Live data from Hacker News

The IMEI Code: Your phone’s other number

tedium.co

111–120 of 174 posts

Re: The IMEI Code: Your phone’s other number

#111

Earlier quoted context omitted.

In Kazakhstan, when a phone is used on a mobile network for the first time, the IMEI of the phone gets locked to that mobile network and that sim card. When you buy the sim card, they photocopy your passport/ID card. No other sim will work in it until you take that photo ID/passport to the mobile companies office to have it unlocked. The photo id (even if expired) becomes the unlock code for the phone. Made phone the…

> Made phone theft drop to pretty much zero Use a nuke to kill a fly?

i imagine that phone theft is more common in poorer regions

Re: The IMEI Code: Your phone’s other number

#112
post #21

Earlier quoted context omitted.

I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones. That was the beginning of the end of my infatuation with the mobile space. I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had…

In Australia, you can report your phone as stolen and it becomes IMEI blocked, not able to be used on Australian phone networks. https://amta.org.au/lost-and-stolen-mobiles/ https://amta.org.au/check-the-status-of-your-handset/

sounds like a dos vector. is there a lot of abuse of this?

Re: The IMEI Code: Your phone’s other number

#113

Earlier quoted context omitted.

There is no privacy concern, really, as this is unique to the device, not subscriber, and only shared with the network operator, who obviously already "tracks" the subscriber through the SIM , which contains the subscriber identifier (IMSI). On the other hand, the IMEI in principle makes tracking and disabling of stolen devices easy. By the way, in the UK it is actually an offence to change the IMEI [1] [1] https://w…

Any immutable id is inherently a privacy concern. Network operators are ISP's, and ISP's have been known to do things like hijack unresolvable DNS entries to a search page with ads. The network operator knows who you are and what imei was associated with your account. I wouldn't be surprised if there were some 'ghost'/virtual profiles associated to an imei similar to how Facebook would do with the like button

Well, there's your phone number. Networks and law enforcement only need that.

Existing privacy level is adequate for members of the public. Anyone who actually, really requires more either has state agencies resources available or is being wanted by state agencies...

Re: The IMEI Code: Your phone’s other number

#114

Earlier quoted context omitted.

I have heard of people calling emergency numbers to test if a phone is working, but never a country making that impossible. Here, I had always assumed that repeated nuisance callers would be investigated to see if there's an actual problem, and charged with a crime if they're doing it for no good reason. Always thought it would make more sense to have a dedicated "test number" for this purpose. Probably with some rat…

A lot of telcos used to have phone numbers you could call that would just say the number you're calling from (like with a computerized voice). I forget what this was called, but it was talked about in phreaking community or so on. Not sure if these "caller identifier" phone numbers are still around today though.

They're easier to make than ever, all you need is Twillio and a bit of Python code. There are quite a few in the US alone, both provided by carriers as well as enthusiasts and other companies in the industry.

Re: The IMEI Code: Your phone’s other number

#115
post #71

Is there any entity or procedure that actually proves what a phone is what it claims to be? Unfortunately, neither IMEI, Serial Number or a combination of both can assert this. I bought a Samsung S24 a week ago off Facebook Marketplace. It was in the box and everything. I cross checked both the IMEIs and also the Serial Number with the #06# test. I even checked them online. Did all the tests, #0 # and even downloaded…

Anything on the display or reported by Linux Kernel can be faked, so no.

Re: The IMEI Code: Your phone’s other number

#116
post #71

Is there any entity or procedure that actually proves what a phone is what it claims to be? Unfortunately, neither IMEI, Serial Number or a combination of both can assert this. I bought a Samsung S24 a week ago off Facebook Marketplace. It was in the box and everything. I cross checked both the IMEIs and also the Serial Number with the #06# test. I even checked them online. Did all the tests, #0 # and even downloaded…

I’m sorry that this happened to you. The debugging and tear down sound like they would make for an extremely interesting blog post though. I encourage you to write it up and post it here - I’d definitely read it.

Some YouTuber bought one of these (not specifically an S24) and found a hidden app that "told" the phone what it should be.

You could set how much RAM you wanted, how much storage, what CPU and so on, and then that info would be shown in all the "about" screens. They went to a few Tb of ram if I remember correctly.

Changing any of these parameters didn't have an impact on what the phone could actually do, just to be clear.

Re: The IMEI Code: Your phone’s other number

#117
post #24

The fact the IMEI is generally not editable seems like a massive privacy hole. Just let people edit it. Then I can be someone new every day and nobody can track me. Mac address randomization does that for wifi. Now do the same for mobile networks.

SMS specifications include "Type 0" messages, also known as Silent SMS. These messages don't trigger any even on the phone when received, but they do send back an ACK that includes IMSI metadata. Silent SM, are literally defined in the RFC and primarily used to covertly track user locations without judicial oversight. GSM, SS7, etc. are massive privacy holes _by design_.

They're not privacy holes by design, but they're not privacy friendly by design either.

When these things were designed, privacy wasn't really a concern and wasn't really thought about in the way it is now. The assumptions were very different, it was assumed that only large and trusted companies could get on SS7 and those would play by the rules, or else face the wrath of the government. Now, a small carrier in a third-world country that routinely violates human rights can get that access.

Re: The IMEI Code: Your phone’s other number

#118
post #56
post #54

From the article: it will generally start with a 35, which is unused as a country calling code It's "unused" because several country codes start with 35: Ireland, Portugal, Luxembourg, Iceland... (This doesn't mean that phones are actually manufactured there... I have a phone with an IMEI starting in 354 and it's definitely not manufactured in Iceland...)

Yeah, they seem to be confusing that with IMSIs or ICCIDs, which are indeed namespaced by mobile country code and international calling code respectively. Based on what other commenters have already pointed out, this seems to be a quite sloppily researched article.

This is interesting - I hadn't noticed this, but my Chinese (Xiaomi) phone indeed has an IMEI starting with 86, which is China's dialling code. Perhaps a coincidence.

The ICCID starts 8944 - not sure of the significance of the 89, but 44 is the UK, where my SIM card (and me) comes from.

Re: The IMEI Code: Your phone’s other number

#119
I prefer to buy second hand iPhones for my family, and usually use Amazon. But the last couple of iPhones haven't been able to connect to the cellular network at all.

Digging into it, it seems they've been IMEI blocked – i.e. reported stolen. Sending them back to Amazon is always such a pain because it means a visit to the post office.

Post reply on HN