Proton Profile picture
Jun 25 12 tweets 2 min read Read on X
A defence contractor has figured out how to track you without ever needing your name, face, or numberplate.

The product, SignalTrace, instead listens to the devices you're carrying, and their sensor clips onto existing cameras your city has likely already got mounted.

1/12
Its full name is ELSAG SignalTrace, made by Leonardo.

The product page subheading is, verbatim: "Identify Suspects by the Electronic Devices They Use."

In surveillance tech this is actually refreshingly honest.

They aren't even trying to hide it.

2/12
The honest truth is that you don't need to know who someone is to track them.

You just need a combination of things they always carry that nobody else does.

70 cars might have an iPhone; only 1 has this iPhone + an Audi head unit + specific Bose headphones + a Garmin.

3/12
That precise constellation, seen together at the same timestamps in the same places, is always you.

It works because every device you own shouts a stable-ish identifier into the air whether you asked it to or not.

Bluetooth, Wi-Fi requests, RFID, the radios in your car.

4/12
No hacking.
No decryption.
Just listening & storing.

And because it logs which signatures travel together, it surfaces devices frequently near yours. Leonardo calls this "detecting convoys."

Read that as: who you commute with, who you live with, who you keep meeting.

5/12
Here's the genuinely significant bit: SignalTrace doesn't need new poles, new contracts, or fresh public approval.

It clips onto ELSAG cameras agencies already bought and already mounted.

Any department running them can switch device-tracking on without a new procurement.

6/12
The @EFF has a name for this: mission creep.

Infrastructure approved for one thing quietly grows into another, and the second thing never has to face the vote the first one did.

Cameras approved to read plates can now log every device that drives past them.

7/12
Leonardo's reassurance is that SignalTrace doesn't decrypt your messages.

This is true, & irrelevant.

Nobody building a movement-tracking system needs your texts.

They need to know a unique bundle of radios was on this corner at 8:14am. Metadata was always the product.

8/12
They also say data is only accessed "when a crime occurs."

Notice what that governs: access, not collection.

Everyone's signatures get swept up regardless. The promise is only about who opens the box afterward, not whether to fill it.

And that box is filled to bursting.

9/12
What you can do:

- Turn Bluetooth and Wi-Fi off when you aren't using them. Radios that aren't on aren't broadcasting.
- Check MAC randomization is enabled.
- Audit the silent stuff: tile trackers, tyre sensors, dash cams, head units advertising to nobody.

10/12
A Faraday pouch can help, but research the product... most are marketing fluff with very little upside.

The real fight isn't personal hygiene though. It's whether your nearby agency can bolt this onto existing cameras without a vote.

That's a local council question.

11/12
The thing about this development is that not much has really changed.

What they've done is taken all manner of signals that are hanging around and pieced them all together.

A network built to see cars just got upgraded to recognise the people inside them. Not good.

12/12

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Proton

Proton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @ProtonPrivacy

Jul 16
Ever wondered why televisions all of a sudden became "smart?"

The advent of the TV-as-a-computer has enabled all kinds of functionality; but with this, our content delivery systems have become real-deal black mirrors.

Let's take a look at how your TV watches YOU...

1/15
Devices like Pi-Holes allow you to more-closely monitor the calls which different devices on your network are making.

One such setup, resident in a Proton employee's house, discovered their TV was making thousands of calls home per hour, to all manner of places.

2/15
Here is the part that stings.

They don't use a single smart feature on it. Never signed into its app store. Everything they watch comes off their own home media server.

The TV was doing no work they asked for, and a second job nobody agreed to, 1000s of times an hour.

3/15
Read 15 tweets
Jul 9
Concerned about malware on your Android device?

Don't worry, we've put together a practical guide that walks you through how to root it out and remove it.

Your first instinct might be to download some kind of software. Don't.

Follow our steps instead...

1/21
We're going to give these instructions as if you had a Pixel running Android 16.

Steps are the same on other Android devices (10-15) but there may be small differences in how things are labelled.

In particular, Samsung devices will have sizeable changes to path labels.

2/21
Step 1: Run a Play Protect scan

Play Protect automatically runs malware scans, but some disable it accidentally.

- Open Play Store
- tap profile icon
- tap Play Protect
- tap Settings
- turn Scan apps with Play Protect ON

Then repeat the first three steps and press Scan.

3/21
Read 21 tweets
Jun 29
Most privacy advice tells you to add things. A VPN, a blocker, another extension, another subscription.

Here's one that works the other way: delete the surveillance machine entirely.

It's 29 years old, free, and many people think it died in 2013.

It's RSS.

1/9
To see why RSS is private, you first have to see why everything else isn't.

Your timeline, your For You page, Google Discover: push systems. The platform picks what you see, and to do that well it has to model you.

The surveillance isn't a side effect here. It's the point.

2/9
RSS is the opposite: pull, not push.

A site publishes a plain list of its recent posts. Your reader checks it and shows you what's new... in chronological order and from sources YOU chose.

Nothing decides what's "relevant." You're the algorithm.

3/9
Read 9 tweets
Jun 10
Researchers just unveiled FROST (fingerprinting remotely using OPFS-based SSD timing), a technique that exploits your SSD's timing to silently detect every site and app you have open.

No clicks.
No interaction.
Just visit a page.

Let's have a look at how it works...

1/7
FROST uses a contention side channel, looking at the interaction of various processes which are using/competing for a given resource.

Measuring input/output operation timings of an SSD, researchers determined the websites which were open in other tabs, even other browsers.

2/7
They could also sus out the open apps on visitors' devices.

Many companies have developed sophisticated applications which run in browsers.

This level of convenience for the user also creates new attack vectors, as browsers become way more than tools for viewing pages.

3/7
Read 7 tweets
Jun 2
Pretty much everyone wants to track you.

The Electronic Privacy Information Center just dropped a report on the 8 Manipulative Design Patterns in Opt-Out Processes.

It analyzes how 38 platforms make it difficult for you to exercise your rights.

How many do you know?

1/10
1. Failing to provide a clear mechanism to opt out of sale and sharing of personal information.

Six companies had a privacy form on their websites, but it didn't contain a choice to opt out of these processes.

This was particularly pronounced with "people search" sites.

2/10
2. Not clearly linking opt-out forms from the homepage and/or the privacy policy.

At least 15 companies (including Google, Meta, OpenAI, & Anthropic) did not clearly link opt-out forms from these pages.

Holding onto data by making things difficult to find or understand.

3/10
Read 10 tweets
May 14
DeGoogled Android user?

Google's next-generation reCAPTCHA, presented to desktop users, prompts you to scan a QR code.

The catch? Google Play Services have to be enabled in order for it to work on these devices.

Let's dig in to what has changed, and possible solutions...

1/7
This should be a familiar sight to anyone who has used Google search, or just encountered a website with Google's reCAPTCHA.

Resources are walled off and a 'challenge' is issued.

If you solve the puzzle (identify cars, bicycles, stairs, whatever) you can carry on.

2/7 Image
Google's new reCAPTCHA, however, presents the user with a QR code, requiring they scan it in order to advance to wherever they're going.

On iOS devices, even old versions, this is a simple process.

On Android devices, it will not work without Play Services v25.41.30+.

3/7 Image
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(