It is good to learn that the Nokia 3310 may make a return, albeit with an Android operating system. The nostalgia for these types of mobile phones has clearly not been lost. What it might suggest is that consumers still want a mobile telephone to remain a mobile telephone and to look like one.
The older mobile phones I have in mind though are the ones that are still used in examinations, investigations and research. Since there is nostalgic sentiment in the air I thought you might be interested in some examples of older mobile phones from my lab toolkit.
Now these old buzzards are used for basic GSM telephony services. There isn't a universal SIM that will work with these as some from my collection operate with a 5-volt SIM and so on. Importantly they are used due to the fact they have an external antenna and extendable external antenna. In some investigation instances RSSI will show network detection and a small amount of RF power whereas mobiles/smartphones with embedded antennas show Emergency Calls Only.
You might recall I have written numerous articles on radio surveys and two that may seem appropriate to this discussion are:
CSA: Mobile Phones and Fringe Coverage
http://trewmte.blogspot.co.uk/2010/06/csa-mobile-phones-and-fringe-coverage.html
GSM Radio Test Measurements
http://trewmte.blogspot.co.uk/2010/06/gsm-radio-test-measurements.html
The next selection of mobiles/smartphones each provide different radio characteristics due to the manufacturer's selection of RF chipset and functionality.
My five beauties, as I call them, are my Nokia 3210s. Great phones and they still operate perfectly well today. You can also see in the photo that all bar one mobile have embedded antenna. Some are mobile phones and some are smartphones. Combined they offer the ability for RF surveys and testing voice telephony, data downloads, instant messaging etc. The common laptop application Network Monitor (NMonitor/NetMonitor) still provides good feedback when connected to the Nokia 3210 (nmon activated). Blackberry requires a bit of setting up with applications such as MagicBerry, BBHTool, etc., and creating JAD-files (depending on what you want to achieve). Now with the Samsung models GT-I8160 and GT-I9100 both are used with 2G and 3G networks and illustrates the point that two models of smartphone from the same manufacturer display didn't RF survey details.
Now I wont bore you with an explanation of the details just to say these investigation RF surveys require knowing the various ServiceMode states. In particular, if you are conducting a PRACH and RACH survey, relevant to investigations for Access Requests (e.g. the phone is not in idle mode but seeking a service), then the GT-I9100 is useful in that it displays not just the LAC but also the Cell ID the RACH (access) request was made. Quite a few mobiles do not do this when looking into the ServiceMode states. You have to be quick, mind you, as the ServiceMode screen changes fairly quickly if you are not ready to take a photo.
Yet another, quite old-ish, mobile phone that I haven't shown so far is the Nokia 6303. The photo shown below should explain everything. But for those not familiar to testing and examination; where a charge in the billing appears for an SMS or at least details of a called number sent an SMS (even if sent message is free) it is quite possible the party receiving the message can read it but the message wont be saved. This is known as a Class 0 message (commonly referred to as a Flash Message). Depending on make and model of mobile phone, part or all of the message which is only held in RAM might still be recoverable, provided seizure and examination is undertaken and completed fairly quickly, as RAM is updating perpetually.
The Nokia 6303 is one of those mobiles that the handset manufacturer in combination with mobile network operator enabled this feature as they foresaw revenue generation from it and also recognised that a reasonable memory storage capacity in handset and SIM card need not be blocked up with trivial messages.
The 6303 came with a 940 MB memory card for downloaded applications etc. This proved to be useful in an investigation where text messages didn't have alphabet characters but a series of dots and dashes. At first it was thought this was incomplete text chat messages or some sort of smiley face that didn't form properly when typed on the screen.
When reviewing hundreds of text messages recovered from a mobile or smart phone it is quite easy to overlook or ignore a message as being meaningless. However, I researched the matter and following testing the message turned out to be Morse Code. I tracked down the application for this and cross-checked with the device that had been examined.
So next time you see a text message with an odd presentation look closely to see if it has relevance and whether your mobile phone forensic suite software has the capability to either identify the message contains additional features or can translate the message.
Hope you have enjoyed this brief look at older mobile phones used in and for mobile forensic examination, investigations and research.
Investigations, Practices and Procedures: Seizure-Forensic Examination-Evidence. Cellular and Satellite Telephones, Call Records-Billing Data, Cell Site Analysis. Telecomms. Computer and Network Analysis. GPS devices & Jammers, Cyber, IoT forensics.
Showing posts with label text messages. Show all posts
Showing posts with label text messages. Show all posts
Thursday, February 23, 2017
Secrets and Evidence of Older Mobiles
Labels:
blackberry,
cell site analysis,
embedded antenna,
Ericsson,
evidence,
examination,
external antenna,
investigation,
Nokia,
phillips,
Research,
RF survey,
Samsung,
secrets,
Sony Ericsson,
text messages
Saturday, March 15, 2014
BYOD risks and minefields
I read the article in CIO Think_Deleted_Text_Messages_Are_Gone_Forever_Think_Again and the discussion that rumbles on about BYOD.
Firstly, a bit surprising the article suggests a "wow" factor associated with recovering deleted text messages. I would have thought it was common knowledge by now in business, generally, and particularly at CIO level.
Secondly, the notion and practice of companies getting employees to use their own devices (BYOD) to access company networks and company information seems to be an open invitation to allow a security breach (intentional or by accident) to happen. The corporate body and individual (at senior level) duty of care place encumbent obligations on both to conduct risk assessments, identify company assets, control dissemenation of company information in order to protect. It might be there are legal risks for companies demanding access to employees phones to go through their personal data.
There appears no persuasive technical/technological evidence to support BYOD propagation on the basis without it a company could not operate. Moreover, why require BYOD policies, practices and procedures that in essence generate further and continuing costs to maintain them anyway whereas in-house company devices (properly controlled) also means retention of company assets, devices have an asset value, depreciation allows for write down and tax relief etc.
BTW the points about assets and finance came from a specialist corporate accountant in this area where as accounting is not my forte. Mind you, brain surgery is not my forte either as I could not get any practice in the subject matter due to the patients; there was a shortage of volunteers.
Firstly, a bit surprising the article suggests a "wow" factor associated with recovering deleted text messages. I would have thought it was common knowledge by now in business, generally, and particularly at CIO level.
Secondly, the notion and practice of companies getting employees to use their own devices (BYOD) to access company networks and company information seems to be an open invitation to allow a security breach (intentional or by accident) to happen. The corporate body and individual (at senior level) duty of care place encumbent obligations on both to conduct risk assessments, identify company assets, control dissemenation of company information in order to protect. It might be there are legal risks for companies demanding access to employees phones to go through their personal data.
There appears no persuasive technical/technological evidence to support BYOD propagation on the basis without it a company could not operate. Moreover, why require BYOD policies, practices and procedures that in essence generate further and continuing costs to maintain them anyway whereas in-house company devices (properly controlled) also means retention of company assets, devices have an asset value, depreciation allows for write down and tax relief etc.
BTW the points about assets and finance came from a specialist corporate accountant in this area where as accounting is not my forte. Mind you, brain surgery is not my forte either as I could not get any practice in the subject matter due to the patients; there was a shortage of volunteers.
Tuesday, November 08, 2011
Screenspy program can read texts and emails
The NewScientist online website ran an article on the 2nd November 2011 about new surveillance method relating to a touchscreen spy that reads text and email messages on your smart phone.
"......dubbed iSpy, that can identify text typed on a touchscreen from video footage of the screen or even its reflection in windows or sunglasses. Video from an ordinary mobile phone camera can be used to spy on a person from 3 metres away. And a snoop with a digital SLR camera that shoots HD video could read a screen up to 60 metres away."
"Their method exploits a feature meant to aid typing on small touchscreens: magnified keys. Letters on a virtual Android or iPhone keyboard pop up in larger bubbles when pressed. The program analyses video footage and identifies the letters based on the bubble locations on screen. Pop-ups for neighbouring letters like E and R can overlap, so the program assigns an accuracy probability to each detected letter. The program correctly identifies letters more than 90 per cent of the time.."
Screenspy program can read texts and emails.html
"......dubbed iSpy, that can identify text typed on a touchscreen from video footage of the screen or even its reflection in windows or sunglasses. Video from an ordinary mobile phone camera can be used to spy on a person from 3 metres away. And a snoop with a digital SLR camera that shoots HD video could read a screen up to 60 metres away."
"Their method exploits a feature meant to aid typing on small touchscreens: magnified keys. Letters on a virtual Android or iPhone keyboard pop up in larger bubbles when pressed. The program analyses video footage and identifies the letters based on the bubble locations on screen. Pop-ups for neighbouring letters like E and R can overlap, so the program assigns an accuracy probability to each detected letter. The program correctly identifies letters more than 90 per cent of the time.."
Screenspy program can read texts and emails.html
Monday, August 15, 2011
Research: critiques of author recognition
Research: critiques of author recognition
With the high-profile Olympics less than 12-months away, the recent looting and rioting that involved the use of voicemail, instant messenging and web-based media and the approach to using "cybercrime" as the new-labelled tool to describe digital investigation and evidential seizure of alleged culpability, these research papers cover some useful ground that might be helpful in evaluating methodology previously unsuspected as fallible to error or mistake, and may have some useful application when applied in author recognition cases which might be relevant to evidence found on mobile phones and computers.
Authors vs. Speakers: A Tale of Two Subfields
The best part of Monday's post on the Facebook authorship-authentication controversy ("High-stakes forensic linguistics", 7/25/2011) was the contribution in the comments by Ron Butters, Larry Solan, and Carole Chaski. It's interesting to compare the situation they describe — and the frustration that they express about it — with the history of technologies for answering questions about the source of bits of speech rather than bits of text.
Practical Attacks Against Authorship Recognition Techniques
The use of statistical AI techniques in authorship recognition (or stylometry) has contributed to literary and historical breakthroughs. These successes have led to the use of these techniques in criminal investigations and prosecutions. However, few have studied adversarial attacks and their devastating effect on the robustness of existing classification methods. This paper presents a framework for adversarial attacks including obfuscation attacks, where a subject attempts to hide their identity imitation attacks, where a subject attempts to frame another subject by imitating their writing style. The major contribution of this research is that it demonstrates that both attacks work very well. The obfuscation attack reduces the effectiveness of the techniques to the level of random guessing and the imitation attack succeeds with 68-91% probability depending on the stylometric technique used. These results are made more significant by the fact that the experimental subjects were unfamiliar with stylometric techniques, without specialized knowledge in linguistics, and spent little time on the attacks. This paper also provides another significant contribution to the field in using human subjects to empirically validate the claim of high accuracy for current techniques (without attacks) by reproducing results for three representative stylometric methods.
With the high-profile Olympics less than 12-months away, the recent looting and rioting that involved the use of voicemail, instant messenging and web-based media and the approach to using "cybercrime" as the new-labelled tool to describe digital investigation and evidential seizure of alleged culpability, these research papers cover some useful ground that might be helpful in evaluating methodology previously unsuspected as fallible to error or mistake, and may have some useful application when applied in author recognition cases which might be relevant to evidence found on mobile phones and computers.
Authors vs. Speakers: A Tale of Two Subfields
The best part of Monday's post on the Facebook authorship-authentication controversy ("High-stakes forensic linguistics", 7/25/2011) was the contribution in the comments by Ron Butters, Larry Solan, and Carole Chaski. It's interesting to compare the situation they describe — and the frustration that they express about it — with the history of technologies for answering questions about the source of bits of speech rather than bits of text.
Practical Attacks Against Authorship Recognition Techniques
The use of statistical AI techniques in authorship recognition (or stylometry) has contributed to literary and historical breakthroughs. These successes have led to the use of these techniques in criminal investigations and prosecutions. However, few have studied adversarial attacks and their devastating effect on the robustness of existing classification methods. This paper presents a framework for adversarial attacks including obfuscation attacks, where a subject attempts to hide their identity imitation attacks, where a subject attempts to frame another subject by imitating their writing style. The major contribution of this research is that it demonstrates that both attacks work very well. The obfuscation attack reduces the effectiveness of the techniques to the level of random guessing and the imitation attack succeeds with 68-91% probability depending on the stylometric technique used. These results are made more significant by the fact that the experimental subjects were unfamiliar with stylometric techniques, without specialized knowledge in linguistics, and spent little time on the attacks. This paper also provides another significant contribution to the field in using human subjects to empirically validate the claim of high accuracy for current techniques (without attacks) by reproducing results for three representative stylometric methods.
Thursday, August 07, 2008
Staggering figures for mobile phone text and data usage
Staggering figures for mobile phone text and data usage
.The Mobile Data Association (http://www.themda.org/Page_Default.asp), a not-for-profit organisation, that provides accurate and factual statistics relating to mobile telephone usage in UK, publish their findings month-on-month. Examples of published stats for April and May 2008 (http://www.text.it/home.cfm) identify staggering figures for text and data usage in the UK. Moreover, their latest findings reveal a huge upward spike in text messaging and data-based communications, often at the expense of conventional voice calls.
.MDA Chairman, Steve Reynolds, added "There are powerful signs all around that mobile Internet access will supersede traditional PC access. The MDA predicts that mobile Internet will become a true rival for traditional desktop internet access." Steve Reynolds comments will further underpin how mobile device wireless data communcations are replacing fixed computer systems.
.
UK Figures for SMS Text Messages (Sent):
May 2008 - 6.5 billion
April 2008 - 6.3 billion
.
UK Figures for Mobile Internet (WAP Users):
May 2008 - 16.43 million
April 2008 - 17.46 million
.
UK Figures for Picture Messaging (Sent):
May 2008 - 46.52 million
April 2008 - 47.13 million
.
The UK possibly has, when measured alongside other countries, the most highly developed mobile phone communication usage in the World, or at least in the Western World, and is producing statistics that do not suggest there is a UK or even a global "downturn" or "recession" when it comes to mobile traffic.
.
From an evidental point of view these statistics and trends shine a very bright torchlight on how underfunded the UK criminal justice legal aid system really is, particularly for experts (like myelf) when I am working for the defence, and particularly so in the Captial where most of the technology crimes takes place. Put simply, we could reach a stage in the criminal justice system where technology is wrongly used to accuse an individual or is used in a crime and in such manner that it wont be properly assessed or scrutinised due to underfunding that much crime using the technology goes undetected and unrecognised by the courts thus perpetrators become immune to prosecution also.
Saturday, June 21, 2008
US Court recognises expectation text message privacy
US Court recognises expectation of text messages privacy
Violation the Fourth Amendment
Right to privacy under Art. I, Sec. 1 of the California Constitution
Interesting case, worth reading, as it relates to a Police Office for the Ontario Police Department and others (one said to be a SWAT Officer) who apparenly used work text messaging services to send personal messages unrelated to work.
U.S. 9th Circuit, June 18, 2008 -
Quon v. Arch Wireless Operating Co., No. 07-55282
Users of text-messaging services have a reasonable expectation of privacy in the contents of copies of messages the service provider stores on its network, the Ninth U.S. Circuit Court of Appeals held on June 18, 2008.
Subscribe to:
Posts (Atom)








