The Small Packet of Bits That Can Save (or Destabilize) a City
Manuel Rábade
39th Chaos Communication Congress (39C3): Power Cycles · Day 2 · Saal Zero
Overview
Manuel Rábade's 39C3 talk, "The Small Packet of Bits That Can Save (or Destabilize) a City," delves into the fascinating and critical infrastructure of Mexico City's Seismic Alert System (SAS). This system, which provides crucial early warnings for earthquakes, relies on the Emergency Alert System (EAS) and its Specific Area Message Encoding (SAME) protocol. Rábade not only dissects the technical intricacies of this life-saving technology but also shares a personal journey driven by curiosity, culminating in open-source contributions that have influenced the system's accessibility.

Key moments
- 0:00 Introduction to seismic alerts and talk agenda
- 3:00 The 1985 Mexico City earthquake and its impact
- 4:00 Geological reasons for Mexico City's earthquake vulnerability
- 4:50 Science behind early warning: seismic vs. radio waves
- 6:40 Mexican Seismic Alert System (SASMEX) architecture explained
- 7:50 Introduction to EAS-SAME for public alert broadcasting
- 9:00 Speaker's personal curiosity sparked by alert radios
The Small Packet of Bits That Can Save (or Destabilize) a City
Speakers: Manuel Rábade
Conference: 39C3
YouTube: https://www.youtube.com/watch?v=4AUjYU1n4-0
Overview
Manuel Rábade's 39C3 talk, "The Small Packet of Bits That Can Save (or Destabilize) a City," delves into the fascinating and critical infrastructure of Mexico City's Seismic Alert System (SAS). This system, which provides crucial early warnings for earthquakes, relies on the Emergency Alert System (EAS) and its Specific Area Message Encoding (SAME) protocol. Rábade not only dissects the technical intricacies of this life-saving technology but also shares a personal journey driven by curiosity, culminating in open-source contributions that have influenced the system's accessibility.
The talk highlights the profound impact of this system on millions of lives in one of the world's most earthquake-prone megacities. By broadcasting alerts wirelessly, it offers precious seconds of warning, allowing residents to take protective measures. However, Rábade's technical exploration uncovers inherent limitations and security vulnerabilities within the decades-old protocol, particularly concerning message authenticity and integrity. This presentation serves as a compelling case study on the delicate balance between accessibility, interoperability, and security in vital public safety systems.
Beyond the technical exposition, Rábade frames his work as an embodiment of the "core of hacking": a deep-seated curiosity to understand how systems function, explore their boundaries, and openly share that knowledge. His investigation into the SAS, from reverse-engineering its alert mechanisms to developing open-source decoders, exemplifies how individual initiative can shed light on critical infrastructure and spark broader conversations about its resilience and security.
Background
▶ Watch: Introduction to seismic alerts and talk agenda (0:00)
The genesis of Mexico's Seismic Alert System (SAS) is rooted in a catastrophic event: the devastating 1985 Mexico City earthquake. This magnitude 8.0 quake, which occurred on September 19, 1985, claimed approximately 14,000 lives and left an indelible mark on the city's collective consciousness. Manuel Rábade, though only one year old at the time, shared a personal connection, recounting how two-thirds of his grandparents' apartment building collapsed during the disaster. This tragedy underscored the urgent need for an effective early warning system.
Mexico City's unique geological characteristics amplify its vulnerability to seismic events. Firstly, the city is built upon what was historically a lake, which was subsequently drained. This soft, unconsolidated lakebed terrain significantly amplifies seismic waves, increasing the destructive potential of distant earthquakes. Secondly, Mexico is situated at the confluence of four major tectonic plates, leading to frequent seismic activity, particularly off its western coast. Earthquakes originating from these coastal regions are typically around 400 kilometers away from Mexico City.
The critical insight that enabled the SAS was the significant speed difference between seismic waves and radio waves. S-waves (seismic waves) travel at approximately 4.5 kilometers per second, meaning it takes about 90 seconds (1.5 minutes) for an earthquake originating 400 km away to reach Mexico City. In contrast, radio waves travel at nearly 300,000 kilometers per second, covering the same distance in just about 1 second. This difference provides a crucial window of opportunity for an early warning.
Following the 1985 earthquake, the Mexican government established an institution dedicated to seismic instrumentation and recording. This body leveraged the aforementioned scientific principle to construct a network of accelerometers along the Pacific coast and a corresponding network of repeaters extending to Mexico City. The system began operations, with its first real-world test occurring in 1991 when an earthquake on the coast triggered an alert in the city. Initially, the system comprised only 12 sensors on the coast, but it has since expanded to cover the entire eastern coast of Mexico.
Rábade's personal involvement began around 2010 when he noticed specialized radios labeled "alertismic" or "earthquake alert" appearing in government agencies. His curiosity was piqued by these devices, which bore logos from NOAA (National Oceanic and Atmospheric Administration) and other institutions. This led him to investigate the underlying technology. He acquired an electronic module, built a receiver, and connected it to the internet, eventually publishing his findings and open-source code. This move garnered significant attention in Mexico City, as the proprietary radios were expensive and restricted to a single vendor. Rábade's work, including workshops on building these receivers, democratized access to the alert system, inspiring new entrepreneurs to enter the market and provide more affordable alternatives, some of which, Rábade notes, utilize code derived from his own open-source publications. His investigation culminated in his graduation work, a thoroughly engineered receiver, and ultimately, this detailed conference talk.
Key Findings
▶ Watch: Geological reasons for Mexico City's earthquake vulnerability (4:00)
Manuel Rábade's deep dive into Mexico City's Seismic Alert System (SAS) revealed several critical findings, encompassing both the system's operational strengths and its inherent security limitations. The core of his findings revolves around the Emergency Alert System (EAS) and Specific Area Message Encoding (SAME) protocol, which, despite its vital role, reflects its origins as a 1960s technology.
One of the primary findings is the simplicity and accessibility of the EAS-SAME protocol. Rábade demonstrated that the signals can be easily received and decoded using readily available Software Defined Radio (SDR) dongles like the RTL-SDR and a simple quarter-wave monopole antenna. This ease of reception, while enabling widespread implementation and fostering community engagement (as seen with Rábade's open-source decoder), also highlights potential vulnerabilities.
The most significant security findings pertain to the protocol's fundamental design:
- Lack of Origin Verification: The EAS-SAME protocol has no built-in mechanism to verify the authenticity or source of the transmitted messages. As Rábade emphatically states, "any transmitter can broadcast a valid signal that can trigger hundreds or thousands of receivers." This means an unauthorized entity with the right equipment could potentially spoof an alert.
- Message Tampering: Related to the lack of origin verification, messages transmitted via EAS-SAME are not digitally signed. This absence of cryptographic integrity allows for the possibility of message tampering, where an attacker could alter the content of an alert before it reaches receivers, potentially changing its severity, event type, or geographic scope.
- Interference or Jamming: Like any wireless communication technology, EAS-SAME is susceptible to interference or jamming. Malicious actors could intentionally disrupt the transmission frequencies, preventing legitimate alerts from reaching the population during a critical event.
Rábade also highlighted specific nuances in the Mexican implementation of EAS-SAME, which deviates slightly from the US standard:
- Regular Test Packets: In Mexico, a small "test" packet is sent every three hours, rather than weekly, to ensure radios are working and receiving signals.
- Earthquake Warning Prioritization: For EQW (Earthquake Warning) events, the message is sent three times, and receivers are mandated to play a specific, pre-recorded tone. Crucially, the Mexican implementation explicitly does not use an optional voice message for earthquake alerts, a departure from the US standard. The official rationale is to privilege the earthquake warning, but Rábade suggests it also effectively creates a market for Mexico-specific receivers.
- Language Limitations: The protocol, designed for basic ASCII characters, has limited capabilities for encoding messages in multiple languages. Furthermore, it supports only one voice channel, restricting the complexity or multilingual nature of any potential voice alerts.
Through his open-source Python decoder and the demonstration of generating valid EAS-SAME .wav files, Rábade concretely illustrated the protocol's inherent simplicity and the relative ease with which its messages can be manipulated or replicated. While emphasizing the illegality of transmitting such signals, his work serves as a powerful proof of concept for the vulnerabilities present in this critical, yet aging, public alert system.
Technical Deep Dive
▶ Watch: Science behind early warning: seismic vs. radio waves (4:50)
The Mexican Seismic Alert System (SAS) leverages the Emergency Alert System (EAS), a network of transmitters, and the Specific Area Message Encoding (SAME) protocol for broadcasting digital alert signals. EAS provides the physical infrastructure for transmission, while SAME defines the digital format of the alert messages. The original purpose of SAME was to attach specific geographic area codes to alerts, ensuring that only relevant regions receive notifications, as radio broadcasts can extend beyond affected zones.
The EAS-SAME system originated in the 1960s in Chicago, USA, initially for broadcasting marine weather conditions. Its evolution has been slow: digital information was introduced in the 1970s, the protocol was published in the 1980s, adopted across the US in the 1990s, and finally adopted by Mexico in 2008. In the US, the system covers approximately 90% of the country with over 700 transmitters, used for a wide range of events like tornadoes and floods. In Mexico, there are around 15 transmitters, primarily covering central Mexico, including Mexico City. These transmitters typically operate at 100 watts of power, providing a range of up to 54 kilometers on flat terrain.
The system utilizes the NOAA Weather Radio band, operating in the VHF spectrum around 162 MHz. There are 10 channels available, including seven standard channels. The audio component of the broadcast uses Wide FM (WFM) modulation with a 16 kHz bandwidth. This is often used to transmit continuous weather forecasts or, in Mexico's past, classical music, providing a carrier for the digital alerts.
When an alert is sent, the digital information is encoded using FSK (Frequency Shift Keying) modulation, reminiscent of older internet modems. The bit period is 1.92 milliseconds, translating to a relatively slow data rate of less than 600 bytes per second. Characters are encoded in 7-bit ASCII, with the least significant bit (LSB) transmitted first.
A SAME message is structured with specific components:
- Preamble: A synchronization sequence to prepare the receiver.
- Header: This critical component is sent three times consecutively. This redundancy, a legacy from the 1960s design, ensures backward compatibility and allows older receivers to function. Modern receivers are expected to perform a "two-out-of-three" majority vote for each byte to reconstruct the message reliably. The header contains vital information:
- Start of Header (ZCZC): A fixed character sequence.
- Originator Code: Identifies the issuing agency (e.g., NWS for National Weather Service).
- Event Type (e.g., EQW, WTT, TO): A three-letter code indicating the nature of the alert. There are approximately 100 such codes.
- Geographic Area Code(s): Specifies the affected regions. A single message can contain multiple area codes.
- Expiration Time (e.g., HHMM): When the alert is no longer valid.
- Issue Date and Time (e.g., YYYYMMDDHHMM): When the alert was issued.
- Transmitter ID: Identifies the specific transmitter.
- Optional Alert Tone: A distinct 1050 Hz tone, included for backward compatibility with older radios from the 1970s that might not decode digital messages.
- Optional Voice Message: A human-recorded message providing additional details.
- End of Message (NNNN): A fixed character sequence indicating the end of the alert.
Mexico's implementation, while based on the EAS-SAME standard, includes specific regulations. The NOM (Official Mexican Standard) mandates that offices and public places must have certified receivers. The technical standard for these systems specifies a response time of less than 5 seconds for certified receivers. As noted, for EQW (Earthquake Warning), the Mexican system sends the SAME message three times, and the receiver must play a specific, pre-recorded tone without an accompanying voice message, a deviation from the US standard designed to prioritize the earthquake alert.
Compared to more modern alerting mechanisms, EAS-SAME shows its age. Contemporary alternatives include the Common Alerting Protocol (CAP), an XML-based standard that supports digital signatures for message authentication and allows for more complex, multilingual content distribution. Another modern approach is Cell Broadcast, the mobile technology commonly used for public alerts on smartphones, though it also comes with its own set of limitations as highlighted in other security research. The EAS-SAME system's reliance on a fixed, unauthenticated, and relatively slow digital protocol underscores the trade-offs between widespread accessibility, resilience in analog environments, and robust security.
Demo / Proof of Concept
▶ Watch: Introduction to EAS-SAME for public alert broadcasting (7:50)
Manuel Rábade's presentation included a compelling demonstration of how to both receive and generate EAS-SAME alert messages, underscoring the system's inherent simplicity and the practical implications of its design.
For receiving the signals, Rábade illustrated that specialized commercial radios are not the only option. Anyone can use an affordable SDR dongle, such as the popular RTL-SDR, coupled with a simple quarter-wave monopole antenna (approximately 45 cm in length). Using software like SDR++, he showed a waterfall display of the 162 MHz VHF band. From his Mexico City location, he could observe signals from six different transmitters, demonstrating the system's broad coverage.
When tuning into one of these channels, the continuous audio broadcast, which historically featured classical music and now typically carries weather forecasts, is audible. However, during an alert, a distinct digital burst of information interrupts this audio. Rábade played an audio clip of this burst, which sounds like the characteristic tones of an old FSK modem. The SDR++ waterfall clearly visualizes these bursts as distinct blocks of activity, showing the three repeated headers and the three end-of-message sequences.
To decode these captured signals, Rábade developed his own Python-based decoder. This open-source tool, available on his GitHub page, processes recorded waveform files. It employs a bandpass filter to isolate the relevant frequencies, the Goertzel algorithm for efficient tone detection, and synchronizes with the signal using preamble detection and a sliding window approach. The output of his script is a clear, human-readable breakdown of the SAME message, displaying fields such as the event type (e.g., EQW), geographic area codes, and issue times.
The logical extension of being able to decode a signal is the ability to generate it. Rábade pointed out that his investigation revealed other existing software, like multimon (a decoder from the 1990s), that also process EAS-SAME. However, for generation, he found a convenient Python module that allowed him to create his own valid EAS-SAME messages. He demonstrated that these generated messages, saved as standard .wav files, are indistinguishable in format from legitimate alert signals.
Rábade emphasized a crucial disclaimer: transmitting such generated signals is strictly prohibited by Mexican law. The frequencies used by the SAS are part of a protected spectrum designated for early warning systems, and interfering with or spoofing these signals carries severe legal consequences. Nevertheless, the ease with which these messages can be decoded and generated serves as a powerful proof of concept, highlighting the inherent vulnerabilities of an unauthenticated, open protocol. This practical demonstration effectively bridges the gap between theoretical understanding and the tangible security implications of the system.
Defensive Implications
▶ Watch: Speaker's personal curiosity sparked by alert radios (9:00)
Manuel Rábade's analysis of the EAS-SAME protocol within the Mexican Seismic Alert System (SAS) reveals several critical defensive implications, primarily stemming from the protocol's age and design simplicity. The core vulnerabilities—lack of origin verification, unsigned messages, and susceptibility to interference/jamming—demand strategic considerations for enhancing the system's resilience and trustworthiness.
For system operators and government institutions like Mexico's CIRES (Centro de Instrumentación y Registro Sísmico), the immediate defensive priority should be to explore mechanisms for message authentication and integrity. While the existing EAS-SAME protocol does not natively support digital signatures, a long-term strategy could involve migrating to or integrating with more modern standards like the Common Alerting Protocol (CAP). CAP, being XML-based, explicitly supports cryptographic signatures, which would allow receivers to verify that an alert originated from an authorized source and has not been tampered with in transit. This would directly address the spoofing and tampering vulnerabilities.
In the interim, efforts could focus on securing the physical transmission infrastructure. This includes robust physical security for all transmitters and central stations, as well as securing the communication links between the sensor networks, central processing, and the broadcast transmitters. Implementing redundant transmission paths and potentially diversifying frequencies (if technically feasible within regulatory constraints) could mitigate the impact of localized jamming or interference.
For receiver manufacturers and developers, while the protocol's simplicity allows for basic hardware, future designs should consider incorporating enhanced validation mechanisms. Although full cryptographic verification is not possible within the current SAME message structure, receivers could implement heuristics or out-of-band checks where possible (e.g., cross-referencing with official government APIs if an internet connection is available, though this compromises the analog resilience). More importantly, the Official Mexican Standard (NOM) and technical standards should be updated to mandate stronger security features in new receiver certifications, potentially requiring CAP compatibility or other secure communication channels.
From a public awareness and policy perspective, it is crucial to educate the population about the official nature of the alerts and the potential for malicious spoofing. While the "earthquake alert tone" is deeply ingrained in Mexican culture, clarifying that unauthorized transmissions are illegal and that official channels are the sole source of truth can help manage public response in case of a false alert. Stricter enforcement against unauthorized transmissions on protected spectrums is also vital.
Rábade's concluding thoughts highlight the perpetual challenge of balancing accessibility, interoperability, and security. The EAS-SAME system's strength lies in its simplicity and resilience in analog environments, making it highly accessible and interoperable with older equipment. However, these very strengths become weaknesses in a modern threat landscape. While modern alternatives like CAP and Cell Broadcast offer enhanced security features, they also introduce new complexities and potential limitations (as seen in other research on Cell Broadcast vulnerabilities). Therefore, the defensive strategy must involve a careful, phased approach: leveraging the strengths of the current system while progressively integrating more secure technologies, ensuring backward compatibility where absolutely necessary for public safety, and continuously evaluating the evolving threat landscape. The goal is to evolve the system without compromising its fundamental life-saving mission.
Key Takeaways
- Life-Saving, Yet Aging Infrastructure: The Mexican Seismic Alert System (SAS), based on the EAS-SAME protocol, is a critical, life-saving early warning system for millions in Mexico City, providing up to 90 seconds of warning for distant earthquakes.
- Fundamental Security Flaws: The EAS-SAME protocol, originating from the 1960s, lacks modern security features such as origin verification and digital signatures. This leaves it vulnerable to spoofing and message tampering by unauthorized parties.
- Ease of Interaction: The signals are easily received and decoded using readily available SDR dongles (e.g., RTL-SDR) and open-source software, as demonstrated by Manuel Rábade's Python decoder. Furthermore, valid EAS-SAME messages can be generated with relative ease, highlighting the practical potential for abuse.
- Mexican Implementation Specifics: Mexico's SAS has unique characteristics, including a non-weekly "test" signal and a specific, tone-based earthquake warning that omits voice messages, deviating from the standard US implementation to prioritize the alert.
- Balancing Act in Critical Systems: The system exemplifies the constant challenge of balancing accessibility, interoperability (especially with older hardware), and robust security in critical public infrastructure. Its analog resilience is a strength, but its lack of authentication is a significant weakness.
- Future for Alert Systems: While modern alternatives like the Common Alerting Protocol (CAP) and Cell Broadcast offer enhanced security features like digital signatures, they also come with their own complexities and limitations, indicating that a perfect solution remains elusive.
About the Speaker(s)
Manuel Rábade is a highly experienced computer and software engineer, deeply rooted in technology since the 1990s. He has been an active member of the free and open-source software (FOSS) community since the 2000s, reflecting his commitment to open knowledge and collaboration. Rábade studied computer engineering at a national university in Mexico and brings over 20 years of experience in software engineering to his work. He is particularly involved in the hacking, radio frequency, and software communities, driven by a profound curiosity to understand how systems truly work, explore their boundaries, and share his discoveries. His personal website is raad.net, where more information about his projects can be found. Rábade's work on the Seismic Alert System is a personal passion project, not conducted in an official government capacity, underscoring his independent, curiosity-driven approach.
All talks from 39th Chaos Communication Congress (39C3): Power Cycles