PGPP (Pretty Good Phone Privacy) Beta Launch
81–90 of 104 posts
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#82Just wanted to say hi – I’m one of the co-founders of this effort and would love to answer any questions or discuss further. Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities.…
Your claim "we don't learn which eSIM your phone gets" is false. The eSIM update protocol, which is implemented in firmware which you do not control, will send you (the carrier) the eSIM's permanent ID (the EID), and you can't stop this. https://news.ycombinator.com/item?id=32416373
Moreover, you provide no protection whatsoever against IMEI tracking, which all carriers implement. IMEIs are reported to the carrier immediately after authentication/attach (AKA), and many will block invalid/unexpected IMEIs. You can't prevent this. Without a solution to IMEI tracking your work on IMSI tracking isn't much use. This won't protect anybody from the telcos. At best it might stop people using a stingray without assistance from the telco (i.e. almost nobody). https://news.ycombinator.com/item?id=32416308
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#83Earlier quoted context omitted.
I think you should clarify this, changing the IMEI in most countries is a criminal offence, do not keep brushing this topic off.
IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).
This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998:
"Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information associated with or contained in a telecommunications instrument"
https://www.congress.gov/bill/105th-congress/senate-bill/493
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#84I commented on a previous post and while it's sort of been answered here i think it still merits being included: https://news.ycombinator.com/item?id=32397969 I still do find it disingenuous to omit it entirely as it implies that all possible issues are averted which they absolutely are not, even if IMEI wasn't a factor.
Every time anybody points out the severe technical flaws in this scheme he either waves it away with happytalk or ignores it.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#85Earlier quoted context omitted.
IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).
> IIRC changing the IMEI in the U.S. is legal. This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998: "Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information asso…
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#86Earlier quoted context omitted.
> IIRC changing the IMEI in the U.S. is legal. This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998: "Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information asso…
To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#87I don't like that this is piggybacking on the recognizable name of an open standard and not-for-profit software while being considerably less open (Where's the RFC? Where's the source code?) and being for-profit. This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.
I'm pretty sure the original PGP program was (and maybe still is?) a for-profit product.
In fact atleast over here in Finland naming one's company is specifically reviewed by the patent and registry bureau to make sure it doesen't resemble any existing companies. It costs around 100-450€ and is mandatory for any new company
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#88Earlier quoted context omitted.
Right now we use Stripe (mostly because it's the the most rock solid choice for payments) -- we don't ask for name or email, though of course Stripe could know that as a card processor. But our approach goes back to decoupling human identity from network identity -- what that payment says is that the holder of that card is a subscriber of the service but not, for example, what network ID you got.
Once you accept some kind of privacy coin (monero) I'll be delighted to buy a years service upfront. I imagine many others will be in the same position. Obviously taking crypto will mean upfront prepayment of accounts (like prepaid mobile credit) instead of monthly billing and will require some reworking.
For a privacy product this should have been there at the start.
Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#89Re: PGPP (Pretty Good Phone Privacy) Beta Launch
#90Earlier quoted context omitted.
To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."
Because it doesn't matter: none of the big three tower operators in the USA authorizes you to use their telecommunications service with a fake IMEI.