Carter Smith
Carter, based in Darwin, is a seasoned security consultant with a rich background in both building and testing the security of software and networks. Proficient in a diverse array of tools and languages, and various web application frameworks, Carter brings a comprehensive IT and development background to his work, being able to think as a developer as well as an adversary.
His security testing expertise extends across a wide spectrum of penetration testing, encompassing web applications, external and internal networks, social engineering, thick client systems, mobile applications, and even physical security domains. Whilst his focus on penetration testing, Carter has broad skills in many aspects of cybersecurity.
Passionate about Open-Source Intelligence (OSINT), Carter's commitment to this field is demonstrated through his appearances on the TV show HUNTED three times, and his active involvement in national Cyber Intelligence hackathons.
Carter pioneers the development of new OSINT techniques, tools and infrastructure.
Session
Modern Bluetooth Low Energy tracking ecosystems: Apple Find My, Samsung SmartThings, Tile, and Google Fast Pair, have each implemented privacy controls designed to prevent persistent observation and protect user privacy. This talk demonstrates how those controls fail in practice. Through passive BLE advertisement collection, protocol-level attacks, linkage analysis, we shows how rotating identifiers can be correlated across time and space to re-identify devices, attribute them to individuals, and reconstruct movement histories.
Specifically, it will explore how:
- Rotating identifier schemes, designed to prevent tracking, can be defeated through cryptographic, temporal, and behavioural linkage analysis
- Passive advertisement collection alone, requiring no active probing, no accounts, and no interaction with target devices or ecosystems and is sufficient to re-identify devices and reconstruct movement
- Cross-vendor artefacts and advertisement structure leak identity signals that individual vendors have not accounted for in their threat models
- The privacy guarantees communicated to hundreds of millions of users do not reflect the practical reality of what passive observers can determine
The session will present a mix of linkage algorithms targeting different artifact classes across the four ecosystems and connect the findings to the broader question of what "privacy by design" actually requires when adversarial passive observation is the threat model.