Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

51–60 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#51
post #6
post #5

Earlier quoted context omitted.

Does this also randomize the IMEI, or just the IMSI? Seems like if the same IMEI shows up over and over again with a different rotating IMSI then the jig is up.

The IMSI. We don't do anything with the IMEI ourselves (it's in the category of hardware identifiers that I'm mentioning above). Some phones can change them when rooted, some can't. The network attach process doesn't use the IMEI inherently by spec, but some cell cores can query for it (for example, to block stolen phones). It's not a network identifier, and strange things sometimes happen with the IMEI that don't ev…

I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#52
post #24
post #22

Earlier quoted context omitted.

> The network attach process doesn't use the IMEI inherently by spec, but some cell cores can query for it (for example, to block stolen phones). How widespread is this practice? Do the major US carriers know my IMEI? I tend to believe that they do from what I've seen in their web interfaces, and that IMSI rotation alone is basically pointless from a privacy standpoint.

This is one of the problems with mobile -- there's isn't any one universally correct answer to this (or most questions), so I'll answer to the best of my knowledge. IMSIs are what are associated with your identity (because it's your SIM and service) in a normal mobile plan, and it's what was (is?) used by carriers when they aggregate / analyze / sell location data. IMEIs can be queried by a network core (not the towe…

Please familiarise yourself with how cell networks actually work, you can't throw out comments like this because it's just not true.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#54

I would love to buy your product, but won't yet. I need a few things: 1) You should explicitly test with privacy-respecting Android flavors like GrapheneOS. I assume it would work using the sandboxed play services hack, but I'm not sure. 2) You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and…

> You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and mandate various other kinds of nannying), and, generally, seems like it's sliding down the path towards some sort of oppressive surveillance state.

What? No such thing exists, stop

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#55
post #6

Earlier quoted context omitted.

The IMSI. We don't do anything with the IMEI ourselves (it's in the category of hardware identifiers that I'm mentioning above). Some phones can change them when rooted, some can't. The network attach process doesn't use the IMEI inherently by spec, but some cell cores can query for it (for example, to block stolen phones). It's not a network identifier, and strange things sometimes happen with the IMEI that don't ev…

I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.

No post body was provided.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#57
post #24

Earlier quoted context omitted.

This is one of the problems with mobile -- there's isn't any one universally correct answer to this (or most questions), so I'll answer to the best of my knowledge. IMSIs are what are associated with your identity (because it's your SIM and service) in a normal mobile plan, and it's what was (is?) used by carriers when they aggregate / analyze / sell location data. IMEIs can be queried by a network core (not the towe…

Please familiarise yourself with how cell networks actually work, you can't throw out comments like this because it's just not true.

I know it's work, but...could you explain?

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#58

Earlier quoted context omitted.

Please familiarise yourself with how cell networks actually work, you can't throw out comments like this because it's just not true.

I know it's work, but...could you explain?

If anyone else asked sure but I reviewed your comments earlier and I think it might be a lost cause.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#59
post #6

Earlier quoted context omitted.

The IMSI. We don't do anything with the IMEI ourselves (it's in the category of hardware identifiers that I'm mentioning above). Some phones can change them when rooted, some can't. The network attach process doesn't use the IMEI inherently by spec, but some cell cores can query for it (for example, to block stolen phones). It's not a network identifier, and strange things sometimes happen with the IMEI that don't ev…

I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out).

I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#60

I don't like that this is piggybacking on the recognizable name of an open standard and not-for-profit software while being considerably less open (Where's the RFC? Where's the source code?) and being for-profit. This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.

That's a neat metaphor.
Post reply on HN