Live data from Hacker News

The IMEI Code: Your phone’s other number

tedium.co

61–70 of 174 posts

Re: The IMEI Code: Your phone’s other number

#61
post #21

Earlier quoted context omitted.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. That was the beginning of the end of my infatuation with the mobile space. I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had…

In Kazakhstan, when a phone is used on a mobile network for the first time, the IMEI of the phone gets locked to that mobile network and that sim card. When you buy the sim card, they photocopy your passport/ID card. No other sim will work in it until you take that photo ID/passport to the mobile companies office to have it unlocked. The photo id (even if expired) becomes the unlock code for the phone. Made phone the…

> Made phone theft drop to pretty much zero

Use a nuke to kill a fly?

Re: The IMEI Code: Your phone’s other number

#62
post #51

Couple of thoughts > The combination of the ICCID and the IMSI basically tells the mobile network, “hey, this person paid for a plan.” As far as I remember, the ICCID never actually appears in standard network messaging. It might be possible for the network to request it, but it's not part of a standard 2/3/4/5g attach. The piece seemed to miss two major uses for the IMEI (or I missed it when reading), which were wor…

> As far as I remember, the ICCID never actually appears in standard network messaging. Yeah, that would be the IMSI (which a given SIM card can have multiple of, e.g. for switching to a more beneficial home network while roaming!) The ICCID is useful for identifying a given physical SIM card (e.g. so that the phone can link a given user-selected profile name to it/the associated phone line for a "preferred line for…

At least in the US, the 911 infrastructure is dated.

In older systems, your caller ID is sent using in-band DTMF tones, which are decoded by the dispatch computer.

On newer E-911 systems they get some additional digital address data from the telephone network, but the record format wasn't designed with VoIP or cellular in mind. So in those cases, the telephone network sends a virtual number and the dispatch computer does a seperate out-of-band lookup with the VoIP/cellular company using that number as a key to get your location.

The whole emergency calling system is layers upon layers of hacks. While they can bolt additional functionality on if they're creative, it's more likely a given feature is _not_ implemented. There's a good chance that by the time the call gets to dispatchers, the IMEI/IMSI isn't displayed anywhere and they just see a random virtual number.

Re: The IMEI Code: Your phone’s other number

#63
post #24

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

Silent SMS is an incredibly convoluted and impractical way of trying to figure out someones location.

The whole purpose of mobile networks is to track a devices location (so you can route data to/from it!). Of course its easy to do it if your the operator or someone who has compromised it.

Re: The IMEI Code: Your phone’s other number

#64
Also a rare UK success story in brute force lawmaking. People used to hack phones IMEI all the time, lots of utils available. Then anything relating to changing an imei was heavily punished and it all stopped. Nobody would host a utility or a guide or even mention it on a forum. If you did mention it you were banned. It was almost instant.

Re: The IMEI Code: Your phone’s other number

#65

Couple of thoughts > The combination of the ICCID and the IMSI basically tells the mobile network, “hey, this person paid for a plan.” As far as I remember, the ICCID never actually appears in standard network messaging. It might be possible for the network to request it, but it's not part of a standard 2/3/4/5g attach. The piece seemed to miss two major uses for the IMEI (or I missed it when reading), which were wor…

> Radio firmware and state machines have always had weird bugs, and even when it conforms to standards (some of which are extremely interpretable), does very weird things in the real world. Pre-smartphone, being able to update phone and radio firmware was extremely rare, so it was common for the networks instead to implement workarounds on a manufacturer or handset basis. Having a hardware ID that identified this was extremely useful

Now that it’s common for devices to be updated regularly, they will typically send an extended form of the IMEI to the network called the IMEISV, which is the same as the IMEI except the final check digit is replaced with a two-digit code indicating the current software version (SV = Software Version).

Re: The IMEI Code: Your phone’s other number

#66
post #5

Earlier quoted context omitted.

I really want mobile networks to accept their role as dumb data pipes. I should be able to just provide a password or certificate and connect. No IEMI, no SIM. And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.

> And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency. You might not, but a whole lot of customers who aren't as technically sophisticated did. When T-Mobile first started doing included international data roaming, they didn't tunnel back. That caused a lot of confusion from customers who didn't realize why stuff they expected to work, like checking their bank balan…

This is interesting. I use Verizon Wireless from the US, and when traveling abroad on their travel pass (roaming), some large multilingual websites serve me the local language instead of English, on sites that serve me English when I'm at home. My browser (Accept-Language header) is configured for only English. I always decline location API browser popups.

The only thing I can think of, assuming they tunnel as you describe, is maybe I first loaded the site from local WiFi instead of mobile data, at which point I was redirected (to a localized subdomain that doesn't redirect back) or got a cookie or something, which lingered as I continued without WiFi.

Re: The IMEI Code: Your phone’s other number

#67
post #15

Earlier quoted context omitted.

Not from the other side of a wide-area network, but if they are continuously in close proximity to you, or can effectively monitor everywhere (three letter agency), then yes. Of course, there are other ways to track you.

Can you elaborate on what you meant by trackable when they're "continously in close proximity to you"?

If they can listen to the radio traffic between your phone and the cell tower, that is.

Re: The IMEI Code: Your phone’s other number

#68
post #21

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. That was the beginning of the end of my infatuation with the mobile space. I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had…

The article literally talks about blacklisting and has a photo of what a blacklisted phone shows when this happens.

Re: The IMEI Code: Your phone’s other number

#69

Earlier quoted context omitted.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. Maybe once upon a time, but I'm pretty sure stolen devices can be blacklisted from networks these days.

Carriers have been blacklisting IMEIs for at least 10+ years. Since phones tended to be carrier-locked back then you couldn't go to a new carrier without being in good standing to get your device's unlock code from the old carrier. Now that devices are available unlocked by default, it is probably harder since it would require carriers to communicate IMEIs?

I looked it up. US Carriers were forced by the US government to start blacklisting them in the final months of 2012. They didn't do it voluntarily.

Australia had been doing it since 2003. IMEIs have been around for 30 years? Everyone having a cellphone is still a relatively recent phenomenon, but according to Pew 80% of American adults had cellphones for several years already before carriers were forced to deal with stolen ones.

Re: The IMEI Code: Your phone’s other number

#70
post #13
post #5

Earlier quoted context omitted.

I really want mobile networks to accept their role as dumb data pipes. I should be able to just provide a password or certificate and connect. No IEMI, no SIM. And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.

How would a networking stack with no hardware addresses even work? The next hop needs a way to reach back to you, before you can negotiate anything fancy like passwords or certificates. Even IPv6 SLAAC starts with a hardware address.

The use of IPv6 in cellular devices is specified by RFC 7066. When a device first registers for a data connection, the network provides an interface identifier to use for the lifetime of the registration, which is guaranteed not to conflict with the one used by the router. The network also allocates a /64 prefix exclusively for use by the device. These two things allows the device to perform SLAAC for link-local and routable addresses without needing to do duplicate address detection.

It’s also worth mentioning SLAAC does not strictly require a hardware address to function. For example, Apple devices implement newer standards from IETF to generate random but stable addresses that don’t reveal information about the hardware addresses (https://support.apple.com/guide/security/ipv6-security-seccb...)

Post reply on HN