Live data from Hacker News

Burner Phone 101

rebeccawilliams.info

141–150 of 198 posts

Re: Burner Phone 101

#141
post #99

Earlier quoted context omitted.

I have no technical knowledge about these, and being cryptocurrency related there will be lots of exasperated huffs, but there are a couple of alternative mobile network related projects: World Mobile and Helium. World Mobile claims 99% coverage of the US, although I think it uses existing networks where there's no native coverage. They're "interesting", but only early days, and I don't know how close they come to wh…

I was imagining mobile operators that cooperated to some extent with the changes I was proposing, or at least didn't obstruct them. If it's using existing GSM protocols, the IMEI would have to be rotated frequently (and it's not that obvious how to do that without making the connection between the old IMEI and the new IMEI apparent), and the SIM technology would have to change. (What it's trying to prove in a privacy…

> There's also the "netheads and Bellheads" theory from the 1990s which can be taken to say that phone companies would never make technical changes to make themselves collect less data, or to be less helpful to government surveillance.

You've got to sell them on something that's useful for them. Present the case that eliminating data collection simplified their network, saves money, reduces staffing, and reduces interaction with government.

Re: Burner Phone 101

#142
post #12

Earlier quoted context omitted.

Silent link esims are quite good for getting your phone to work on any country or network. I have one, not for privacy but more for better phone coverage and it works pretty well. No ID and you pay in crypto - btc/monero etc. ( https://silent.link/ ) For me the main use is that I'm on o2 in the UK, but if in some dead spot with no signal I can flip the sim settings and connect via EE or whatever.

>For me the main use is that I'm on o2 in the UK, but if in some dead spot with no signal I can flip the sim settings and connect via EE or whatever. Why not just get an EE SIM if that's your main use?

It sounds like their need is to be on multiple networks. Where I live (not UK), all carriers have dead zones, some dead zones are dead for all carriers, but most aren't. Being able to use multiple networks sounds lovely.

Re: Burner Phone 101

#143
post #61

> Strong PIN, not biometrics And also be aware of "shoulder surfing", which is different today in 2 ways it wasn't in the past. In the past, the risk was something like someone looking at you type in your PIN on a bank ATM, or maybe your password on an computer keyboard. Today, shoulder surfing is mainly different in 2 ways: (1) near-ubiquitous high-resolution surveillance camera networks, which can be places/scale a…

Shoulder surfing is exactly the risk factor that biometrics are meant to mitigate.

Every time you type your PIN - that's an opportunity to snoop it.

Neither will protect you against rubber hose cryptography.

Re: Burner Phone 101

#144
post #38

Earlier quoted context omitted.

When you ROAM, you traffic abroad is routed to your home country ( for security reasons among other things) and then off to the internet from there. You can check that your public IP, when roaming, is an IP from your cellco.....unsure if there are any changes with 5G though. You are not bypassing any firewall as your traffic is actually happening at home. If you access local sites, traffic is coming from home.

Not home country, home PLMN(~=carrier). IIRC there were changes in 4G/LTE that lets the GW be at visiting carriers. I'm suspecting that that post-4G architecture is just formalization of actual commercial deployment. Latency for roaming data was long inconsistent with the 3G diagrams, and exorbitant roaming fees that would be consistent with the diagrams also started rapidly subsiding from late 3G era.

~carrier---> cellco.

Re: Burner Phone 101

#145
post #39

When I was working at EFF, I started writing (but never finished) a couple of essays along the lines of "the degree of trackability of mobile phones is an unfortunate accident, and we should fix it". It basically comes from routing requirements (especially to receive incoming phone calls) combined with billing requirements (to make people pay for their connectivity) combined with the empirical requirement to see whic…

I absolutely understand the sentiment and the goals that citizens should, by default, not be tracked. However, how do you square that with the proof, time and again, that truly secure and encrypted networks are primarily use by criminals (drug/human traffickers, and plenty of other people) who, through their trade, make the world a shittier place for the rest of us?

Me and the government have slightly differing opinions of what a "criminal" should be. I am a gender outlaw in many states

Re: Burner Phone 101

#146
post #24

One thing I didn't see covered is to never have your "real phone" and your "burner phone" on you (or in the same location) at the same time while powered. Easy enough to say "Gee...these 2 phones are always together or nearby when activated" or "this phone shuts off right before this one powers up". Although, I suspect there are a few other ways to determine identity easier. Such as tracking the device identifier and…

So many online services use the proximity of phones to determine things like related persons and related accounts. Facebook is notorious for this. In one building I lived at Facebook would constantly show me the names of everyone coming in and out as "You might know this person" even though I had no idea who they were.

Or people who stay next door at an Airbnb and I had a quick chat with in person, like I didn't give them any contact information nor did they give me theirs so how ...

Re: Burner Phone 101

#147
post #139
post #90

Earlier quoted context omitted.

Also, never power up or down, or switch in or out of airplane mode on your burner while at home (or work). Cellular network disconnection and connection events are rare and hence notable.

Isn't buying a SIM traceable by itself? if for example the shop has CCTV recordings or the email where you got the eSIM

Normally, unless (as I mentioned in another reply) you buy your SIM at a going-away party for a foreign student or backpacker who's leaving the country and doesn't need a local mobile number any more.

(Then you just need to worry about the CCTV recording of the place where you pay cash tor the pre paid Visa cards you use to top up the prepaid SIM...)

Re: Burner Phone 101

#148
post #39

When I was working at EFF, I started writing (but never finished) a couple of essays along the lines of "the degree of trackability of mobile phones is an unfortunate accident, and we should fix it". It basically comes from routing requirements (especially to receive incoming phone calls) combined with billing requirements (to make people pay for their connectivity) combined with the empirical requirement to see whic…

I absolutely understand the sentiment and the goals that citizens should, by default, not be tracked. However, how do you square that with the proof, time and again, that truly secure and encrypted networks are primarily use by criminals (drug/human traffickers, and plenty of other people) who, through their trade, make the world a shittier place for the rest of us?

This is the "witch hunt" problem.

If you have two networks, one encrypted and one not, and the unencrypted network is significantly easier / cheaper to use or has better network effects, that's where most people will naturally flock. The only ones who will put in the effort to use the encrypted one are criminals and a few principled technologists / civil libertarians. In such a world, the mere fact of using the encrypted network is suspicious in itself.

We define "criminals" here as "anybody the government doesn't like." In the US, this is mostly child predators, drug traffickers, thieves, and maybe a few (legal) sex workers. In other places, this is mostly homosexuals, human-rights activists, journalists and the opposition.

The way to fix the "witch hunt" problem is to make all networks encrypted and secure.

While cryptocurrency is mostly used by criminals, as the traditional financial system is just good enough for most people, TLS is used by everybody, as it is just the default way to do things on the internet nowadays. This is despite the fact that TLS makes wiretapping criminals' communications much harder.

The US and Europe[1] should use the influence they have over standards bodies to make prosecuting the latter group of "criminals" much harder, recognizing that this comes at the expense of also letting some criminals in the EU/US sense of the word run free. It is just the morally right thing to do.

[1] I mostly mean American and European companies and organizations which participate in the process of standard setting, not governments, which mostly cannot do things for complicated political reasons.

Re: Burner Phone 101

#149
post #39

When I was working at EFF, I started writing (but never finished) a couple of essays along the lines of "the degree of trackability of mobile phones is an unfortunate accident, and we should fix it". It basically comes from routing requirements (especially to receive incoming phone calls) combined with billing requirements (to make people pay for their connectivity) combined with the empirical requirement to see whic…

I absolutely understand the sentiment and the goals that citizens should, by default, not be tracked. However, how do you square that with the proof, time and again, that truly secure and encrypted networks are primarily use by criminals (drug/human traffickers, and plenty of other people) who, through their trade, make the world a shittier place for the rest of us?

But this has been "squared" already. Can the police enter your home without a warrant? No? Why? I bet criminals are pretty secretive around their stuff too, no?

Re: Burner Phone 101

#150

Earlier quoted context omitted.

I absolutely understand the sentiment and the goals that citizens should, by default, not be tracked. However, how do you square that with the proof, time and again, that truly secure and encrypted networks are primarily use by criminals (drug/human traffickers, and plenty of other people) who, through their trade, make the world a shittier place for the rest of us?

That's only the case because the truly secure and encrypted networks are not the default.

This has changed before. HTTP used to be just fine. Only your bank used HTTPS. Now everyone uses HTTPS. It's the default, if you don't support it on your webserver, customers will have troubles reaching it.
Post reply on HN