Ask EFF

Cooper Quintin (Public Interest Technology Team Member · EFF), Lisa Femia, Thorin Klosowski (Activism Team Member · EFF), Alexis Hancock (Director of Engineering, Public Interest Technology Team · EFF), Hannah Zhao

DEF CON 33 · Day 1 · Main Stage

Overview

This DEF CON talk, "Ask EFF," brings together key members of the Electronic Frontier Foundation (EFF)'s Public Interest Technology and Activism teams to discuss their multifaceted approach to defending digital rights. Speakers Alexis Hancock, Cliff, Thorin Klosowski, and Cooper Quintin delve into a range of open-source tools, investigative research, and advocacy efforts designed to empower individuals, fight mass surveillance, and push for stronger privacy protections in an increasingly digital world. The session highlights the EFF's unique blend of legal expertise, technical prowess, and grassroots activism, demonstrating how these elements converge to address pressing issues from web encryption to targeted malware.

Watch on YouTube

Visual summary for Ask EFF by Cooper Quintin, Lisa Femia, Thorin Klosowski, Alexis Hancock, Hannah Zhao
Visual summary for Ask EFF by Cooper Quintin, Lisa Femia, Thorin Klosowski, Alexis Hancock, Hannah Zhao

Key moments

  1. 0:54 EFF Speaker Introductions and Team Overview
  2. 2:26 Introduction to Serbot and the Encrypt the Web initiative
  3. 2:50 EFF's mission: making security free and ubiquitous
  4. 4:09 Serbot's impact: Over 80% of web traffic is HTTPS
  5. 6:40 Introduction to Surveillance Self-Defense (SSD) website

Ask EFF

Speakers: Alexis Hancock (Director of Engineering, Public Interest Technology Team, EFF); Cliff (Public Interest Technology Team, EFF); Thorin Klosowski (Activism Team Member, EFF); Cooper Quintin (Public Interest Technology Team Member, EFF)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=QmkyPl2UZHY

Overview

This DEF CON talk, "Ask EFF," brings together key members of the Electronic Frontier Foundation (EFF)'s Public Interest Technology and Activism teams to discuss their multifaceted approach to defending digital rights. Speakers Alexis Hancock, Cliff, Thorin Klosowski, and Cooper Quintin delve into a range of open-source tools, investigative research, and advocacy efforts designed to empower individuals, fight mass surveillance, and push for stronger privacy protections in an increasingly digital world. The session highlights the EFF's unique blend of legal expertise, technical prowess, and grassroots activism, demonstrating how these elements converge to address pressing issues from web encryption to targeted malware.

The talk serves as a comprehensive update on the EFF's ongoing battles against pervasive online tracking, government overreach, and corporate data exploitation. It showcases projects like Cerbot, which has been instrumental in encrypting the web, and Privacy Badger, a browser add-on combating third-party trackers. Beyond tools, the speakers detail their investigative work through Threat Lab, exposing dangers like stalkerware and pre-installed malware on consumer devices. This presentation is crucial for anyone interested in understanding the practical and policy-level defenses against digital threats, offering insights into how technologists, lawyers, and activists can collectively build a more secure and private internet.

Why this talk matters is evident in the EFF's commitment to making security "ubiquitous and common sense for everyone." The speakers articulate a mission that transcends technical solutions, emphasizing the importance of education through initiatives like Surveillance Self-Defense and the strategic use of technology to force legislative and industry change. By sharing both their successes and the ongoing challenges, the EFF team provides a vital roadmap for digital self-defense and collective action against the ever-evolving landscape of digital surveillance and privacy erosion, particularly relevant in an era where comprehensive federal privacy laws remain elusive in the United States.

Background

▶ Watch: EFF Speaker Introductions and Team Overview (0:54)

The Electronic Frontier Foundation (EFF) was founded on the principle of defending civil liberties in the digital world. The context for much of their work, as highlighted in this talk, stems from the increasing ubiquity of digital interaction and the corresponding rise in surveillance and data collection. A significant turning point mentioned was the Snowden leaks, which underscored the extent of government mass surveillance and catalyzed initiatives like "Encrypt the Web." Prior to these revelations, securing web traffic with TLS certificates was often a costly and complex endeavor, leading to a largely unencrypted internet where sensitive data was routinely transmitted in the clear.

The problem landscape has since evolved, with the EFF identifying a critical shift in the sources of surveillance. While initial concerns often centered on government entities like the NSA, the talk emphasizes that a substantial portion of modern surveillance now originates from private corporations. These companies collect vast amounts of personal data, which, crucially, can then be legally purchased by government agencies without the need for a warrant. This circumvents traditional legal protections and highlights a significant loophole in privacy safeguards. The speakers lament the ongoing absence of a comprehensive federal privacy law in the United States, contrasting it with regulations like Europe's GDPR, which, despite its imperfections, offers a baseline of protection.

Furthermore, the internet is rife with outdated and often misleading security advice. Thorin Klosowski notes that many security guides, even if well-intentioned at their inception, quickly become obsolete due to the rapid pace of technological change. This creates a need for continually updated, accessible, and practical guidance that helps everyday people assess their risks and make informed decisions about their digital security. The EFF's work, therefore, is not just about building tools but also about providing context, education, and advocacy to address these systemic issues, whether they stem from technological vulnerabilities, legal gaps, or a lack of public awareness.

Key Findings

▶ Watch: Introduction to Serbot and the Encrypt the Web initiative (2:26)

The EFF team presented several key findings and contributions across their diverse projects:

  1. Ubiquitous HTTPS via Cerbot: Alexis Hancock highlighted the transformative impact of Cerbot, a primary client for Let's Encrypt. This initiative has driven the encryption of over 80% of global web traffic with HTTPS, a monumental achievement in making casual spying on public Wi-Fi networks significantly harder. This success demonstrates the power of open-source tools in achieving widespread security improvements.
  2. Evolving Security Guidance with Surveillance Self-Defense (SSD): Thorin Klosowski detailed the longevity and adaptation of SSD, the internet's "longest running continually updated security guides." A key finding was the necessity to shift from tech-centric, military-derived language like "threat modeling" to more accessible concepts like "security planning." This change makes security advice more relatable and effective for a broader audience, emphasizing personalized risk assessment rather than rigid, one-size-fits-all directives.
  3. Privacy Badger's Role Against Data Brokers: Cooper Quintin underscored the increasing importance of Privacy Badger in combating corporate data brokers. The finding here is that these brokers legally collect and sell vast quantities of user data to law enforcement, effectively allowing government surveillance without a warrant. Privacy Badger, by blocking third-party trackers, directly cuts off a significant source of this data, becoming a crucial defense in the absence of federal privacy laws.
  4. Stalkerware as a Human Rights Issue: The Threat Lab project, particularly through the work of Eva Galperin, revealed that stalkerware (or spouseware) was frequently misclassified by antivirus companies as "potentially unwanted programs (PUPs)" rather than malicious spyware. The EFF's advocacy led to major AV companies including specific signatures for these tools, recognizing them as a critical threat, often linked to domestic abuse.
  5. Validation of "Ice Block" App Security: Threat Lab's reverse engineering of the "Ice Block" app, designed to warn immigrants about ICE presence, found that it was not an "op" and handled data responsibly. It did not send data to third parties or store unique device IDs, providing crucial technical reassurance to a vulnerable community.
  6. Unregulated Daycare App Data Collection: Alexis Hancock's investigation into apps like Brightwheel and High Mama exposed a completely unregulated industry. Findings included a severe lack of basic security features like two-factor authentication (2FA), open cloud storage buckets for children's photos, and a legal loophole where COPPA (Children's Online Privacy Protection Act) did not apply because parents, not children, were the direct users of the app. This led to significant security improvements in the industry.
  7. Pervasive "Bad Box" Malware on Low-Budget Android Devices: Alexis Hancock's personal experience and subsequent investigation uncovered pre-installed malware called "Bad Box" on low-budget Android devices, including TV boxes and tablets. This botnet, primarily linked to ad fraud, impacts an estimated 10 million Android devices. A critical finding was that major retailers like Amazon knowingly sold these malware-laden devices, highlighting a systemic supply chain vulnerability.
  8. Ray Hunter's Insights into IMSI Catchers: Cooper Quintin's long-running obsession with IMSI catchers (fake cell towers) culminated in the Ray Hunter tool. Initial deployments at protests revealed no signs of police using IMSI catchers in those specific contexts. This finding shifts the focus for activists towards other prevalent surveillance methods, such as license plate readers, facial recognition, commercial data brokers (like Locate X and Fog Data Science), and phone forensics tools (like Cellebrite). Ray Hunter also provides valuable "ground level truth" on how these technologies technically operate.

Technical Deep Dive

▶ Watch: EFF's mission: making security free and ubiquitous (2:50)

The EFF's work is deeply rooted in technical expertise, manifesting in both the development of open-source tools and rigorous investigative methodologies.

Cerbot and HTTPS Ubiquity:

At its core, Cerbot is a command-line client that automates the process of obtaining and renewing TLS/SSL certificates from Let's Encrypt, a free, automated, and open certificate authority. Prior to Cerbot and Let's Encrypt, securing a website with HTTPS often involved purchasing certificates from commercial CAs, manual configuration of web servers (e.g., Apache, Nginx), and complex renewal processes, leading to significant cost and operational overhead. Cerbot abstracts this complexity, allowing web administrators to secure their sites with a few simple commands. Its widespread adoption has been a critical factor in pushing global web encryption beyond 80%, making it significantly harder for passive network attackers (like those on public Wi-Fi) to intercept unencrypted traffic. The "S" in HTTPS, denoting "secure," is directly attributed to the encryption provided by these certificates, safeguarding data submitted through forms, payment systems, and general browsing.

Privacy Badger's Tracker Blocking Mechanics:

Privacy Badger is a browser add-on that automatically learns to block invisible trackers. Unlike traditional ad blockers that rely on static blacklists, Privacy Badger operates dynamically. When a third-party domain appears to be tracking a user across multiple websites without their permission, Privacy Badger automatically blocks that tracker. It achieves this by identifying third-party domains that set cookies or send unique identifiers, then blocking requests to those domains if they appear to be tracking the user's browsing behavior. This self-learning approach means it can adapt to new tracking methods and is particularly effective against supercookies and other persistent identifiers. By limiting the data collected by advertising and analytics companies, Privacy Badger directly impedes the creation of detailed user profiles, which are often aggregated and sold by data brokers.

Surveillance Self-Defense (SSD) Methodology:

SSD's technical contribution lies in its pedagogical approach to security. Instead of dictating specific tools, it teaches security planning and risk assessment. This involves guiding users through understanding their unique threat landscape, identifying potential adversaries, and evaluating the sensitivity of their data and communications. The guides explain why certain security practices are important (e.g., using a password manager, understanding VPN limitations) rather than just what to do. This empowers users to make informed decisions that align with their personal risk tolerance and context, moving beyond the often-intimidating "threat modeling" terminology.

Threat Lab's Investigative Techniques:

The Threat Lab employs a range of technical investigative methods. For instance, in analyzing the "Ice Block" app, they performed reverse engineering, static analysis (examining the code without running it), and dynamic analysis (observing its behavior while running). This allowed them to inspect network traffic, scrutinize code for data transmission to third parties, and identify the storage of unique identifiers.

A crucial supporting tool mentioned is APKEP, developed by EFF's Bill. APKEP is an automated utility for downloading APKs (Android application package files) from the Google Play Store and other Android marketplaces. This enables researchers to systematically acquire mobile applications for in-depth analysis, such as identifying malware, privacy vulnerabilities, or tracking mechanisms, as was done in the "Bad Box" and potential data broker investigations.

Ray Hunter's IMSI Catcher Detection:

Ray Hunter is a specialized software tool designed to detect IMSI catchers (also known as Stingrays or cell-site simulators). These devices are essentially fake cell towers that trick mobile phones into connecting to them, allowing the capture of unique identifiers like the IMSI (International Mobile Subscriber Identity) from the SIM card and the IMEI (International Mobile Equipment Identity) from the phone hardware. Ray Hunter runs on inexpensive hardware, specifically a $20 mobile hotspot (e.g., an old Android phone or a dedicated hotspot device). It functions by monitoring the network traffic between the device's cellular modem and the cell towers it connects to. The software contains signatures and behavioral patterns that indicate the presence and operation of an IMSI catcher, such as unusual network handoffs, forced 2G downgrades (which make calls/SMS easier to intercept), or specific signal characteristics. This technical approach provides "ground-level truth" on how these covert surveillance tools operate in the real world.

"Bad Box" Malware Analysis:

The "Bad Box" investigation involved deep dives into low-budget Android devices. Alexis Hancock identified pre-installed malware on a Dragon Touch tablet, sharing artifacts with previously documented Android TV box infections. The malware establishes a botnet, downloading additional payloads and engaging in activities like ad fraud. The technical analysis likely involved examining firmware images, reverse engineering pre-installed applications, monitoring network communications for command-and-control (C2) traffic, and identifying persistent mechanisms that ensured the malware's survival across reboots or factory resets. The discovery that these devices came with a Yandex-based browser and an outdated Android version, alongside non-standard upgrade systems, pointed to a fragmented and insecure software supply chain.

Demo / Proof of Concept

▶ Watch: Serbot's impact: Over 80% of web traffic is HTTPS (4:09)

While the talk did not feature a live, in-person demonstration of a tool, the speakers effectively presented several "proofs of concept" through the results of their investigative work and the practical application of their tools in real-world scenarios. These examples demonstrated the efficacy of the EFF's approach and the tangible impact of their efforts.

Ray Hunter in Action:

Cooper Quintin described the deployment of Ray Hunter as a community-driven proof of concept. The software, running on inexpensive mobile hotspots, was distributed to individuals and utilized at various protests across the US, including the "no kings" protests. While the specific findings were that no IMSI catchers were detected at these events, the deployment itself served as a real-world test of the tool's capability to monitor for these devices. This demonstrated that the EFF could equip activists with a practical, low-cost solution to detect sophisticated surveillance technology, thereby informing community security planning and validating the tool's effectiveness in a live environment. The ongoing collection of this "ground-level truth" data is a continuous demonstration of Ray Hunter's utility as a research and protective tool.

The Daycare App Investigation:

Alexis Hancock's personal experience with the Brightwheel daycare app evolved into a powerful proof of concept for the Threat Lab's advocacy and technical analysis. Her investigation uncovered severe security deficiencies, including the lack of two-factor authentication (2FA) for parent and school accounts, and the use of "open cloud buckets" for sensitive child data. By applying her technical expertise in Android security and leveraging the EFF's legal resources, she was able to directly engage with the CTO of Brightwheel. The outcome – the implementation of 2FA and improved account segmentation by Brightwheel, and the establishment of a vulnerability program by High Mama – served as a direct demonstration that focused technical investigation combined with legal and advocacy pressure can force significant security improvements in an otherwise unregulated industry. This wasn't a live demo, but a compelling narrative of how a single technical deep dive led to industry-wide change.

"Ice Block" App Reverse Engineering:

The Threat Lab's analysis of the "Ice Block" app provided a technical proof of concept for their reverse engineering capabilities. When concerns arose about the app potentially being a trap to collect data on undocumented immigrants, the EFF team performed static and dynamic analysis. Their finding that the app was not sending data to third parties or storing unique IDs demonstrated their ability to quickly and accurately assess the security and privacy posture of sensitive applications, providing crucial, evidence-based reassurance to a vulnerable community. This illustrated the power of independent technical audits in building trust and combating misinformation.

"Bad Box" Malware Exposure:

Alexis Hancock's investigation into the "Bad Box" malware on her daughter's Dragon Touch tablet was another significant proof of concept. By meticulously tracing the malware's presence and linking it to a larger botnet, she demonstrated that pre-installed malware on consumer electronics is a pervasive and severe threat. The subsequent publication in TechCrunch and the outcome of Dragon Touch removing their tablets from sale, along with Google suing unnamed Chinese nationals, collectively proved that thorough investigative reporting, backed by technical evidence, can lead to accountability and disrupt compromised supply chains, even when facing a systemic issue.

Defensive Implications

▶ Watch: Introduction to Surveillance Self-Defense (SSD) website (6:40)

The insights shared by the EFF team offer crucial defensive implications for a wide range of stakeholders, from individual users to web administrators and security researchers.

For Web Administrators and Developers:

The primary takeaway from the Cerbot discussion is the imperative to implement HTTPS for all web services. Given that over 80% of the web is now encrypted, and tools like Cerbot make TLS certificates free and automated, there is no longer an excuse for running unencrypted HTTP sites. This fundamentally raises the bar for network-level surveillance. Web engineers and system administrators should ensure Cerbot is installed and properly configured on all web servers, regularly verifying certificate renewals to maintain secure connections.

For General Internet Users:

  1. Combat Corporate Surveillance: Install and regularly use Privacy Badger in your web browser. This directly reduces the amount of data collected by third-party trackers, which are a major source of information for data brokers who legally sell data to governments. Understand that in the absence of federal privacy laws, tools like Privacy Badger are your primary defense against mass corporate data collection.
  2. Educate Yourself with Surveillance Self-Defense (SSD): Regularly consult the EFF's Surveillance Self-Defense guides. Shift your mindset from rigid "threat modeling" to flexible "security planning." Learn how to assess your personal risks and adapt your security practices based on your activities and environment (e.g., attending a protest vs. routine browsing). Pay attention to continually updated guidance, as security advice quickly becomes outdated.
  3. Beware of Low-Budget Android Devices: Exercise extreme caution when purchasing inexpensive Android tablets or TV boxes from online retailers like Amazon or AliExpress. The "Bad Box" investigation revealed that these devices are often pre-installed with malware straight out of the box, creating botnets for ad fraud and other malicious activities. If you own such a device, consider disabling it or at least isolating it on a segmented network.
  4. Enable Two-Factor Authentication (2FA): Alexis Hancock's daycare app investigation highlighted the critical importance of 2FA. Enable 2FA on all your online accounts, especially those handling sensitive personal or financial information, and particularly for apps related to children. This simple step significantly enhances account security against unauthorized access.
  5. Understand Your Phone's Data Footprint: Be aware of the vast amount of data your phone collects (location, app usage, etc.). Regularly review and adjust privacy settings on your mobile operating system (iOS, Android). While disabling 2G was mentioned as a technical recommendation for enhanced mobile security, the broader implication is to be conscious of what your device is sharing.
  6. Recognize the Threat of Data Brokers to Government Surveillance: Understand that government agencies can legally purchase vast amounts of personal data from commercial data brokers. This means even if you're not directly targeted by government surveillance, your everyday online activities can still be accessed indirectly. This reinforces the need for strong individual privacy practices and advocacy for comprehensive privacy laws.

For Activists and Targeted Communities:

  1. Re-evaluate IMSI Catcher Concerns: While IMSI catchers are a threat, Ray Hunter's findings suggest they may not be as prevalent at protests as other forms of surveillance. Focus your security planning on more commonly observed tactics: license plate readers, facial recognition technology, commercial data from brokers, and phone forensics tools like Cellebrite (which can extract all data from a seized phone).
  2. Build Community Resilience: As Cliff and Alexis suggested, foster mutual aid networks and community preparedness. This includes not just digital security but also alternative communication and support networks. "We protect us" is a core principle for collective defense.
  3. Beware of Stalkerware: If you or someone you know is in an abusive situation, be aware of stalkerware. Ensure antivirus software is up-to-date and configured to detect these types of spyware, which are often marketed for illicit monitoring of partners.

For Security Researchers and Advocates:

  1. Contribute to Open-Source Tools: Projects like Ray Hunter thrive on community contributions. Researchers can contribute to these tools to improve their detection capabilities and expand their reach.
  2. Utilize Tools like APKEP: For mobile app analysis, APKEP provides a valuable foundation for automated APK downloads, facilitating large-scale research into app privacy and security.
  3. Advocate for Comprehensive Privacy Law: The EFF's work consistently highlights the critical gap left by the absence of a federal privacy law in the US. Continued advocacy for such legislation is paramount to creating systemic protections.
  4. Leverage "Coders Rights": For researchers reporting vulnerabilities, the EFF's "Coders Rights" initiative provides legal advice and support, addressing the frustrations of non-responsive companies.

Key Takeaways

  • Multi-pronged Defense: The EFF employs a unique and effective strategy blending open-source technology development, legal advocacy, and grassroots activism to defend digital rights and privacy.
  • HTTPS is a Major Victory: Tools like Cerbot and the Let's Encrypt initiative have made HTTPS encryption ubiquitous, significantly hindering casual surveillance and making the web more secure for everyone.
  • Corporate Data Brokers are a Primary Surveillance Threat: In the absence of federal privacy laws, private companies legally collect and sell vast amounts of personal data to government agencies, bypassing warrant requirements and creating a critical loophole in privacy protections.
  • Targeted Research Protects Vulnerable Communities: The Threat Lab's investigative work on issues like stalkerware, the "Ice Block" app, and pre-installed malware directly addresses specific threats faced by at-risk populations, often leading to tangible security improvements.
  • Community-Driven Tools Inform Defense: Projects like Ray Hunter provide crucial "ground truth" about surveillance technologies, enabling the EFF to update security guidance and refocus defensive efforts on the most prevalent threats (e.g., license plate readers, facial recognition, commercial data, Cellebrite, over IMSI catchers at protests).
  • Personal Vigilance and Community Building are Essential: In a landscape where legal protections are often insufficient, individual security planning (e.g., using Privacy Badger, enabling 2FA, vetting devices) and building resilient community networks ("we protect us") are vital for digital self-defense.

About the Speaker(s)

The talk featured several dedicated members of the Electronic Frontier Foundation (EFF) team, each bringing unique expertise to the discussion:

Alexis Hancock is the Director of Engineering for the Public Interest Technology team at EFF, where she has worked for about seven years. She primarily focuses on the Cerbot project, which automates TLS certificates for web servers, and played a pivotal role in the investigation into the security practices of daycare apps. Her work emphasizes making security ubiquitous and common sense for everyone.

Cliff is Alexis's peer and also leads a team within the Public Interest Technology crew at EFF, having been with the organization for about a year. He contributes to the broader mission of developing open-source tools and advocating for digital rights.

Thorin Klosowski is a member of the Activism Team at EFF and works on their Surveillance Self-Defense (SSD) website. With a background as a journalist, he is passionate about creating and maintaining continuously updated security guides that are accessible and actionable for everyday people, moving away from overly technical jargon.

Cooper Quintin is on the Public Interest Technology team at EFF and has been with the organization for 11 years. He currently works on the Ray Hunter project, a tool for detecting IMSI catchers, and previously contributed to Privacy Badger. Cooper describes himself as "obsessed" with IMSI catchers and led the technical analysis of the "Ice Block" app.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent DEF CON community update from EFF covering legitimate work across multiple fronts — HTTPS adoption, stalkerware classification, supply-chain malware, IMSI catcher detection — but nothing here is a research drop. This is a status report on ongoing EFF projects, not a technical deep-dive into novel attack or defense territory.

Heather Calloway (CISO) — SOLID

EFF's annual DEF CON update is credible, mission-driven, and covers real ground — from HTTPS ubiquity to supply chain malware to activist surveillance threats. But it's a portfolio review, not an argument, and it never rises to the level of forcing a decision or changing how a security leader operates.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33