Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

91–100 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#91
post #79

I don't like that this is piggybacking on the recognizable name of an open standard and not-for-profit software while being considerably less open (Where's the RFC? Where's the source code?) and being for-profit. This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.

I'm pretty sure the original PGP program was (and maybe still is?) a for-profit product.

Not as far as I know:

> It was this bill that led me to publish PGP electronically for free that year [1991]

https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html

> It was on this day in 1991 that I sent the first release of PGP to a couple of my friends for uploading to the Internet. First, I sent it to Allan Hoeltje, who posted it to Peacenet, an ISP that specialized in grassroots political organizations, mainly in the peace movement. [...] Then, I uploaded it to Kelly Goen, who proceeded to upload it to a Usenet newsgroup that specialized in distributing source code.

https://www.philzimmermann.com/EN/news/PGP_10thAnniversary.h...

Symantec later bought it and things changed, but thanks to there being an open standard (OpenPGP) and RFCs, people can and did write compatible software. With varying degrees of compatibility, admittedly.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#92

This is great if you are using an old SIM that still operates using IMSI on the sNode B Tower, its also bad because this is simply another overlay band-aid fix which bloats and slows your phone down, the privacy phones made by Obsidian Intelligence Group (obsidianintel.com) don't have this problem and they are also impervious to the SS7 network, I would check them out.. You can find more info on their twitter page @O…

Can you guide a good review ia that phone?

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#94

Earlier quoted context omitted.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

Ok so I should have said in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case), however the 3gpp spec that governs all networks and devices, like your phone, prohibits IMEI changing -its not an innocuous operation as people assume Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing. A curso…

The 911 issue seems small compared to the threat of totalitarian surveillance states, at least to me. I also have the strong intuition there's some way to implement emergency calling anonymously or pseudonymously using cryptographic trickery. In the end, I prefer living somewhere I can change the IMEI if I want

And a hint--I believe it's actually quite easy using an edXposed module if you want to root your Android phone.

Of course, then you've got a rooted phone, which is less secure.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#95

Earlier quoted context omitted.

IIRC changing the IMEI in the U.S. is legal. It may go against standards or something, but that's not a crime (though it would be an excuse for a carrier to kick you off their network, should they find out). I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).

> IIRC changing the IMEI in the U.S. is legal. This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998: "Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information asso…

I appreciate you looking this up.

There are lots and lots of laws, though, that are either unenforceable because they're badly written or just not enforced. The sibling comment pointing out the part you left out is on point, and I would be surprised if any sort of prosecution would ever happen. I'm paying my phone bill and I want to change my IMEI, so what? I'm not defrauding anyone. I am inclined to believe two things:

1) Nobody would ever bother me about this, and

2) Courts would agree with me if push came to shove

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#96

This is great if you are using an old SIM that still operates using IMSI on the sNode B Tower, its also bad because this is simply another overlay band-aid fix which bloats and slows your phone down, the privacy phones made by Obsidian Intelligence Group (obsidianintel.com) don't have this problem and they are also impervious to the SS7 network, I would check them out.. You can find more info on their twitter page @O…

Seems like a weird AstroTurf.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#97

Earlier quoted context omitted.

To be fair you're leaving out the last part of that sentence "... so that such instrument may be used to obtain telecommunications service without authorization."

Because it doesn't matter: none of the big three tower operators in the USA authorizes you to use their telecommunications service with a fake IMEI.

Authorization by whom? I think if I'm paying my bill I have the telco's authorization. They're trying to prevent fraud that gets you free phone service here.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#98
post #6
post #5

Earlier quoted context omitted.

Does this also randomize the IMEI, or just the IMSI? Seems like if the same IMEI shows up over and over again with a different rotating IMSI then the jig is up.

The IMSI. We don't do anything with the IMEI ourselves (it's in the category of hardware identifiers that I'm mentioning above). Some phones can change them when rooted, some can't. The network attach process doesn't use the IMEI inherently by spec, but some cell cores can query for it (for example, to block stolen phones). It's not a network identifier, and strange things sometimes happen with the IMEI that don't ev…

Which means that the tower owners that PGPP partners with could absolutely still track users based on the IMEI if they configure their equipment to always ask for it. (It won't work in some edge cases like duplicate IMEIs but those are not super common).

They may not be doing it right now, but if this sort of thing catches on, it is likely that they will start trying to do it.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#99
post #47

Earlier quoted context omitted.

>He had something called PGPFone a long time ago, though it didn't get much traction. Does anyone have a copy of it? I can't find it ANYWHERE. Actually used it way back when, it worked surprisingly OK and was the first softphone I used.

Here you go: http://www.pgpi.didisoft.com/products/pgpfone/

Looks like the only downloadable on that mirror is the manual.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#100

Earlier quoted context omitted.

Ok so I should have said in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case), however the 3gpp spec that governs all networks and devices, like your phone, prohibits IMEI changing -its not an innocuous operation as people assume Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing. A curso…

> Ok so I should have said [that changing the IMEI of a phone is a criminal offense] in sensible societies because IMEI changing does cause real issues like lack of 911 (in this case) This would mean that, in sensible societies, failing to carry a phone on your person is a criminal offense. It is a position only a true idiot could even articulate .

And again my point has been proven, you're assuming I'm making the argument that you've somehow come up with from what I said which does not even remotely match what i said, read it again and consider the possible reasons why 911 might not be usable.

This is not difficult.

Post reply on HN