Small Packet of Bits That Can Save or Destabilize a City

Manuel Rabid

RF Village @ DEF CON 33 · Day 1 · RF Village

Overview

Manuel Rabad's talk, "Small Packet of Bits That Can Save or Destabilize a City," delves into the fascinating and critical world of wireless alert systems used for public safety, particularly focusing on earthquake and weather warnings. The presentation offers a unique blend of technical deep dive into the underlying radio frequency (RF) protocols and a compelling narrative of personal discovery, set against the backdrop of Mexico City's history with seismic events. Rabad meticulously explores how these life-saving systems operate, their inherent technical limitations, and the surprising ease with which their signals can be generated, raising significant questions about security and trust in critical infrastructure.

Watch on YouTube

Visual summary for Small Packet of Bits That Can Save or Destabilize a City by Manuel Rabid
Visual summary for Small Packet of Bits That Can Save or Destabilize a City by Manuel Rabid

Key moments

  1. 0:00 Introduction and overview of the talk's scope
  2. 2:00 Speaker's personal journey and motivation for this project
  3. 4:30 Geological reasons for Mexico City's earthquake vulnerability
  4. 7:00 The science: seismic waves vs. radio frequency speed
  5. 8:30 Founding of the Mexican Seismic Alert System (SASMEX)
  6. 9:45 The distinctive, impactful sound of the SASMEX alert

Small Packet of Bits That Can Save or Destabilize a City

Speakers: Manuel Rabad, RF Enthusiast, Independent Researcher

Conference: RF Village

YouTube: https://www.youtube.com/watch?v=3C-_TaYht68

Overview

Manuel Rabad's talk, "Small Packet of Bits That Can Save or Destabilize a City," delves into the fascinating and critical world of wireless alert systems used for public safety, particularly focusing on earthquake and weather warnings. The presentation offers a unique blend of technical deep dive into the underlying radio frequency (RF) protocols and a compelling narrative of personal discovery, set against the backdrop of Mexico City's history with seismic events. Rabad meticulously explores how these life-saving systems operate, their inherent technical limitations, and the surprising ease with which their signals can be generated, raising significant questions about security and trust in critical infrastructure.

The talk primarily examines two key systems: the Mexican Seismic Alert System (SASMEX), which leverages radio frequency (RF) to provide crucial minutes of warning before an earthquake hits, and the more broadly adopted EAS-SAME (Emergency Alert System - Specific Area Message Encoding) protocol, used in both the US and Mexico for various emergencies. Rabad's journey from an amateur enthusiast building his own receiver to a formal academic project underscores the accessibility of these technologies. The core message revolves around the double-edged sword of simplicity in design: while it ensures widespread adoption and resilience, it also introduces profound vulnerabilities that could be exploited to cause widespread panic or undermine public trust, thereby destabilizing a city rather than saving it.

This presentation matters immensely because it highlights how legacy technologies, often overlooked in modern security discourse, form the backbone of essential public safety infrastructure. Rabad's work exposes the critical balance between accessibility, interoperability, and security in systems designed to protect millions of lives. By demonstrating how easily these alert signals can be received, decoded, and even generated, he compels us to reconsider the defensive posture required for systems that, by their very nature, are designed to be universally accessible, yet demand absolute integrity.

Background

▶ Watch: Introduction and overview of the talk's scope (0:00)

The genesis of Rabad's exploration, and indeed Mexico's advanced seismic alert system, lies in the devastating 1985 Mexico City earthquake. This catastrophic event resulted in approximately 40,000 casualties, the collapse of around 400 buildings, and affected 100,000 homes, deeply scarring the collective memory of generations. Mexico City's unique geological vulnerability — built on a soft lakebed that amplifies seismic waves, and situated between the North American and Cocos tectonic plates which generate frequent seismic activity — makes it exceptionally prone to severe earthquakes. On average, the city experiences 10-20 small to medium earthquakes annually, with 1-3 strong ones, and a very strong one roughly every ten years, like the 2017 event.

Following the 1985 disaster, scientists and engineers recognized a critical window of opportunity. The 1985 earthquake originated 390 kilometers from Mexico City. While seismic waves travel at approximately 4.5 kilometers per second, RF signals travel at 300,000 kilometers per second. This speed differential translates to a precious 1 minute and 24 seconds of warning time if an alert could be transmitted instantaneously via RF from the epicenter to the city. This scientific insight led to the establishment of the Center for Seismic Instrumentation and Recording (CIRES) in 1986. CIRES initially installed a network of accelerometers in Mexico City to measure seismic activity and then proposed a system: a network of sensors along the coast where tectonic plates meet, transmitting data via RF to a central station in Mexico City. If a significant seismic event was detected, an alert would be broadcast to the entire population.

This ambitious vision materialized into the Mexican Seismic Alert System (SASMEX), activated in 1991. A key component was the development of a very distinctive, unforgettable alert sound that immediately triggers a sense of urgency among Mexico City residents. Initial alerts were disseminated through direct links to government entities, the subway system, radio and television stations, and schools. In 2008, SASMEX began integrating the EAS-SAME transmitter network, installing receivers in government and commercial buildings. Today, SASMEX comprises an expanding network of sensors and about 15-20 transmitters, covering the central, most populated region of Mexico. This system provides alerts for approximately 30 million people, making it a vital piece of critical infrastructure, despite relying on what Rabad describes as "legacy technology." The speaker also mentions ongoing efforts to implement Cell Broadcast alerts, though these are still in testing and not yet widely effective in Mexico.

Rabad's personal journey into this field began in the early 2010s when he noticed the "Public Alert" and "NOAA" logos on government-installed receivers. Intrigued, and seeing breakout boards from SparkFun discussing NOAA, he realized the technology might be more accessible than assumed. He built his own receiver using a dedicated IC, the Si4707, and even developed a Twitter bot, sismo_alerta, to broadcast alerts, demonstrating the power of open information. This led to workshops, public interest, and eventually, government acknowledgment (and warnings about unofficial channels). Critically, a private company held exclusive rights to sell authorized receivers, sparking public criticism. This pressure eventually led the government to establish an official technical standard, allowing other companies to build compliant receivers – some of which now utilize Rabad's publicly released software, a testament to the open-source spirit. This research culminated in his engineering degree project, where he formally built and documented a receiver, delving into the intricate details of the EAS-SAME protocol. This academic deep dive revealed the protocol's surprising simplicity and lack of robust security, sparking the core idea for this talk.

Key Findings

▶ Watch: Geological reasons for Mexico City's earthquake vulnerability (4:30)

Manuel Rabad's investigation into wireless alert systems uncovers several critical findings, highlighting the intricate balance between functionality, accessibility, and security in life-saving infrastructure.

Firstly, the EAS-SAME (Emergency Alert System - Specific Area Message Encoding) protocol, despite its age, remains a cornerstone of public safety alerts in both the US and Mexico, achieving critical infrastructure status. Its continued relevance underscores the enduring power of simple, robust designs, even as they become "legacy technology."

Secondly, the talk reveals the inherent simplicity and lack of robust security in the EAS-SAME protocol. Rabad demonstrates that the protocol, relying on AFSK (Audio Frequency Shift Keying) modulation and ASCII encoding, lacks fundamental mechanisms for origin verification or message authentication. This means that theoretically, "anybody can generate these signals," making the system vulnerable to unauthorized transmission, tampering, or jamming. The protocol's reliance on triple message repetition for error detection (two out of three bits must match) is a rudimentary form of resilience, but it does not protect against malicious signal injection.

Thirdly, Rabad highlights how Mexico has customized the international EAS-SAME standard for its SASMEX system. Notable changes include sending the RWT (Regular Weekly Test) daily (every three hours) instead of weekly, and crucially, transmitting EQW (Earthquake Warning) messages three times without an accompanying voice message or warning tone. Instead, the receiver is mandated to play the official audio within 5 seconds for 60 seconds. These modifications render standard US EAS-SAME receivers incompatible with Mexico's earthquake alerts, leading to potential vendor lock-in or limiting choices for consumers. Rabad speculates this might have been driven by commercial interests, given the significant price difference between official Mexican receivers and readily available US models.

Finally, Rabad's work confirms the ease of receiving, decoding, and even encoding EAS-SAME signals using readily available tools and open-source software. Through his personal project and academic work, he demonstrates that a standard SDR dongle can capture these signals, and tools like multimon or custom Python scripts can easily extract the embedded information. While generating these signals is technically straightforward, he strongly emphasizes the severe legal repercussions and ethical dangers of unauthorized transmission, particularly for public safety systems.

Technical Deep Dive

▶ Watch: The science: seismic waves vs. radio frequency speed (7:00)

The technical core of Rabad's presentation lies in the detailed exposition of the EAS-SAME protocol, its historical evolution, and its specific implementation in Mexico.

The EAS-SAME system has its roots in the 1960s with marine weather broadcasts from the Chicago area. Initially, these were simple voice reports transmitted on VHF frequency 162.55 MHz. In the 1970s, the warning alarm tone was introduced, designed to activate receivers even if their speakers were off. By 1988, after a decade of development, the National Weather Service (NWS) released the SAME protocol, a digital layer built upon this existing infrastructure. The NOAA Weather Radio (NWR) network, which utilizes this protocol, now covers 90% of the 50 US states with over 750 transmitters, operating with a range of up to 40 miles on flat terrain and using wide FM modulation.

The SAME protocol itself is a digital format transmitted using AFSK (Audio Frequency Shift Keying) modulation. This means digital data is represented by shifts between two specific audio frequencies: 2083.3 Hz for a logical zero and 1562.5 Hz for a logical one. Each bit has a bit period of 192 milliseconds, translating to a modest data rate of approximately 520 bytes per second. Before each digital burst, a 16-byte preamble consisting of alternating AB 10101011 sequences is sent. This preamble is crucial for receivers to synchronize with the incoming data stream. The characters within the message are encoded using ASCII, with the least significant bit (LSB) transmitted first.

An EAS-SAME message is structured into four main sections: a header, an alert tone (optional, but standard in the US), an optional voice message, and an end of message signal. Crucially, the header contains all the vital information about the alert. To improve resilience against transmission errors, the entire SAME protocol message (header and end of message) is transmitted three times. Receivers are designed to perform a 2-out-of-3 bit voting mechanism: if two of the three received bits for a given position are identical, that bit is considered valid. This rudimentary error correction highlights the protocol's simplicity and lack of more advanced error-checking mechanisms or cryptographic integrity.

The header itself begins with the sequence ZCZC (Start of Header) and includes several key fields:

  • Originator: Identifies the issuing agency (e.g., NWS, Civil Defense).
  • Event Type: Specifies the nature of the alert (e.g., EQW for Earthquake Warning, RWT for Regular Weekly Test, TOA for Tornado Warning).
  • Geographic Area Code: A specific code identifying the targeted geographic region(s). This allows receivers to filter alerts relevant to their location, preventing unnecessary alarms for events outside a user's configured area.
  • Expiration Time: When the alert is no longer valid.
  • Issue Date and Time: When the alert was issued.
  • Transmitter ID: Identifies the transmitting station.

Mexico's implementation of EAS-SAME for SASMEX introduces specific customizations:

  • The RWT (Regular Weekly Test) is sent daily, every three hours, rather than weekly. This rigorous testing schedule reflects the high importance of the system in Mexico. If a receiver doesn't get this daily test, it's an indication for the user to check their antenna and setup.
  • For EQW (Earthquake Warning) alerts, the system sends three identical header messages without an accompanying voice message or the standard warning tone. Instead, compliant receivers are programmed to play the distinctive official audio within 5 seconds of receiving the EQW message, for a duration of 60 seconds. This modification means that standard US EAS-SAME receivers, which expect a voice message and warning tone, will not function correctly for earthquake alerts in Mexico. This incompatibility was a point of contention, as it effectively mandated the purchase of specific, more expensive receivers authorized by the Mexican government.

Demo / Proof of Concept

▶ Watch: Founding of the Mexican Seismic Alert System (SASMEX) (8:30)

Manuel Rabad's presentation moves seamlessly from theory to practical demonstration, showcasing how EAS-SAME messages can be received, decoded, and even generated.

Receiving EAS-SAME Messages:

Rabad explains several methods for receiving these alerts. Beyond commercial weather radios like the Midland models common in the US or the government-authorized receivers in Mexico, dedicated integrated circuits (ICs) like the Si4707 offer a single-chip solution for tuning, decoding, and processing the signals. This was the same IC he used in his early personal projects and his formal degree work.

The most flexible and widely accessible method demonstrated is using an SDR dongle (Software Defined Radio) combined with software like SDR++. Rabad shows a screenshot of SDR++ displaying multiple strong NOAA Weather Radio signals in Mexico City, indicating robust coverage. He then plays an audio recording of a live signal, which, when tuned to one of the NWR frequencies, typically broadcasts a continuous weather report. The critical moment for an alert is when the distinctive digital "brrr" sound of the AFSK bursts interrupts the voice report, signaling the transmission of a SAME message. These bursts are visibly distinct in the SDR++ waterfall display, appearing as three strong initial digital signals (the header repetitions) followed by three smaller ones (the end of message repetitions).

Decoding EAS-SAME Messages:

Once a signal is recorded, decoding it is straightforward. Rabad mentions multimon, a well-known open-source tool capable of decoding various AFSK protocols, including SAME. By feeding a recorded audio file into multimon, the raw ASCII message, including the header fields like ZCZC, originator, event type (e.g., EQW, RWT), geographic area codes, and timestamps, can be extracted.

For those interested in a deeper understanding, Rabad also developed his own Python decoder. This custom script leverages libraries like scipy and numpy to process recordings in the sigua format. It employs a band-pass filter to isolate the relevant frequencies and the Goertzel algorithm to efficiently detect the dominant tones corresponding to logical zero and logical one. Synchronization is achieved through preamble detection, and a sliding window technique is used to identify bit transitions, ultimately extracting the message stream. He illustrates how his decoder can parse a real recording, apply the 2-out-of-3 bit validation, and output the complete, decoded SAME message.

Encoding / Generating EAS-SAME Messages:

Rabad briefly touches on the ease of generating these signals. While he opted not to build his own encoder (as a Python library already exists for this purpose), he explains that it's a relatively simple process. By inputting the desired header information, the library can generate a .wav file containing the correctly modulated AFSK signal. This generated audio file can then be fed back into a decoder to validate its correctness.

However, Rabad issues a strong and unequivocal warning against transmitting these generated signals. He emphasizes that unauthorized transmission on public safety frequencies is highly illegal in both Mexico and the US, carrying severe penalties including potential imprisonment. Beyond the legal ramifications, he stresses the profound ethical implications of tampering with systems designed to save lives, highlighting the potential for widespread panic or desensitization to genuine threats. He reminds the audience that while understanding how these systems work is crucial for security research, actively interfering with them endangers public safety.

Defensive Implications

▶ Watch: The distinctive, impactful sound of the SASMEX alert (9:45)

The detailed analysis of the EAS-SAME protocol, particularly its simplicity and lack of modern security features, reveals significant defensive implications for critical infrastructure operators and public safety agencies.

The most glaring vulnerability is the lack of origin verification and message authentication. Because the protocol relies on simple AFSK modulation and ASCII encoding without cryptographic signatures or secure key exchanges, any individual with basic RF knowledge and equipment (like an SDR dongle capable of transmitting) can theoretically generate and broadcast an EAS-SAME message. This opens the door to malicious actors creating false alarms, causing widespread panic, or even issuing "all clear" messages during a real emergency, which could have catastrophic consequences.

Related to this is the risk of message tampering. Even if an original, legitimate signal is broadcast, an attacker could potentially intercept, alter, and re-transmit it, changing critical information such as the event type, geographic area, or duration. This could lead to confusion, misdirection of emergency services, or an erosion of trust in the alert system.

Furthermore, the system's reliance on a fixed channel (e.g., specific NWR frequencies) makes it susceptible to interference or jamming. A malicious actor could flood the frequency with noise, preventing legitimate alerts from reaching receivers, or intentionally transmit conflicting signals to create chaos. There is no mechanism for channel hopping or adaptive frequency selection to mitigate such attacks.

The dependence on specialized hardware for receiving, even if it's a simple AFSK decoder, means that if the system were ever to be significantly modernized or secured with new protocols, existing receivers would become obsolete, requiring costly and time-consuming upgrades across potentially millions of devices. This creates a strong inertia against change, perpetuating the use of older, less secure technologies.

Finally, the language limitations of a voice-based system, as highlighted by Rabad, present a challenge in diverse populations. While multiple frequencies can be used for different languages, this is not ideal and adds complexity.

To address these vulnerabilities, Rabad suggests several improvements and future directions:

  • Transition to Secure Protocols: The primary recommendation is to move towards more secure, authenticated protocols. The Common Alerting Protocol (CAP) is cited as a suitable alternative. CAP is an XML-based standard designed for all-hazard emergency alerting, which inherently supports features like digital signatures for origin verification and message integrity. Implementing CAP would significantly reduce the risk of spoofing and tampering.
  • Leverage Cell Broadcast: Rabad champions Cell Broadcast as a more robust last-mile delivery mechanism. As part of the GSM protocol, Cell Broadcast operates at lower network layers, making it resilient to network congestion or even the absence of data plans on individual SIM cards. It ensures that messages are pushed directly to all compatible devices within a cell tower's range, offering a more reliable and authenticated delivery path compared to traditional RF broadcasts. While Mexico is still testing its implementation, its potential for secure and widespread alerts is significant.
  • Public Awareness and Education: For legacy systems that remain in use, public awareness campaigns about their limitations and the importance of official channels are crucial. This helps to build resilience against potential misinformation campaigns or hoaxes.
  • Regulatory Modernization: Governments and regulatory bodies must continuously evaluate and update technical standards for public safety systems, prioritizing security alongside accessibility and interoperability. The trade-offs are complex, but the potential for malicious exploitation of insecure systems demands proactive measures.

Ultimately, the defensive implications underscore a fundamental dilemma: how to balance the need for widespread accessibility and interoperability in public warning systems with the imperative for robust security. Adding complex security layers can introduce new points of failure, potentially hindering the very purpose of an alert system, which is to deliver timely warnings without fail. This complex challenge requires ongoing research, collaboration between engineers and policymakers, and a commitment to incremental but significant improvements.

Key Takeaways

  • Legacy Vulnerabilities: Critical public safety systems like EAS-SAME, despite their life-saving function, are often built on legacy technologies with inherent security weaknesses, including a lack of origin verification and message authentication.
  • Simplicity and Accessibility: The simplicity of AFSK modulation and ASCII encoding makes EAS-SAME messages easily receivable and decodable using inexpensive tools like SDR dongles and open-source software like multimon or custom Python scripts.
  • Life-Saving Impact: Mexico's SASMEX system, utilizing a customized EAS-SAME protocol, provides crucial early earthquake warnings, demonstrating the profound life-saving potential of these RF-based alert systems for millions of people.
  • Customization and Incompatibility: National customizations to international standards, such as Mexico's unique EQW format and daily RWT schedule, can lead to incompatibility with generic receivers and potentially create market monopolies for authorized vendors.
  • Ethical and Legal Risks: While technically straightforward to generate EAS-SAME signals, unauthorized transmission is illegal and carries severe penalties, posing significant risks to public safety by potentially causing panic or eroding trust in official alerts.
  • Future-Proofing through Modern Protocols: Future improvements for these systems lie in adopting more secure, authenticated protocols like Common Alerting Protocol (CAP) (with digital signatures) and leveraging resilient, lower-layer communication channels such as Cell Broadcast to enhance both security and reliability.

About the Speaker(s)

Manuel Rabad is an experienced software engineer and an enthusiastic independent researcher in the field of radio frequency security. His journey began in the 1990s, learning computers and electronics, followed by heavy involvement in the FOSS (Free and Open Source Software) community in the 2000s. He pursued a degree in Computer Engineering at the Autonomous National University of Mexico. With two decades of professional experience in software engineering across marketing, startups, government, and fintech, Rabad has developed a broad skill set encompassing software, hardware, and infrastructure. More recently, he has been collaborating with RF Village in Mexico, contributing to security events, CTFs, and talks. Rabad explicitly states that he is an enthusiast rather than an expert in seismic science or alert systems, driven by curiosity to understand how things work, explore their boundaries, and share knowledge. His passion led him to personally build an EAS-SAME receiver, which evolved into his engineering degree project, culminating in the research presented in this talk.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent RF village talk from a genuine enthusiast who did real hands-on work — built a receiver, wrote a decoder, navigated Mexican regulatory politics around SASMEX. The vulnerability surface isn't new (EAS spoofing has been documented for years, including the 2013 Montana zombie-alert incident), but the Mexico-specific angle, the SASMEX protocol delta analysis, and the open-source ecosystem story add legitimate local color that most English-language coverage misses.

Heather Calloway (CISO) — WEAK

Rabad does real technical work — the protocol analysis is credible, the demo is accessible, and the vulnerability is genuine. But the talk stops exactly where it needs to start: it names the risk without telling the institutions responsible for it what to do next.

→ Top-rated talks at RF Village @ DEF CON 33

All talks from RF Village @ DEF CON 33