Live data from Hacker News

The IMEI Code: Your phone’s other number

tedium.co

51–60 of 174 posts

Re: The IMEI Code: Your phone’s other number

#51

Couple of thoughts > The combination of the ICCID and the IMSI basically tells the mobile network, “hey, this person paid for a plan.” As far as I remember, the ICCID never actually appears in standard network messaging. It might be possible for the network to request it, but it's not part of a standard 2/3/4/5g attach. The piece seemed to miss two major uses for the IMEI (or I missed it when reading), which were wor…

> As far as I remember, the ICCID never actually appears in standard network messaging.

Yeah, that would be the IMSI (which a given SIM card can have multiple of, e.g. for switching to a more beneficial home network while roaming!)

The ICCID is useful for identifying a given physical SIM card (e.g. so that the phone can link a given user-selected profile name to it/the associated phone line for a "preferred line for contact" indicator in dual-SIM phones), and probably also as an identifier when dynamically assigning a new IMSI over the air.

> for the sake of emergency calling

The IMEI can indeed be an identifier of last resort for emergency calls. I wonder if some countries use it to block abuse/spam calls to emergency services, or more importantly, why some others aren't?

In Germany, for example, SIM-less emergency calls are no longer possible, supposedly due to many people calling the local emergency number to test whether a used phone is in working condition without inserting a SIM card... I don't know what they're doing with the IMSI in that case, and if it's locking these callers out, why they can't do the same for the IMEI.

Re: The IMEI Code: Your phone’s other number

#52

Earlier quoted context omitted.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. Maybe once upon a time, but I'm pretty sure stolen devices can be blacklisted from networks these days.

Carriers have been blacklisting IMEIs for at least 10+ years. Since phones tended to be carrier-locked back then you couldn't go to a new carrier without being in good standing to get your device's unlock code from the old carrier. Now that devices are available unlocked by default, it is probably harder since it would require carriers to communicate IMEIs?

Not sure, I think that there are international lists of stolen IMEIs. Maybe it's just in Europe, though.

Re: The IMEI Code: Your phone’s other number

#53
post #28

Earlier quoted context omitted.

There is no privacy concern, really, as this is unique to the device, not subscriber, and only shared with the network operator, who obviously already "tracks" the subscriber through the SIM , which contains the subscriber identifier (IMSI). On the other hand, the IMEI in principle makes tracking and disabling of stolen devices easy. By the way, in the UK it is actually an offence to change the IMEI [1] [1] https://w…

This is 100% a privacy concern if you're dealing with state level actors.

They can track you with or without the IMEI. Next identifier is the IMSI read from your SIM card and I guess you're not replacing it every day...

Re: The IMEI Code: Your phone’s other number

#54
From the article:

    it will generally start with a 35, which is unused as a country calling code
It's "unused" because several country codes start with 35: Ireland, Portugal, Luxembourg, Iceland... (This doesn't mean that phones are actually manufactured there... I have a phone with an IMEI starting in 354 and it's definitely not manufactured in Iceland...)

Re: The IMEI Code: Your phone’s other number

#55
post #15

If someone knows your IMEI can they track you?

Not from the other side of a wide-area network, but if they are continuously in close proximity to you, or can effectively monitor everywhere (three letter agency), then yes. Of course, there are other ways to track you.

I think this is only true for older mobile networks. In 4G and 5G, I don't think the IMEI is part of any unencrypted radio message anymore.

Even the IMSI is only used when absolutely necessary, i.e. for the initial attachment procedure when cold starting a device or entering a new routing area; after that, it's replaced by an alias called TMSI to make tracking phone users a bit harder.

New Android versions will supposedly have a switch in their settings to show a warning every time the IMEI or IMSI is transmitted in plantext [1].

[1] https://cs.android.com/android/platform/superproject/main/+/...

Re: The IMEI Code: Your phone’s other number

#56
post #54

From the article: it will generally start with a 35, which is unused as a country calling code It's "unused" because several country codes start with 35: Ireland, Portugal, Luxembourg, Iceland... (This doesn't mean that phones are actually manufactured there... I have a phone with an IMEI starting in 354 and it's definitely not manufactured in Iceland...)

Yeah, they seem to be confusing that with IMSIs or ICCIDs, which are indeed namespaced by mobile country code and international calling code respectively.

Based on what other commenters have already pointed out, this seems to be a quite sloppily researched article.

Re: The IMEI Code: Your phone’s other number

#57
post #46

Earlier quoted context omitted.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

Could you elaborate on this? What is a 'visual voicemail'? What would a 'silent SMS' have to do with that?

Visual voicemail is where an app on your phone can show you a list of voicemails and you can click a button to play them, as opposed to you having to dial a number to access voicemail (the old "press 2 to hear the next message" stuff).

Re: The IMEI Code: Your phone’s other number

#58
post #53
post #28

Earlier quoted context omitted.

This is 100% a privacy concern if you're dealing with state level actors.

They can track you with or without the IMEI. Next identifier is the IMSI read from your SIM card and I guess you're not replacing it every day...

Disclaimer: used to work in SIGINT, so please treat anything I say about this with appropriate skepticism.

There are people that for various reasons do cycle out their SIM card frequently as a means to avoid tracking. This is ineffective. Changing the IMEI/discarding devices entirely is more effective.

Re: The IMEI Code: Your phone’s other number

#59
post #46

Earlier quoted context omitted.

They are primarily used for configuring your visual voicemail lol. Stop the hyperbolic statements.

Could you elaborate on this? What is a 'visual voicemail'? What would a 'silent SMS' have to do with that?

I'm not sure if Visual Voicemail really uses silent SMS, but even older phones had a series of indicators such as "voicemail waiting", "message waiting" etc. which the network could control via binary SMS payloads.

By sending one that clears all of them in a network that doesn't use them (or sending one equivalent to the current state for one that does), you can achieve the outcome of initiating SMS-MT (mobile-terminated) delivery to a given ME (phone) without any user notification.

SMS delivery by necessity involves paging the device, revealing its location at a finer level (base station instead of paging area).

So I wouldn't say silent SMS were designed as a spying tool, but they're one out of several ways to silently "ping" a phone and force it to communicate with the network without having to wait for it to cross location area boundaries, get or make a call etc.

Re: The IMEI Code: Your phone’s other number

#60

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

Definitely don't let people edit it. iOS and Android don't allow picking your own MAC address for good reasons – people would inevitably pick 12:34:56, 00:00:00 etc. and cause problems for themselves and others.

To increase privacy, either randomize it (but make it much longer at the same time to avoid collisions) and/or remove it from as many signalling contexts as possible and keep it as a device-local identifier only (which then probably also doesn't have to be unique across manufacturers).

Post reply on HN