You assign users a temporary IMSI which is done in the cloud right? How does this protect against IMSI catchers and Stingrays if they are done local to you? Local cell tower spoofing? Also, this is just for data? So if you have another SIM for voice/SMS this is completely negated?
PGPP (Pretty Good Phone Privacy) Beta Launch
41–50 of 104 posts
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#42Earlier quoted context omitted.
> There are credit cards that aren't linked to a person My desire to know more intensifies.
https://www.amexgiftcard.com/ Go to the grocery store, buy with cash, you're good to go.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#43Just wanted to say hi – I’m one of the co-founders of this effort and would love to answer any questions or discuss further. Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities.…
- Given that your Android app is security-critical for its users, are you planning on open-sourcing it in the near future?
- How exactly does your app work on Android? How does it rotate the IMSI? (I don't know a lot about eSIMs but I would have thought a regular app can't easily change the carrier/network settings.)
- As for the relay functionality, I suppose on Android this "simply" sets up a VPN once the network connection is established?
[0]: https://www.usenix.org/conference/usenixsecurity21/presentat...
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#44Earlier quoted context omitted.
This is one of the problems with mobile -- there's isn't any one universally correct answer to this (or most questions), so I'll answer to the best of my knowledge. IMSIs are what are associated with your identity (because it's your SIM and service) in a normal mobile plan, and it's what was (is?) used by carriers when they aggregate / analyze / sell location data. IMEIs can be queried by a network core (not the towe…
> IMEIs can be queried by a network core (not the tower) and US carriers probably do this every once in a while to check against their stolen phone database. It can be changed on some devices but not others. It's not inherently tied to you as a person but of course it is tied to that device. It's also linked to the rotating IMSI, so all of the rotating IMSIs that are used at the times the IMEI is interrogated are lin…
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#45This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#46Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#47Just wanted to say hi – I’m one of the co-founders of this effort and would love to answer any questions or discuss further. Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities.…
Um what? Is PRZ involved? Is he ok with your using that name? He had something called PGPFone a long time ago, though it didn't get much traction. There have also been tons of other encrypted voice programs. Obscuring traffic patterns without stupendous amounts of dummy traffic is quite difficult. That someone is connected to your network at all is already a huge giveaway. I have trouble seeing how something like thi…
Does anyone have a copy of it? I can't find it ANYWHERE. Actually used it way back when, it worked surprisingly OK and was the first softphone I used.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#48Earlier quoted context omitted.
https://www.amexgiftcard.com/ Go to the grocery store, buy with cash, you're good to go.
No. All payment cards in the United States require strong government identity and KYC, per US federal law. To activate these cards you must provide identity information. Providing false information is a crime.
No. Gift cards can be purchased in-person in the US, with cash. Said gift cards are activated at the register upon purchase. These can then be gifted to someone else, and further activation (or registering your personal information with the card) is not required.
Edit: I just checked the Visa gift card issuer's site for a card I have (and never had to activate or provide personal information to), and for shopping online it just says:
>In the Payment Method section, enter the Card information as you would a credit or debit card. In the Billing Address section, fill in your name and address.
So when I check out online, I can enter any information that I like, presumably as long as it ties back to a valid address of some kind - there is zero effort on the part of the card issuer to verify that I am who I say I am. I would only need a PIN when making purchases with it as a debit card in-person. I should make it clear that I'm not saying that providing false information is legal, just that the point about being required to provide "strong government identity" to activate gift cards has been false for a long time.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#49Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#50I still do find it disingenuous to omit it entirely as it implies that all possible issues are averted which they absolutely are not, even if IMEI wasn't a factor.