Live data from Hacker News

The IMEI Code: Your phone’s other number

tedium.co

31–40 of 174 posts

Re: The IMEI Code: Your phone’s other number

#31
post #11

I'm interested in the general thrust, but this article is sloppy at best. > Check digit: The final digit is essentially used to validate the prior 14 digits with an algorithm. Similar digits exist in other types of identifier codes, such as the Universal Product Code (UPC) and the International Standard Book Number (ISBN). The algorithm that the mobile industry uses, the Luhn algorithm, is also used for social securi…

Many non-American SSN systems do have check digits.

Re: The IMEI Code: Your phone’s other number

#32
post #24

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

Re: The IMEI Code: Your phone’s other number

#33

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

There is no privacy concern, really, as this is unique to the device, not subscriber, and only shared with the network operator, who obviously already "tracks" the subscriber through the SIM , which contains the subscriber identifier (IMSI). On the other hand, the IMEI in principle makes tracking and disabling of stolen devices easy. By the way, in the UK it is actually an offence to change the IMEI [1] [1] https://w…

Any immutable id is inherently a privacy concern. Network operators are ISP's, and ISP's have been known to do things like hijack unresolvable DNS entries to a search page with ads. The network operator knows who you are and what imei was associated with your account.

I wouldn't be surprised if there were some 'ghost'/virtual profiles associated to an imei similar to how Facebook would do with the like button

Re: The IMEI Code: Your phone’s other number

#34
post #15

Earlier quoted context omitted.

Not from the other side of a wide-area network, but if they are continuously in close proximity to you, or can effectively monitor everywhere (three letter agency), then yes. Of course, there are other ways to track you.

Can you elaborate on what you meant by trackable when they're "continously in close proximity to you"?

Snooping, or hijacking, the radio pathway between you and your network operator.

Re: The IMEI Code: Your phone’s other number

#35
post #31
post #11

I'm interested in the general thrust, but this article is sloppy at best. > Check digit: The final digit is essentially used to validate the prior 14 digits with an algorithm. Similar digits exist in other types of identifier codes, such as the Universal Product Code (UPC) and the International Standard Book Number (ISBN). The algorithm that the mobile industry uses, the Luhn algorithm, is also used for social securi…

Many non-American SSN systems do have check digits.

The Brazilian CPF (our equivalent to the SSN) goes up to eleven (literally) by including not one, but two check digits; IIRC, the first one (the tenth digit) is computed over the first nine digits, and the second one (the eleventh digit) is computed over the first ten digits.

Re: The IMEI Code: Your phone’s other number

#36
post #24

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

I remember using one of those dongles with a SIM card that you could talk to with an API and use that to send flash SMS. Full screen warnings to friends. Only option was 'OK' and the text was gone afterwards.

Re: The IMEI Code: Your phone’s other number

#37
post #15

Earlier quoted context omitted.

Not from the other side of a wide-area network, but if they are continuously in close proximity to you, or can effectively monitor everywhere (three letter agency), then yes. Of course, there are other ways to track you.

Can you elaborate on what you meant by trackable when they're "continously in close proximity to you"?

https://en.wikipedia.org/wiki/IMSI-catcher

Re: The IMEI Code: Your phone’s other number

#38
post #5

Earlier quoted context omitted.

I really want mobile networks to accept their role as dumb data pipes. I should be able to just provide a password or certificate and connect. No IEMI, no SIM. And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.

And while we're at it, how come if I have a phone without a sim I can't at least navigate to a carrier webpage to buy an esim? The phone could pop up a menu saying "Here are the available networks", and you pick one, connect and it says "Welcome to AT&T, enter credit card number here", and you type a number and hit OK and you're connected. Oh wait - just like Wifi!! Why are mobile networks so far behind?

Kinda like this? https://en.m.wikipedia.org/wiki/Apple_SIM

Re: The IMEI Code: Your phone’s other number

#39
post #27
post #18

Earlier quoted context omitted.

A MAC address is 48 bits and an IMEI is about the same entropy-wise. That's not nearly enough room to avoid duplicates (even SLAAC requires duplicate address detection, and IPv6 has a lot more bits to work with). You'd need a whole new layer 2 protocol, though to be fair you might be able to strip it down to just doing collision detection/avoidance and leave addressing up to layer 3 with IPv6, but that's not going to…

Surely the uniqueness is only required at the bottom end of the stack before the first 'router' ie the cell tower

> Surely the uniqueness is only required at the bottom end of the stack before the first 'router' ie the cell tower

Not if you need to send a message to $thatUniquePhone.

Over simplifying considerably, but if a land line places a call to a mobile, the "220-1234 calling for 220-7890" message enters the network. The `220-7890` phone number needs to map to the unique modem address so you can look up which tower the call setup data should be sent to. If - by sheer coincidence - I also have your MAC address and am attached to a tower 3 states away... which tower(s) do you forward the call setup data to?!

Re: The IMEI Code: Your phone’s other number

#40
post #21

Earlier quoted context omitted.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. That was the beginning of the end of my infatuation with the mobile space. I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had…

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. Maybe once upon a time, but I'm pretty sure stolen devices can be blacklisted from networks these days.

I believe the point is that they could've been blacklisted from the start and instead carriers would just put up their hands say "there's nothing we can do" despite there being something they can do.

It's like when your apple laptop gets stolen and then starts using your applecare support and apple won't help you get it back.

Of course, if you decided not to pay your phone bill I'm sure that device would get blackslisted real fast.

Post reply on HN