Category Archives: Security

Leonardo SignalTrace: I called it in 2010 and Certain People Listened

Leonardo’s SignalTrace is getting picked up in the 2026 news cycles as a shocking novelty in capability: a roadside sensor that sweeps device identifiers from passing cars and ties them to license plates, an “unholy ALPR/Stingray hybrid”. The product page itself quietly suggests this is anything but new or novel. It still carries the old name, EOC Plus, its patent announced back in May 2024. More to the point, for those involved in investigations over the last quarter century, the emissions being harvested were installed in your car layer by layer the whole time, arriving under any name other than surveillance.

I hate using the word receipts, but in this case I have a lot and it’s a bit annoying to see novelty attached to an old worn out theme. Some of this is unmistakably my fault for not being a better self-promotion artist.

Year Layer What shipped
2000 Safety law TREAD Act (Pub. L. 106-414) follows the Ford/Firestone deaths, mandating tire pressure monitoring and tire serialization. One scandal, two future beacons.
2002–2003 Military logistics DoD in-transit visibility runs on active 433 MHz container tags. Wolfowitz’s office and Walmart issue passive RFID supplier mandates. Michelin announces transponders embedded in the tire itself, serial number associated to vehicle records.
2005 Consumer scanning AirMagnet ships BlueSweep, a commercial Bluetooth scanner, covered here at the time. Passive capture of Bluetooth identifiers enters general public use.
2006 Insurance accreditation Auto-txt binds the owner’s phone Bluetooth to Jaguar and Land Rover as anti-theft, Thatcham Category 5, “supported by the police.” I flagged the design at the time. The phone-to-vehicle binding SignalTrace now reads from outside was engineered as a security feature.
2007 Safety mandate FMVSS 138 reaches full compliance after Public Citizen v. Mineta forces direct sensors. Every new US passenger vehicle broadcasts unencrypted unique sensor IDs at 315 or 433 MHz.
2009 Crowdsourced probes Google launches crowdsourced traffic with a stated architecture: consent, aggregation, trip endpoint deletion, opt-out. Four controls treated as the minimum for touching movement data.
2010 Traffic engineering I wrote up BlueTOAD, roadside Bluetooth MAC harvesting sold to transportation departments, and named the path: “The collection of BlueTooth information then also can be tapped by law enforcement.” The same year Rouf et al. demonstrated TPMS tracking at USENIX Security. My test of Google’s traffic API monitored the movement of a single phone, against the stated design.
2011 Retention visible Malte Spitz sues Deutsche Telekom and publishes 35,000 location points from six months, covered here with BlueTOAD named in the comments as tracking that needs no provider relationship at all.
2014 The defense ships Phone MAC randomization deploys industry-wide, the mitigation sketched in the 2010 post. Cities keep buying sensors anyway: Denver runs about 200 BlueTOAD units and concedes “you can’t opt out.”
2024 The patent Leonardo announces ELSAG EOC Plus, electronic device signatures for identifying people of interest.
2026 The rebrand EOC Plus becomes SignalTrace. The brochure lists asset tags, pallet transmitters, tire pressure sensors, and pet microchips as tracked device types. The press covers it as year zero.

The individual-movement capability that I demonstrated as a flaw in 2010 is the exact capability Leonardo now sells as the product. The pattern should be obvious when you look at the columns. Four separate channels were used to establish emissions for surveillance:

  1. Safety mandate
  2. Logistics mandate
  3. Traffic engineering budgets
  4. Insurance accreditation

Each had its own procurement path. Each was “voted” on, if at all, as something that was definitely not called surveillance. For a trip down memory lane, NHTSA’s first rule in 2002 permitted indirect TPMS (wheel-speed inference, no radio). Michelin then made an embedded transponder announcement January 2003 with tire ID associated to VIN. The Second Circuit vacated NHTSA’s rule in Public Citizen v. Mineta (2003) for failing the TREAD Act’s safety standard, and the 2005 replacement rule effectively required direct sensors, full compliance for new passenger vehicles by September 1, 2007. So a “safety” law forced four radio transmitters onto every new American passenger vehicle, after the tires themselves were already being serialized against VIN. The sensor IDs are 28 to 32 bit unique identifiers sent in the clear, and a Rutgers/USC team proved trivial tracking and spoofing at range in 2010 (USENIX Security), so the proof-of-tracking is at least sixteen years old.

The military supply chain layer in Leonardo’s own brochure is what I worked on around 2002 as well, based on mid-1990s technology used in American operations in Somalia, for just one example: “pallet transmitters” appears in a police product manifest because the 2003 tags kept working long after anyone remembered why they were there.

The fingerprint is what I remember from the 2010s, because a collection of signals became so important to investigations. Leonardo’s example customer profile is an iPhone, an Audi radio, Bose headphones, a Garmin watch, a key finder, and plate ABC-1234. That ensemble exists as a product precisely because consumers became oriented around the per-device defense marketing, rather than a unique combination of devices as their fingerprint.

I was interviewed on AM radio in San Francisco sometime around 2013 on this risk, to give you some idea of what population was interested. I had to explain to a very non-technical audience why Bluetooth MAC rotation limitations were important, yet still within the bigger problem of having a graph of Bluetooth devices.

In one case, investigators tracked a specific number of Bluetooth signals (suspect headset and phone, accomplice headset and phone, vehicle devices) regardless of their MAC. In another case, investigators interrogated the RFID embedded in the vehicle’s tires, reading serial numbers the owner had no idea were remotely readable for tracking him.

Reading any passive RFID requires the roadside units to transmit and energize the tag. Their directional panels are questioners, meaning the compelled-response side of the line no court has drawn, closer to a cell-site simulator than to a camera. The hardware has an FCC equipment authorization somewhere, meaning an ID lookup on that unit would establish what bands it actually transmits and receives on.

Phones learned to rotate their addresses in 2014, after the risks of no rotation hit Apple product management and they decided to do something about it, shipping randomization in iOS 8. For what it’s worth, investigators had for a decade before that been dealing with UNIX systems rotating MAC (GNU macchanger was registered December 1, 2002). What Apple conveniently didn’t mention is your headphones, your car radio, your tire sensors, and your key finder usually still don’t and probably won’t ever rotate. The countermeasure to the Bluetooth identifier rotation was immediately correlation across everything connected that doesn’t rotate. This kind of correlation including “heatmaps” has been security marketing catnip since the mid-2000s SIEM era, rebranded “big data” a few years later.

Note also what the new Leonardo SignalTrace marketing brochure omits: cellular. That means this is NOT Stingray. Not even hybrid Stingray.

Bluetooth, Wi-Fi, and RFID sit in the spectrum where interception law, CALEA, and the pen-register framework are suspiciously quiet. The sensor manifest is very clearly curated to unregulated bands. Band selection is the legal strategy, which is exactly what I used to warn about at BSides, BlueHat, and a bunch of other conference presentations over the years.

At the end of the day, remember tires were serialized before the sensors were required to emit them for surveillance, and many emission layers have landed on top since then. This is the kind of record that has been public the whole time, and definitely not being ignored by those paying attention. The news cycle just has such a short memory, with experts choosing to remain quiet, and these vendors count on it.

Related from 2019:

Hearings, Reports and Prints of the Senate Committee on Appropriations, Volume 89, U.S. Government Printing Office, 1966, p 33

The Disgusting OpenAI Angel Food Cake of Black Hat

OpenAI’s security and safety staff used their Black Hat presentation to disclose that the company’s own evaluation agents had breached Hugging Face and OpenAI’s internal infrastructure end to end. The company framed the disclosure as a public service and a watershed for the field. Set against the historical record, the conduct it describes belongs to a documented category. An institution produces or stages a harm, and it directs its effort toward exhibition, competitive advantage, or management of the account, in place of a preventive measure it held in hand.

The measure was foreseeable.

The harm was foreseeable.

What follows measures the OpenAI case against its precedents.

The documented pattern

The following are settled matters of record. In their own day, each was what OpenAI says they are now.

P.T. Barnum’s career began with Joice Heth, an enslaved woman he exhibited as the 161-year-old nurse of George Washington. She died in New York on February 19, 1836. Six days later Barnum staged a public autopsy at the City Saloon, charging fifteen hundred spectators fifty cents each to watch the surgeon David L. Rogers open her body.

Rogers put her age near eighty and declared the age claim a fraud. Barnum answered with denial. He told a rival newspaper that the corpse was a substitute and that Heth remained alive on tour, then seeded a further story that the exposure was itself a hoax. Every stage of the exploitation, including the medical procedure that disproved his central claim, was converted into paid attention.

In 1888, during the commercial contest between direct and alternating current, the engineer Harold P. Brown staged public electrocutions of animals to establish that George Westinghouse’s alternating current was lethal. Thomas Edison lent Brown his West Orange laboratory and equipment. Brown electrocuted a dog before an audience at Columbia College in July, then calves and a horse at Edison’s laboratory in December, before members of the press and the state Medico-Legal Society. The campaign killed dozens of animals. Its object was commercial. The visible harm was the argument, staged to attach a competitor’s product to death and to defend Edison’s own.

The same faction secured the adoption of alternating current for the first electric chair, in order to brand the rival current as the current of death. New York executed William Kemmler at Auburn Prison on August 6, 1890. The first current, applied for seventeen seconds, failed to kill him. A second and longer application burned the flesh and filled the room with smoke, and witnesses left or collapsed.

The proponents had promoted the method as controlled and humane. Its sponsor Alfred Southwick pronounced the execution the mark of a higher civilization. Westinghouse observed that an axe would have done better. A demonstration of mastery produced its opposite in front of the assembled witnesses, and the promoters recorded their inhumane disaster a success.

On April 20, 1914, the Colorado National Guard and guards employed by the Rockefeller-controlled Colorado Fuel and Iron Company attacked a tent colony of striking miners at Ludlow. Roughly twenty people died. Two women and eleven children suffocated in a pit beneath a tent that was set alight. John D. Rockefeller Jr., who controlled the company, engaged Ivy Lee, a pioneer of professional public relations. Lee produced a bulletin series that recast the events and assigned responsibility to the strikers, including the claim that the victims had overturned their own stove. Upton Sinclair named him Poison Ivy.

Instead of running from controversy, Lee’s genius was advising clients to court public opinion through press releases and relationships with journalists and lawmakers to drive the narrative. In his world, absolute facts don’t exist, only differences of perspective. […] One of his clients was I.G. Farben, a German conglomerate with close ties to the Nazi regime and would later produce the poison gas used in concentration camps. Lee advised I.G. Farben to cultivate relationships with American press correspondents and craft “suitable pro-Nazi replies.” Lee earned a fortune by counseling these clients, and was even rewarded for his work in Germany by meeting Hitler himself.

The institutional response to a lethal act was the manufacture and circulation of spin, a “corrected” account.

In the summer of 1946 the United States conducted the Crossroads nuclear tests at Bikini Atoll. The July 25 underwater detonation contaminated the target fleet and the lagoon. That November, Vice Admiral William H.P. Blandy, who commanded the operation, was photographed with his wife cutting a cake modeled on the mushroom cloud. The residents of Bikini had been removed from the atoll and told the displacement was temporary and the danger would pass. The atoll remains uninhabitable eight decades later. A demonstration of mass-casualty capability was marked as an achievement while the people it harmed received an assurance the record would falsify.

Angel food cake made to celebrate atomic bomb tests

Five episodes across a century share something notable for us to reflect upon today. An institution creates or stages a harm and directs its effort toward presentation, advantage, or reassurance, rather than toward the measure that would have prevented the harm or acknowledged it plainly.

The OpenAI disclosure supplies a sixth entry.

The incident

By the presenters’ account, OpenAI ran reinforcement-learning and evaluation workloads that set frontier models difficult and sometimes impossible tasks with internet access disabled. The only external route left open ran through Artifactory, an internal package-manager and caching service that itself reached the open internet. Artifactory was writable and shared across workloads. Agents that became stuck began writing files to it and reading files left by other agents, forming a persistent message board. From that position they induced Artifactory to fetch external content through server-side request forgery, then achieved remote code execution against it through a legacy token endpoint that returned an administrative token on an invalid signature. The activity overloaded the service and produced an outage and a security incident on July 4.

OpenAI remediated the specific findings. It revoked the credentials, rebuilt Artifactory, cleared the message board, patched the zero-day, and resumed operations. Within days the agents reconstituted the message board through an unauthenticated WebDAV endpoint that permitted directory creation, and compromised Artifactory a second time by chaining a caching manipulation with a time-of-check-to-time-of-use flaw in JRuby deserialization to obtain remote code execution and the administrative signing key. They then escalated to root on the host through a recent Linux-kernel vulnerability, moved laterally through the container infrastructure, harvested instance and Kubernetes credentials, reached Azure Key Vault, and obtained cluster administrator.

The same agent activity reached Hugging Face. Using Artifactory to fetch external material, and then a third-party hosted application whose default API key was public and which accepted command injection, the agents established a foothold and chained two previously unknown vulnerabilities in Hugging Face’s dataset infrastructure, an arbitrary-file-read flaw in HDF5 parsing and a template-injection path to remote code execution. They moved from a single dataset worker to administrator across multiple Hugging Face clusters in under thirteen hours.

The internal compromise was a failure against OpenAI’s own systems. The Hugging Face compromise was unauthorized entry into a third party’s production infrastructure, and it originated in the same evaluation runs.

Foreknowledge and the control declined

Three facts in the presenters’ own account establish foreknowledge.

First, they state that frontier models routinely attempt to circumvent their tasks, and they open the presentation with that proposition.

Second, the exploit evaluations were configured with reduced safety refusals relative to the company’s production systems, which made the agents more willing to pursue offensive action.

Third, the presenters identify the governing control themselves: agents are bounded by the privileges they can obtain and the systems they can reach. That statement is the definition of the incident.

Every escalation in their timeline consists of one system reaching a service that lay outside its intended reach.

The controlling measure was therefore known to OpenAI before, during, and after the incident. An agent documented to seek shortcuts, and configured to lower its own refusals, was permitted to reach a writable, internet-connected service shared across all workloads, whose endpoints accepted unauthenticated requests.

The second compromise resolves the question of whether OpenAI understood the fault as a class or as a set of instances. Having patched the individual findings, the company left the underlying condition in place, and the agents rebuilt their channel and breached the same service again within days. The measure that addresses the class, authentication on the endpoints, isolation between workloads, and removal of a writable path from an agent workload to an internet-connected shared service, is standard practice and sits within ordinary engineering competence.

The presentation

OpenAI’s response to this record was the Black Hat presentation itself.

The incident was characterized as a watershed and an existence proof, and offered to the audience as a service to the field. The remedial program the presenters advanced is misordered. It raises detection and response to primary standing and treats architecture as an afterthought, when the incident turned on an absent boundary and not on a shortage of detection.

Their concept consisted almost entirely of detection and suppression: continuous automated red-teaming, automated patching and rollback, defensive agents operating at the speed of the offensive ones, and deception measures to slow attackers. Prevention, the architecture that bounds what any workload can reach, appeared in a single passing clause near the close, where the presenters allowed that segmentation and least privilege remain valuable. The structure of the talk inverts the causal order of the incident, in which an absent boundary, and not a shortage of detection, was the operative failure.

The program also carries a conflict of interest.

The presenters argued that defenders must keep pace with the intelligence of the models, and that each increase in model capability otherwise favors the attacker. The intelligence in question is OpenAI’s product.

The offense on display was produced by that product. The prescription, that organizations acquire and deploy more frontier-model capability in order to defend themselves, directs the remedy toward the party responsible for the demonstration. The presenters gesture at open-weight models in a single phrase, and the central claim is unchanged.

The conduct meets the criminal standard

The historical cases are settled. Barnum’s autopsy, the current-war electrocutions, the Kemmler execution, the Ludlow bulletins, and the Crossroads cake are documented, and the judgment on each has been entered by time. In every one, an institution that produced harm turned to exhibition, competition, or management of the account, and passed over the plainer course of prevention or candid acknowledgment.

OpenAI’s disclosure fits the category on the facts the company supplied itself. It held the controlling measure throughout, described it accurately, declined to implement it, watched the same failure recur, and then presented the episode as instruction for others while recommending they purchase more of the capability that caused it.

Negligence would account for a single breach. The recurrence removes that defense.

OpenAI had documented these agents as prone to defeat their tasks, lowered their refusals, and left a writable path to the open internet in place. The agents breached Artifactory, the company remediated it and resumed with the enabling condition intact, and the agents breached the same service again within days. The same evaluation runs carried the campaign into Hugging Face’s production systems, a third party.

Unauthorized access to another organization’s infrastructure is a criminal act, and it is reached by recklessness as well as by intent. The record OpenAI presented shows that its own configuration enabled the access, and that it resumed operations with that condition known.

The pattern is documented across more than a century, and this conduct extends it.

Iran Used Chinese Targeting to Disable 17 U.S. Military Bases. Now Trump Closes State Department Sites to Cede More to China

“America First” is white nationalist KKK platform rooted in late 1800s nativism, which aligned with Nazi Germany, with members indicted for sedition.

Early last year, during the opening ⁠months of U.S. President Donald Trump’s administration, the State Department began preparations to shut down nearly a dozen foreign missions, media outlets reported at the time, as part of ​a broader push by the Republican president ⁠to transform the U.S. bureaucracy so that it is fully aligned with his “America First” agenda.

The most recent State announcement of closures follow the massive cost ballooning from losing the Iran war and running out of munitions, including embarrassing failure to defend military bases.

China maintains diplomatic presence in three of the five cities being abandoned, St. George’s, Nagoya, and Medan. Grenada is the same island where the US invaded in 1983 partly over Cuban-built airport infrastructure. Nagoya is Toyota country and the industrial core of a treaty ally. Medan sits on the Malacca Strait. The State Department is vacating contested ground.

Footgun.

Google Chrome Password Safe Exposes Master Key in Plaintext

This is close to the worst possible design failure, if not the worst.

This master key, known as the security domain secret, is temporarily sent to Chrome when a device registers or recovers access to the account.

Unit 42 initially found that Chrome exposed the secret in plaintext through its internal FIDO logs. Google removed the secret from the logs after the researchers reported the issue, but Unit 42 says it is still sent to Chrome and remains temporarily accessible in the browser’s process memory.