07:12.600 --> 07:13.900] Here's how they do the authentication. [07:14.240 --> 07:24.620] This is how, when you place a call, and you say, you know, I want to place a call, how the system checks that you are who you are and that you're legit. [07:27.420 --> 07:35.080] With AMPS, you just send out, you know, I'm the serial number, I'm going to call this number, and this is my number. [07:35.080 --> 07:35.980] So send that out. [07:36.100 --> 07:40.960] And they say, okay, that's your number, that's your ESN, go for it. [07:42.020 --> 07:43.600] They don't do that in CDMA. [07:44.380 --> 07:53.120] What they have is shared secret data, which is inside the phone, and it's also in the telephone company database that they're going to check. [07:53.700 --> 07:57.960] That gives them a lot of advantages on really knowing who you are. [07:57.960 --> 08:04.620] Now the trick is not to send this shared secret data in the clear over the air, because you're going to intercept it and it defeats the whole purpose. [08:04.980 --> 08:12.340] So what they use is an encryption algorithm to send out the shared secret data to do the authentication. [08:14.620 --> 08:16.820] This encryption algorithm called CAVE. [08:16.940 --> 08:18.040] I'm not familiar with it. [08:21.680 --> 08:27.260] The people who make these standards don't like to give out the encryption algorithms, you know, for the same reasons. [08:27.940 --> 08:30.720] Same political reasons that you guys already know about. [08:31.740 --> 08:35.480] I have copies of the CAVE algorithm if anyone's interested. [08:36.000 --> 08:37.860] Mark has copies of the CAVE algorithm. [08:38.180 --> 08:40.620] Of course, you're not supposed to have it unless you build a cell phone with yourself. [08:40.860 --> 08:42.860] Okay, well, I'll build a cell phone. [08:47.760 --> 08:59.820] The A key is another little bit of data that's in your phone, in your CDMA phone, and the database that the telephone company has for authentication. [09:00.180 --> 09:02.680] The A key is used to update the shared secret data. [09:02.680 --> 09:11.720] So, even if, let's say, you did figure out what the shared secret data was for a phone, they can update it. [09:12.700 --> 09:19.860] So, one day, you may be able to place a call, but, say, with a cloning type situation. [09:20.160 --> 09:23.700] But then the phone, you're cloning, so you get updated shared secret data and you're working. [09:24.660 --> 09:25.800] It's pretty secure. [09:28.240 --> 09:30.200] This is also the same for CDMA. [09:31.000 --> 09:34.040] And also, the phones that are coming out now are dual mode. [09:34.180 --> 09:36.900] They'll do analog and either TDMA or CDMA. [09:37.300 --> 09:43.320] And they can do this authentication over the AMP's analog channel. [09:43.460 --> 09:48.060] So, they don't have... these phones don't have to send out their ESN in the clear. [09:48.240 --> 09:51.800] They can do this kind of authentication with the analog system. [09:52.840 --> 09:55.400] If the base system is set up to do it. [09:56.300 --> 09:58.140] I want to add something on the authentication. [09:58.480 --> 09:58.700] Go. [09:59.980 --> 10:05.500] I know a cryptographer who says that the algorithm can probably be broken in a few days of work. [10:06.140 --> 10:12.920] And that he once asked the people on the committee why they restrict the document publication or document. [10:12.920 --> 10:17.940] And the person said they don't want mathematicians and computer scientists to get a hold of it. [10:18.020 --> 10:19.980] They don't want to start analyzing it and writing papers about it. [10:20.300 --> 10:20.560] Wow. [10:21.280 --> 10:23.120] So, let's all get a hold of that algorithm. [10:25.640 --> 10:27.260] Here's how you do it with the cave algorithm. [10:28.920 --> 10:33.280] So, what happens is the mobile is going to send... [10:33.280 --> 10:35.240] It's going to generate a random number. [10:36.080 --> 10:39.700] It's going to take its ESN, its min, and its shared secret data. [10:40.000 --> 10:41.400] Run it through the cave algorithm. [10:42.140 --> 10:44.280] And then generate this authentication client. [10:45.280 --> 10:50.400] It's going to send the random number it generated and the authentication client to the base. [10:51.180 --> 10:53.300] Along with its ESN and min in the clear. [10:53.300 --> 10:58.300] But that doesn't do anything because what you really need is the shared secret data. [10:59.540 --> 11:02.400] It sends that along with a count. [11:02.780 --> 11:09.320] The count keeps track of how many times the phone has done this. [11:09.520 --> 11:13.720] Which is another little trick to stop phoning. [11:14.060 --> 11:22.380] So, if you have two phones out there with the same shared secret data, ESN and min, and they're placing calls, the count's going to be off on the different phones. [11:29.880 --> 11:31.880] CDMA also has encryption for voice. [11:32.020 --> 11:32.880] I didn't finish the slide. [11:34.020 --> 11:42.600] The way they do it is they use what's a private code to spread the signal in the spread spectrum. [11:44.400 --> 11:46.180] And it isn't that secure. [11:46.380 --> 11:50.020] Many of you guys know a lot about cryptography. [11:50.720 --> 11:55.340] It's kind of similar to an engineer system with a really long key. [11:55.500 --> 12:00.860] I don't think that CDMA encryption is... or voice is really that secure. [12:03.400 --> 12:08.940] But, on the other hand, it's really... it's going to be hard to monitor CDMA conversations. [12:08.940 --> 12:10.380] And I'll talk a little bit about that more. [12:15.800 --> 12:17.580] Here's the main advantages of CDMA. [12:18.120 --> 12:22.680] Get about ten times the capacity, ten times the channels of amps. [12:23.040 --> 12:24.320] Get better voice quality. [12:25.060 --> 12:29.400] There's provisions in the specifications for doing data and fax over CDMA. [12:29.720 --> 12:31.720] But there's some problems with that, I think. [12:32.120 --> 12:35.500] I think that will reduce the amount... reduce the capacity of the system. [12:36.160 --> 12:37.900] And also, the capacity is dynamic. [12:37.900 --> 12:39.080] It's not set. [12:39.400 --> 12:45.940] If you add more channels on south, it will just create the quality of the overall... of all the channels. [12:46.440 --> 12:49.440] So, it's more flexible than, say, CDMA. [12:49.640 --> 12:54.660] Where you're stuck with three... three times the capacity of amps. [12:56.700 --> 12:59.560] Okay, that's it on CDMA. [12:59.560 --> 13:01.200] Let me talk about CDPD now. [13:02.580 --> 13:03.960] The market, the system. [13:04.440 --> 13:04.980] Same kind of stuff. [13:05.340 --> 13:07.800] Authentication and encryption. [13:10.440 --> 13:13.620] CDPD is really pretty neat. [13:13.840 --> 13:20.220] What you do is you use the time in between the... when amps channels aren't being used. [13:20.320 --> 13:23.140] The time between ending a call and placing another call on an amps channel. [13:23.140 --> 13:28.400] And you use that to send packets across wireless data. [13:30.600 --> 13:32.740] So, it's pretty cheap to implement. [13:33.760 --> 13:37.260] You already have these cellular base stations out there. [13:37.400 --> 13:38.620] They already have transmitters. [13:38.900 --> 13:41.380] They already paid to have their buildings set up. [13:41.500 --> 13:42.160] All the equipment's there. [13:42.160 --> 13:45.300] At $50,000 for a CDPD base station to that. [13:45.440 --> 13:48.440] The cell would probably cost me ten times that to get it all done. [13:49.340 --> 13:52.620] And you can do wireless data. [13:54.080 --> 13:59.060] So, who knows, maybe in a few years we'll all be flying down the highway seven miles an hour on IRC. [14:02.960 --> 14:04.220] The, uh, yeah. [14:04.780 --> 14:05.800] Friends don't have friends. [14:06.880 --> 14:07.840] Drive, long honors. [14:12.300 --> 14:14.740] Yeah, on IRC on the air. [14:17.140 --> 14:18.640] Here's the CDPD market. [14:20.180 --> 14:21.800] It's coming out pretty soon. [14:22.940 --> 14:26.380] It's set up in Seattle, Las Vegas, and Dallas now. [14:26.940 --> 14:29.360] However, I don't think they're selling service yet. [14:29.360 --> 14:34.780] I don't think you can go up and say, if you're in Las Vegas, and say, Oh, I've got my CDPD phone on. [14:35.000 --> 14:35.760] Can you hook me up? [14:35.820 --> 14:36.660] I don't think we'll do that yet. [14:36.800 --> 14:37.800] It's still testing. [14:38.280 --> 14:46.300] Um, it's gonna be set up in Baltimore, San Francisco, the main, um, the big cities. [14:47.160 --> 14:53.020] And, I would expect this to be set up in a lot of different places by this time next year. [14:53.780 --> 14:59.340] Um, there's the equipment manufacturers, uh, mobile stations, Cincinnati Microwave, and PCSC. [15:00.380 --> 15:06.060] Um, base stations, you have Motorola, AT&T, making us. [15:09.120 --> 15:13.280] Right, um, I would say soon. [15:13.440 --> 15:14.740] I think it's deployed now. [15:14.820 --> 15:17.200] In other words, they're setting up base station equipment now. [15:17.800 --> 15:19.320] Um, it's kind of tricky. [15:19.640 --> 15:24.120] You know, they'll say the system, the phone companies will say the system's set up when it's only a couple cells. [15:24.120 --> 15:26.280] You know, they'll say, we're offering CDPD service. [15:26.420 --> 15:28.680] Well, yeah, but, you know, what's the coverage? [15:28.940 --> 15:30.000] Is it the whole city? [15:30.500 --> 15:30.620] What? [15:31.060 --> 15:35.740] Oh, another interesting thing with CDPD is you're gonna be able to roam between the different carriers. [15:36.900 --> 15:45.760] If system A stops in one area, but there is system B, you can go across the carrier while [15:50.680 --> 15:52.400] you're going, while you're stalling on. [15:52.700 --> 15:54.520] Um, here's a CDPD system. [15:55.200 --> 15:57.020] It's not that fast, but it's pretty fast. [15:57.020 --> 16:05.020] What you have is 19.2 kilobits per second channel that's shared on the, by the other CDPD users in the cell. [16:06.500 --> 16:08.880] You've got a fair amount of error correction overhead on that. [16:09.060 --> 16:12.780] And once you check the error correction, it's down to like 14 kilobits per second. [16:13.280 --> 16:17.240] Once you check the rest of the packet stuff, it'll probably be down to about 12. [16:18.760 --> 16:22.580] So, you've got about a 12 kilobits per second throughput shared channel. [16:22.580 --> 16:28.920] Um, it's not bad if it's, if you compare it to the other wireless data systems that are out now. [16:29.880 --> 16:41.600] Um, the modulation is GMSK, which is kind of a, kind of like PSK, but it's, um, for optimized for Gaussian noise. [16:42.100 --> 16:48.560] Um, and the way it works, as I've said before, is you hop around on the unused amps channels. [16:49.300 --> 16:53.200] Um, the way you pay for this is on a per packet basis. [16:53.660 --> 16:56.460] You're no longer paying for time like you do with amps regularly. [16:57.180 --> 16:59.860] Um, which is one of the big advantages. [17:00.260 --> 17:03.580] I'm not sure how much it costs or exactly how big these packets are. [17:04.220 --> 17:08.020] Um, but it should be, hopefully, pretty cheap. [17:09.020 --> 17:12.760] Also, you're going to be able to do, um, IP over CDP. [17:12.760 --> 17:16.840] CDP is designed to be just an extension of existing networks. [17:17.260 --> 17:20.480] Um, which is really pretty neat. [17:21.260 --> 17:28.780] It's a little tricky because, since you're mobile, the routing isn't determined by your address anymore. [17:28.900 --> 17:33.020] And you're going to need special base stations, which are basically mobile routers. [17:33.640 --> 17:36.560] Routers designed to, to route to these mobile stations. [17:44.970 --> 17:53.150] CDP uses, at least in the spec, specific cases for using Diffie-Hellman encryption with a 256-bit key. [17:54.390 --> 17:55.250] That's how it works. [17:55.410 --> 17:56.730] I'm not going to go over it. [17:56.830 --> 17:57.970] Do you guys know about Diffie-Hellman? [17:58.570 --> 17:59.370] I know some of you guys do. [18:00.030 --> 18:04.230] Um, the key size is kind of, isn't really that big, is it? [18:04.950 --> 18:09.970] Um, it's big enough to probably take a while. [18:10.710 --> 18:20.010] Make it probably not useful to hack it, uh, you know, after the station you're trying to hack in intercepted the data and they're, uh, 200 miles away now. [18:20.690 --> 18:24.930] Um, after you encrypt it, the way it looks is like this. [18:26.370 --> 18:32.190] A mobile station will come up and say, you know, I'm here, I want to start, I want to start connecting. [18:32.450 --> 18:34.630] And they'll say, okay, well, let's exchange keys. [18:34.630 --> 18:37.310] So you exchange keys before you do the authentication. [18:39.030 --> 18:43.550] Um, the Aerolink is encrypted with RC4. [18:43.710 --> 18:44.770] I'm not familiar with RC4. [18:45.850 --> 18:47.350] Um, it's an encryption algorithm. [18:48.130 --> 18:48.610] Um, [18:52.820 --> 18:55.640] and so it's, in the spec at least, it's pretty secure. [18:55.880 --> 19:00.240] I'm not sure whether they're going to start out using encryption when the, when the system is first coming along. [19:00.240 --> 19:01.720] Um, it'll be interesting to see. [19:06.040 --> 19:06.720] Okay. [19:07.640 --> 19:11.180] Um, here's how they do authentication on CDP. [19:11.940 --> 19:24.260] Uh, the identity is based on what's called your network entity identifier, which is, um, like your, certain knowledge is to say your net address. [19:24.980 --> 19:35.460] Um, also there's a authentication sequence number, which is the counter, just like CDMA, where every time you authenticate it, it keeps track of how many times. [19:35.720 --> 19:40.120] And which, which, with each authentication sequence number is a random number. [19:40.800 --> 19:44.800] It keeps, um, so it works like this. [19:46.480 --> 19:54.780] You send your NEI to the, um, your NEI, your ASN, and the random number to the base. [19:55.280 --> 19:58.580] Um, the base checks it, confirms it or denies it. [19:59.040 --> 20:04.160] Um, and then they can update the random number and increment the ASN. [20:04.160 --> 20:16.040] So, if you come back again and you have, say you have the NEI, but you don't have the right ASN, you're a few numbers off, then it won't work. [20:16.500 --> 20:18.340] Um, it's another thing to try and decline. [20:19.840 --> 20:20.440] Okay. [20:23.990 --> 20:25.050] Security issues. [20:26.150 --> 20:29.010] Um, is it possible to monitor CDMA and CDP? [20:29.510 --> 20:32.610] Um, how would you intercept the authentication information? [20:33.250 --> 20:37.090] And it's possible to clone CDMA and CDPD? [20:37.450 --> 20:37.570] Yeah. [20:38.070 --> 20:38.850] Can you just go ahead? [20:39.490 --> 20:40.270] Oh, sure. [20:43.860 --> 20:44.460] Okay. [20:50.120 --> 20:52.020] Monitoring CDPD and CDMA. [20:52.520 --> 20:55.280] The basic idea here is hack the phone. [20:55.580 --> 21:00.220] Um, you're not gonna build a CDMA receiver with parts and radio stuff. [21:00.380 --> 21:03.020] But, it's all in the phone, right? [21:03.680 --> 21:07.600] The real trick is gonna be getting the phone to do what you want. [21:07.600 --> 21:12.020] Um, people are doing that now with AMP cytophunks. [21:12.360 --> 21:14.100] And I think it's just gonna continue like that. [21:14.820 --> 21:23.100] Um, monitoring the CDMA forward channel, that's what the base transmit, I think is gonna be difficult but possible. [21:24.380 --> 21:35.160] It'll be basically a matter of tricking your phone into monitoring other channels and getting some other, um, some other things aligned correctly. [21:35.160 --> 21:41.560] I think monitoring the reverse channel is gonna be very difficult because the modulation used on the forward channel and the reverse channel are different. [21:42.120 --> 21:47.760] I don't think you can use your CDMA phone to monitor the reverse channel. [21:48.220 --> 21:50.960] Um, you're gonna have to do something specialized to do that. [21:50.960 --> 21:58.900] Um, with CDPD, monitoring the forward channel is not too big a deal, I think. [21:59.340 --> 22:01.800] Um, because that's what your CDPD phone is doing anyway. [22:02.260 --> 22:07.000] You're just sitting along monitoring the forward channel, waiting for packets that are coming to you. [22:07.000 --> 22:10.440] And what you want to do is just look at all the packets, right? [22:11.160 --> 22:13.400] Um, but hopefully the packets are gonna be encrypted. [22:13.980 --> 22:15.820] Well, maybe not hopefully. [22:16.200 --> 22:18.720] Um, depends on your point of view. [22:19.400 --> 22:25.840] Um, monitoring the reverse channel on CDPD is gonna be difficult but I think possible. [22:26.040 --> 22:28.020] It uses the same kind of modulation as the forward channel. [22:28.020 --> 22:33.380] It's a matter of, um, getting the modem to work right with it. [22:36.860 --> 22:37.500] Okay. [22:38.740 --> 22:40.300] Recepting authentication information. [22:44.340 --> 22:44.980] Okay. [22:45.600 --> 22:50.460] Um, one thing I put in there is home location register databases. [22:51.120 --> 22:55.140] That's the database that has all the authentication information, alright? [22:55.400 --> 22:56.980] That's some computer somewhere, right? [22:56.980 --> 23:00.740] And, hey, well, uh, it could be hacked, right? [23:01.220 --> 23:08.000] And if you got that, then you have all the authentication information you needed, um, to clone a phone. [23:08.900 --> 23:10.700] But, there's some problems with that. [23:11.160 --> 23:15.200] Remember these counts that are counting, um, how many times you authenticate. [23:15.820 --> 23:20.840] If you clone a phone and use it more than once, the count's gonna be off. [23:20.980 --> 23:25.180] If the guy's phone that you cloned, if he's using his phone regularly. [23:25.180 --> 23:25.660] Yeah? [23:25.940 --> 23:30.560] Well, the need that you cloned it for real information that his ones were for real. [23:30.680 --> 23:31.320] That's right. [23:31.680 --> 23:31.800] Yeah. [23:32.440 --> 23:32.800] Yeah. [23:33.220 --> 23:33.340] Yeah. [23:35.140 --> 23:39.120] So, you're using, you cloned the phone and, um, you're using it. [23:39.740 --> 23:41.920] Uh, you're implementing the count on his phone. [23:42.400 --> 23:44.820] Well, your phone, but it thinks it's his phone. [23:45.480 --> 23:48.520] Um, then the guy you cloned comes along for us to use his phone. [23:48.520 --> 23:50.140] Um, and, to counsel on. [23:50.280 --> 23:52.160] Well, you know, it's pretty obvious. [23:52.400 --> 23:54.620] It's gonna be pretty obvious that a clone happened. [23:57.460 --> 24:04.320] Well, all, they're gonna hopefully have these, um, home location registered databases networked pretty well. [24:04.840 --> 24:05.640] So, what? [24:08.500 --> 24:09.200] I don't know. [24:09.200 --> 24:14.120] Um, so you can do authentication anywhere in the country. [24:14.480 --> 24:16.860] Um, and it'll come back, correct? [24:17.760 --> 24:22.320] Um, I'm gonna keep, I kinda have to hurry up here, probably. [24:22.900 --> 24:23.020] Yeah. [24:25.000 --> 24:25.360] Okay. [24:27.100 --> 24:33.340] Um, maybe I'll just jump to the conclusion, and you can ask me more detailed questions on the count. [24:33.340 --> 24:36.980] Um, digital cellular is coming. [24:37.300 --> 24:38.360] Look for it next year. [24:38.680 --> 24:39.220] Fire. [24:39.780 --> 24:40.140] Sorry. [24:42.220 --> 24:43.420] I'm making voices. [24:44.000 --> 24:44.560] Oh. [24:44.780 --> 24:45.000] Okay. [24:45.480 --> 24:49.320] Um, digital cellular is coming. [24:49.920 --> 24:53.960] It's gonna be much more secure than AMS as far as monitoring it and cloning it. [24:54.720 --> 24:58.340] Um, monitoring is probably possible, but it's gonna be difficult. [24:59.440 --> 25:02.020] Cloning is probably possible, but very difficult. [25:05.500 --> 25:06.780] And, that's it for me. [25:07.080 --> 25:07.580] I'll take questions. [25:07.860 --> 25:07.960] Yeah? [25:08.220 --> 25:10.040] How big is the, uh, sequence number? [25:10.700 --> 25:11.920] How long is the sequence number? [25:12.000 --> 25:15.180] I think in, uh, these eight bits. [25:15.940 --> 25:16.720] And it wraps around. [25:17.060 --> 25:18.400] How big is the sequence number? [25:18.940 --> 25:27.460] Well, right, so you're saying, why not, if I have part of the authentication information, but I don't have the right sequence number, why not keep trying it until you get it right? [25:28.200 --> 25:31.960] Yeah, but wouldn't they kinda notice when you're sitting there and keep trying new authentication? [25:31.960 --> 25:33.960] You know, new counts? [25:34.500 --> 25:34.620] You know? [25:35.020 --> 25:35.740] I mean, they would notice. [25:37.760 --> 25:38.220] Yeah? [25:38.600 --> 25:40.020] The individual is coming. [25:40.540 --> 25:42.380] They're gonna have to leave the AMS system off, or? [25:43.140 --> 25:43.880] That's true. [25:44.040 --> 25:44.680] A lot of phones. [25:44.800 --> 25:45.080] Right. [25:45.520 --> 25:47.340] Yeah, how long is AMS gonna be around for? [25:47.600 --> 25:48.460] Probably a while. [25:48.780 --> 25:51.280] I mean, they're still selling everybody AMS phones, right? [25:51.280 --> 25:53.900] And they're making money off it. [25:54.000 --> 25:54.460] It's working. [25:55.080 --> 25:58.520] Um, you know, maybe it'll be ten years. [25:58.860 --> 25:59.140] I don't know. [26:00.400 --> 26:01.040] Way in the back. [26:07.990 --> 26:11.190] Oh, what's the spreading technique with CDMA? [26:12.230 --> 26:15.290] It's a direct sequence spread spectrum. [26:17.830 --> 26:18.430] Go. [26:24.480 --> 26:29.460] Are they gonna overlay the spread spectrum on top of existing analog channels? [26:29.820 --> 26:30.780] Probably not. [26:31.120 --> 26:32.900] Um, but I think they could. [26:33.460 --> 26:36.380] All they're gonna do is set aside a 1.23 megahertz chunk. [26:38.240 --> 26:38.760] Yeah. [26:38.780 --> 26:40.600] Are you saying the scanning is not pseudorandom? [26:40.900 --> 26:41.500] It's a sequential? [26:42.240 --> 26:44.860] Um, you mean with the count thing, or? [26:45.080 --> 26:45.800] With the spread spectrum. [26:46.040 --> 26:47.220] With the spread spectrum. [26:47.540 --> 26:47.980] With the spectrum. [26:48.240 --> 26:51.780] You mean, is the spread sequence, it's pseudorandom? [26:52.000 --> 26:52.420] How much is it? [26:52.820 --> 26:53.180] Yeah. [26:54.080 --> 26:56.260] And your phone knows what the sequence is. [26:57.320 --> 26:57.420] Nick? [26:57.500 --> 26:59.140] Yeah, what's the shared? [27:00.080 --> 27:01.660] The shared secret data. [27:02.000 --> 27:02.120] Okay. [27:03.760 --> 27:04.280] That's.. [27:04.280 --> 27:04.600] . [27:05.260 --> 27:05.780] Right. [27:05.780 --> 27:16.280] But it's a field, it's a data field that's in your phone, and it's also in the cellular phone company's database. [27:18.760 --> 27:24.980] Kind of, but the trick is not to send the shared secret data, they don't send the shared secret data across the channel in the clear. [27:24.980 --> 27:25.860] Yeah, give it to you. [27:29.860 --> 27:30.300] Yeah. [27:31.500 --> 27:32.060] Uh-huh. [27:33.720 --> 27:34.800] Yeah, let me find that. [27:35.940 --> 27:41.460] I was curious, when it comes to the random number, it's in a book. [27:43.880 --> 27:44.320] Right. [27:44.320 --> 27:45.900] Uh-huh. [27:48.640 --> 27:50.480] No, the other side, yeah, I didn't explain that. [27:50.680 --> 27:52.660] The other side does exactly the same thing. [27:53.060 --> 27:55.320] They have the random number because you send it to them. [27:55.320 --> 27:56.600] They have your ESN. [27:56.700 --> 27:57.340] They have your min. [27:57.540 --> 27:59.000] They have the shared secret data. [27:59.440 --> 28:05.680] So, they take the same quantities and run it through the CAVE algorithm and just see if the auth matches. [28:06.040 --> 28:07.700] Oh, it's the same way crypt and how it matches? [28:07.920 --> 28:08.640] Yeah, exactly. [28:08.800 --> 28:10.640] It's a lot like crypt on a UNIX system. [28:11.120 --> 28:11.260] Okay. [28:13.040 --> 28:13.600] You're welcome. [28:14.240 --> 28:14.340] Yeah. [28:15.280 --> 28:16.720] Can you clarify something? [28:16.920 --> 28:19.020] Is the count stored in the phone with the [28:22.120 --> 28:22.340] switch? [28:22.800 --> 28:26.280] Um, the count is stored in the phone and in the switch. [28:26.280 --> 28:26.580] Okay. [28:27.100 --> 28:39.060] So, one thing you could do is if the phone tries to make the call and the switch says it can't go through to the proper count, can you tell the phone to keep trying with a different count until it gets it? [28:39.060 --> 28:42.140] Yeah, that's... Yeah, can you just keep trying with a different count until it gets it? [28:42.180 --> 28:43.260] The other guy said the same thing. [28:45.720 --> 28:46.080] Um... [28:46.080 --> 28:46.720] Yeah, you could. [28:46.820 --> 28:47.620] Honestly, why not? [28:47.780 --> 28:49.080] If you could trick your phone into doing it. [28:49.080 --> 28:53.360] But I'm saying that the system would notice you're kind of bashing away on this count. [28:53.520 --> 28:57.020] It would probably, if the system is smart, cut you off completely. [28:57.320 --> 29:01.340] Oh yeah, in CDMA, the base can lock your phone. [29:03.960 --> 29:06.160] So, kind of a nice one there. [29:06.980 --> 29:07.320] Yeah. [29:09.960 --> 29:10.500] Tracking. [29:10.900 --> 29:11.440] Tracking. [29:12.580 --> 29:12.740] Sure. [29:19.410 --> 29:25.550] So, you want to know whether the system can track you as you go around cell to cell? [29:25.850 --> 29:27.110] Like it knows where you're at? [29:28.350 --> 29:28.910] Yeah. [29:29.790 --> 29:31.410] It's going to know where you're at. [29:32.650 --> 29:34.510] I'm not sure to what degree. [29:36.050 --> 29:37.170] But it's... [29:39.980 --> 29:40.540] Okay. [29:40.820 --> 29:42.420] Go ahead and tell us about GSM. [29:43.760 --> 29:48.440] What they started doing was just seeing which cell had the strongest signal. [29:52.960 --> 29:55.720] And you're now thinking of doing it where there's a tiny difference [30:01.410 --> 30:03.030] between which cell handles the call. [30:03.150 --> 30:09.670] Because otherwise, if you're in the building, the wrong cell might actually take the call because there's just the building in the call for 30 seconds. [30:10.090 --> 30:14.650] Meaning that at call setup, which is only once, they have your position. [30:14.850 --> 30:18.170] We calculated this to be at 50 meters or 100 meters accurate. [30:19.210 --> 30:31.430] So, yes, they are working on, for reasons maybe not even related to tracking people or big brotherism, but they are working on getting the position and falling down much more accurately than the cell level. [30:32.430 --> 30:32.870] Right. [30:33.110 --> 30:38.070] So they can, at least with GSM, know your position much more accurately than the cell level. [30:38.790 --> 30:42.070] I don't see why they couldn't do the same thing with CDMA. [30:42.830 --> 30:43.890] Actually, I was thinking... [30:43.890 --> 30:45.770] I mean, you could also use that as like a service. [30:46.170 --> 30:48.990] You could do positioning with the cellular system. [30:49.650 --> 30:49.810] You know? [30:50.190 --> 30:52.130] They find out where you're at and then they tell you. [30:52.490 --> 30:53.090] So then you know. [30:53.290 --> 30:55.550] And you can find yourself on your little digital map, I guess. [30:56.030 --> 30:56.430] Yeah? [30:56.670 --> 30:57.370] Are there going to be [31:02.100 --> 31:02.980] other access to the database? [31:03.940 --> 31:04.740] Good question. [31:05.020 --> 31:08.860] We might have to find out if there'll be informal registration if you can't access the database. [31:09.240 --> 31:14.620] Yeah, I mean, this is all based on these databases being up and running and being able to exchange information. [31:15.760 --> 31:18.780] And all these different cellular companies having their own database. [31:19.380 --> 31:21.020] So, who knows? [31:29.830 --> 31:30.310] Okay. [31:30.790 --> 31:30.970] Right. [31:31.550 --> 31:32.030] With... [31:32.030 --> 31:32.110] Yeah. [31:32.230 --> 31:33.750] One of the big problems... [31:33.750 --> 31:40.750] One of the things that's hard to do with CDMA is you have this pseudorandom sequence that you're multiplying your bit stream coming out of your vocoder with. [31:42.170 --> 31:44.190] It's more complicated than that, but just to say that. [31:44.470 --> 31:48.750] How do you have the pseudorandom sequence at the transmitter and the receiver synchronized? [31:49.690 --> 31:57.870] The way they do it on CDMA is that there's a pilot channel that transmits just the pseudorandom sequence. [31:58.270 --> 32:01.230] So, the mobile picks that up and uses that to send it right back. [32:01.370 --> 32:03.350] So, you just get a time delay in the transmission. [32:03.890 --> 32:05.090] And they take that into account. [32:05.290 --> 32:05.330] Yeah? [32:09.160 --> 32:09.560] Yeah? [32:09.560 --> 32:13.040] Did the government have a say in the CAVE algorithm or something? [32:13.820 --> 32:17.220] Did the government have a say in using the CAVE algorithm? [32:17.440 --> 32:18.220] So they did not. [32:19.360 --> 32:24.880] Well, yeah, but why would the government want to get your authentication information, you know? [32:26.400 --> 32:27.280] They do in Europe. [32:27.460 --> 32:27.860] They do? [32:28.200 --> 32:29.060] They do in Europe. [32:29.140 --> 32:29.700] They have a say. [32:30.060 --> 32:32.040] Oh, they had a say in designing the specs. [32:32.520 --> 32:33.300] I don't know. [32:34.180 --> 32:35.120] I'm not sure at all. [32:35.200 --> 32:38.080] I would say probably not in the US, but... [32:39.940 --> 32:40.840] Right, but... [32:41.500 --> 32:42.180] Okay, okay. [32:42.340 --> 32:44.580] But remember, clipper's different. [32:44.980 --> 32:49.480] This is using encryption to do your authentication, right? [32:49.760 --> 32:49.960] Yeah. [32:50.640 --> 32:53.980] The voice encryption for CDMA isn't that great, okay? [32:55.080 --> 32:56.400] It's not that secure. [32:59.980 --> 33:00.460] So... [33:00.460 --> 33:00.720] Okay. [33:01.200 --> 33:01.880] Anyone else? [33:02.560 --> 33:03.640] They won't listen again. [33:03.780 --> 33:06.660] All right, maybe we'll move on to some of the other people on the cellular panel here. [33:08.720 --> 33:09.780] Bernie, you want to go next? [33:10.000 --> 33:10.120] Yeah. [33:10.480 --> 33:12.080] I'm just going to talk here because I don't have any slides. [33:25.190 --> 33:25.910] Is this working? [33:26.090 --> 33:26.210] Yeah. [33:27.870 --> 33:36.370] Well, I had hoped to actually have a demonstration of how one could legally or not so legally clone a cellular phone. [33:36.510 --> 33:40.050] That is, duplicate the telephone number and shield number of a cellular phone into one or the other. [33:40.050 --> 33:45.690] And a whole bunch of my stuff was ripped off last night while I was doing the clipper chip demonstration. [33:45.750 --> 33:50.710] So I don't have any working demonstration to show you people. [33:51.370 --> 33:52.950] I had three phones that got ripped off. [33:53.070 --> 33:56.970] But anyway, I can at least let you hear what cellular signals sound like. [33:57.450 --> 33:59.410] And I can touch upon how it's done. [33:59.630 --> 34:06.130] I did install software which enables you to perform this feat with a standard MS-DOS PC. [34:06.290 --> 34:07.690] That's installed on the network. [34:08.010 --> 34:11.030] And anyone interested in downloading that can get it. [34:11.070 --> 34:14.390] It's in a directory called CellSoft, C-E-L-L-S-O-F-T. [34:14.890 --> 34:18.110] And I'm not as familiar with the network as some of the other people are here. [34:18.110 --> 34:22.070] So if you talk to the folks in the Network Operations Center, you can download the code. [34:22.190 --> 34:25.210] There's about 700k of files in that directory. [34:26.710 --> 34:29.970] So I'm not going to go into too many technical details. [34:30.330 --> 34:37.030] But I would imagine there's a fair number of people here that don't know a lot about cellular communications. [34:37.510 --> 34:42.810] And I'm just going to go into some of the basics about the theory, how it works without the technical details. [34:42.810 --> 34:44.870] Just sort of the layman's explanation. [34:45.430 --> 34:47.090] And then I can take some questions afterward. [34:47.090 --> 34:53.350] I want to touch also on the problems with cellular fraud with the AMP system, which Jason did not go over. [34:54.870 --> 35:00.490] Basically how that is done and what's trying to be done to prevent that or at least cut it down. [35:01.650 --> 35:07.850] So I'm going to touch on mobile communications or mobile telephone communications from the early days. [35:10.090 --> 35:15.130] Car phones or mobile phones have really been around since like the 1950s. [35:15.790 --> 35:22.790] And the way they worked generally is that basically cellular phones, I'll tell you, and car phones, they are not telephones. [35:23.230 --> 35:24.990] They are two-way radios. [35:25.550 --> 35:32.510] And they are what are what would be referred to as full duplex two-way radios. [35:32.510 --> 35:35.670] That is, they allow you to hear and speak at the same time. [35:35.670 --> 35:41.770] Unlike, say, a CB radio or some other form of two-way walkie-talkie or something, you have to take turns talking. [35:41.890 --> 35:44.690] You can only transmit while you're not listening. [35:44.810 --> 35:46.710] And you can only listen while you're not transmitting. [35:46.830 --> 35:50.790] You have to take turns on a regular phone, like in your house or business. [35:50.790 --> 35:53.030] You can obviously talk and hear at the same time. [35:53.230 --> 36:01.690] So you're actually dealing with a radio transmitter and a radio receiver in a mobile or cellular telephone that are working simultaneously. [36:01.710 --> 36:07.730] Your voice is being transmitted to the other person and the other person's voice is being transmitted to you at the same time. [36:07.730 --> 36:11.990] So both people can interrupt each other like most people talk on phones. [36:13.750 --> 36:16.150] If I'm going too simply for people, stop me. [36:18.630 --> 36:21.830] In the 1970s... [36:22.830 --> 36:24.770] I'll talk about the old mobile phone system. [36:24.830 --> 36:38.470] The way that worked basically is there was in every metropolitan area, and there were only phones in metropolitan areas until fairly recently because there wasn't enough of a customer base to make it feasible to offer the service because you can get the revenue from the subscribers. [36:39.670 --> 36:49.030] There was one radio transmitter tower known as a repeater, a repeater being that it can receive a signal and retransmit it. [36:49.130 --> 37:11.130] It can receive your signal from the car or mobile unit and then retransmit it from a high place usually on top of a mountain on a tower at a much higher power level over a broad distance so that your signal would be going from, say, your car up to this tower and then picked up easily by it since it's at a high location and it has a line of sight view of all the area and that would retransmit it at [37:11.130 --> 37:12.130] a much higher power level. [37:13.110 --> 37:30.370] The older mobile telephone service worked with one tower in the area and because there was a very limited number of radio frequencies available and they were usually in the VHF range, in the 150 to 160 megahertz range, you had a very limited number of people that could talk at any given time. [37:31.130 --> 37:38.370] And I mean very limited in like 10 or 12 people in a given area that is like a town or something. [37:38.590 --> 37:40.910] But that was when only really rich people had phones. [37:41.210 --> 37:46.170] So in the 70s, that didn't work out too well because more people wanted phones. [37:46.290 --> 37:50.390] Doctors and lawyers, they wanted phones and other people with money. [37:50.390 --> 37:55.150] So they developed a new system called IMTS, the Improved Mobile Telephone Service. [37:56.290 --> 38:01.650] That used more channels in both the VHF and UHF ranges. [38:02.330 --> 38:10.610] Again, around 150 to 160 megahertz in the UHF range in the roughly 450 to 460 megahertz range. [38:10.950 --> 38:16.850] Standard FM type signals and they were not encrypted in any way. [38:16.850 --> 38:21.030] So you could just pick them up with a regular radio receiver or scanner as it were. [38:22.810 --> 38:26.310] The IMTS systems had maybe 20 or 30 channels. [38:26.870 --> 38:29.410] And that was even better than the older system. [38:29.770 --> 38:34.150] But obviously those still got clogged and you had to wait sometimes years to get a number. [38:35.110 --> 38:43.430] So the folks at the Bell Operating Companies, actually AT&T, knew that this was going to be a problem years and years ago. [38:43.430 --> 38:46.190] So they worked on developing a new technology called cellular. [38:46.470 --> 39:00.170] And the reason it's called cellular is if you were to look at a map of area that's covered by a cellular system that would show where all the cellular transmitters and receivers are that communicate with the mobile units. [39:00.730 --> 39:05.170] You see each tower covers a small geographical range. [39:05.350 --> 39:08.430] And if you were to look at a map of that, it would look like a honeycomb arrangement. [39:08.430 --> 39:11.690] It would look like cells, like in a beehive. [39:11.890 --> 39:13.810] So that's where the word cellular comes from. [39:14.830 --> 39:19.930] The big difference between cellular and the older types of mobile phones is there's a lot of differences. [39:19.930 --> 39:25.830] But the main thing is that there's not one central transmitter and receiver that goes through all this thing. [39:27.330 --> 39:29.770] And there's much more frequencies used with cellular. [39:29.770 --> 39:37.170] When cellular went into effect, the first system went into operation in Chicago in the early 80s. [39:37.910 --> 39:46.830] And cellular started with 666 channels in the frequency range from 870 to 890 megahertz. [39:55.830 --> 40:09.610] And then the reverse channel, that is from the mobile units to the cell sites, they are 45 megahertz lower than that. [40:12.370 --> 40:14.150] Roughly, where did I write that down? [40:19.140 --> 40:20.140] 830, 835. [40:21.380 --> 40:22.500] No, 835 to 845. [40:22.740 --> 40:23.720] Give me that. [40:23.880 --> 40:24.820] 35 to 50. [40:25.920 --> 40:26.420] Roughly. [40:26.660 --> 40:27.460] Can't do math now. [40:27.520 --> 40:27.960] I'm too tired. [40:28.320 --> 40:30.340] Roughly 835 to 855 megahertz. [40:30.540 --> 40:33.520] And the channels are spaced in 30 kilohertz steps. [40:33.920 --> 40:37.400] So that provides for a lot of good voice fidelity. [40:37.400 --> 40:38.400] It's pretty clear. [40:38.600 --> 40:41.160] And I'll give you a demonstration of how clear that is in a short while. [40:42.300 --> 40:51.640] In any given cellular area, say in a city like Manhattan, you're talking about dozens and dozens, if not scores, of cell sites. [40:52.020 --> 40:56.360] And each of those 666... [40:56.360 --> 41:03.400] And now, actually they ran out of channels a few years ago and added more to about 832 channels. [41:03.400 --> 41:07.120] There was a lot of controversy about the cellular companies asking for those extra frequencies. [41:07.360 --> 41:16.100] Because when the cellular companies went to the FCC back in the early 80's saying, we need this much radio spectrum for our cellular services. [41:16.100 --> 41:20.940] The FCC said, well, you know, what gives you the right to use up all this radio spectrum? [41:20.940 --> 41:22.660] And they said, well, we'll try to make it very efficient. [41:22.680 --> 41:26.220] Because cellular, we're designing it so that all the frequencies will be in use. [41:27.480 --> 41:28.620] And it will be a lot more efficient. [41:28.700 --> 41:33.660] We'll be able to put hundreds or if not thousands of people on the phones at any given moment. [41:33.960 --> 41:36.760] So the FCC went ahead and said, okay, well, we'll do this for you. [41:37.540 --> 41:40.160] But a few years later, they realized that that wasn't going to be enough. [41:40.400 --> 41:43.180] And they went back to the FCC and said, oh, well, we made a mistake. [41:43.240 --> 41:44.140] We're going to need more frequencies. [41:44.140 --> 41:47.720] The more frequencies available means the more they can sell and the more money they can make. [41:47.800 --> 41:50.520] And cellular companies are indeed making a lot of money. [41:50.800 --> 41:56.100] But any given metropolitan area, you'll have scores of cell sites. [41:56.500 --> 42:03.080] And they're very low power as opposed to the old mobile phones, which would be 40 or 50 watts of transmission power. [42:03.400 --> 42:09.660] The newer small pocket cellular phones like this one's made by Oki. [42:12.360 --> 42:14.560] And this one here is made by Motorola. [42:15.040 --> 42:20.860] They only transmit 600 milliwatts of RF output at their highest power level. [42:20.900 --> 42:23.080] That's six tenths of a watt. [42:23.460 --> 42:37.320] Now, when I say full power level, the power output on these phones is continuously changing because the cellular system, basically the computers, sense how close you are to a cell site. [42:37.320 --> 42:45.000] If you're very close to a cell site, it can pick you up very easily without having to... you transmit the full 600 milliwatts. [42:45.120 --> 42:54.400] So the system will adjust your power output on the cellular found down to as low as, I believe, 10 milliwatts, which is an extremely weak signal. [42:54.400 --> 42:57.980] But it can be still picked up if you're nearby a cell site. [42:58.040 --> 43:04.000] So it adjusted, I believe, in four dB steps from a few milliwatts up to 600 milliwatts. [43:06.480 --> 43:14.440] That makes it very difficult to intercept the reverse channel, that is the signal from the phone to the cell site. [43:14.560 --> 43:15.660] You have to be pretty near the phone. [43:16.160 --> 43:24.960] But the forward channels from the base stations, the cell sites to the phones themselves, can be picked up miles away with the standard radio receiving equipment. [43:27.720 --> 43:28.540] Let's see. [43:31.340 --> 43:40.580] There was a big problem with cellular fraud that started happening probably back around 1985, I'd say. [43:41.000 --> 43:46.900] And it has to do with how cellular phones work that made it possible. [43:47.440 --> 43:55.500] When you turn on a cellular telephone, the first thing it does, when you turn it on, is it sends its... [43:55.500 --> 43:58.340] When you turn it on, they make a little noise. [43:59.960 --> 44:01.860] You people have probably heard that, you have cellular phones. [44:02.220 --> 44:06.060] As soon as it makes that sound, what it does is it looks for the nearest cell site. [44:07.900 --> 44:09.400] Usually, it will find... [44:09.400 --> 44:11.540] There's something called an initial paging channel. [44:11.540 --> 44:21.040] If you have your system on the local phone company's system, such as NYNEX Mobile... [44:21.040 --> 44:21.820] What are they here? [44:22.220 --> 44:22.820] NYNEX... [44:24.060 --> 44:26.000] Cellular One and NYNEX. [44:26.420 --> 44:30.420] The way the FCC set this up is the first 666... [44:30.420 --> 44:34.980] The first 333 of the 666 channels were signed to the local phone company. [44:35.140 --> 44:40.020] And the second 333 of the 666 channels were signed to a competing company. [44:40.020 --> 44:46.280] And the reason they did that was they felt that each market should have two cellular carriers to provide competition. [44:46.660 --> 44:53.980] But as it turns out, the competing companies in each area pretty much were always in cahoots with each other... [44:53.980 --> 44:56.780] and decided to fix the rates so that you both had to pay about the same much. [44:56.980 --> 45:08.700] If you go to any area of the cellular service, you'll find that the pricing structure for both the wireline carrier, which is the local bill operating company, and the non-wireline company, which would be like Cellular One. [45:08.940 --> 45:11.240] You'll find that the pricing is almost identical. [45:11.600 --> 45:17.220] So they realized that if they got into price wars with each other, it would be actually reasonably priced and we wouldn't have to pay so much. [45:17.300 --> 45:21.820] So they decided they're gonna set their prices high at both ends and we pay for that. [45:23.020 --> 45:29.560] So the FCC's attempt at providing an open market so that people could compete... [45:29.560 --> 45:34.000] or the two companies would compete each other and keep prices down didn't work out that well in my respect. [45:34.160 --> 45:36.840] It's not outrageous, but it's still a lot more than it should be in my opinion. [45:37.340 --> 45:47.700] You can pay as much as $40 a month, I think, in some areas just for the basic access, just for the right to use a cellular phone, to have the cellular phone number turned on. [45:47.700 --> 45:49.280] It might even be more in some areas of the country. [45:50.100 --> 45:52.020] And that's regardless of any calls you make. [45:52.120 --> 45:57.500] You still have to pay a per minute charge on the communications that you make with the phone. [45:57.580 --> 46:00.340] Whether you receive the call or make the call, you're still using a cellular system. [46:00.580 --> 46:03.920] You might have to pay anywhere from 10 cents to... [46:04.960 --> 46:09.000] In some areas, off-peak airtime is as low as 9 cents. [46:10.140 --> 46:14.860] In other areas, peak airtime, which is in Philadelphia from 7 a.m. [46:16.080 --> 46:23.540] to 9 p.m., peak time in Philly is, depending on the rate plan you have, it can be 70 cents a minute. [46:23.780 --> 46:25.860] In other areas, it's a little bit higher. [46:25.980 --> 46:27.120] In some areas, it's lower. [46:27.600 --> 46:30.140] You'd have to call your local cellular carrier to find out what their rates are. [46:30.260 --> 46:34.660] But as you can see, it could add up to a few hundred dollars a month if you use your phone for any amount of time. [46:37.880 --> 46:38.420] Let's see. [46:41.920 --> 46:43.480] Oh, back on cellular fraud. [46:44.240 --> 46:45.420] The way anybody... [46:45.420 --> 47:00.840] The way they keep anybody from just buying a cellular phone or stealing a cellular phone and just using it and talking forever on it and bringing up bills that they wouldn't have to pay is that each cellular telephone has programmed into it in a ROM, a read-only memory. [47:00.840 --> 47:05.120] It's an electronic serial number that's unique to that particular telephone. [47:05.660 --> 47:08.040] It's an eight-digit hexadecimal number. [47:08.760 --> 47:17.760] And the first two digits of the eight hexadecimal digits define the manufacturer of the phone. [47:17.940 --> 47:22.540] For instance, if it's a Novotel, I know the first two digits are 8E. [47:23.520 --> 47:28.300] For Motorola, the label's not on this one, but it varies. [47:28.600 --> 47:41.180] So the bottom line is each cellular carrier, each cellular phone manufacturer, as can be differentiated from the phone carriers, the companies like NYNEX and Cellular One, they don't make phones. [47:41.240 --> 47:44.900] They just buy phones from Motorola or Oki or Panasonic and put their name on it. [47:44.980 --> 47:53.100] But every phone that you buy, no matter what company it's from, is going to have a unique serial number programmed into it, that ostensibly you're not supposed to be able to change. [47:53.680 --> 48:02.620] Along with that number is the cellular telephone number, which has an area code and an exchange, and a last 24 digits, just like a regular phone, also programmed into it. [48:02.960 --> 48:11.040] That second phone number is usually programmed into RAM memory, which you can change usually from the keyboard of the phone. [48:11.200 --> 48:16.220] You're not supposed to know how to do that, but a lot of times you can get instructions for your phone that tell you how to do that. [48:16.220 --> 48:30.880] If you just change the phone number of your phone, it's not going to work though, because what happens is when you sign up a cellular phone with a service, with a cellular carrier, of course you buy your phone usually from a cellular dealer who's affiliated with one of the two carriers in your area. [48:31.320 --> 48:32.700] They'll do a credit check on you. [48:33.360 --> 48:45.280] If that comes out okay, then you'll sign a contract saying you'll agree to pay the carrier X amount of dollars a month, maybe $20, $30 a month, for basic access plus so much per minute of air time. [48:45.720 --> 48:50.160] In some areas they do it in six second increments, but in a lot of areas it's still one minute. [48:50.480 --> 48:57.320] Six second increments would be preferable, because if your call is one minute and six seconds, you only pay for one minute and six seconds as opposed to two minutes. [48:57.460 --> 48:59.140] And over time that can add up to a lot of savings. [48:59.320 --> 49:09.020] But anyway, when you make your call, the first thing the phone does is it sends its electronic serial number and the telephone number to the nearest cell site. [49:09.020 --> 49:19.140] And that in turn goes to the mobile telephone switching office, which compares it with a database to see if indeed you've paid your bill and will it process the call. [49:20.040 --> 49:21.420] I'll take your questions in a few minutes. [49:22.780 --> 49:35.840] If it doesn't match, if they don't see that number in their database, or if there's some, like the phone number that it's getting from you is not assigned to be affiliated with that particular electronic serial number, or it will not process the call. [49:36.540 --> 49:54.780] Now, since each cellular carrier maintains its own database of legitimate electronic serial number slash telephone number combinations for all their subscribers, up until a few years ago, each company only knew if you were a legitimate subscriber on your system, [49:54.880 --> 49:55.820] if you were in that system. [49:55.840 --> 50:04.140] If you were from San Francisco and came to Manhattan and tried to use your cellular phone, it wouldn't know if you were a legitimate subscriber or not. [50:04.460 --> 50:14.100] All it would know is from the phone number and area code that you were a subscriber on, say, a Pacific Bells system in California, and it would just take your call. [50:14.180 --> 50:20.060] Whenever you're using a phone in a system that's not your home system, the one you sign a contract with, it's called roaming. [50:20.780 --> 50:30.340] And up until a few years ago, it just assumed that if it was with another bell carrier or a carrier had signed an agreement to... [50:31.640 --> 50:38.920] Literally cellular carriers would make agreements with each other, like, we'll handle calls for your people if you handle calls for our people, and we'll work out the billing. [50:39.100 --> 50:40.760] You reimbursed us, we'll reimburse you, etc. [50:42.080 --> 50:48.640] But until they had all these systems linked together, it just would assume you were a valid roamer, and it would process the call. [50:48.980 --> 50:59.900] So back in 1986, I believe it was, a lot of people figured out that if they just programmed your phone from the keypad, which is pretty easy to do... [50:59.900 --> 51:05.180] Actually, back in 86, a lot of the phones, you couldn't program from the keypad, yet you had to actually program a chip in there. [51:05.900 --> 51:11.560] Often it was referred to as burning a prom, because you have to burn out little links in the chip with a chip programmer. [51:12.340 --> 51:24.300] But if you change the phone number in a cellular phone to something other than your number and went to another city, often it would work, and they wouldn't know who to send the bill to, because the phone number wouldn't come back to... [51:24.300 --> 51:27.060] It would be a fake number, or somebody else would get the bill. [51:27.460 --> 51:34.160] So phone companies really took a bath on that for a while, and they decided, well, we're going to try to put a stop to that, and set up some sort of validation process. [51:34.660 --> 51:40.060] And they started sharing databases, and more recently they started networking that database. [51:40.060 --> 51:45.500] So instead of having to ship tapes around the country, now they can be online on something called... [51:45.500 --> 51:47.560] I think they're using something called the IS41 protocol. [51:48.020 --> 51:50.300] I don't know what network they're sending that information over. [51:50.600 --> 51:51.560] Does anybody know that? [51:52.640 --> 51:53.420] I guess not. [51:53.640 --> 51:58.060] But they can send this data back and forth in real time. [51:58.060 --> 52:09.840] If I take my phone to San Francisco and try to use it, it will be able to validate the authenticity of my phone, and that I'm a legitimate subscriber, within the first few seconds of the call. [52:10.020 --> 52:14.920] If it finds out I'm not legitimate, the call will terminate or not even start to get processed. [52:14.920 --> 52:21.720] So they kind of put the fake roaming method of fraud out of business a few years ago. [52:22.140 --> 52:25.840] What some people had figured out how to do, particularly with some phones, it was easier than others. [52:26.020 --> 52:27.580] There was a phone made by Mitsubishi. [52:27.760 --> 52:30.040] I think it was called the Mitsubishi 800, Model 800. [52:30.860 --> 52:41.220] If you put a special ROM chip into it, it made it come up with a random electronic serial number and phone number every time you turned it on. [52:41.800 --> 52:56.280] So basically, you got free phone calls all the time, but those phones don't work anymore in most areas because they've improved the software at the cellular companies to detect that, and the real-time authentication puts an end to it as well. [52:57.720 --> 53:01.100] Cellular fraud has become more sophisticated after that. [53:01.320 --> 53:11.580] When they put the kibosh on the fake roaming, criminals had figured out how to intercept these electronic serial numbers and phone number pairs. [53:12.420 --> 53:15.640] Remember, you have to get both numbers matching to get them to work. [53:15.640 --> 53:37.540] So some people had figured out how to intercept what's called the reverse control channel, which is the frequency that's being sent from the cellular phone to the nearest cell site, which initially it sends these two codes to the local repeater and that's sent to the mobile telephone switching office for analysis. [53:37.780 --> 53:43.060] If you have a radio receiver, you can pick up these signals if you're relatively close to where the phones are. [53:43.060 --> 53:59.380] So what some criminals did is they decided to set up a specialized radio receiver, not unlike this one, it's manufactured by ICOM Corporation, along with a computer and some other equipment that would allow you to actually demodulate this data, which sounds like roughly 10,000 [53:59.380 --> 53:59.700] baud. [54:00.760 --> 54:03.560] And if you hear it, it just sounds like a buzzing noise. [54:03.600 --> 54:09.100] In fact, I can probably let you hear what the data sounds like in a second here. [54:12.720 --> 54:13.760] Let's see... [54:18.330 --> 54:19.810] I'm going through... [54:19.810 --> 54:22.530] Who's the non-wire line carrier in this area? [54:22.710 --> 54:23.290] Is it cellular one? [54:23.910 --> 54:24.430] Okay. [54:25.670 --> 54:27.390] Let's see if I can pick up... [54:29.850 --> 54:30.370] Belt... [54:30.370 --> 54:32.370] Or NYNEX is... [54:38.510 --> 54:40.490] Now I'm going to pick up the forward channel. [54:41.730 --> 54:42.390] There we go. [54:46.590 --> 54:48.090] Okay, I'm going to put the mic up to the speaker. [54:48.150 --> 54:53.490] I'll let you hear what the data sounds like from the initial paging channel on the NYNEX system. [54:53.670 --> 55:06.950] And this is basically sending out a signal in this area to all cellular phones saying, if you pick this signal up, send me a signal back, and we'll find a channel to put you on that's not being used by someone else. [55:06.950 --> 55:07.910] So this is what that sounds like. [55:12.790 --> 55:14.670] Not very pleasant to listen to. [55:14.790 --> 55:17.190] But to some people, it's music to their ears. [55:20.950 --> 55:23.210] This is a data stream that is not encrypted. [55:23.850 --> 55:32.130] If you have equipment to demodulate that data stream, which is not terribly difficult to do, you can use this data for illicit purposes. [55:32.310 --> 55:35.090] Now bear in mind, this was the forward control channel you were hearing. [55:35.750 --> 55:38.870] This does not contain the electronic serial numbers. [55:39.010 --> 55:40.490] It does contain phone numbers. [55:41.130 --> 55:49.010] But without the electronic serial numbers, which are only sent from the phones to the cell sites, having the phone number isn't going to do any good if you want to commit fraud. [55:49.510 --> 55:53.170] To commit fraud, you need to get a receiver or a specialized device. [55:53.310 --> 55:59.350] There's a company called Curtis Electro Devices in Mountain View, California. [55:59.350 --> 56:03.710] Their phone number is area code 415-964-3846. [56:03.990 --> 56:07.910] They make a device called a cell phone ESN reader for about $1,300. [56:08.570 --> 56:09.510] Which is... [56:11.670 --> 56:16.850] Phone number is area code 415-964-9846. [56:17.410 --> 56:21.830] That device is designed for cellular dealers and installers. [56:23.370 --> 56:26.550] A lot of times, somebody comes with a cellular phone and they've had it. [56:26.630 --> 56:29.370] It's like an old phone and they didn't have it activated for a long time. [56:30.150 --> 56:31.570] They want to get it... [56:32.070 --> 56:33.190] I'll take questions at the end. [56:35.230 --> 56:40.410] Somebody comes into a dealership and they want to get their phone activated if it's one they've owned already and they haven't had it activated for a while. [56:40.410 --> 56:50.290] And if the label isn't on, the serial number isn't visibly stamped on or if the person doesn't have the paperwork for it, to find out what the electronic serial number of that phone is, you can use one of these devices. [56:50.570 --> 57:02.090] Just hold it up near the phone and turn it on and it will pick up that initial data stream that's being transmitted on roughly 800... anywhere between 835 to 855 MHz. [57:02.550 --> 57:06.510] And it will decode that and display it on the unit as well as the phone number of that unit. [57:06.510 --> 57:10.770] So it's picking up the same information that would be sent to the cell site when you turn your phone on. [57:11.110 --> 57:21.430] And that information can be programmed into cellular phones with special software to enable you to duplicate or clone that cellular phone. [57:21.530 --> 57:23.690] So that's what people decided to take advantage of. [57:24.210 --> 57:35.090] There are case histories of people being busted with one of these devices hidden in a Domino's pizza box standing on a busy intersection picking up cellular telephone, serial numbers and phone numbers. [57:35.090 --> 57:43.070] And it's really got the cellular industry upset because they don't really have much defense against this. [57:43.550 --> 58:02.710] When the cellular original AMPS telephone specifications were put together I don't know, probably 10 or 15 years ago for cellular, one of the requirements for those phone manufacturers was that the electronic serial number should not be readily alterable in a cellular telephone. [58:03.230 --> 58:10.510] And a lot of companies sort of came up with their own definition of what readily alterable was actually going to mean. [58:11.630 --> 58:22.550] Some cellular phone manufacturers made it pretty difficult to do which obviously would take more time to figure out to make it difficult or they just made it really easy to do because they figured nobody is going to be smart enough to open up a phone. [58:22.550 --> 58:25.270] They didn't know about people like us. [58:30.210 --> 58:33.870] Some companies use some sort of a... [58:33.870 --> 58:36.090] I wouldn't really call it an encryption algorithm so much. [58:36.590 --> 58:46.030] It just looks at different addresses in the phone for different parts of the electronic serial number instead of them being in a nice little memory address you can just find those eight hexadecimal digits. [58:46.030 --> 58:59.910] But a lot of people have hacked this stuff out and figured out what different phone models have their ESNs and what memory addresses and how to write information to that memory address so that that phone can then be... its identity can be changed. [59:02.790 --> 59:14.390] The interception of these electronic serial numbers slash telephone numbers has become most prevalent in really big metropolitan areas like New York, Los Angeles, Miami. [59:15.290 --> 59:17.210] It's a lot more prevalent in those areas. [59:17.410 --> 59:35.930] In fact, I've read of instances where even street gangs who had traditionally made a lot of their money from the sale of drugs had found out that an even safer and more lucrative form of revenue was to provide bogus electronic serial number and phone numbers to subscribers. [59:35.930 --> 01:00:02.770] And there's been cases of, you know, gangs and so forth providing this as a service to people on the street setting up a computer in their... in a car and they would just drive up to a parking lot or something where people would know they were to meet them and they plug the computer into a person's phone and upload a stolen electronic serial number and phone number into their customer's phone for [01:00:02.770 --> 01:00:07.290] a flat fee like $100 or $200 or whatever it was. [01:00:07.650 --> 01:00:11.090] And this required no real expense on their part. [01:00:11.190 --> 01:00:15.710] They weren't buying a raw product for resale like they were with drugs. [01:00:15.730 --> 01:00:17.650] It was like an infinite resource. [01:00:17.770 --> 01:00:18.110] It was free. [01:00:18.210 --> 01:00:19.310] You could just pick them out of the air. [01:00:20.170 --> 01:00:46.930] After about a month or two, when that person's serial number and phone number had been abused and the real person who was assigned those numbers they'd realize when they got a $10,000 phone bill with the calls to Haiti and South America and Europe wherever that I didn't make these calls and the phone carrier would end up eating those charges and have to change that person's cellular telephone [01:00:46.930 --> 01:00:47.330] number. [01:00:47.910 --> 01:00:50.710] They'd change the phone number, the electronic serial number would remain the same. [01:00:50.810 --> 01:01:05.510] But remember, if you change the phone number at the computer end, at the phone company end and on the phone end, the old purloined electronic serial number will no longer work because it won't be transmitting the new correct phone number with it. [01:01:05.690 --> 01:01:07.030] So it'd be out of business. [01:01:07.610 --> 01:01:22.550] Some cellular carriers had made it a point to, once they found out fraud was one particular phone number, serial number was being stolen and used, that they would monitor the activity on that account to maybe get an idea of who was committing the fraud. [01:01:22.550 --> 01:01:24.650] And they've had various success with that. [01:01:24.910 --> 01:01:31.690] A lot of times, what they would do is just simply call the phone numbers that showed up on the bill and say, who called you on this time and date? [01:01:31.890 --> 01:01:37.670] And amazingly, a lot of people got convicted just on that basis. [01:01:38.350 --> 01:01:40.050] I think there was a recent case where, [01:01:43.070 --> 01:01:46.390] I think there was a famous singer a few months ago. [01:01:47.690 --> 01:01:56.050] Black Singer's father was, I forget the singer's name, some celebrity's name, his father was murdered on some highway and the car was stolen and people were... [01:01:56.730 --> 01:01:57.390] Michael Jordan? [01:01:57.390 --> 01:01:57.450] Michael Jordan. [01:01:57.590 --> 01:01:58.150] That's right, it was. [01:01:58.390 --> 01:02:00.310] Not a singer, I just knew it was some celebrity. [01:02:14.650 --> 01:02:16.930] Michael Michael Jordan's father's car phone. [01:02:17.730 --> 01:02:26.670] And when the police found out there was a car phone in this car, they went right to the cellular carrier and said, Hey, have there been any phone calls recently on this account? [01:02:27.230 --> 01:02:28.690] And the phone company said, Sure. [01:02:30.070 --> 01:02:45.450] Traditionally, I wouldn't say traditionally, but generally speaking, like regular phone companies, cellular phone companies are very willing to provide law enforcement agencies with their information without warrants. [01:02:45.550 --> 01:02:52.210] In other words, I know for a fact in the Philadelphia area that many police officers just call certain contacts. [01:02:52.430 --> 01:02:56.810] It's either Metrophone or about Atlantic Mobile Systems and ask them this information. [01:02:56.970 --> 01:02:57.490] They'll give it to you. [01:02:57.570 --> 01:02:59.490] So there's very little security from that respect. [01:03:00.330 --> 01:03:08.950] If you even are using your cellular phone legitimately and don't want to know that, don't want anyone to know that you're calling certain phone numbers, and don't call from a cellular phone. [01:03:09.030 --> 01:03:18.430] One that can be easily monitored and two, the numbers are readily given out to anyone who calls that is friendly with the great people at the cellular phone company. [01:03:20.190 --> 01:03:25.310] So, anyhow, they traced this to this girlfriend and the girlfriend was pressured and she gave up the guy's name. [01:03:25.430 --> 01:03:28.450] And fortunately, they got the guys who killed this person. [01:03:28.570 --> 01:03:31.270] But anyway, it just goes to show how easy this is done. [01:03:31.270 --> 01:03:36.790] Another example of this kind of surveillance is the O.J. [01:03:36.890 --> 01:03:37.370] Simpson case. [01:03:37.530 --> 01:03:43.010] Now, we had hoped to have someone come with actual audio tapes of the O.J. [01:03:43.150 --> 01:03:49.510] Simpson cellular telephone calls during this little escape route on the highway out in the West Coast. [01:03:49.610 --> 01:03:51.850] But the person who was supposed to come with that didn't show up. [01:03:51.850 --> 01:03:53.310] How about the Prince Charles stuff? [01:03:53.490 --> 01:03:53.850] Do you have that? [01:03:54.890 --> 01:03:55.430] I'm sorry? [01:03:55.610 --> 01:03:56.530] Prince Charles stuff? [01:03:56.650 --> 01:03:57.010] No. [01:03:57.570 --> 01:04:01.490] I heard an excerpt from that on the BBC on shortwave several months ago. [01:04:01.870 --> 01:04:05.610] And I recorded it and I wanted to bring it with me, but I couldn't find the tapes. [01:04:07.950 --> 01:04:08.890] And that was pretty interesting. [01:04:09.030 --> 01:04:22.790] In fact, the specialist that was interviewed on the BBC came to the conclusion that the type of monitoring that was being done of Prince Charles and Lady Diana was not by a typical scanner type user. [01:04:23.290 --> 01:04:33.210] It was their opinion that they listened to the recordings and came to the conclusion that it was probably done by someone at the telephone company or by a government agency. [01:04:33.430 --> 01:04:38.630] Because they were the only people that really had the ability to monitor things as well as they were monitored. [01:04:38.950 --> 01:04:42.790] But that was just conjecture on this expert's part in the BBC, so what can I say? [01:04:44.850 --> 01:04:51.790] So a lot of phones are being... a lot of cellular phone customers are being ripped off from this cloning thing. [01:04:52.270 --> 01:04:55.030] Now, cloning in and of itself I don't think is a bad thing. [01:04:55.170 --> 01:04:57.050] If it's used for fraud, I think it's a bad thing. [01:04:57.230 --> 01:05:04.450] But there are a lot of perfectly legitimate applications for cloning a phone, for taking the electronic serial number and phone number from one phone and putting it into another phone. [01:05:04.450 --> 01:05:09.530] For instance, if I have a phone installed in my car, this is a Motorola... [01:05:10.010 --> 01:05:13.490] In fact, I took the case cover off it so you can see what the circuitry looks like. [01:05:13.650 --> 01:05:15.270] Afterwards, you can come up and take a look at this if you want. [01:05:15.550 --> 01:05:20.450] This is a Motorola typical installed car phone. [01:05:20.610 --> 01:05:23.750] Also, they sell this as a bag phone, like a little carrying bag in your shoulder. [01:05:24.210 --> 01:05:35.270] Unlike the portable phones that are handheld, the car phones and what are called transportable or bag phones transmitted a maximum power for three watts, which is five times greater than 600 milliwatts. [01:05:35.330 --> 01:05:38.950] And that's why sometimes with a portable phone, you get lousy reception in some areas. [01:05:39.030 --> 01:05:47.070] But with the one in the car, you get better results because you have one a better antenna on the car than the little rubber ducky on your portable. [01:05:47.070 --> 01:05:49.470] And you're dealing with three watts of power, just five times more. [01:05:52.750 --> 01:05:54.870] So, these car phones... [01:05:56.170 --> 01:06:09.230] If I have one of these phones in my car and I want to have one in my other car, and I only drive one car at a time, or if I want to get a portable phone now, I would have to go back to my cellular carrier and say I want another phone. [01:06:09.430 --> 01:06:13.730] Or if I bought a phone used from newspaper or something, I'd say I want to get another phone number. [01:06:13.730 --> 01:06:15.390] I want to use this other phone. [01:06:15.650 --> 01:06:16.470] Can I get it done? [01:06:16.630 --> 01:06:18.050] Can I get it set up on the same number? [01:06:18.090 --> 01:06:19.310] I already have an account with you. [01:06:19.410 --> 01:06:24.490] Can I just have this second phone assigned the same phone number and only be using one phone at a time? [01:06:24.790 --> 01:06:26.950] The cellular carriers will not let you do this. [01:06:27.290 --> 01:06:34.350] They would say, well, you have to get a second phone number and pay us another $20, $30, $40 a month for access, even if you don't use that other phone. [01:06:35.670 --> 01:06:49.950] It's analogous to what AT&T would do pre-divestiture and charge you a monthly fee for every phone in your house, regardless of if they were just all the same phone number. [01:06:50.030 --> 01:06:53.950] You can go out to anywhere and buy a phone and just plug it in your house and you don't have to pay any more. [01:06:54.030 --> 01:06:55.010] You're still paying your phone bill. [01:06:56.430 --> 01:07:04.210] I feel, and a lot of people in the hacker community feel, if you're paying your phone bill, why should you have to pay extra just for having more than one phone? [01:07:04.210 --> 01:07:05.990] You're still going to pay for all your calls and your air time. [01:07:06.390 --> 01:07:19.930] So a lot of people, enterprising people have figured out that it's decided it's perfectly legitimate to take phone number out of a phone number and electronic serial number out of one phone and put it in another phone. [01:07:20.270 --> 01:07:33.070] And the difficulty in doing that, the difficulty in applying that is that the cellular system detects that the cellular phone is being used. [01:07:33.070 --> 01:07:37.690] It knows that this phone number, this ESN and phone number is being used at this moment. [01:07:37.890 --> 01:07:52.270] If it detects on the system in another cell site or in the same cell site that another phone with that same serial number and phone number is being used, it's going to... there's some phone company that's going to assume that someone has illegally purloined that number pair and is trying to rip you off. [01:07:52.270 --> 01:07:59.550] So they will... in most areas, there's software installed at the cellular system that can detect this and it'll flag it and it'll shut that phone number off. [01:07:59.730 --> 01:08:06.170] In which case, you'd have to go to the carrier and if you're wise, you'll just say, hey, my phone stopped working. [01:08:06.370 --> 01:08:07.110] What's going on? [01:08:07.310 --> 01:08:12.110] And they would reassign you a new phone number for your phone, which they would program into it. [01:08:12.110 --> 01:08:15.790] And then you'd go home and clone the new phone number into your other phone. [01:08:15.870 --> 01:08:17.290] And just don't make the same mistake again. [01:08:17.390 --> 01:08:20.190] By having both phones on at the same time, it can detect that. [01:08:24.840 --> 01:08:28.400] So, in fact, I tried doing that the other night. [01:08:28.440 --> 01:08:33.640] I'd cloned this electronic serial number and phone number of a Novatel hand-held phone. [01:08:33.760 --> 01:08:35.280] That was one of those that was stolen last night. [01:08:35.540 --> 01:08:37.380] Into a Motorola bag telephone. [01:08:39.020 --> 01:08:40.280] And got it to work. [01:08:40.780 --> 01:08:45.120] And I figured, well, what would happen if actually I had one phone on and I tried to use the other one? [01:08:45.160 --> 01:08:48.940] So I called the 2600 offices on the one phone. [01:08:49.540 --> 01:08:52.820] I called the voicemail system, actually, on my normal phone, which I have an account on. [01:08:53.440 --> 01:08:58.260] And, you know, I was listening to the greeting message on the voice bulletin board. [01:08:58.520 --> 01:09:01.440] Then I called that same number on the clone phone. [01:09:02.700 --> 01:09:05.080] And the call went through on the clone phone. [01:09:05.680 --> 01:09:07.000] Actually, the clone phone was the Motorola. [01:09:07.200 --> 01:09:12.900] I think I called first on the Motorola phone, which – had originally had a different number in it. [01:09:13.360 --> 01:09:18.580] And the phone company assumed it was the Novatel phone because it had, like, Novatel's electronic serial number in the Motorola phone. [01:09:18.760 --> 01:09:19.680] The call went through fine. [01:09:19.740 --> 01:09:20.720] I left it on speaker phone. [01:09:20.720 --> 01:09:33.900] And then I called the voicemail system with the portable phone, and what happened was the call went through on the portable phone, and the other one stopped working as soon as the call started going on this one. [01:09:34.000 --> 01:09:41.500] So I know that on the Atlantic mobile system in Philadelphia, they have software that will immediately shut down the second one. [01:09:41.640 --> 01:09:43.700] So I don't know whether that set up a red flag. [01:09:43.800 --> 01:09:44.560] The phone still works. [01:09:44.720 --> 01:09:48.520] Actually, I won't know tomorrow if it works because I don't own that phone, I don't have that phone anymore. [01:09:48.520 --> 01:09:54.220] But if they shut it off, I'll have to go to them and say, you know, what happened? [01:09:54.640 --> 01:10:08.540] So if anyone is interested in actually doing this, I have provided software on HOPE Net here to allow people to change the electronic serial number of their cellular phone. [01:10:09.540 --> 01:10:21.340] Ostensibly, I'm hoping that they would only put the electronic serial number and phone number of one phone that they're already legit authorized to use into their other phone so they can pay one monthly access fee instead of, you know, a redundant monthly access fee. [01:10:22.620 --> 01:10:26.820] It's on a directory called, I think I said this before, cell soft. [01:10:27.080 --> 01:10:32.440] And the people at the network operations center can help you download that if you're not familiar with how to do it yourself. [01:10:32.780 --> 01:10:34.220] It's about 700k of code. [01:10:34.800 --> 01:10:50.060] I have materials at my table here at the end with all the radio receiving equipment showing you how to make the cable to connect between the cellular phone and your PC to actually accomplish this. [01:10:50.060 --> 01:10:52.160] There are companies that will sell those cables to you. [01:10:52.280 --> 01:10:54.260] Unfortunately, they're not inexpensive. [01:10:54.580 --> 01:11:00.040] But I'll give you the phone number of a company that sells these cables called California Grapevine Communications. [01:11:00.620 --> 01:11:04.300] They're out in Laguna Hills, California. [01:11:04.920 --> 01:11:06.420] Telephone number... [01:11:07.060 --> 01:11:11.580] Oh, they have a toll-free number, 800-457-4556. [01:11:11.860 --> 01:11:12.860] You might want to ask for Greg. [01:11:12.860 --> 01:11:13.540] He's very helpful. [01:11:13.540 --> 01:11:16.520] And he has phones... [01:11:16.520 --> 01:11:22.040] Yeah, again, it's area code 800-457-4556. [01:11:22.440 --> 01:11:30.780] Using the software that's available free on HOPE Net and these cables, you can program various cellular telephones. [01:11:30.960 --> 01:11:36.900] Certain Motorola models, Panasonic, Mitsubishi, some RadioShack phones. [01:11:36.900 --> 01:11:38.580] Now, each phone has a different connector. [01:11:39.040 --> 01:11:41.260] Some phones you can just plug into a connector on the outside of the phone. [01:11:41.280 --> 01:11:43.280] Others you have to attach to a chip that's inside the phone. [01:11:43.600 --> 01:11:45.980] But regardless, you can buy a lot of these different cables from him. [01:11:46.020 --> 01:11:49.220] They vary in price from about $100 up to a couple hundred dollars for the cables. [01:11:49.480 --> 01:11:52.040] You can probably make one for a few dollars in parts. [01:11:52.420 --> 01:11:54.560] And I have that information available at our table. [01:11:54.740 --> 01:11:56.320] Cable diagrams are doing that. [01:11:56.320 --> 01:11:58.500] Oh yeah, our materials, we have the cabling diagrams that are doing that. [01:11:58.700 --> 01:12:06.740] If you're not really a good solderer and haven't ever built any kind of electronic cable before, you might want to be better off buying the cables. [01:12:07.000 --> 01:12:08.480] Because the amount of time you'll be fooling around. [01:12:08.720 --> 01:12:12.140] Because sometimes there's fine connectors you've got to solder and stuff. [01:12:12.200 --> 01:12:15.960] If you're a good solderer, just by all means make it yourself and you can do the whole thing for a few bucks. [01:12:16.120 --> 01:12:17.140] But if not... [01:12:25.720 --> 01:12:26.260] That's right. [01:12:26.980 --> 01:12:29.640] If you've never used a soldering iron before, do not try this at home. [01:12:30.400 --> 01:12:32.220] Because you won't have any luck. [01:12:32.380 --> 01:12:33.920] You're just not going to get it to work, believe me. [01:12:34.360 --> 01:12:42.040] One of the other things I've found is this software is very picky in regards to the parallel printer interface that it interfaces with. [01:12:43.640 --> 01:12:47.040] If you're using a high-speed computer, turn the turbo mode off. [01:12:47.120 --> 01:12:52.380] Or if you can slow the speed down, make it as slow as possible. [01:12:52.620 --> 01:12:56.760] It works very well with the XTs and 286s and 386s. [01:12:56.760 --> 01:13:01.440] But if you want to run it on a 46 or a Pentium, you want to try to slow it down, put it out of turbo mode. [01:13:01.720 --> 01:13:04.560] If you have a laptop that you can change the speed and make it as slow as possible. [01:13:06.140 --> 01:13:06.420] Some... [01:13:08.300 --> 01:13:08.760] I'm sorry? [01:13:10.320 --> 01:13:13.340] I don't have software on the net to allow you to do this for a Macintosh. [01:13:13.860 --> 01:13:14.480] Oh, I see. [01:13:14.620 --> 01:13:14.900] Emulating. [01:13:15.020 --> 01:13:16.560] Well, you would have difficulty doing that. [01:13:16.720 --> 01:13:19.560] You might get the software to run, but you wouldn't be able to get it to interface with the phone. [01:13:19.700 --> 01:13:21.540] Because Macs don't have parallel printer ports on them. [01:13:23.140 --> 01:13:23.500] You'd... [01:13:23.500 --> 01:13:24.580] Well, okay. [01:13:24.860 --> 01:13:25.500] I don't know. [01:13:25.640 --> 01:13:26.240] I haven't tried it. [01:13:26.440 --> 01:13:27.160] I don't have a Mac. [01:13:27.320 --> 01:13:27.940] You can try it? [01:13:28.040 --> 01:13:29.580] You can try it for free, so... [01:13:29.580 --> 01:13:30.060] I'll let you know. [01:13:30.100 --> 01:13:30.600] Oh, great. [01:13:30.740 --> 01:13:31.720] Yeah, I'd appreciate knowing that. [01:13:31.760 --> 01:13:32.780] There's trouble with IBM. [01:13:35.340 --> 01:13:35.700] Exactly. [01:13:36.000 --> 01:13:39.860] That's the trouble with some of the parallel printer ports. [01:13:40.600 --> 01:13:40.960] If... [01:13:41.520 --> 01:13:43.360] There are different types of parallel printer ports. [01:13:43.480 --> 01:13:49.400] Some are one-directional, some are bi-directional, some are faster than others, and so forth. [01:13:50.200 --> 01:13:57.200] And while parallel printer ports are supposed to be standardized, we find there's a lot of variations between different computers. [01:13:57.420 --> 01:14:03.360] I have gone to computer stores, just like computer supermarkets, and bought just standard parallel printer cards for like $10. [01:14:03.980 --> 01:14:05.520] And some of them work, some of them don't. [01:14:05.620 --> 01:14:06.400] I've found no... [01:14:06.860 --> 01:14:09.760] I've even found two by the same model, same manufacturer. [01:14:09.920 --> 01:14:10.780] One worked and one didn't. [01:14:10.960 --> 01:14:13.100] And they worked fine with the printer, but didn't work with the software. [01:14:13.260 --> 01:14:18.080] So you might have to go through a couple of computers and a couple of printer ports before you find one that will actually work. [01:14:18.700 --> 01:14:20.840] But you just have to fool around until you get it to work. [01:14:21.000 --> 01:14:21.960] It's what hacking is all about. [01:14:29.420 --> 01:14:37.900] So I just want to let you folks know, I'm going to put myself on the line here and show you how easy it is to intercept a cellular telephone call. [01:14:38.960 --> 01:14:43.460] I will say that I am not going to do this intentionally. [01:14:43.540 --> 01:14:52.400] I'm going to search for some source of interference that I heard over at the table at my booth that was very close to cellular telephone frequency. [01:14:52.580 --> 01:14:58.360] And if I happen to intercept a cellular telephone call while I'm looking for this interference source, then I'll turn it off pretty soon. [01:14:59.920 --> 01:15:01.520] So you'll have to listen to this. [01:15:02.700 --> 01:15:11.060] And I'll mention, the reason this is illegal is Congress in 1986 passed a law called the Electronic Communications Privacy Act, which... [01:15:11.060 --> 01:15:11.220] Is that a disclaimer? [01:15:11.460 --> 01:15:11.900] I'm sorry? [01:15:12.020 --> 01:15:12.700] Is that a disclaimer? [01:15:12.960 --> 01:15:13.760] You could call it that. [01:15:14.880 --> 01:15:15.940] You could call it a disclaimer. [01:15:16.240 --> 01:15:20.340] In 1986, Congress passed a law called the Electronic Communications Privacy Act. [01:15:21.060 --> 01:15:23.360] And that had a lot of provisions in it. [01:15:23.480 --> 01:15:32.140] One of them, which was heavily lobbied by the cellular industry, to make it illegal to intercept cellular telephone conversations. [01:15:33.100 --> 01:15:36.320] Now, that's a very difficult, if not impossible, law to enforce. [01:15:36.440 --> 01:15:39.800] And I'm against any law that can't be enforced, because there's just no point in it. [01:15:39.880 --> 01:15:41.100] We have way too many laws as it is. [01:15:41.100 --> 01:15:43.420] But it's a ludicrous law. [01:15:43.620 --> 01:15:44.280] We know. [01:15:44.480 --> 01:15:44.800] Okay. [01:15:45.460 --> 01:15:50.260] It's a pretty ludicrous law, because the radio spectrum is... [01:15:50.880 --> 01:15:52.660] It's just radio signals floating all around. [01:15:52.800 --> 01:15:53.480] They're passing through... [01:15:53.480 --> 01:15:58.800] There are hundreds of cellular telephone calls floating right through this room, through our bodies, through our homes. [01:15:59.120 --> 01:16:09.680] And if you have a radio that receives a certain frequency range, and cellular happens to be within that range that it can pick up, then, you know, why shouldn't you be able to pick them up? [01:16:09.680 --> 01:16:11.440] If somebody wants to encrypt them, fine. [01:16:11.560 --> 01:16:12.660] Then they can make it hard to pick up. [01:16:12.760 --> 01:16:14.740] But these are broadcasts in the clear. [01:16:15.160 --> 01:16:28.520] And the cellular telephone lobby wanted to make their customers feel that their conversations were secure by paying off certain politicians to pass a law that would make it illegal to do this. [01:16:28.640 --> 01:16:29.880] Now, it's very easy to do. [01:16:30.200 --> 01:16:31.900] So that doesn't stop anybody from listening. [01:16:32.020 --> 01:16:37.820] If anything, I think this law has probably made more people listen to cellular calls just to find out what all the controversy is about. [01:16:38.680 --> 01:16:40.500] Yeah, it's a common hobby. [01:16:41.440 --> 01:16:48.420] Prior to that law, ever since 1934, it has been completely illegal to listen to any radio frequency. [01:16:48.600 --> 01:16:54.880] That was one of the few... one of the laws that American citizens... one of the regulations that American citizens enjoyed. [01:16:55.060 --> 01:16:57.240] The radio spectrum was free and open. [01:16:57.340 --> 01:16:58.840] Anyone could listen to any signal they want to. [01:16:58.840 --> 01:17:01.400] But now they started censoring the radio spectrum. [01:17:01.680 --> 01:17:05.180] And it is now illegal to listen to cellular telephone conversations. [01:17:05.400 --> 01:17:09.200] It is not illegal to listen to cordless telephone conversations. [01:17:09.380 --> 01:17:15.240] Those in the 46 to 40... from the base station, it's 46 to 47 megahertz. [01:17:15.500 --> 01:17:17.400] They are completely legal to listen to. [01:17:17.660 --> 01:17:18.940] I don't see any distinction. [01:17:19.140 --> 01:17:20.700] I think they should both be legal to listen to. [01:17:20.700 --> 01:17:24.320] So this is what... this is the control channel that we listened to before. [01:17:24.900 --> 01:17:27.160] And then you will hear maybe some interference after that. [01:17:51.340 --> 01:17:52.160] I don't know. [01:17:52.440 --> 01:17:53.880] I don't think it's that big of a deal. [01:18:01.460 --> 01:18:02.900] All right, kids. [01:18:04.080 --> 01:18:05.120] So thanks for calling. [01:18:07.480 --> 01:18:09.200] Yeah, tonight I sleep here. [01:18:09.320 --> 01:18:10.600] I go early tomorrow morning. [01:18:11.440 --> 01:18:12.120] Yeah. [01:18:13.060 --> 01:18:15.340] Now this particular interference was... [01:18:23.680 --> 01:18:26.140] Was probably originating from... [01:18:28.520 --> 01:18:32.160] This is probably the other side of a cellular phone conversation. [01:18:32.580 --> 01:18:35.340] Whereby the person with a cellular phone had a hands-free phone. [01:18:35.440 --> 01:18:43.720] I found that the hands-free speaker phones often only allow you to intercept the other end of the conversation. [01:18:43.720 --> 01:18:45.340] On phones without... [01:18:48.380 --> 01:18:51.480] Without speaker phones, you can often hear both sides. [01:18:51.580 --> 01:18:52.680] And I hear some other interference. [01:18:52.800 --> 01:18:53.600] Maybe this is a different kind. [01:18:54.360 --> 01:18:56.240] Save it, rate it, type in back. [01:18:56.840 --> 01:18:59.380] Yeah, the smoke it, knowing you don't have any money to get bigger. [01:19:03.900 --> 01:19:04.340] There. [01:19:04.460 --> 01:19:13.220] Now if you heard that buzzing noise, that was the cellular system telling that particular phone to change frequencies. [01:19:13.220 --> 01:19:20.560] And the reason it told that phone to change frequencies probably is that person was traveling in a car and getting out of range between one cell site. [01:19:20.720 --> 01:19:28.560] Which cell sites may be just less than a mile in diameter to several miles in diameter depending on how populated the area is. [01:19:28.560 --> 01:19:38.380] So that buzzing noise was digital data being sent at about 10,000 baud to the cellular phone, to the computer and the cellular phone saying switch to this other channel. [01:19:38.520 --> 01:19:43.320] And then if you're driving around a cellular phone, sometimes you hear a drop out for about half a second or a quarter second. [01:19:43.500 --> 01:19:44.140] That's what's happened. [01:19:44.200 --> 01:19:45.000] You've shifted frequencies. [01:19:45.320 --> 01:19:51.980] Now someone listening to cellular phone calls, that's annoying because it's like all of a sudden, where do they go? [01:19:51.980 --> 01:19:56.020] And you might be listening to one conversation and another one will just sort of pop up in the same frequency. [01:19:56.100 --> 01:19:57.700] You wonder why, and that's what's happening. [01:19:58.100 --> 01:19:59.840] There is equipment and software on the market. [01:19:59.960 --> 01:20:04.060] In fact, somebody was supposed to come up with me and bring some of that stuff, but he didn't come. [01:20:05.180 --> 01:20:06.420] That actually... I'm sorry? [01:20:06.880 --> 01:20:07.240] Okay. [01:20:08.400 --> 01:20:15.320] Someone will be putting that software on the net that allows you with the right hardware to track these calls. [01:20:15.320 --> 01:20:18.000] And that's just exactly what was done with the O.J. [01:20:18.100 --> 01:20:18.740] Simpson surveillance. [01:20:19.480 --> 01:20:28.620] Not only are calls very easily intercepted, but the location of the cellular phone can be very easily determined by the cellular carrier as well as in the O.J. [01:20:28.700 --> 01:20:29.800] Simpson situation. [01:20:30.180 --> 01:20:32.460] And the way they do that is their computer system... [01:20:32.460 --> 01:20:39.860] I'll oversimplify this, but their computer system knows which cell site you're communicating through based on the channel that you're on. [01:20:39.860 --> 01:20:41.820] And their system just tells you what cell site. [01:20:41.900 --> 01:20:43.900] And they have to look on their map, which they have on a computer. [01:20:44.000 --> 01:20:45.580] They can just say, okay, he's in this cell site. [01:20:45.800 --> 01:20:46.800] Now he's in this cell site. [01:20:46.840 --> 01:20:47.620] Now he's in this cell site. [01:20:47.860 --> 01:20:52.700] And if it's going in this direction, and that's where the major thrufer is through that area, they can tell roughly where you are. [01:20:52.780 --> 01:20:55.140] They can't pinpoint you down to, you know, a few feet. [01:20:56.160 --> 01:21:01.080] But I imagine as the systems get more sophisticated, they'll be able to tell you where you are probably within a few hundred feet. [01:21:02.360 --> 01:21:05.540] There's new technology out there called GPS, Global Positioning System. [01:21:05.540 --> 01:21:12.780] And eventually, when cellular phones have that built into them as a standard feature, they could probably tell you where you are within 10 or 15 feet. [01:21:13.240 --> 01:21:14.520] Now, I'd like to start taking questions. [01:21:15.040 --> 01:21:15.120] Yeah? [01:21:21.850 --> 01:21:22.410] Mm-hmm. [01:21:23.550 --> 01:21:23.890] Right. [01:21:24.910 --> 01:21:25.710] Mm-hmm. [01:21:33.070 --> 01:21:33.270] All right. [01:21:33.410 --> 01:21:34.310] They could triangulate. [01:21:35.310 --> 01:21:44.990] What he's saying, basically, is they could tell the cellular system to tell your phone to switch to this channel in one cell site, then switch to another channel in a nearby cell site. [01:21:44.990 --> 01:21:54.190] And it can measure, since the cellular system is constantly monitoring the signal strength from your phone for legitimate reasons, so it can know how to adjust the power level on your phone and whether they hand it off to the next cell or not. [01:21:54.390 --> 01:22:05.090] They can compare the signal levels from the surrounding cells coming from your phone and, you know, triangulate more precisely as where you're located. [01:22:05.090 --> 01:22:09.700] So do you agree with the dropouts? [01:22:10.440 --> 01:22:10.860] Yes. [01:22:11.280 --> 01:22:16.560] My guess is that they don't do this on a regular basis because it involves time and effort. [01:22:17.080 --> 01:22:17.780] What do you hear? [01:22:17.780 --> 01:22:23.820] And you would hear the dropouts briefly, but it could be caused for other reasons. [01:22:23.980 --> 01:22:29.800] I mean, if you're right between the borders between two cell sites, oftentimes it'll switch back and forth. [01:22:30.020 --> 01:22:41.200] Kind of analogous to, on FM radio, if you're driving between two cities and there's one station in the other city in the same frequency as the station in the city you left, like both stations, like one will come in and the other one will pop in and it goes back and forth. [01:22:41.480 --> 01:22:46.020] That'll happen with cellular sometimes, so it wouldn't necessarily mean you're under surveillance. [01:22:49.420 --> 01:22:54.360] That's true, or don't use one that has been, has your legitimate telephone number and serial number stored in it. [01:22:54.600 --> 01:22:56.760] And not only don't use it, keep it shut off. [01:22:57.360 --> 01:22:59.940] That's, yes, that's a key point. [01:23:00.940 --> 01:23:06.060] Your phone does not have to be used, be in use for the cellular company to know where you are. [01:23:08.260 --> 01:23:14.340] If the phone is just on, as soon as you turn that phone on, it sends its information to the cellular system. [01:23:15.720 --> 01:23:31.000] And the system can poll you, the cellular operator can, cellular system operator can poll your phone, find out what, where you are just, or whether your phone is on and whether you're in the area, just by doing a quick poll to that frequency. [01:23:39.210 --> 01:23:40.550] Yeah, a lot of... [01:23:40.550 --> 01:23:49.220] That's not really a problem, but as far as changing the shell number of that particular Motorola, where does the problem come in between that? [01:23:49.300 --> 01:23:54.620] Yeah, this person just asked, some cellular phones have the provision for having more than one phone number in them. [01:23:54.620 --> 01:24:01.380] The reason you would want to do that is if you travel between two cities very frequently, you wanted to save money. [01:24:01.960 --> 01:24:04.740] The roaming fees from these cellular carriers are really high. [01:24:04.940 --> 01:24:12.040] Like, it can be as much as $3 a minute if you're from another city and you're using a different city's system. [01:24:12.340 --> 01:24:15.080] They really rape you on these roaming charges. [01:24:15.080 --> 01:24:21.500] It's sometimes cheaper to get service in another city assigned to the same serial number, but it would be a different phone number. [01:24:22.220 --> 01:24:28.200] And ostensibly, if you have a phone that has several phone number capability, you can legitimately have different phone numbers in different cities. [01:24:28.480 --> 01:24:30.920] But he was asking, how do you do this with the software? [01:24:31.140 --> 01:24:39.440] You would still have to change the serial number individually each time you wanted to change, illegitimately change phone numbers. [01:24:39.440 --> 01:24:44.120] If you have a legitimate phone number in this other city, you wouldn't have to change ESNs. [01:24:44.260 --> 01:24:46.820] But you can only do one at a time. [01:24:50.180 --> 01:24:56.060] Some phones have the ability to be activated without ringing. [01:24:56.760 --> 01:24:58.200] Not all phones are like that. [01:24:58.320 --> 01:25:00.680] But that's a particularly scary Big Brother type of thing. [01:25:00.760 --> 01:25:04.320] You could be just driving along and they could hear what you're saying to the person in your car. [01:25:04.480 --> 01:25:07.460] Or listen to what you're listening to on your car radio. [01:25:08.220 --> 01:25:14.300] I've accidentally intercepted cellular telephone calls where I could hear somebody on hold. [01:25:14.880 --> 01:25:17.860] And I could hear them having a conversation with the other person in the car. [01:25:17.900 --> 01:25:19.500] Because the microphone in the phones are pretty sensitive. [01:25:19.660 --> 01:25:21.300] And a lot of these phones are hands-free. [01:25:21.360 --> 01:25:22.540] They have a microphone up in the visor. [01:25:23.280 --> 01:25:29.460] And I've heard some really interesting, by accident of course, some really interesting conversations with people in their cars talking to each other. [01:25:30.880 --> 01:25:31.640] Arguments, whatever. [01:25:51.930 --> 01:25:55.450] Yeah, that's another application for surveillance with cellular phones. [01:25:55.450 --> 01:26:00.530] I could make a phone call on a portable phone like this. [01:26:00.830 --> 01:26:02.550] And just leave it on. [01:26:02.710 --> 01:26:04.850] And sort of hide under the table here. [01:26:05.030 --> 01:26:06.030] And then go home. [01:26:06.170 --> 01:26:11.450] And anything being said in this room with an earshot of the microphone would be transmitted to my home system. [01:26:12.390 --> 01:26:14.210] Now, it would be very expensive to do that. [01:26:15.210 --> 01:26:16.610] Until the battery ran off, of course. [01:26:16.810 --> 01:26:17.770] Until the battery ran off, right. [01:26:17.890 --> 01:26:19.990] If you had it plugged into AC, you could run it even longer. [01:26:19.990 --> 01:26:32.450] But I've heard that law enforcement agencies have equipment that's available to them to allow a cellular telephone to be attached to the underside of a vehicle with a microphone cable being run to the inside of the vehicle. [01:26:32.650 --> 01:26:35.030] And they can just call... a modified cellular phone. [01:26:35.150 --> 01:26:38.590] They can just call this thing and listen to what's going on in your car. [01:26:38.790 --> 01:26:41.290] Now, legally, of course, they'd have to get a warrant to do that. [01:26:41.290 --> 01:26:45.530] But frankly, the number of warrants issued for this kind of stuff is an extremely low number. [01:26:45.870 --> 01:26:49.290] Last year, I think there were only about 140 legal wiretaps. [01:26:50.170 --> 01:26:51.470] Now, those are phone wiretaps. [01:26:51.570 --> 01:26:54.150] But I think other types of surveillance is less common. [01:26:54.370 --> 01:27:00.590] As far as... legal, warranted electronic surveillance is most often done via telephone. [01:27:01.850 --> 01:27:07.510] Like monitoring this way, the legal warrants issued for that sort of thing, it's a very small number. [01:27:07.510 --> 01:27:13.410] Yet, the equipment sold to be able to do this to law enforcement agencies is in the millions of dollars a year. [01:27:13.590 --> 01:27:14.750] The numbers don't add up. [01:27:14.850 --> 01:27:19.550] If all these things... all this surveillance was being done legally, there'd be no very small market for this equipment. [01:27:19.690 --> 01:27:23.750] And millions of dollars worth of this equipment is being sold to law enforcement agencies every year. [01:27:23.850 --> 01:27:24.690] And they keep buying new stuff. [01:27:24.870 --> 01:27:26.230] So, they're using it on somebody. [01:27:26.390 --> 01:27:28.470] And it's anybody's guess as to who? [01:27:35.780 --> 01:27:39.860] Yeah, if you come over to the table, I'll even modify the electronic serial numbers of or... [01:27:39.860 --> 01:27:41.760] Oh, the insecure phones. [01:27:41.900 --> 01:27:44.480] No, I don't know which ones have that ability. [01:27:44.600 --> 01:27:50.040] Maybe you know which phones can be activated without ringing them so you can hear the audio from the microphone. [01:27:55.160 --> 01:27:57.000] Okay, well, the GSM... [01:27:58.000 --> 01:27:58.800] Not GSM? [01:28:00.020 --> 01:28:00.760] Which system? [01:28:01.400 --> 01:28:02.760] Oh, the old analogs... [01:28:03.340 --> 01:28:07.620] Well, the analog system in Europe might be more successful with that kind of thing. [01:28:07.680 --> 01:28:11.420] But I've heard that there are some phones on the American AMP system that have that capability. [01:28:11.680 --> 01:28:12.820] I don't know which ones they are. [01:28:12.960 --> 01:28:13.180] I'm sorry. [01:28:13.620 --> 01:28:19.540] You were specific about when you have two phones cloned and if they're both on and they're not being used. [01:28:19.680 --> 01:28:20.020] And [01:28:24.560 --> 01:28:25.540] what exactly happens... [01:28:25.540 --> 01:28:26.060] Well, you'll... [01:28:26.060 --> 01:28:34.840] The question was if you have two phones cloned with the same phone number, legitimately or illegitimately, and somebody calls that phone number, what happens? [01:28:34.900 --> 01:28:35.540] Which phone rings? [01:28:35.720 --> 01:28:37.480] Well, before that phone... [01:28:37.480 --> 01:28:45.340] Before either phone would ring, you're gonna have a system conflict because the system's gonna see one phone here and another phone there and it won't know which phone to send the signals to. [01:28:45.680 --> 01:28:47.100] So, which channel, whatever. [01:28:47.280 --> 01:28:51.480] Both phones, if they're both in the same cell site, can't be working in the same frequency because the system can't handle that. [01:28:51.660 --> 01:28:54.020] So, odds are... [01:28:54.020 --> 01:28:54.740] I've tried that. [01:28:54.840 --> 01:28:58.780] In some systems, the software will ring both phones but only one will pass audio. [01:28:59.020 --> 01:29:00.460] In other areas, neither will ring. [01:29:00.940 --> 01:29:03.780] In other areas, only one will work and the other one won't work at all. [01:29:03.900 --> 01:29:08.160] So, it really depends on the system's software and what hardware they're using on that particular network. [01:29:08.620 --> 01:29:12.820] It's the last phone that registered itself with the system? [01:29:13.180 --> 01:29:14.800] Okay, there's an answer to your question. [01:29:14.920 --> 01:29:15.660] I've had both rings. [01:29:16.280 --> 01:29:16.800] I'm sorry? [01:29:16.940 --> 01:29:17.720] I've had both rings. [01:29:19.120 --> 01:29:19.860] Oh, you've had them both? [01:29:19.940 --> 01:29:22.280] Yeah, I've had that too, but have you had the audio work through both of them? [01:29:22.940 --> 01:29:23.460] Oh, yeah. [01:29:23.620 --> 01:29:30.680] Okay, I haven't actually experienced that, but I've been able to get both of them to ring, but only one of them would pass the audio, so go figure. [01:29:31.400 --> 01:29:36.600] I imagine there are some systems where that would work that don't have the newer software installed in the cellular system. [01:29:36.600 --> 01:29:37.960] What about the variations of it? [01:29:40.420 --> 01:29:43.160] Hey, do you have your modem processing side of the phone in your PDF? [01:29:44.820 --> 01:29:47.760] Yeah, I would say that it's very easy to intercept. [01:29:47.760 --> 01:29:53.240] It's as easy to intercept data transmissions that are being sent over a cellular modem as it is to pick up voice. [01:29:53.400 --> 01:29:56.540] You would have to hook up a modem or some sort of demodulator to your receiver. [01:29:56.900 --> 01:29:58.540] But, yeah, that would not be very secure. [01:29:59.280 --> 01:29:59.640] Encrypted? [01:30:00.340 --> 01:30:01.280] You mentioned encryption. [01:30:01.720 --> 01:30:04.600] There are products on the market to encrypt cellular conversations. [01:30:04.720 --> 01:30:06.200] In fact, yesterday I talked about the Clipper chip. [01:30:06.200 --> 01:30:10.420] AT&T makes a cellular phone, an AT&T cellular phone, with a Clipper chip in it. [01:30:10.600 --> 01:30:14.360] But, if you heard my thing on Clipper chip yesterday, you probably won't want to use that. [01:30:20.700 --> 01:30:21.060] Oh! [01:30:23.120 --> 01:30:24.860] Okay, I'll do that as soon as I get out of here. [01:30:24.960 --> 01:30:27.600] And it's probably, I'm probably way past my allotted time. [01:30:27.780 --> 01:30:32.880] So, if you have any other questions about this stuff, I'll be at the table at the far end here, near the windows, demonstrating. [01:30:33.580 --> 01:30:35.100] You can play with this receiver. [01:30:35.220 --> 01:30:35.900] Look at the phones. [01:30:36.440 --> 01:30:40.200] You can try to find some interference to cellular frequencies yourself, if you'd like to. [01:30:41.000 --> 01:30:41.360] And, uh... [01:30:41.360 --> 01:30:42.000] Okay, hold on. [01:30:42.420 --> 01:30:45.300] Also, Mark is going to tell us about the Oki 900. [01:30:45.580 --> 01:30:45.700] Yeah. [01:30:45.700 --> 01:30:46.720] We've been here forever, I know. [01:30:46.920 --> 01:30:47.760] But, if you want to hear... [01:30:47.760 --> 01:30:48.140] No, we haven't. [01:30:48.440 --> 01:30:48.840] Keep going? [01:30:49.440 --> 01:30:50.000] All right. [01:30:50.260 --> 01:30:50.920] We'll keep going. [01:30:51.140 --> 01:30:51.860] We're the Energizer. [01:30:52.120 --> 01:30:59.360] Mark has developed some really interesting software and hardware that allows certain phones to do a lot of amazing things that you shouldn't be able to do. [01:30:59.360 --> 01:31:01.600] But, uh, he's going to talk about that now. [01:31:12.220 --> 01:31:12.660] Okay. [01:31:16.000 --> 01:31:16.440] Um... [01:31:16.440 --> 01:31:18.920] I'm going to talk about, um, Oki selling phones. [01:31:21.520 --> 01:31:21.960] Um... [01:31:21.960 --> 01:31:23.420] And, I just have a room. [01:31:24.880 --> 01:31:25.320] Uh... [01:31:25.320 --> 01:31:27.320] This is, uh, Oki... [01:31:27.320 --> 01:31:28.780] Actually, he has a 900 there. [01:31:29.460 --> 01:31:30.620] That's a Oki 900. [01:31:30.980 --> 01:31:34.000] And this one's the 1150, which would be a successor to it. [01:31:34.260 --> 01:31:35.760] And, uh, this was a year ago. [01:31:35.760 --> 01:31:38.460] And the AT&T is, uh, saying yes. [01:31:38.680 --> 01:31:40.540] I have the model numbers up there. [01:31:42.040 --> 01:31:42.560] Um... [01:31:42.560 --> 01:31:45.280] Oki makes the, uh, two AT&T phones. [01:31:45.540 --> 01:31:46.940] The master numbers up there. [01:31:47.040 --> 01:31:49.140] 900 is really, uh... [01:31:49.140 --> 01:31:50.100] We have a 3730. [01:31:50.940 --> 01:31:52.960] And the 1150 is a 3760. [01:31:53.220 --> 01:32:00.280] The AT&T versions of the Oki phones are just a different case, different keypad or something with the inside and the software is all the same. [01:32:01.540 --> 01:32:04.740] Um, AT&T also sells other phones that are made by other companies. [01:32:04.740 --> 01:32:08.060] Um, however, who else makes it? [01:32:09.020 --> 01:32:12.080] Apparently, you know, you could, uh, produce some process for AT&T to sell. [01:32:14.820 --> 01:32:15.220] Um... [01:32:15.220 --> 01:32:15.500] Um... [01:32:16.060 --> 01:32:16.460] Um... [01:32:16.460 --> 01:32:18.880] I just have a chart up there of the phones. [01:32:19.940 --> 01:32:20.340] Um... [01:32:20.340 --> 01:32:26.960] There's also an 800 series, a 1200 series phones that go to the next, which are, uh, car, phone, transportable phones, or whatever. [01:32:27.880 --> 01:32:28.240] Uh... [01:32:28.240 --> 01:32:29.900] And I'll get back to that in a while. [01:32:32.000 --> 01:32:32.360] Um... [01:32:32.360 --> 01:32:32.540] Um... [01:32:32.540 --> 01:32:36.080] I, I bought a Nokia 900 about three or four years ago when it first came out. [01:32:36.820 --> 01:32:44.060] And a few months after I had it, I was at a conference, at the Hackers Conference in Lake Tahoe, and I met someone else who had just bought Nokia 900. [01:32:44.060 --> 01:32:50.100] And he was really interested in, um, and trying to modify the software to add some features and things like that. [01:32:50.720 --> 01:32:56.480] And he already purchased the, uh, Oki technical manual, and is already doing a lot of stuff with the phone. [01:32:57.180 --> 01:33:01.640] Um, so he convinced me to, to work on it with him. [01:33:02.220 --> 01:33:06.760] Yeah, we could install it on the internet, um, back and forth across the internet for a year or so. [01:33:08.500 --> 01:33:08.900] Um... [01:33:08.900 --> 01:33:14.520] And one of the first things we did is, is pulled the ROM out and read, read all the code out of the phone. [01:33:15.160 --> 01:33:24.060] And then, um, uh, my friend wrote a disassemble for it, for, um, the 8051 processor, which is, uh, pretty much what they use in the 900. [01:33:24.300 --> 01:33:25.780] They use a variant of the 8051. [01:33:26.140 --> 01:33:27.560] It's the same instruction set, though. [01:33:29.000 --> 01:33:33.360] Uh, and we also had the, um, schematics for the phone that came from the Oki technical manual. [01:33:34.080 --> 01:33:43.500] And we used the schematics to figure out what, what devices were hooked up to the CPU, and at what, what memory locations and addresses they were mapped to. [01:33:43.640 --> 01:33:46.760] So that we could understand what, what devices the code was trying to access. [01:33:47.920 --> 01:33:53.840] Uh, so we disassemble the code, and if you ever disassemble the code, uh, you don't get much. [01:33:54.080 --> 01:33:55.780] It just turns numbers into letters. [01:33:57.560 --> 01:34:00.780] And, basically, you just get a list of instructions, and still a bunch of numbers. [01:34:01.080 --> 01:34:16.440] So what you have to do is, is go through code, and basically single step through the code in your head, figure out what it's trying to do, and, and then start putting comments in, or, or giving subroutines names, once you figure out what a subroutine does, [01:34:16.860 --> 01:34:21.120] and slowly, slowly you can sort of piece together what's going on in the phone. [01:34:21.660 --> 01:34:26.960] Uh, and the OP has, uh, the 900 had about 40 K bytes worth of code in it. [01:34:27.100 --> 01:34:28.520] So there's, there's a lot of code. [01:34:29.060 --> 01:34:37.600] Um, about, about half of it's, actually, about a quarter of it is, um, test and diagnostic routines that are built into the phone. [01:34:38.300 --> 01:34:48.460] Um, about, about another quarter of it, um, is actually the, the protocol processing for, for doing all the cellular phone, um, protocol. [01:34:48.460 --> 01:34:53.660] And then about half of it's just the user interface, dealing with all the menus and things that Oki has. [01:34:53.720 --> 01:34:54.420] It has a lot of features. [01:34:55.660 --> 01:35:04.580] Um, so, so we really, uh, basically avoided looking at any, any of the user interface code, because that wasn't too interesting. [01:35:04.960 --> 01:35:08.520] And I was mostly interested in the, the test and diagnostics parts of the code. [01:35:09.060 --> 01:35:12.000] And, um, and the protocol handling and stuff. [01:35:13.160 --> 01:35:23.700] And one of the first things we noticed on the schematics was that there was a jack on the bottom of the phone, and there were a few wires there labeled, like, data in, data out, and clock, and some other things. [01:35:25.300 --> 01:35:26.460] Finding out the little jack. [01:35:27.320 --> 01:35:28.780] Almost every phone has a little jack. [01:35:28.940 --> 01:35:37.500] It's usually there for, for hooking up, uh, cigarette lighter adapters for power, or an external antenna, um, and, and also for doing diagnostics or programming the phone. [01:35:38.540 --> 01:35:42.240] Um, so we wanted to figure out how to use this interface. [01:35:42.240 --> 01:35:52.640] And, um, basically, basically what we do is just trace down the schematic where these, these three data lines go, and they just went straight into the processor. [01:35:53.000 --> 01:36:04.640] And then, um, all I have to do is go through all the code in the processor, uh, find the routines that access those IO pins on the processor, and, and try to disassemble them and figure out how they work. [01:36:05.540 --> 01:36:13.300] Um, so, um, and hooked up in the oscilloscope and watched what happens when the phone was turned on, and this and that. [01:36:13.840 --> 01:36:21.800] Uh, so I originally tried to build an interface to talk to the phone to try to start figuring out how it worked. [01:36:22.340 --> 01:36:25.840] Um, and getting connectors to this phone was almost impossible. [01:36:26.620 --> 01:36:32.680] So I sort of hand made some, some little printed circuit boards that, that made contact with the pins. [01:36:32.940 --> 01:36:37.360] And I hooked up to a parallel port and a PC, and, and started experimenting with it. [01:36:37.700 --> 01:36:44.320] And sort of figured out a little what the code was doing, and then I could, I could play with it on the PC and read the code, and slowly try to figure out how it was working. [01:36:44.940 --> 01:36:58.540] Um, and eventually I figured out how it worked, and, and basically what it was ready to do was, um, talk to the CPU and enter diagnostic modes and, and send commands to, to, to do lots of diagnostic things. [01:36:58.960 --> 01:37:02.040] Um, and those would be things like turn the transmitter on and off. [01:37:02.400 --> 01:37:09.620] Um, send signaling tones, send control messages, receive control messages, get, get the signal strength or the battery level. [01:37:10.460 --> 01:37:15.060] Um, all, all the sorts of normal test functions you'd want to do with a radio. [01:37:15.400 --> 01:37:19.840] Um, and also read and write memory locations in the phone, in EEPROM and ROM. [01:37:20.280 --> 01:37:26.340] Uh, and, and you could also access a lot of the, the, um, other chips. [01:37:26.920 --> 01:37:29.660] Such as, uh, the Oki's have a DTMF decoder in them. [01:37:29.860 --> 01:37:32.940] So you could, you could sit there and read DTMF tones. [01:37:33.560 --> 01:37:38.580] Uh, and all these, all these commands are also available through the keyboard in a special test mode. [01:37:38.760 --> 01:37:45.000] You can enter, you can enter by turning the phone on and, and putting in a certain key combination and you can get in a test mode and execute them by hand. [01:37:45.200 --> 01:37:50.080] But it's a lot more useful if you can actually have a computer talking to the phone executing these commands. [01:37:51.200 --> 01:38:04.760] Um, so, uh, up there is a, is a little chart of the Oki, Oki phones, um, and what CPU they use. [01:38:04.760 --> 01:38:06.180] And there's, there's really two CPUs. [01:38:06.300 --> 01:38:13.620] There's these, the 8051-like CPU that's, that's used in the 900 and older 800 series car phones. [01:38:14.020 --> 01:38:21.580] And then there's the Aladdin 50, which is a new phone, and they switched to this Oki processor called an MSM65x227. [01:38:22.400 --> 01:38:28.140] Uh, which is, uh, a pretty gross chip, but it's, it's neat, but it has a really gross instruction set. [01:38:28.500 --> 01:38:33.740] Um, and it, it was kind of based on an 8051, but it's not compatible at all. [01:38:34.040 --> 01:38:41.780] So, one nice thing about the 8051 is that there are a lot of tools available, already available, because it's made, 8051s are made by almost any company that makes chips. [01:38:41.780 --> 01:38:45.880] Um, so there were lots of free assemblers and disassemblers and such. [01:38:46.040 --> 01:38:48.400] And that there was nothing for the 1150 for that new chip. [01:38:49.560 --> 01:38:53.540] Um, also halfway through the 800 series, they switched to this new processor. [01:38:53.760 --> 01:38:57.880] And also now they're in the 1200 series car phones, which, which only use this new processor. [01:38:59.020 --> 01:39:04.540] Um, and then, oh, I'll also have a list of what ROM is in the phone. [01:39:04.540 --> 01:39:13.100] Um, the 900 used a, a 27512-like ROM, but in a, in an SOIC package, a strange package. [01:39:13.660 --> 01:39:20.000] Um, the, the car phones are really nice if you wanna, if you wanna play with a, a phone because they're cheap. [01:39:20.220 --> 01:39:23.220] And they use a normal DIP socketed EEPROM for the code. [01:39:23.220 --> 01:39:29.900] So, uh, one thing I did when I did a lot of development and testing was I plugged an EEPROM emulator into one of the car phones. [01:39:30.100 --> 01:39:33.860] And I could assemble code and dump it into the phone in a few seconds and, and try things out. [01:39:34.780 --> 01:39:40.880] And then every minute it would be simple to take a routine and import it to one of the other phones because the, the code between all the different phones is pretty similar. [01:39:43.840 --> 01:39:52.880] The, uh, in the 900s, they used to socket the ROMs in the early versions and about halfway through the production, they, they switched and started, um, soldering them on. [01:39:53.060 --> 01:39:57.340] And I, I was told it was really because of, um, reliability problems with the sockets. [01:39:57.540 --> 01:39:59.640] SOIC sockets are, are pretty kludgy. [01:40:01.140 --> 01:40:04.740] Um, the EEPROMs are always, all soldered on. [01:40:04.740 --> 01:40:12.720] And in the older phones, with the 8051, it was just a standard 28C64 in a surface mount package. [01:40:13.140 --> 01:40:19.540] Uh, in the newer phones, the CPU chip actually has four kbytes of EEPROM built into the CPU internally. [01:40:19.840 --> 01:40:23.000] So there's no way to access the EEPROM externally. [01:40:23.300 --> 01:40:27.260] You can't, um, you can no longer pull out the CPU and put it in an EEPROM programmer. [01:40:27.620 --> 01:40:30.060] Because the CPU is the only thing they can actually talk to. [01:40:31.980 --> 01:40:33.460] You can't put a clip on it either. [01:40:33.460 --> 01:40:35.420] There's no direct access to the memory. [01:40:35.760 --> 01:40:40.460] The CPU, the CPU has to access code that accesses the EEPROM. [01:40:41.260 --> 01:40:46.580] Um, and, so they, they actually had a really good chance of making a very secure phone. [01:40:46.880 --> 01:40:49.220] They would be very difficult to change the serial number on. [01:40:49.400 --> 01:40:52.280] But they screwed up and left all these neat debug mode commands in there. [01:40:52.900 --> 01:40:56.660] Um, and it turns out it's, it's a much less secure phone than the 900 was. [01:40:56.840 --> 01:41:00.000] It's, it's really trivial to, to go in and modify things like the ESN. [01:41:00.000 --> 01:41:07.260] Whereas on the 900, they, they, um, you either have to pull the chip out or there were some other, simpler ways around it. [01:41:07.340 --> 01:41:08.960] But it involved a little hardware stuff. [01:41:10.520 --> 01:41:10.960] Um, [01:41:21.180 --> 01:41:27.180] that's an attempt at, um, what an internal, what it looks like inside, um, uh, a phone. [01:41:27.180 --> 01:41:32.480] Um, you got your antenna on top and then you have this thing called a duplexer. [01:41:33.000 --> 01:41:37.580] Um, and those, those little F boxes are filters. [01:41:37.920 --> 01:41:48.660] Uh, and what the duplexer does is it lets, it lets, uh, the transmitting and receiving sections of the phone both access the antenna without them interfering with each other. [01:41:48.660 --> 01:41:52.380] So, the phone's transmitting a signal out. [01:41:52.600 --> 01:41:58.020] It goes into the duplexer and the signal only goes out the antenna and doesn't get back into the receive section. [01:41:58.740 --> 01:42:02.020] And it also keeps the, uh, well, that's about it. [01:42:02.200 --> 01:42:09.880] Anyways, the filters, um, on there filter out the, the frequencies so only the, the right frequencies can get through to the phone. [01:42:09.880 --> 01:42:16.680] So, on the receiver, you have, uh, a filter there that only lets in the frequencies coming from the base station. [01:42:17.220 --> 01:42:23.840] So, generally, with a cell phone, you could not receive transmissions from another cell phone because of these filters. [01:42:24.360 --> 01:42:30.820] Um, unless these filters don't work too great or the phone is very near and they can't filter out the entire signal. [01:42:31.700 --> 01:42:36.680] But if it's, if it's a well-designed phone, it, it shouldn't be able to receive, uh, transmissions from another phone. [01:42:38.340 --> 01:42:47.320] So, these signals, um, uh, well, to, to tune the phone, there's a synthesizer there in the middle, uh, labeled synth. [01:42:47.580 --> 01:42:50.960] And, uh, actually in the 900, most phones have two synthesizers. [01:42:51.080 --> 01:42:53.660] One for the receive channel, one for the transmit channel. [01:42:53.920 --> 01:42:56.800] Uh, in the 1150, they figure out a way to do it with one synthesizer. [01:42:57.240 --> 01:43:01.560] Um, and the synthesizer controls these, these two things called mixers. [01:43:02.100 --> 01:43:03.820] Um, I'm not too up on this RF stuff. [01:43:03.820 --> 01:43:10.860] But, they basically up, up convert or down convert the audio frequencies to the right channel that you're gonna transmit on. [01:43:11.860 --> 01:43:20.720] And these frequencies, then, uh, these signals go through this audio processing chip, which, uh, does a few things with the audio and handles, um, the data and signaling. [01:43:20.720 --> 01:43:22.740] Like, there's, there's a modem in, in the phone. [01:43:22.980 --> 01:43:26.520] Not like a modem used for data talking on a, on a phone line. [01:43:26.660 --> 01:43:33.680] But, it's what takes, um, takes handoff messages and control messages from this 10 kilohertz, uh, signaling system. [01:43:33.940 --> 01:43:36.820] And converts it, converts it into a data channel. [01:43:37.440 --> 01:43:49.780] So that data, the data from that audio chip goes, um, attached to the CPU, which can then, uh, read and write, send, basically send and receive data to, to, to, to make calls and follow handoffs and things. [01:43:50.880 --> 01:43:58.220] Um, so, the CPU on, on the Oki either has this external e-prong where all your memories and ESN and everything is stored. [01:43:58.660 --> 01:44:01.240] Or, and it also has, uh, a ROM for the code. [01:44:01.980 --> 01:44:07.780] And then the Okis have a second 8051 in, in both of the Okis that just control the keypad and the display. [01:44:08.180 --> 01:44:14.800] Just, uh, monitors the keypad for presses and, um, listens to what the processor wants to display and displays things on the LCD. [01:44:15.520 --> 01:44:18.540] And there, the two processors are connected up through a little serial link. [01:44:19.680 --> 01:44:25.600] And, and then, um, the main CPU has another set of data lines that go to the jack on the bottom of the phone. [01:44:26.340 --> 01:44:34.980] So, so, besides being able to go into the test modes and stuff, you can also, uh, basically, you can see what's, what's being sent between the keyboard and the display and the main CPU. [01:44:38.680 --> 01:44:52.560] Um, so, um, I had this, I had this real neat interface, uh, and I had this problem, uh, using it with a parallel port because the PC basically couldn't keep up with the data range without losing things. [01:44:52.560 --> 01:45:00.880] So, I built a, um, an interface to a serial port instead, which made it a lot easier, made it usable on, on machines besides PCs. [01:45:01.160 --> 01:45:03.340] And, in particular, my friend wanted to use it on a Sun. [01:45:04.060 --> 01:45:14.300] Um, so, so I built a little, a little board with a PIC processor on it that converts the, this clock, uh, data stream coming out of the Oki into standard RS-232. [01:45:16.680 --> 01:45:20.440] And, then I had this neat interface, but I only had one of them with this really kludgy connector. [01:45:20.820 --> 01:45:25.520] And I really wanted to sell the thing, uh, and I started hunting around for connectors. [01:45:26.080 --> 01:45:29.960] And I tried Oki and, and, um, they, they wouldn't sell me a connector. [01:45:30.100 --> 01:45:30.660] It was proprietary. [01:45:30.680 --> 01:45:33.280] And I called the company to make the connector and they wouldn't sell me one. [01:45:33.880 --> 01:45:41.260] And, um, finally after searching around for about a year and talking to all these manufacturers up, I found, I found somebody who makes accessories who would, who would sell me the connectors. [01:45:41.260 --> 01:45:43.380] And so now I have a good source of connectors. [01:45:44.180 --> 01:45:47.940] And so about a year ago, I was finally able to sell the interface. [01:45:49.920 --> 01:45:51.720] So I have a small box. [01:45:52.540 --> 01:45:53.500] Well, I forgot it. [01:45:53.600 --> 01:45:58.580] But it's a small little 2x2 inch box or so that you can use. [01:45:58.700 --> 01:46:02.280] You plug it into a serial port on a PC and connect it up to your Oki. [01:46:05.700 --> 01:46:08.120] And I also have a bunch of software that goes with it. [01:46:08.200 --> 01:46:09.380] A little programming library. [01:46:09.380 --> 01:46:12.840] It basically lets you access all the test modes and commands in the phone. [01:46:13.420 --> 01:46:14.900] And you can write your own programs. [01:46:14.900 --> 01:46:16.520] And I provide a few sample programs. [01:46:18.980 --> 01:46:21.180] Ah, here's one of my boxes. [01:46:21.940 --> 01:46:24.500] The other one was stolen last night during the Clipper Chips seminar. [01:46:26.200 --> 01:46:27.240] So it's a little box. [01:46:27.420 --> 01:46:28.080] It plugs into the serial port. [01:46:28.220 --> 01:46:29.340] And this plugs into the bottom of your phone. [01:46:36.220 --> 01:46:47.460] And one thing I actually really wanted this for is when I originally got my phone and had it for a few weeks, it was a real pain to type in all the 200, you have up to 200 names and numbers you can store on the phone for people. [01:46:48.200 --> 01:46:50.440] And I filled out this little card and returned it to Oki. [01:46:50.500 --> 01:46:53.660] And I said, please put a serial interface on here so I can upload these from my computer. [01:46:54.980 --> 01:46:57.900] And finally, a year or two later, I was actually doing it myself. [01:46:59.380 --> 01:47:04.100] So, I have a neat program that lets you upload and download all your telephone number of memories from a PC. [01:47:04.340 --> 01:47:05.000] Should you tell it to them? [01:47:06.940 --> 01:47:11.400] Um, I brought some movie to sell here and I'm selling it for $100. [01:47:14.060 --> 01:47:16.500] I have a bunch of them with me. [01:47:16.680 --> 01:47:17.400] You can find me around. [01:47:18.820 --> 01:47:19.220] Um... [01:47:21.120 --> 01:47:22.720] Yes, I sell them in the mail order. [01:47:22.900 --> 01:47:24.240] It's a slightly higher price. [01:47:33.660 --> 01:47:35.080] It's called the CTEC. [01:47:35.200 --> 01:47:37.660] It's the Cellular Telephone Experimenters Kit. [01:47:39.460 --> 01:47:43.520] The kit refers to the fact that it's sort of a software tool kit. [01:47:43.820 --> 01:47:45.160] The hardware is all assembled. [01:47:45.580 --> 01:47:50.480] But I don't provide software for scanning or monitoring. [01:47:51.040 --> 01:47:57.880] I provide a sample source of a program that monitors the control channel and shows you the messages going off the control channel. [01:47:58.140 --> 01:48:14.080] Um, and if you want to hack in something to actually monitor calls and things like that, um, it's, it's trivial five or ten lines of C code to write, to write a program to scan calls, um, get the, the phone number of the mobile and follow handoffs and follow the call through. [01:48:15.300 --> 01:48:15.740] Um... [01:48:15.740 --> 01:48:17.280] It can receive ESNs. [01:48:17.500 --> 01:48:23.620] Um, the phone, like I said before, the phones are only designed to receive what the base station transmits. [01:48:23.620 --> 01:48:27.240] And ESNs are only transmitted by other phones to the base station. [01:48:27.540 --> 01:48:27.620] Okay. [01:48:27.820 --> 01:48:31.560] So the phone normally cannot receive any ESNs. [01:48:31.660 --> 01:48:32.380] It doesn't do that. [01:48:32.560 --> 01:48:36.840] Also, I wrote a program, um, that uses, uh, the interface there that's pretty neat. [01:48:37.200 --> 01:48:40.260] So if you buy an interface, um, find me and I'll give you the program. [01:48:41.020 --> 01:48:42.080] What's your name? [01:48:42.660 --> 01:48:44.600] Oh, me? [01:48:44.900 --> 01:48:45.620] Yeah. [01:48:46.020 --> 01:48:47.520] Um, I'll put it on the screen. [01:48:50.720 --> 01:48:56.560] There are, there are rumors that, that the OK can receive ESNs if you modify the ROM. [01:48:57.080 --> 01:48:59.840] I've, I've never seen a confirmation of that. [01:49:02.800 --> 01:49:10.240] Um, there's, there's rumors about it, there's, there's a small chance it could be possible if the other, if the phone transmitting the ESN was very close to you. [01:49:10.420 --> 01:49:12.140] There might be enough signal that gets through to do it. [01:49:12.420 --> 01:49:13.420] I, I haven't tried. [01:49:14.120 --> 01:49:17.920] Um, I also don't support ESN programming with my kit. [01:49:18.420 --> 01:49:21.960] It's possible you can figure out how to do it, but I don't, I don't, I don't support that. [01:49:28.140 --> 01:49:32.940] So, um, I think that's about it unless there's some questions. [01:49:41.660 --> 01:49:46.380] There, there's a, there's a company called C2 Plus that will clone phones for you for a price. [01:49:46.380 --> 01:49:48.880] However, they, they don't do OOPIs because they want to help. [01:49:49.380 --> 01:49:51.240] I have a telephone number here if you want that. [01:49:51.640 --> 01:49:55.800] Um, uh, C2 Plus, sorry. [01:49:57.400 --> 01:50:03.520] Yeah, uh, yeah, they do, uh, yeah, pretty good. [01:50:03.680 --> 01:50:12.980] Uh, C2 Plus is, uh, area code 2052640264 and ask for extension number 30. [01:50:13.240 --> 01:50:15.980] They will clone a whole lot of different phones for you. [01:50:15.980 --> 01:50:18.740] They vary in price from $150 to a dollar. [01:50:19.380 --> 01:50:21.560] Also, two other companies that, uh, do the service. [01:50:21.720 --> 01:50:26.960] Cellular Phone Clone, 800-819-9979. [01:50:28.000 --> 01:50:33.680] And CelluSoft Technologies at area code 616-399-639. [01:50:33.680 --> 01:50:44.020] All these companies require you to send a copy of your cellular service agreement to prove that you are a legitimate authorized user of this particular electronic shield or phone number. [01:50:44.020 --> 01:50:46.760] We're fully putting that information into a second phone number for you. [01:50:47.100 --> 01:50:47.960] Do you have follow-up? [01:50:48.180 --> 01:50:48.600] Let's throw on. [01:50:48.840 --> 01:50:49.180] Let's throw on. [01:50:49.360 --> 01:50:51.240] Oh, yeah, they're stocking the table. [01:50:51.360 --> 01:51:06.080] Um, one other thing, I actually, I sell a slightly better version of my interface with, with actually some, some really neat scanning software, monitoring software, um, for another company, which markets it to, to cellular companies and a lot of course with the stuff. [01:51:06.080 --> 01:51:14.560] And, uh, for, um, a lot of the cybersecurity is actually using it for fraud, fraud detection and also quality of service monitoring and stuff. [01:51:18.720 --> 01:51:21.060] What does that mean, quality of service monitoring? [01:51:21.240 --> 01:51:33.160] They, they, they are, they use it like they can make a, they call through my interface on a PC and drive around. [01:51:33.160 --> 01:51:38.940] And the PC will log all the handoffs and the power button changes and everything that the phone is going through into the file. [01:51:39.180 --> 01:51:49.340] And then they can go back and review it, figure out if their system, if their cell system is screwed up and told them to hand off to nowhere, or drop their signal straight to those, and the power button lost, and things like that. [01:51:50.860 --> 01:51:58.480] And then they actually, at least in the Bay Area, the GT was using it and they, they found out a whole bunch of problems with their system just by using my interface for a few days. [01:51:58.480 --> 01:52:02.440] The question is, that upgraded version, what capabilities do they have? [01:52:03.380 --> 01:52:09.600] Um, basically a full scanning, all handoffs, you can keep those, you can keep those off the air. [01:52:10.360 --> 01:52:18.580] Um, it also gives you, you can also put a list of people's names and mobile numbers in there, and tell it to just watch for those particular numbers to come up. [01:52:28.540 --> 01:52:31.220] I don't sell it, but that company sells it. [01:52:31.500 --> 01:52:33.840] Well, they sell it to anybody or they sell it to. [01:52:34.640 --> 01:52:39.920] I, I think they're being slightly careful about who they sell it to, but I don't think that... [01:52:39.920 --> 01:52:41.160] Well, see, this is... [01:52:42.340 --> 01:52:45.760] This is your big cast to learn C programming, you're writing yourself for free. [01:52:46.200 --> 01:52:50.840] I think they sell it for, possibly in the $350 to $500 range. [01:52:51.260 --> 01:52:52.340] Sounds kind of high. [01:52:52.500 --> 01:52:55.760] It's a little high, they, um, they're probably going to lower the pricing. [01:53:01.080 --> 01:53:03.400] Uh, you can talk to me later if you want, keep going up. [01:53:03.400 --> 01:53:05.420] Do you get source code to the libraries that don't begin? [01:53:05.640 --> 01:53:10.560] No, you don't get source code to the libraries, it's an object code, it runs on PC, uh, with Turbo C. [01:53:11.400 --> 01:53:15.140] But the problem with that is that you're tying to one operating system. [01:53:15.160 --> 01:53:16.840] Yes, you've got to use it under DOS. [01:53:17.160 --> 01:53:18.920] And it also works on HP-100s. [01:53:20.460 --> 01:53:23.900] I have a, I have a version of the library that runs under some of us also. [01:53:24.320 --> 01:53:26.660] But what if you want to use it on different operating systems? [01:53:27.620 --> 01:53:35.140] If you want to, if you want to try to use it under something else, uh, if there's enough people interested in a particular operating system, they may support it under other systems. [01:53:35.460 --> 01:53:38.800] Or you can, or you can try to reverse engineer my stuff in regular... [01:53:48.320 --> 01:53:53.980] Um, I also have a new version of the interface, a prototype that I'm working on, that, um, is basically just this cable. [01:53:54.140 --> 01:53:57.360] And I built all the electronics into the connector, so it's really, really small. [01:53:57.840 --> 01:54:01.800] And I'm hoping to, um, to be producing those in a month or two. [01:54:01.800 --> 01:54:07.540] What's the coolest thing for where, um, if you had to say one thing to delete? [01:54:08.860 --> 01:54:11.260] Well, there's something you really need with the 1150. [01:54:11.600 --> 01:54:14.100] I, I can tell you about that I'm actually hoping to do. [01:54:14.380 --> 01:54:16.560] It's probably going to take a while, because it takes a lot of time. [01:54:16.860 --> 01:54:22.680] Um, the, the 1150 has this 4K of EEPROM in the CPU. [01:54:22.680 --> 01:54:26.980] And the EEPROM is, there isn't a separate data space or program space. [01:54:27.380 --> 01:54:29.520] All the EEPROM, everything's in the same address space. [01:54:29.900 --> 01:54:37.220] So, it's possible to put code, upload code through the JAP into the EEPROM, um, and then get the phone executed. [01:54:38.140 --> 01:54:43.640] Um, however, you have to have a computer telling, telling your phone, please go execute this code. [01:54:44.140 --> 01:54:52.940] Um, so one, one device I'm going to try to build is, um, we have this, this connector that plugs to the bottom of the phone, without a cable attached. [01:54:53.300 --> 01:54:59.000] And it has a, uh, microprocessor inside it, and an 8K by EEPROM inside, just inside the connector. [01:54:59.400 --> 01:55:01.780] And you can deploy this connector to your phone. [01:55:02.240 --> 01:55:05.620] When you do that, it'll turn the phone on, um, upload a program. [01:55:05.960 --> 01:55:08.420] Which, what I probably write is a complete scanner program. [01:55:08.720 --> 01:55:10.480] Upload the program and the telephone execute it. [01:55:10.760 --> 01:55:14.100] So you have this little teeny plug, and you can plug in any cell phone to an alternative scanner. [01:55:15.420 --> 01:55:18.080] As long as you have that little teeny plug stuck in a wall. [01:55:18.720 --> 01:55:29.580] Uh, are you aware of the code that Spy Supply is selling to, uh, upload to the chip in the Ultimate 900, to turn it into a scanner? [01:55:29.720 --> 01:55:31.500] Do you know if that's a hoax or if you have... [01:55:32.200 --> 01:55:33.820] I don't know about that code. [01:55:33.820 --> 01:55:37.540] But I've heard, I've heard more people talk about it, and I haven't seen anything about it. [01:55:37.620 --> 01:55:39.280] It's built into the NEC theater. [01:55:40.840 --> 01:55:43.500] It's likely it can work, than what people are doing. [01:55:45.920 --> 01:55:51.040] How much do they sell that for? [01:55:51.440 --> 01:55:52.940] I think it's like 500 bucks. [01:56:00.440 --> 01:56:02.540] I think I have zero minutes left here. [01:56:02.760 --> 01:56:04.260] Someone just gave us a few hours ago. [01:56:06.800 --> 01:56:07.820] So, that's it. [01:56:07.900 --> 01:56:09.000] You can see the other information. [01:56:09.460 --> 01:56:10.940] Thank you. [01:56:18.800 --> 01:56:19.680] Thank you.