"Cell site simulators" Somehow I don't think they'd call it that if I "simulated a law enforcement officer", presented a "simulated identification document", or enticed someone to pay me for a "simulated service", opening mail addressed to my "simulated persona" but not to me, etc. These devices are fraudulently impersonating users' cell service carriers. They are fake cell towers.
I can't really find a statement on that either way. The 3 requirements in this memo do not include such a stipulation, though. (The requirements are to minimize the capture, destroy extra data, and not use extra data.) Part of their operation involves MITM'ing between the phone and the network[0], which probably means the network has not been told it's happening.
Even if they have permission, do you think that's as stringent as it would be if they had to subpoena this from the network? Some agencies are using these things daily, or hundreds of times in a few years, without even telling the courts.[1] The FCC only approved them for emergency use.[2] They are probably not licensed for most of the times they are used, even if the network says OK.
Without carrier permission, they might be violating some type of interference regulations, but I would also think the fake cell device itself and maybe its operator would need FCC licenses regardless of carrier permission. As an Ars Technica post I linked in another comment shows, the cell sites are probably being used outside of the constraints of their FCC licenses.
Comments
"Cell site simulators" Somehow I don't think they'd call it that if I "simulated a law enforcement officer", presented a "simulated identification document", or enticed someone to pay me for a "simulated service", opening mail addressed to my "simulated persona" but not to me, etc. These devices are fraudulently impersonating users' cell service carriers. They are fake cell towers.
They likely operate with permission from the cell service carriers, which would make a big difference legally.
I can't really find a statement on that either way. The 3 requirements in this memo do not include such a stipulation, though. (The requirements are to minimize the capture, destroy extra data, and not use extra data.) Part of their operation involves MITM'ing between the phone and the network[0], which probably means the network has not been told it's happening.
Even if they have permission, do you think that's as stringent as it would be if they had to subpoena this from the network? Some agencies are using these things daily, or hundreds of times in a few years, without even telling the courts.[1] The FCC only approved them for emergency use.[2] They are probably not licensed for most of the times they are used, even if the network says OK.
[0] https://en.wikipedia.org/wiki/Stingray_phone_tracker#Interce... [1] http://www.wired.com/2014/03/stingray/ [2] http://arstechnica.com/tech-policy/2014/09/new-e-mail-shows-...
Do they? Why would the Govt. tell the carriers about it?
Because without carrier permission, they're violating Federal laws administered by the FCC.
Without carrier permission, they might be violating some type of interference regulations, but I would also think the fake cell device itself and maybe its operator would need FCC licenses regardless of carrier permission. As an Ars Technica post I linked in another comment shows, the cell sites are probably being used outside of the constraints of their FCC licenses.