Live data from Hacker News

The IMEI Code: Your phone’s other number

tedium.co

41–50 of 174 posts

Re: The IMEI Code: Your phone’s other number

#41
post #24

Earlier quoted context omitted.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

Can they be disabled/blocked on the device, when not needed because the user has disabled "visual voicemail" with their carrier?

Re: The IMEI Code: Your phone’s other number

#42
post #21

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. That was the beginning of the end of my infatuation with the mobile space. I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had…

In Australia, you can report your phone as stolen and it becomes IMEI blocked, not able to be used on Australian phone networks.

https://amta.org.au/lost-and-stolen-mobiles/

https://amta.org.au/check-the-status-of-your-handset/

Re: The IMEI Code: Your phone’s other number

#43

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

they WANT you to be stuck with it because then they can track you no matter what

Re: The IMEI Code: Your phone’s other number

#44
post #24

Earlier quoted context omitted.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

https://www.heise.de/news/Zoll-BKA-und-Verfassungsschutz-ver...

Not sure where you get your information, but these are routinely used by police to covertly track targets.

Re: The IMEI Code: Your phone’s other number

#45
post #27

Earlier quoted context omitted.

Surely the uniqueness is only required at the bottom end of the stack before the first 'router' ie the cell tower

> Surely the uniqueness is only required at the bottom end of the stack before the first 'router' ie the cell tower Not if you need to send a message to $thatUniquePhone. Over simplifying considerably, but if a land line places a call to a mobile, the "220-1234 calling for 220-7890" message enters the network. The `220-7890` phone number needs to map to the unique modem address so you can look up which tower the call…

> which tower(s) do you forward the call setup data

Whichever one has most recently communicated with the user in question (based on the credentials or certificate provided, in the original example)

Re: The IMEI Code: Your phone’s other number

#46
post #24

Earlier quoted context omitted.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

Could you elaborate on this? What is a 'visual voicemail'? What would a 'silent SMS' have to do with that?

Re: The IMEI Code: Your phone’s other number

#47
post #11

I'm interested in the general thrust, but this article is sloppy at best. > Check digit: The final digit is essentially used to validate the prior 14 digits with an algorithm. Similar digits exist in other types of identifier codes, such as the Universal Product Code (UPC) and the International Standard Book Number (ISBN). The algorithm that the mobile industry uses, the Luhn algorithm, is also used for social securi…

The geographic aspect of SSNs no longer applies either. My kids have SSNs that start with different digits than my own which was assigned under the old regime where the first digit indicated where the SSN was issued.

Re: The IMEI Code: Your phone’s other number

#48
post #24

Earlier quoted context omitted.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

I remember using one of those dongles with a SIM card that you could talk to with an API and use that to send flash SMS. Full screen warnings to friends. Only option was 'OK' and the text was gone afterwards.

My old Nokia C2-01 allows sending them from the menu ;-)

Re: The IMEI Code: Your phone’s other number

#49
post #5

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

I really want mobile networks to accept their role as dumb data pipes. I should be able to just provide a password or certificate and connect. No IEMI, no SIM. And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.

> And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.

You might not, but a whole lot of customers who aren't as technically sophisticated did. When T-Mobile first started doing included international data roaming, they didn't tunnel back. That caused a lot of confusion from customers who didn't realize why stuff they expected to work, like checking their bank balance, didn't. (It also made throttling speeds a lot more difficult.)

So to fix that, T-Mobile tunnels you back to a few endpoints in the States. Banking apps are generally happy, as are Netflix and Spotify. Most customers are happy because their phone "just works" the same as it "always has".

For those of us who want to avoid the latency, we get a local SIM for data (if possible).

Re: The IMEI Code: Your phone’s other number

#50

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

Mobile phones are a massive privacy hole. Almost by definition.

And smartphones 10 times more (or more, depends on how many apps you installed, almost all of them include some sort of trackers).

IMEI is (almost) the last of my privacy problems.

Post reply on HN