Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

71–80 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#71
post #28

I would love to buy your product, but won't yet. I need a few things: 1) You should explicitly test with privacy-respecting Android flavors like GrapheneOS. I assume it would work using the sandboxed play services hack, but I'm not sure. 2) You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and…

Thanks -- to your comments / questions: 1) we have tested with GrapheneOS and it does work. Relay works well with GrapheneOS. With some amount of configuration, the mobile plans also work, though it can be a bit tricky to set up. 2) We have many egresses (via Fastly) -- across North America, South America, Europe, and Asia -- and more planned. The London egress is used when you're on mobile data by default, but if yo…

Has the app been tested to work with GrapheneOS (without requiring Google Play Services). This question applies to both the esim function and/or the relay feature.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#72

This is great if you are using an old SIM that still operates using IMSI on the sNode B Tower, its also bad because this is simply another overlay band-aid fix which bloats and slows your phone down, the privacy phones made by Obsidian Intelligence Group (obsidianintel.com) don't have this problem and they are also impervious to the SS7 network, I would check them out.. You can find more info on their twitter page @O…

You have a cellphone that does not use an IMSI to authenticate to your provider?

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#73

This is great if you are using an old SIM that still operates using IMSI on the sNode B Tower, its also bad because this is simply another overlay band-aid fix which bloats and slows your phone down, the privacy phones made by Obsidian Intelligence Group (obsidianintel.com) don't have this problem and they are also impervious to the SS7 network, I would check them out.. You can find more info on their twitter page @O…

No post body was provided.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#74

I commented on a previous post and while it's sort of been answered here i think it still merits being included: https://news.ycombinator.com/item?id=32397969 I still do find it disingenuous to omit it entirely as it implies that all possible issues are averted which they absolutely are not, even if IMEI wasn't a factor.

No post body was provided.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#75
post #8

Earlier quoted context omitted.

What payment methods are available, and what data do you collect for billing? Could I pick up an eSIM compatible Android tomorrow for cash at the local pawn shop, and get service using your system without handing over anything identifiable?

Right now we use Stripe (mostly because it's the the most rock solid choice for payments) -- we don't ask for name or email, though of course Stripe could know that as a card processor. But our approach goes back to decoupling human identity from network identity -- what that payment says is that the holder of that card is a subscriber of the service but not, for example, what network ID you got.

Do you accept visa/mc/amex giftcards? Stripe merchants can opt to decline these cards.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#76
post #28

Earlier quoted context omitted.

Thanks -- to your comments / questions: 1) we have tested with GrapheneOS and it does work. Relay works well with GrapheneOS. With some amount of configuration, the mobile plans also work, though it can be a bit tricky to set up. 2) We have many egresses (via Fastly) -- across North America, South America, Europe, and Asia -- and more planned. The London egress is used when you're on mobile data by default, but if yo…

Has the app been tested to work with GrapheneOS (without requiring Google Play Services). This question applies to both the esim function and/or the relay feature.

Currently on GrapheneOS relay works without Google Play Services. eSIM support _does_ require "sandboxed Google Play": https://grapheneos.org/usage#sandboxed-google-play-esim

Much much more discussion on this here: https://github.com/GrapheneOS/os-issue-tracker/issues/159

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#77

Earlier quoted context omitted.

You can buy visa gift cards for cash

I haven't been able to do that in Europe without providing ID for well over a decade.

Ive never been asked for ID to buy a gift card in USA. I thought Europe was once renowned for it's strong financial privacy laws? my, things have changed.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#78

Earlier quoted context omitted.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

Ok so I should have said in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case), however the 3gpp spec that governs all networks and devices, like your phone, prohibits IMEI changing -its not an innocuous operation as people assume Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing. A curso…

> Ok so I should have said [that changing the IMEI of a phone is a criminal offense] in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case)

This would mean that, in sensible societies, failing to carry a phone on your person is a criminal offense. It is a position only a true idiot could even articulate.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#79

I don't like that this is piggybacking on the recognizable name of an open standard and not-for-profit software while being considerably less open (Where's the RFC? Where's the source code?) and being for-profit. This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.

I'm pretty sure the original PGP program was (and maybe still is?) a for-profit product.
Post reply on HN