Live data from Hacker News

PGPP (Pretty Good Phone Privacy) Beta Launch

invisv.com

31–40 of 104 posts

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#31
post #26
post #23

Earlier quoted context omitted.

Your somewhat evasive answers don't really instill confidence. The answer is no, you cannot. Payment cards are PII.

I don't see what was evasive, happy to answer in more detail if there's something you're seeing not answered above. We use Stripe as a credit card processor -- so we have what Stripe's (very well documented) APIs provide. That reveals that you purchased the service, but we don't know anything about the network identity you have nor your Internet usage, because architecturally we don't have that information. I underst…

> There are credit cards that aren't linked to a person

My desire to know more intensifies.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#34
post #26

Earlier quoted context omitted.

I don't see what was evasive, happy to answer in more detail if there's something you're seeing not answered above. We use Stripe as a credit card processor -- so we have what Stripe's (very well documented) APIs provide. That reveals that you purchased the service, but we don't know anything about the network identity you have nor your Internet usage, because architecturally we don't have that information. I underst…

> There are credit cards that aren't linked to a person My desire to know more intensifies.

https://www.amexgiftcard.com/

Go to the grocery store, buy with cash, you're good to go.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#35
post #26

Earlier quoted context omitted.

I don't see what was evasive, happy to answer in more detail if there's something you're seeing not answered above. We use Stripe as a credit card processor -- so we have what Stripe's (very well documented) APIs provide. That reveals that you purchased the service, but we don't know anything about the network identity you have nor your Internet usage, because architecturally we don't have that information. I underst…

> There are credit cards that aren't linked to a person My desire to know more intensifies.

You can buy visa gift cards for cash

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#37
post #2

Just wanted to say hi – I’m one of the co-founders of this effort and would love to answer any questions or discuss further. Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities.…

Um what? Is PRZ involved? Is he ok with your using that name? He had something called PGPFone a long time ago, though it didn't get much traction. There have also been tons of other encrypted voice programs.

Obscuring traffic patterns without stupendous amounts of dummy traffic is quite difficult. That someone is connected to your network at all is already a huge giveaway. I have trouble seeing how something like this can work without a very big operator (think Cloudflare or AWS) being involved, and anything that size would have to get in bed with regulators. It's a lot easier if you're only trying to do low bandwidth text.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#38

So without this, your internet activity on a mobile phone can be linked to you even with a VPN?

Yes. With a traditional VPN you are trusting that VPN provider with all of your traffic. They know your identity and everything you do. The two hop architecture we use decouples that information such that neither hop has both the user's identity and their usage information. In our case, the second hop is Fastly.

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#39

So without this, your internet activity on a mobile phone can be linked to you even with a VPN?

Yes. With a traditional VPN you are trusting that VPN provider with all of your traffic. They know your identity and everything you do. The two hop architecture we use decouples that information such that neither hop has both the user's identity and their usage information. In our case, the second hop is Fastly.

Yes, that’s true. But let’s say I trust my VPN provider and do not trust my cell service provider. Does PGPP add value for me in that case?

Re: PGPP (Pretty Good Phone Privacy) Beta Launch

#40
You assign users a temporary IMSI which is done in the cloud right?

How does this protect against IMSI catchers and Stingrays if they are done local to you? Local cell tower spoofing?

Also, this is just for data? So if you have another SIM for voice/SMS this is completely negated?

Post reply on HN