Question-1: What is ByLock?
Answer-1: ByLock, developed and used by the members of FETO (the Fethullahist Terrorist Organization), is a messaging application that has the ability to make technical surveillance as difficult as possible. Following analyses within application stores, it is detected that ByLock application was seen for the first time in Google Play in 11th of April, 2014. In 20th of May, 2014 it can be seen that ByLock application was upgraded to v1.0.8 and number of downloads reached over 5.000 and just 11 days after (1th of June, 2014) this number climbed to 10.000. Two and a half months later on (24th of August, 2014) it is determined that the number of downloads hit over 50.000. According to the last statistics, dated in 19th of January 2015, user count was just over 100.000.
Q-2: What sort of information was gained from application server?
A-2: Below is the brief information, used by the server and seized by MIT (National Intelligence Organization) from ByLock application database:
- ByLock users’ account info
- Content of the messages among Block users
- Voice call records among Block users
- ByLock users’ activity details (logging in etc.)
- Access records that demonstrates which user linked to the server through which IP
- Info regarding files that are sent/received by ByLock users
- Each ByLock users’ directory records
Q-3: Is it true that a special encryption method was used through application development process and in user messaging feature? Were any additional safety measures taken for initial start-up and application usage? Are there any different features from other instant messaging apps?
A-3: With reference to both my previous reverse engineering practices (detailed in this report) and the server-side source code obtained from the server which appears in the MIT Technical Report, it can be said that ByLock application is a messaging app using advance encryption methods and prioritizing anonymity. Regarding features like storing all messages encoded in the server, users’ necessity to know User ID of the contact and entailment of both sides to add exact User ID value of one another before enabling communication, disabling the directory of the phone; it is considered that ByLock is developed with a way and purpose unlike the generally excepted messaging apps in our day.
Q-4: There is information that thousands of logins on ByLock were carried out with the phone number of my own. That cannot be possible for me to login in just one day. What is the reason for that?
A-4: I have encountered similar statements in some of the pleas I came across and those people are posing questions like ‘how come they logged in several times in one day?’. Firstly, it is necessary to point out that; every access record in CG-NAT does not indicate a login by itself. You may be logged in just once but while you are messaging, transferring files, adding a new individual to your directory, different connections might be establishing for those activities in the background. This particular case exists in access protocols used in internet because of its very nature. Thereby, one user can have several thousand links to the ByLock server in one day.
Q-5: While ByLock application was in use, it seems like I was in Ankara. However I was in Adana on that exact date and hour. What is the reason for that case?
A-5: Although the answer to that question can be found on the report, if I should explain it briefly; the IP address, assigned to the user for internet connection, remains attached to the same user for a long time even if the user switches base stations and throughout that IP’s usage, address is in use seen source location is pinned to wherever that IP address is assigned to the user in the first place. Therefore it can be said regarding your question; due to the differences in data and voice networks in GSM architecture, while in data network the base station info attached to the user when initial session is began, is registered in GPRS and NAT CDR records during user’s whole session, on the other hand, in voice network, base station that gives service is registered in CDR whenever GSM activation (incoming/outgoing call or SMS, location update etc.) takes place. Hence, controlling and confirming tasks regarding subscribers should be based on location info of voice network.
Q-6: Say, I downloaded the ByLock application, tried to use it but I couldn’t, then erased it. Am I on the list?
A-6: Whilst making lists regarding ByLock users, it is know that there is a precondition of connecting to the ByLock server at least three different days. Therefore, if you couldn’t manage to work out the app after you downloaded it and then erased it, it is possible to say that your name is not and won’t be on the list.
Q-7: What is the reason for contacts on ByLock and casual phone calls are completely different?
A-7: Although there are details on the relevant part of the report, but if I may summarize, ByLock application does not use phone’s directory it is installed on, instead it uses its own new directory created by its user. Individuals who want to communicate via application have to know each other’s user identity number -identified as User ID- and send requests mutually for adding one another. Only under these circumstances one user can add another one on ByLock directory and later on establish communication.
Q-8: It can be seen on my both Google Play and App Store history that I haven’t downloaded ByLock by any means. How am I supposed to use ByLock?
A-8: Even tough application stores are used to easily install apps to the smartphones, but it is not the only way to do so. For instance, applications can be installed to Android smartphones via Bluetooth, SD card or directly from computer. Also it is possible to download and install any APK package file from internet. With the phones that use iOS operating system, application can be installed from a source other than a application store via jailbreaking.
Q-9: There was no trace of ByLock in phone’s image. What does it mean?
A-9: Until now, considering the issue, we have taken thousands of images of mobile phones and analysed them. As you can see the details in the report, type and quantity of digital evidence that can be harvested from a smartphone depends on basic parameters like how long it is being used or whether it has gone under any deletion process. Just because there is no trace of ByLock application in a device, doesn’t mean ByLock has never been installed on the device before. Application’s own files and junk files can be erased from mobile phone’s memory and after a given time all of those traces might be unavailable.
Q-10: Is it possible to make faulty evaluation due to IP conflict?
A-10: Thus far, I have never encountered IP conflict-derived victimization among ByLock cases I studied in detail. Besides relevant organizations of the state carried out vital analysis on the data, derived from the systems of the operator that has experienced the forespoken IP conflict issue before and necessary measures has been taken way before compiling a list to avoid misjudgement. Furthermore, as I said before, considering the criteria that requires at least 3 different days, there is no chance of coming across of IP conflict victimization.
Q-11: Is it possible that I am being considered a ByLock user because of a remote installation?
A-11: Although this issue is detailed on the relevant part of the report, but if I may summarize, you cannot be indicated a ByLock user as a result of a remote installation. But there might be a direct link to the ByLock server through some other application you have actually installed. Highlighting on the fact that in the case of coming across with such a case, through analysis of that traffic it can be understood that you are not a real ByLock user and sent a request to the ByLock server via routing.
Q-12: Is it possible that ByLock is installed on a phone that is dated and without internet infrastructure?
A-12: This issue is over-speculated on the press lately. Such as owners of Nokia phones listed as ByLock users. But there is a crucial point that shouldn’t be ignored; IMEI’s can be cloned or copied. Especially in order that the smuggled smartphones to work within the networks here in Turkey, they are copying old phone’s trouble-free IMEIs to those smuggled phones and this is a quite common practice. In such a case, it is anticipated that operator records maintain the copied IMEI used to belong to an old Nokia phone, instead of the original one on the Android device.
Q-13: Is it possible that ByLock is found on my second-hand phone?
A-13: It is possible to discover ByLock on the phone you bought as second-hand. But keep in mind that the reason you are on the mentioned lists is not your phone contains ByLock, but using the ByLock application is.
Q-14: Is it possible for ByLock to be used in desktop PCs and tablet PCs?
A-14: Desktop version of ByLock is not available. However, it can be managed for ByLock to operate in PCs, especially via emulators often preferred by application developers. But that requires that the developer to have advance computer skills.
Q-15: Is it possible to download ByLock by mistake? If possible, what is the situation for those that downloaded the app and never used it? Are the messages sent via ByLock obtained and if yes, do those messages contain any organizational interactions and activities?
A-15: It is not possible to download ByLock by mistake. After all you may have downloaded the app just out of curiosity. Even so, considering the operating logic of ByLock, you first have to sign in the application server and log in to create your own directory, add individuals and establish communications with those contacts via calls or messages. All those activities recorded by operators. There is no need for you to worry if you downloaded the app but never used it.
All messages sent via ByLock are encrypted and stored in the database located on the ByLock servers by its nature. Taking into consideration sample contents of the MIT Technical Report and contents of law court papers, it is anticipated that encrypted messages obtained from the database on the ByLock server were decrypted. It is known that there are organizational regulatory messages and instructions to the members of the organization.
You can find my technical report about ByLock Application and Its Communication Infrastructure at this post.

