Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

61–70 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#61

I would love to buy your product, but won't yet. I need a few things: 1) You should explicitly test with privacy-respecting Android flavors like GrapheneOS. I assume it would work using the sandboxed play services hack, but I'm not sure. 2) You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and…

> You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and mandate various other kinds of nannying), and, generally, seems like it's sliding down the path towards some sort of oppressive surveillance state. What? No such thing exists, stop

https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin...

"UK mobile phone operators began filtering Internet content in 2004[9] when Ofcom published a "UK code of practice for the self-regulation of new forms of content on mobiles".[107] This provided a means of classifying mobile Internet content to enable consistency in filtering. All major UK operators now voluntarily filter content by default."

It's Wikipedia, so take it with a grain of salt, but...

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#62

Earlier quoted context omitted.

> You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and mandate various other kinds of nannying), and, generally, seems like it's sliding down the path towards some sort of oppressive surveillance state. What? No such thing exists, stop

https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin... "UK mobile phone operators began filtering Internet content in 2004[9] when Ofcom published a "UK code of practice for the self-regulation of new forms of content on mobiles".[107] This provided a means of classifying mobile Internet content to enable consistency in filtering. All major UK operators now voluntarily filter content by default." It's Wikipe…

Read it again. (Wikipedia is correct)

Actually to save everyone else's time I'll explain the actual real world implications:

The "big 4" (over x customers) must implement "best effort" blocking, which varies between network (it's all useless because DNS is easy and satisfied the law), however unlike the USA, the UK has 100s if not 1000s of ISPs who are not subject to said regulation and can do what they want. This is because in the UK we do not stomp on competition which means independent ISPs are allowed to exist and pay the same price as everyone else for the same access.

While I'm here, there has never and never will be a "firewall" - the free market design of UK telecoms does not allow it to happen and there are no central points to filter, anyone who disagrees otherwise is a genuine moron or willfully ignorant, it doesn't matter the result is the same, since the reality trump's opinion.

If you'd like to discuss these things in real detail I have contact ability so message me instead of absolute nonsense on here - there is no excuse to be ignorant we live in an informational society.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#63
This is great if you are using an old SIM that still operates using IMSI on the sNode B Tower, its also bad because this is simply another overlay band-aid fix which bloats and slows your phone down, the privacy phones made by Obsidian Intelligence Group (obsidianintel.com) don't have this problem and they are also impervious to the SS7 network, I would check them out.. You can find more info on their twitter page @Obsidian_Intel as well.. I picked one up a few weeks ago and it is fantastic I couldn't be happier with it.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#64

Earlier quoted context omitted.

I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

Ok so I should have said in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case), however the 3gpp spec that governs all networks and devices, like your phone, prohibits IMEI changing -its not an innocuous operation as people assume

Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing.

A cursory Google suggests:

A bill was introduced in the United States by Senator Chuck Schumer in 2012 that would have made the changing of an IMEI illegal, but the bill was not enacted.

So in the USA specifically it is not a crime but in many places it is due to the aforementioned life at risk issue.

As devices are made for global .markets in general, the above does not apply anyway as you cannot change it without manufacturer tools anyway, at which point different regulation applies.

IMEI changes also have limited effect when fingerprinting is relatively easy.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#65
post #10
post #9

>PGPP does not support traditional phone calling/SMS and doesn’t include a phone number. Instead we recommend that users install and use more secure apps such as Signal and Matrix for voice and video. Doesn't signal require a phone number to use? Or did they fix that?

It does, but you can use any number, even a VoIP number. (And you can connect to the VoIP provider with PGPP Relay enabled.)

A service with throwaway numbers would be nice... a lot like https://www.emailnator.com/ does for email. But it would be even better if they wouldn't require a phone number or email.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#66
post #42

Earlier quoted context omitted.

https://www.amexgiftcard.com/ Go to the grocery store, buy with cash, you're good to go.

No. All payment cards in the United States require strong government identity and KYC, per US federal law. To activate these cards you must provide identity information. Providing false information is a crime.

Nonsense and balderdash sneak, I can walk into any grocery store which isn't fancy and buy a hundred buck's worth of Visa with cash.

You said this with remarkable confidence and were dead wrong. You should reflect on that.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#67

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Web_blocking_in_the_United_Kin... "UK mobile phone operators began filtering Internet content in 2004[9] when Ofcom published a "UK code of practice for the self-regulation of new forms of content on mobiles".[107] This provided a means of classifying mobile Internet content to enable consistency in filtering. All major UK operators now voluntarily filter content by default." It's Wikipe…

Read it again. (Wikipedia is correct) Actually to save everyone else's time I'll explain the actual real world implications: The "big 4" (over x customers) must implement "best effort" blocking, which varies between network (it's all useless because DNS is easy and satisfied the law), however unlike the USA, the UK has 100s if not 1000s of ISPs who are not subject to said regulation and can do what they want. This is…

I can tell you feel frustrated. I appreciate you engaging.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#68
post #47

Earlier quoted context omitted.

Um what? Is PRZ involved? Is he ok with your using that name? He had something called PGPFone a long time ago, though it didn't get much traction. There have also been tons of other encrypted voice programs. Obscuring traffic patterns without stupendous amounts of dummy traffic is quite difficult. That someone is connected to your network at all is already a huge giveaway. I have trouble seeing how something like thi…

>He had something called PGPFone a long time ago, though it didn't get much traction. Does anyone have a copy of it? I can't find it ANYWHERE. Actually used it way back when, it worked surprisingly OK and was the first softphone I used.

Here you go: http://www.pgpi.didisoft.com/products/pgpfone/

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#69
The IMSI change is only truly effective if paired with an IMEI rotation - which as others have noted is legal (usa). So now we have a service provider that supports IMSI rotation I guess it is up to folks who can work on the hardware level to add support for IMEI rotation. I heard that GrapheneOS is developing its own hardware. It's possible we may have a very effective defense against cellular layer privacy attacks in the near future.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#70

Earlier quoted context omitted.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

Ok so I should have said in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case), however the 3gpp spec that governs all networks and devices, like your phone, prohibits IMEI changing -its not an innocuous operation as people assume Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing. A curso…

Is no panacea to this problem everything has it's limits. Pairing an IMEI+IMSI rotation (which is perfectly lawful in many countries, grey in some and criminally prohibited in only a few) can be a very effective defense against network level threats to privacy.
Post reply on HN