RayHunter - software for passive detection of IMSI catchers

Is the long arm of the law reaching out for you, trying to get a fix on the location of your Librem 5? :scream:

Find out with RayHunter

I just bought one of the Orbic hotspots that it’s fully supported on, will update this thread with more info once I try it out.

https://hackers-arise.com/sdr-signals-intelligence-for-hackers-discover-rayhunter-an-open-source-tool-by-eff-for-detecting-cellular-spying/

6 Likes

The BM818 used by the L5 appears to use a Qualcomm chip (or only a Qualcomm-compatible one?), so it could be interesting to see if RayHunter can be ported to the L5.

I’m not sure it is possible to use a modem for this and for normal operations concurrently however. If not, it would decrease the usefulness of a L5 port…

1 Like

I’ve been wondering the same since the pinephone is listed as a device it has been ported to.

1 Like

Installation to Orbic using linux software PureOS desktop was quick and easy. Pulled up the RayHunter web interface over the USB connection at http://192.168.1.1:8080

Not sure if the Orbic needs at active SIM card to collect data or not. I turned on my Librem 5 cell modem with Tello SIM and RayHunter recorded nothing under history.

Maybe I should take it for a drive around some known Flock camera locations and see if it picks anything up.

1 Like

Sounds like SnoopSnitch for Android.

https://f-droid.org/en/packages/de.srlabs.snoopsnitch/

2 Likes

After some testing I don’t think that Rayhunter will work without an active SIM. I bought my Orbic ‘new open box’, and it did include a SIM but no active data plan.

Informative github issue that discusses issues with Verizon carrier unlock for Orbic as well as inexpensive SIM options. Winner seems to be Telnyx SIMs for $2/mo with 100MB data cap.

2 Likes

From that F-droid page it looks to me like SnoopSnitch is problematic several different ways.

All I can find is their IoT SIM that is $2/month + 7.8 cents per MB up to 100 MB, then each MB starts getting cheaper.

Yes, I saw the “uses a non free network service” and “tracks you” warnings. The former, I think, is from the devs’ own project called GSMMap which is a log of what networks do which things. You’ve got an option to submit your testing results to them.

Either that or the active test function, where the software calls a number that it knows, which in turn sends a silent SMS back for the purpose of finding out whether your phone can detect such things. That’s what the “makes phonecalls” and “answers phonecalls” permissions are for. It won’t do that unless you explicitly tell it to, however.

The “tracks you” bit? That could be from the “submit your data to fill in our network safety map” function, or it could be the bit that lets you submit details about detected IMSI catchers. The tracking information there would be fairly detailed - your physical location, the local cell towers and then the suspect cell tower. That is again optional.

In any case, I personally don’t worry about this thing trying to subvert my phone. The authors seemed trustworthy enough and I imagine that the audience who they gave their talk to would have ripped them apart if they had that kind of intention. This is where they introduced it: Schedule 31. Chaos Communication Congress

1 Like

That must be the one then. I have Telnyx account but have not yet logged into to check the SIM card offerings.

I don’t have an account with them and had a lot of trouble navigating their site, but that would be a huge price difference for what seem to me very similar products, but who knows what they might be thinking. But 100MB/month for $2 does sound too good to be true.

I just ordered 5 of them for $5. If you’re in the US or Canada I’d be willing to mail you a few if you want to test them out.