homehome Home chatchat Notifications


How primary school students used metadata to track down a 'whistleblower' in two hours

It's that easy.

Tibi Puiu
December 14, 2016 @ 7:10 pm

share Share

Pre-teens hunt for the snitch. Credit: ABC.net

Pre-teens hunt for the snitch. Credit: ABC.net

The University of Melbourne recently co-organized a special a ‘cyber fox hunt’ event in which 12 teams were placed in the shoes of a data analyst working for the federal police. One of the teams, comprised of three pre-teens still in primary school, managed to track down a hypothetical whistleblower in under two hours. The team only metadata at their disposal; information like IP addresses, email addresses, phone numbers, and location data, which service providers are forced to store for two years by Australian law.

All but one team managed to track down the hypothetical ‘Minecorp’ employee who was emailing confidential information to an investigative journalist at ‘MineWatch’. The winning team took under an hour to find the whistleblower. This speaks about how easy it is to track a person — any person — using only abstract information.

Here’s what Gen, a 12-year-old from Team Sherlock, thought of it all.

“It was a lot easier than I expected,” she said.

“Basically what happened was we found the data that had the Google searches and the ones that corresponded with searches the whistleblower would use. We then found the IP address they used with the Google searches and we linked the IP address to their email. We used the email to find their phone number and their address.”

Search query metadata. Credit: Robin Doherty.

Search query metadata. Credit: Robin Doherty.

Using an analytics software called Kibana, the kids first mined the logs of Minecorp to see whether anyone had searched on Google for “MineWatch” or “Anna Dupont”, the name of the journalist who broke the story. They got a list of IPs who made the searches, which they then used as filters for e-mail addresses associated with these addresses. You can now search mobile providers databases to get the phone number and billing address linked to the e-mail.

Metadata stored by the Australian government also includes who emailed who and who phoned who. So, the kids only had to find out who e-mailed anna@minewatch.org.au. They could do this because they could also access Anna Dupont’s metadata.

Finally, the phone’s metadata also logs where a suspect whistleblower has traveled. Based on patterns, you can predict where the person will turn out and make an arrest.

Job done — and it took some 12-year-olds two hours to complete.

The purpose of this exercise was to show just how easy it is to use metadata, which you can theoretically use without a warrant in the land down under. Australia has been collecting metadata since October 2015, but the United States has been doing it for far longer, as a real whistleblower revealed. Elsewhere, metadata is used to track down and kill terrorists in drone attacks. The problem is the same metadata used to spot patterns sometimes fails and leads to innocent people ending up on the NSA’s kill list.

More than anything, though, this little experiment makes it very clear how metadata is a breach of privacy. The information that’s collected does not contain conversations or anything tangible, but even these ‘footprints’ are enough to track your activities — with ease.

Think you can do better than the pre-teens? Take the Snitch Hunt challenge and find out. 

share Share

Mexico Will Give U.S. More Water to Avert More Tariffs

Droughts due to climate change are making Mexico increasingly water indebted to the USA.

Chinese Student Got Rescued from Mount Fuji—Then Went Back for His Phone and Needed Saving Again

A student was saved two times in four days after ignoring warnings to stay off Mount Fuji.

The perfect pub crawl: mathematicians solve most efficient way to visit all 81,998 bars in South Korea

This is the longest pub crawl ever solved by scientists.

This Film Shaped Like Shark Skin Makes Planes More Aerodynamic and Saves Billions in Fuel

Mimicking shark skin may help aviation shed fuel—and carbon

China Just Made the World's Fastest Transistor and It Is Not Made of Silicon

The new transistor runs 40% faster and uses less power.

Ice Age Humans in Ukraine Were Masterful Fire Benders, New Study Shows

Ice Age humans mastered fire with astonishing precision.

The "Bone Collector" Caterpillar Disguises Itself With the Bodies of Its Victims and Lives in Spider Webs

This insect doesn't play with its food. It just wears it.

University of Zurich Researchers Secretly Deployed AI Bots on Reddit in Unauthorized Study

The revelation has sparked outrage across the internet.

Giant Brain Study Took Seven Years to Test the Two Biggest Theories of Consciousness. Here's What Scientists Found

Both came up short but the search for human consciousness continues.

The Cybertruck is all tricks and no truck, a musky Tesla fail

Tesla’s baking sheet on wheels rides fast in the recall lane toward a dead end where dysfunctional men gather.