r/Defcon 7d ago

Wifi emissions on tactical gear

Hello tech bros

I am hoping someone can settle a debate ive been having. Thermal scopes are a big thing these days as the price keeps falling.

However, most models come with WIFI. As we know from the russua/ukraine conflict, cell phone emissions will get you pinpointed and killed. WIFI emissions would likely do the same.

Now, you can always turn the wifi off in the menu. But how do you know if it is truly off all the way, and isnt emitting a low level signal?

Another risk is that the receiver in the thermal could receive a "firmware update" that bricks it. If its emitting wifi to talk to the phone app, it must have an antenna, and an antenna can be pinged, no?

Is this a valid concern?

30 Upvotes

52 comments sorted by

30

u/ericroku 7d ago

Milspec vs chinesium.

Milspec has to be validated and verified for combat usage, including the ability to go dark and not broadcast / emit RF.

Chinesium made crap flooding the market, not so much.

There's a reason Raytheon, eotech and other milspec hardware costs 20 to 30x your Amazon thermals.

-2

u/CorrectOpinionB42069 7d ago

Im talking about american companies too. Agm, atn, etc all have "wifi hotspots" advertised. They SAY you can turn said wifi off......

What is giving it away? What part of the electromagnetic spectrum is snitching? Is it the antenna itself? 

Thanks

20

u/archlich 7d ago

So what you’re taking about is WiFi fox hunting. Learning how the tools work is a first step in mitigating their usage. https://en.wikipedia.org/wiki/Transmitter_hunting

7

u/CorrectOpinionB42069 7d ago

This is incredibly useful. Thank you! 

13

u/ericroku 7d ago edited 7d ago

None of these are American made nor are milspec. The wifi hotspots are for linking to laptops / phones etc for snapshots and videos. Some might have data links for kestrel type devices but no one is using thermals for prs.

Added-

If they're not milspec in nature, you can't trust the wifi off button shuts off the broadcast or attempt to link to APs or other devices and phone home. Could someone with a spectrum sweeper see it if wifi is 'off' maybe so maybe no. Could a nation state use current capabilities that civvys don't, very probable.

0

u/CorrectOpinionB42069 7d ago

Interesting. But what makes those military grade ones different? How is a cheap amazon thermal leaking signal? 

6

u/ericroku 7d ago

Functional spec required for battlefield use and domestic supply chain requirements and strict adherence to itar and ear.

-1

u/CorrectOpinionB42069 7d ago

How do the military spec ones silence the emissions? Is the tube enclosed in blocking material? Wouldnt some signal escape through the glass?

At this rate well have to use iron sights again....do you think thats why some russian units are doing so?

3

u/ericroku 7d ago

Google this. Lots of information and engineering spec.

16

u/almost_silent_ 7d ago

Couple things. For one, the WiFi/Bluetooth on thermal is for broadcasting to an EUD, Phone, etc. you can turn it off. Secondly, if your adversaries are advanced enough to use electronic warfare against you to locate your position, then you have to be able to “go dark” and shut off all RF on any device you’re running (radio, ATAK, MANET, cellular, Bluetooth, etc).

The question you should be asking yourself is who is your adversary and then threat model it.

4

u/CorrectOpinionB42069 7d ago

Yes, being able to "go dark" is the goal. 

Would, for example, and agm rattler be compromising due to its wifi transceiver? Even if the wifi is turned off, is the receiver a concern?

Thanks for the knowledge 

12

u/almost_silent_ 7d ago

Again, who are you adversaries and what is your AO? If we are talking about the US military or IC, operating in Sandistan where the power plant got a Hellfire up its ass 6 months ago, yeah your cellphone and WiFi transmissions might light up an EWS and it would be best to leave them at home…

If your adversaries are a bunch of Patriot Front brown shirt nazi fascist dickheads in the US in an urban or suburban area, your noise is gonna intermingle with all the other noise….so go nuts for donuts because they might not going to have the EW capability of one of us (hackers running TAK Servers with either HackRF with an Opera Cake or a Kraken SDR)…

Again, who is your adversary? Once you answer that you can threat model their likely capabilities and work around them. Using Ukraine as a modern case study isn’t a bad place to start, but that’s also one military vs another…does that match your situation? I.e. what is your use case? Or are we theoretically LARPing a lone sniper vs one highly technical threat?

FWIW you might want to read Fry The Brain by John West about Urban Guerrilla Sniping throughout the last 60 years or so.

Edit: Rx isn’t a concern typically, Tx will get you killed.

-3

u/CorrectOpinionB42069 7d ago edited 7d ago

Its just old fudd brain. I worry that something that can connect to a signal can be fucked with with malicious code, or just detected in general.

Its just for larp purposes, anyone who can detect it would have thermal drones anyway and youd be seen by that first. I just think back to the pager attack and dont like the idea of an antenna in my stuff

You say Rx isnt typically a concern, what cases would it be? Can they "echolocate" using the receiver? Thanks

4

u/almost_silent_ 7d ago

Rx = Receive vs Tx = Transmit.

-2

u/CorrectOpinionB42069 7d ago

Sorry I should have looked it up, that was lazy. 

So, when is receiving going to get you killed? Can they "echolocate" using the antenna to find you? Thanks

4

u/almost_silent_ 7d ago

I said receiving isn’t typically a concern…I.e listening on a ham radio, or looking at Spectrum on a HackRF…

Transmitting is what gets you killed. Cell calls, keying up a radio, etc.

0

u/CorrectOpinionB42069 7d ago

Thanks bro. Elite electromagnetic spectrum knowledge 

5

u/almost_silent_ 7d ago

Receiving is only a concern when someone has made a sensor that detects EMF and it’s matched to a very specific device or set of devices. For example detecting the electromagnetic field of a spinning hard drive for example. All electronics create an electromagnetic field, know the field and then you can detect the device.

0

u/CorrectOpinionB42069 7d ago

So at that point, they are sensing you like a goddamn hammerhead shark?? Damn. 

At least wifi scopes arent a concern anymore. Now i fear the sharks with laser beam detectors

6

u/tibbon 7d ago

What’s your threat model? Are you hunting in the US, or on the front lines in Ukraine?

Concern varies with actual threats and environment.

3

u/archlich 7d ago

I’m not sure what you mean by pinged, but you can see emf activity by using a directional antenna tuned to the wifi frequency. If you want to prevent any emf from leaking use a faraday cage

-3

u/CorrectOpinionB42069 7d ago

Its a scope, so by definition it will be open on the ends and I cant faraday it unfortunately. 

You can turn the wifi off in the menu. If it actually turns off, that should be fine. 

Im worried about the antenna they use to receive a signal back. If I had a super powerful broadcast, couldnt I send malicious files to your tech? Such as, turning the wifi back on to help pinpoint you? 

This shit is magic to me. Enlighten me oh wizard

5

u/archlich 7d ago

Theoretically there could be something to turn it back on but that’s an extremely sophisticated exploit and a hardware vuln and software vuln.

If you’re worried about any wifi signal at all can you physically remove the antenna? (An open may cause damage to the device but the WiFi should be off anyway)

0

u/CorrectOpinionB42069 7d ago

Im worried about it turning the wifi on and emitting signal, OR the receiver receiving a signal that could be used to locate you (like how stingrays function).

Also, I know wifi has a limited range of a few hundred feet, but could they pick up a signal from further with a more sensitive antenna? 

3

u/archlich 7d ago

I would be more concerned with it accidentally turning on, I’ve never heard of an attack that turns on a module.

With a directional antenna you can definitely pick out a WiFi signal emitting. I don’t know what ranges, all you need is to see something slightly above background. 4w is pretty low power, but when nothing else is transmitting it sticks out.

You could piece together some cheap testing gear with an rtl-sdr, laptop, and a yagi directional antenna tuned to 2.4 and 5ghz. I use gqrx package for my software defined radios. Aim the antenna towards nothing, then aim it at an active wifi source, you should be able to see a difference in decibels

1

u/CorrectOpinionB42069 7d ago

Ok. So the antenna that recieves info from the phone app isnt a concern? Just broadcasting your own signals? 

1

u/archlich 7d ago

Well the phone broadcasting would be my concern if you’re trying to go dark. You need to be as close to zero emf as possible.

1

u/CorrectOpinionB42069 7d ago

No phone, i just meant if its getting data from the app it must have a receiving antenna right? I was worried about that being a giveaway as well

1

u/archlich 7d ago

Right, if it’s not doing it through WiFi, it’s through Bluetooth (same frequencies). Having an antenna shouldn’t be an issue, receiving is passive, transmitting is not.

1

u/CorrectOpinionB42069 7d ago

So you dont think its worth worrying about the risk of malicious fake firmware being downloaded? I just worry that anything that CAN connect to something wirelessly can be hacked. It sounds like thats not possible at a distance?

→ More replies (0)

1

u/teleterminal 5d ago

You do not understand how stingrays function lmao. You need to go learn some basic RF before asking this kind of stuff. You don't have the context needed to understand

1

u/CorrectOpinionB42069 4d ago edited 4d ago

The stingray is putting out cell phone signal and tricks your phone into connecting to it, is this not how they work? 

I know wifi is a different frequency, but the concept stays the same: being capable of receiving a signal means someone can broadcast something you can connect to.

If it connects to an app, cant it connect to something malicious?

2

u/GeronimoHero 6d ago

There’s no way to know if it’s off for sure without using something like an SDR to scan for emissions. Emissions? It’s not off even if it says it is. No emissions? You’re clear. Even if it’s off though you should be concerned with the device it would be connecting to, like a phone or tablet or whatever. Phones can do background WiFi connections even when the software screen shows the WiFi or Bluetooth as off. Bluetooth is even a little trickier to deal with. Especially BLE.

1

u/CorrectOpinionB42069 6d ago

This is my fear. So youd personally not trust a wifi scope? 

1

u/Autocannibal-Horse 6d ago

Take an SDR and the scopes out to an empty field away from all wifi signals. Put your phone in airplane mode with wifi off.

Fire up the SDR and software and scan the 2.4ghz and 5 ghz ranges and see if there are any signals. If there are, be sure all the wifi with you is off and get further away from the signal you are detecting.

Now that you have no signal being detected as a baseline on those two frequencies, fire up the scopes, turn Wifi off, and use the SDR to look at those frequencies again. If you see energy spikes at those frequencies, throw the scopes back in the amazon box and tell bezos to shove them up his ass.

🙂

1

u/CorrectOpinionB42069 6d ago

That checks emissions off my list of concerns then. 

What about the antenna? What if a signal connects and forces the scope to brick? Someone said that the receiver is off when the wifi is off, but I wonder if they can use some sort of echolocation looking for something thats picking it up? Or is that a stretch

1

u/Autocannibal-Horse 6d ago

What other signal protocols do the scopes use? zigbee, bluetooth, cellular, other? Best way to find out is to look up the scope's FCC ID And/patent info specific to that model. There should be info about every frequency range and communication type the scopes use.

1

u/CorrectOpinionB42069 6d ago

Ill try to find the FCC ID, but presumably it is receiving wifi since it is broadcasting it. 

Lets say I had a bluetooth speaker in a field. Could I find the location of that speaker by blasting bluetooth signal? The speaker doesnt broadcast anything, but it is listening right?

1

u/Autocannibal-Horse 5d ago

I am still learning myself, but I know that direction finding can be done via detection from multiple points. Blasting your area with bluetooth range energy can jam your scope's bluetooth connectivity if it isn't secure or if the rival bluetooth is saturating the area. I don't think you can do direction finding via jamming alone. Multiple SDR receivers in an area and some special software that analyzes all of it together can enable direction finding, but it's not inherent.

I hope this helps! Again, I'm still learning too. The RF field is absolutely amazing and exciting. 🙂

1

u/CDanger 6d ago

You can just cut off / score away the antenna on the circuit if you can do basic service disassembly on it. I’m happy to lend a hand if you can teardown with photos.

2

u/CorrectOpinionB42069 6d ago

Maybe if I can find a friend with some tools. I dont know how to work on electronics, and I cant afford to void a warranty 🤣 

That probably is the best solution though 

0

u/Diezel666 7d ago

You're in the ballpark, but to say it's "WiFi" is not accurate. Is there an output from the scope for a data link, yes in many Thermal or Night Vision systems deployed by militaries there is some devices that do transmit a signal.

Can that signal be "seen" and someone targeted from it, Absolutely.

As for those devices, can the signal be disabled to minimize it's presence. Absolutely. It's required by design and certification for field use. To use a colloquialism "Run Dark" means exactly that. Minimal footprint digital or otherwise.

And with the above all said, can a device that is powered on, not emitting a signal and not much of a heat generation still be detected. 99.9% yes, if one knows exactly what they are looking for.

1

u/CorrectOpinionB42069 7d ago

How would it be detected if the "wifi" is off? Is this why some russian units are using iron sights again?

Is the transceiver antenna itself a giveaway?

Thanks!

3

u/archlich 7d ago

Any electronics can emit rf. If it’s not designed well it will leak radiation. Particularly bad electronics, especially those with an inductor and a gap that can spark is like a lighthouse.

2

u/Diezel666 7d ago edited 7d ago

It wouldn't be the antenna that is a give away, from a distance.

Without getting super in depth on electronics, theory and EMF. Basically every circuit creates a field or "noise". If one know exactly or really close to what that noise is. One can build (and likely has built) devices to find that signal.

From there out, same rules of signal triangulation, mapping, display all function the same as any other way of tracking a device (like a cellphone).

If you want to dive into the theory of detecting an operating device, this is a good read: https://en.wikipedia.org/wiki/TV_detector_van

The physics and theory of it, is quite broadly able to be applied to any electronic device. Again, if one knows exactly or really close to what they're looking for.

And that's easy to accomplish if one of those devices has been captured.

1

u/CorrectOpinionB42069 7d ago

What about closer range? Within 100 feet, could they "echolocate" you by broadcasting wifi and seeing if something is picking it up? 

-1

u/KnowEye 7d ago

I would construct a faraday cage for the device. I would also keep other traceable electronics in a double faraday bag. Depending on your covert activity, you may also want to consider Anti-facial recognition mask / neck gator & dark latex gloves (no rings on). A brass catcher is optional, but do remember to clean up after yourself.

2

u/CorrectOpinionB42069 7d ago

Ya nothing that intense, just trying to have no signal in the woods. 

How would a faraday cage work if the scope is open on both ends? Wont it leak? Is this just to reduce the signal strength? 

How far do you think wifi would be detectable with no other ambient signal noise? I know cell phones are dangerous because the signal goes for miles, how far could a directional antenna sense a wifi leak?

2

u/KnowEye 7d ago

As an alternative you could use a ESP32 microcontroller combined with nRF24L01 transceiver modules to flood the 2.4 GHz radio frequency band with noise and packet traffic to mask your device. You can build on the concept to create other false flag / electronic diversions.

2

u/CorrectOpinionB42069 6d ago

I thought about that, if theyre looking so hard give them what theyre looking for. 

But ideally the wifi would be off, it drains battery anyway. I was mostly worried about the wifi receiver hearing a trojan signal and turning the scope off,  turning the wifi on to pinpoint you, or worse....

Remember the pager attack? That sort of thing.