Cool, I like the esp idea but won't you have to walk fairly slowly with a default ESP antenna? High gain might be better.. If you're wearing a cap you may not care as much being seem from above vs from the front.
Maybe attach a little windspeed meter to the top of the antenna on your hat too ;)
Voting, and participating locally in policy discussions has far greater traction.
The fact is with satellite to cell service online, there is a far greater risk automotive and civilian telemetry meta-data is collected regardless of what people want or do on the ground.
It is naive to believe individuals can affect political policy with gadgets. =3
Glad this one is getting the "second chance" bump back to the front page. It's great content and it's timely. It's a great video.
If you're not inclined to watch the video I'll save you a click to the youtube description and add a bit more detail than the earlier sibling for the devices shown:
Simulacra
"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."
"Wardriving Platform: A Full WiFi & BLE Security Toolkit. A headless wireless security research platform controlled entirely from your phone via Bluetooth. The platform supports dual-band WiFi (2.4GHz + 5GHz), Bluetooth Low Energy scanning and attacks, wardriving with GPS mapping, packet capture, and much more"
"Rayhunter is a project for detecting IMSI catchers, also known as cell-site simulators or stingrays. It was first designed to run on a cheap mobile hotspot called the Orbic RC400L, but thanks to community efforts, it can support some other devices as well."
OUI Spy is cool. I got the pair of earrings for my girlfriend's kid's bday a few months ago. It's fun and disappointing driving around finding all the Flock cameras I hadn't noticed.
>"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."
If they became cheap enough, you could deploy them "permanently" to leave around town. Hang 'em on the same pole the Flock cameras are mounted, or on the ground in one of those hide-a-key things shaped like a rock on the ground near the pole. Just toss one out as you drive by type of situations. It's all solid state, so should be okay being tossed around a bit.
BLE spam tools rely on a handful of specific payload types, Apple Continuity and proximity pairing, Fast Pair model IDs, Swift Pair. Simulacra specifically does not use any of these so it does not cause pop ups on any devices. It also produces WiFi probe requests not just ble signals.
Great video, thanks for posting. Since Meshtastic keeps coming up in the video — if anyone here is heading to Burning Man, there's a dedicated mesh network for the event. I will have a couple nodes running on it :)
I'd love to know how it does. One of meshcore's claims is that it scales better than meshtastic. The 900 MHz band is limited and herding cats without a shepherd is a hard problem. Music festivals are a good stress test.
idk if this is off topic or not because its an ad playing on their channel but wow the non-skippable ad about 'clearing out stuck poop fast' from an ai doctor really added a lot of value to my life before the video rolled. this is what I get for not opening in a browser with ad block. is this what youtube looks like now without ads?
The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesfoce, Google, Microsoft, and Discord to interact with them. It is a disgrace.
Defcon stopped caring about privacy, hacker ethos, and digital sovereignty a long time ago.
Go there if you want to talk to their military recruiters or buy/sale snake oil security SaaS. It is really just another corpocon at this point.
> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them. It is a disgrace.
They have a sign similar to the ones at stadiums or events that say recording is in progress and that by being there you agree to be recorded... being here means you agree... not that there is any enforcement but very flocky and thus ironic.
You have your choice of salesforce, google, or discord to interact with them.
They do not use or support any privacy preserving comms, and thus, they are just a surveillance capitalism marketing village pretending to care about encryption and privacy.
Defcon was always the most government-aligned conference. Historically, BlackHat was Defcon's slightly more counter-culture counterpart/foil. These days, I don't think anti-establishment hackers have any physical conference gathering.
Paying cash is nothing compared to all of the cameras installed in and around the location of the con. Which also means nothing towards the hotels definitely not accepting cash unless you're willing to stay at hotel with the working girls and dealers.
> The "Crypto and Privacy" village at Defcon demands you agree to the privacy policies of Salesforce, Google, Microsoft, and Discord to interact with them.
Do you have a citation for this? I am not seeing anything on their website and they did not come up to me and demand I sign anything when I was there?
Last time I was there the only ways to engage with the community were via slack, google groups, github, or discord. All centralized proprietary surveillance capitalism products, and no decentralized/FOSS options.
Is anyone familiar with the laws surrounding police basically operating their own pseudo cell towers?
I would assume this would be highly illegal for individuals, what sort of hoops did law enforcement need to jump through to get this type of approval? Did FCC need to rubber stamp this?
In general, interfering with a radio link can be hundreds of thousands of dollar fines, and years in prison.
Almost every RF (legal) communication device consumers own will back off broadcasting if it detects collision or interference.
The fact many governments of the past few decades feel entitled to run intelligence campaigns on their own citizens often points to a degenerative despotic trend.
The best plans simply don't require secrecy, and everyone has fun. =3
John Oliver did a piece on this a couple of weeks ago. The videos are not widely available outside of the US, but here's a Guardian write-up [0], and in the UK you can get access to the episode via catch-up if you have Sky Atlantic.
TLDR: the police do this whenever they want, pretty much.
I'm not sure I understand Simulacra. I get the idea, just spam devices around the area in hopes you're lost in the crowd. But anything designed to track you is purpose built to handle tons of devices moving about. Maybe if everyone had one in their pocket we could overload the surveillance devices, but at best you're just bloating their logs.
Seconding this, plus, the original devices stays always visible to the tracker? Does it really matter if there's your sole device in the range, vs always-present yours + ton of noise?
Simulacra is meant to send out signals that look identical to other real signals making it harder to decipher what's real vs what's not. The unique identifiers of those devices show up and never show again once they churn. They have a fresh set of identifiers each time one is produced. Its never going to be perfect but if you can hide the real stuff in a ton of fake stuff it offers a level of obfuscation that otherwise wouldn't be there.
47 comments
[ 0.25 ms ] story [ 38.5 ms ] thread-ESP32 based device that tries to detect bluetooth/MAC addresses of flock cameras and beeps when it does
- a Stingray detector that runs on a second-hand mobile hotspot
- a device that alerts you about things that are moving approximately with you (AirTags, SSIDs, etc).
Is it this thing?
https://simeononsecurity.com/articles/flock-you-detection-pr...
https://github.com/Em3ritus/simulacra
That list reads like a fist year lab schedule. lol =3
https://www.youtube.com/watch?v=fBlAMqoJ5BA
The fact is with satellite to cell service online, there is a far greater risk automotive and civilian telemetry meta-data is collected regardless of what people want or do on the ground.
It is naive to believe individuals can affect political policy with gadgets. =3
If you're not inclined to watch the video I'll save you a click to the youtube description and add a bit more detail than the earlier sibling for the devices shown:
Simulacra
"Simulacra continuously fabricates a churning crowd of plausible-but-fake wireless devices around you — drowning your real devices in noise so that passive trackers, ALPR add-ons, and co-travel correlators can't reliably pick your signal out of the crowd — while passively watching for the trackers that follow you."
https://github.com/Em3ritus/simulacra
---
Biscuit Ultra
"Wardriving Platform: A Full WiFi & BLE Security Toolkit. A headless wireless security research platform controlled entirely from your phone via Bluetooth. The platform supports dual-band WiFi (2.4GHz + 5GHz), Bluetooth Low Energy scanning and attacks, wardriving with GPS mapping, packet capture, and much more"
https://biscuitshop.us/products/biscuit-ultra
---
Rayhunter
"Rayhunter is a project for detecting IMSI catchers, also known as cell-site simulators or stingrays. It was first designed to run on a cheap mobile hotspot called the Orbic RC400L, but thanks to community efforts, it can support some other devices as well."
https://github.com/EFForg/rayhunter
---
OUI Spy
"ESP32-S3 multi-mode surveillance-detection board"
• Foxhunter — single-target RSSI-proximity tracker for radio direction finding
• Detector — multi-target BLE scanner with OUI filtering + web config portal
• PCAP — raw 2.4GHz Wi-Fi packet capture, Wireshark-ready (dev branch)
• BLE Sniff — raw Bluetooth LE advertising capture, Wireshark-ready (dev branch)
• Flock-You — Flock cam detection with GPS wardriving, JSON/CSV/KML export
https://colonelpanic.tech/
https://github.com/colonelpanichacks/oui-spy
"Oh, it's that guy with the bluetooth spammer."
https://xkcd.com/1105/
https://www.burningmesh.org/
Consider yourself lucky you didn't get the outright pornographic ones for boner pills "my husband fucked me 50 times".
Reporting them does nothing. Google does not care.
Defcon stopped caring about privacy, hacker ethos, and digital sovereignty a long time ago.
Go there if you want to talk to their military recruiters or buy/sale snake oil security SaaS. It is really just another corpocon at this point.
What does this look like in practice?
They do not use or support any privacy preserving comms, and thus, they are just a surveillance capitalism marketing village pretending to care about encryption and privacy.
HOPE still exists
MoneroKon and Monerotopia.
Wouldn't you be essentially doxxing yourself by attending?
Do you have a citation for this? I am not seeing anything on their website and they did not come up to me and demand I sign anything when I was there?
https://cryptovillage.github.io/ shows nothing has changed.
I would assume this would be highly illegal for individuals, what sort of hoops did law enforcement need to jump through to get this type of approval? Did FCC need to rubber stamp this?
Almost every RF (legal) communication device consumers own will back off broadcasting if it detects collision or interference.
The fact many governments of the past few decades feel entitled to run intelligence campaigns on their own citizens often points to a degenerative despotic trend.
The best plans simply don't require secrecy, and everyone has fun. =3
TLDR: the police do this whenever they want, pretty much.
[0] https://www.theguardian.com/tv-and-radio/2026/aug/03/john-ol...
https://www.youtube.com/watch?v=gmnL_Y9CsI0