Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

81–90 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#82
post #2

Just wanted to say hi – I’m one of the co-founders of this effort and would love to answer any questions or discuss further. Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities.…

Hi, less than 48 hours ago you had a "Show HN".

Your claim "we don't learn which eSIM your phone gets" is false. The eSIM update protocol, which is implemented in firmware which you do not control, will send you (the carrier) the eSIM's permanent ID (the EID), and you can't stop this. https://news.ycombinator.com/item?id=32416373

Moreover, you provide no protection whatsoever against IMEI tracking, which all carriers implement. IMEIs are reported to the carrier immediately after authentication/attach (AKA), and many will block invalid/unexpected IMEIs. You can't prevent this. Without a solution to IMEI tracking your work on IMSI tracking isn't much use. This won't protect anybody from the telcos. At best it might stop people using a stingray without assistance from the telco (i.e. almost nobody). https://news.ycombinator.com/item?id=32416308

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#83

Earlier quoted context omitted.

I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

> IIRC changing the IMEI in the U.S. is legal.

This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998:

"Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information associated with or contained in a telecommunications instrument"

https://www.congress.gov/bill/105th-congress/senate-bill/493

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#84

I commented on a previous post and while it's sort of been answered here i think it still merits being included: https://news.ycombinator.com/item?id=32397969 I still do find it disingenuous to omit it entirely as it implies that all possible issues are averted which they absolutely are not, even if IMEI wasn't a factor.

Yeah he totally ignored most of my comments in the other thread, then simply resubmitted his "startup" again here less than 48 hours later.

Every time anybody points out the severe technical flaws in this scheme he either waves it away with happytalk or ignores it.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#85

Earlier quoted context omitted.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

> IIRC changing the IMEI in the U.S. is legal. This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998: "Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information asso…

To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#86

Earlier quoted context omitted.

> IIRC changing the IMEI in the U.S. is legal. This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998: "Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information asso…

To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."

Because it doesn't matter: none of the big three tower operators in the USA authorizes you to use their telecommunications service with a fake IMEI.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#87
post #79

I don't like that this is piggybacking on the recognizable name of an open standard and not-for-profit software while being considerably less open (Where's the RFC? Where's the source code?) and being for-profit. This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.

I'm pretty sure the original PGP program was (and maybe still is?) a for-profit product.

I'm pretty sure you shouldn't try to piggyback off of a for-profit company's name either.

In fact atleast over here in Finland naming one's company is specifically reviewed by the patent and registry bureau to make sure it doesen't resemble any existing companies. It costs around 100-450€ and is mandatory for any new company

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#88
post #8

Earlier quoted context omitted.

Right now we use Stripe (mostly because it's the the most rock solid choice for payments) -- we don't ask for name or email, though of course Stripe could know that as a card processor. But our approach goes back to decoupling human identity from network identity -- what that payment says is that the holder of that card is a subscriber of the service but not, for example, what network ID you got.

Once you accept some kind of privacy coin (monero) I'll be delighted to buy a years service upfront. I imagine many others will be in the same position. Obviously taking crypto will mean upfront prepayment of accounts (like prepaid mobile credit) instead of monthly billing and will require some reworking.

Not accepting Monero and not having the app open source and on F-Droid are also why I won't even think about subscribing to this service for now.

For a privacy product this should have been there at the start.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#90

Earlier quoted context omitted.

To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."

Because it doesn't matter: none of the big three tower operators in the USA authorizes you to use their telecommunications service with a fake IMEI.

There is no such thing as a "fake" IMEI.
Post reply on HN