Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices by Matt Blaze (mattblaze@federate.social)

  1. Matt Blaze (mattblaze@federate.social)'s status on Monday, 27-Nov-2023 20:56:41 UTC Matt Blaze Matt Blaze

    Hey! Your tax deductible donations to the Tor Project will be matched 1:1, so now is an excellent time to support privacy and anonymity on the 'net. https://blog.torproject.org/friends-of-tor-match-2023/

    (Disclosure: I'm a proud "Friend of Tor".)

    In conversation Monday, 27-Nov-2023 20:56:41 UTC from federate.social permalink

    Attachments


  2. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:58 UTC Matt Blaze Matt Blaze

    Every few years, I remember that https://ProjectMF.org/intro.html exists, dust off my old blue box/signaling test set, dial in, and stick it to Ma Bell like it’s 1972.

    I no longer have a POTS line, so I had to use a Bluetooth-POTS simulator box with a cellphone. But it works.

    Here’s a quick audio sample I just recorded: https://www.mattblaze.org/audio/ProjectMFsample.mp3

    In conversation Tuesday, 21-Mar-2023 04:54:58 UTC from federate.social permalink

    Attachments


    1. https://cdn.masto.host/federatesocial/media_attachments/files/110/058/558/330/790/216/original/5a3f011a335b8ad3.jpeg
    2. Project MF Introduction

  3. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:57 UTC Matt Blaze Matt Blaze
    in reply to

    Very quick and approximate explanation: Back in the mid-late 20th century, long distance phone trunks used "in band" signaling - audio tones - to send the phone number you were calling to a remote switch. With some trickery (involving sending a brief burst of 2600 Hz during a long distance call), a regular phone user could drop in to this interface and dial a new number, which would conveniently bypass the long distance billing system as well as allow dialing otherwise restricted numbers.

    In conversation Tuesday, 21-Mar-2023 04:54:57 UTC from federate.social permalink
  4. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:56 UTC Matt Blaze Matt Blaze
    in reply to

    This technique - called "blue boxing" for precise reasons probably lost to history - no longer works, and making free long distance calls no longer has the appeal it once did in any case. So ProjectMF is pretty much the only way to play with a blue box today.

    Purists will probably want to build their own blue box, but I enjoy the irony of repurposing an official telco signaling test set to act as my blue box tone generator.

    In conversation Tuesday, 21-Mar-2023 04:54:56 UTC from federate.social permalink
  5. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:55 UTC Matt Blaze Matt Blaze
    in reply to

    My favorite toll fraud arms race story, which I've never seen documented:

    As the blue box era ended in the early 80's with in-band signaling trunks becoming obsolete, a new service started to emerge that would also allow "free" (to the user) calls: 3rd party long distance dial-around networks provided by MCI and SPC.

    You'd dial the local number for the service, enter a 5 digit customer code, and then a 7 digit phone number, which they'd connect you to. This was cheaper than AT&T.

    ...

    In conversation Tuesday, 21-Mar-2023 04:54:55 UTC from federate.social permalink
  6. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:54 UTC Matt Blaze Matt Blaze
    in reply to

    You'd be billed by the company according your your 5 digit customer code. But if you weren't a customer or didn't want to pay for your calls, you could just enter any valid customer code, and the bill would go to them instead.

    So phone phreaks, naturally, tried to find valid codes, mostly by randomly trying 5 digit numbers.

    This was tedious, so someone automated the search using the newly introduced high-tech Hayes autodial modem

    ....

    In conversation Tuesday, 21-Mar-2023 04:54:54 UTC from federate.social permalink
  7. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:53 UTC Matt Blaze Matt Blaze
    in reply to

    The search software would dial one code after another until it found one that worked, which it would then log. But how did it distinguish working codes from non-working codes? Working codes would successfully complete a call, and non-working codes wouldn't.

    The code-scanning software would use each code under test to attempt to dial a modem dial up. If the code was valid, the Hayes modem would report "CONNECTED", effectively telling the software that it found a valid code.

    But...

    In conversation Tuesday, 21-Mar-2023 04:54:53 UTC from federate.social permalink
  8. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:51 UTC Matt Blaze Matt Blaze
    in reply to

    That only briefly stopped the phreaks. They just modified the software to dial a NON-modem number, and would recognize a code as valid if the Hayes modem *didn't* connect.

    Eventually MCI and SPC had to make the codes longer.

    Anyway, that was a cute example of an arms race that I watched in real time as it happened circa 1980.

    In conversation Tuesday, 21-Mar-2023 04:54:51 UTC from federate.social permalink
  9. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:51 UTC Matt Blaze Matt Blaze
    in reply to

    This made scanning for codes very easy. You could just set the software running overnight, and in the morning, you'd have a bunch of new valid codes to use and share.

    But MCI and SPC caught on....

    Their solution: Include the sound of a modem answering a call at the end of the "invalid code entered" recording. This made the software think that every code was valid, effectively rendering it useless. Clever countermeasure!

    Except...

    In conversation Tuesday, 21-Mar-2023 04:54:51 UTC from federate.social permalink
  10. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:49 UTC Matt Blaze Matt Blaze
    in reply to

    Not long afterward, I was on the other side (sort of), at Bell Labs.

    In conversation Tuesday, 21-Mar-2023 04:54:49 UTC from federate.social permalink
  11. Matt Blaze (mattblaze@federate.social)'s status on Tuesday, 21-Mar-2023 04:54:48 UTC Matt Blaze Matt Blaze
    in reply to

    PS on the phone phreaking era. None of it was really about making free calls. It's hard to overstate just how fantastically *empowering* it felt to discover this secret way into the phone network, with the ability to route your voice all over the world, dial numbers no one else could call, and generally explore apparently uncharted territory. And then to discover others who found their way in to, like membership in a secret society. All before the Internet.

    In conversation Tuesday, 21-Mar-2023 04:54:48 UTC from federate.social permalink
  12. Matt Blaze (mattblaze@federate.social)'s status on Thursday, 29-Dec-2022 01:16:30 UTC Matt Blaze Matt Blaze

    "What does this button do?"

    -- Elon Musk, about an hour ago.

    In conversation Thursday, 29-Dec-2022 01:16:30 UTC from federate.social permalink
  13. Matt Blaze (mattblaze@federate.social)'s status on Saturday, 26-Nov-2022 14:00:34 UTC Matt Blaze Matt Blaze

    I’m getting an unreasonable amount of enjoyment out of this early holiday present I got for myself. (From traintrackr.io, which I believe is having a sale.)

    #nerd

    In conversation Saturday, 26-Nov-2022 14:00:34 UTC from federate.social permalink

    Attachments


    1. https://cdn.masto.host/federatesocial/media_attachments/files/109/395/376/845/428/417/original/758ca965b6b59c30.jpg

User actions

    Matt Blaze

    Matt Blaze

    Scientist, safecracker, etc. McDevitt Professor of Computer Science and Law at Georgetown. Formerly UPenn, Bell Labs. So-called expert on election security and stuff. https://twitter.com/mattblaze on the Twitter. Slow photographer. Radio nerd. Blogs occasionally at https://www.mattblaze.org/blog . I probably won't see your DM; use something else. He/Him. Uses this wrong.

    Tags
    • (None)
    ActivityPub
    Remote Profile

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          35232
          Member since
          26 Nov 2022
          Notices
          13
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • Privacy
          • Source
          • Version
          • Contact

          Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.