Live data from Hacker News

Burner Phone 101

rebeccawilliams.info

61–70 of 198 posts

Re: Burner Phone 101

#61
> Strong PIN, not biometrics

And also be aware of "shoulder surfing", which is different today in 2 ways it wasn't in the past.

In the past, the risk was something like someone looking at you type in your PIN on a bank ATM, or maybe your password on an computer keyboard.

Today, shoulder surfing is mainly different in 2 ways: (1) near-ubiquitous high-resolution surveillance camera networks, which can be places/scale and capture images that humans practically didn't; and (2) with machine learning, they don't even need to see what buttons you press, only see movements of your arm.

(Randomizing button positions on a touchscreen can help, and also help fight forensics like traces your fingers leave for where they touch. But randomization means you need to be able to see your screen, which reduces the ways you have to hide your screen from the view of others.)

Re: Burner Phone 101

#62
Kudos to this article for:

1. starting with threat modeling (though they don't call it that);

2. mentioning that your OPSEC affects not only you but also people connected to you; and

3. mentioning that maybe you should just leave the device at home (because it's basically a surveillance machine that you pay for).

(A more common article format would be to unload a pile of supposed security&privacy measures without putting them into context, and wouldn't properly set expectations for what that gives you. Neither of which is very helpful, and can be very counterproductive.)

Re: Burner Phone 101

#63
> Buy phone & service in cash

Step one is already difficult here in Australia: to do so you must hand over your personal details and ID. At least that was true for anything with a SIM card for sale back in the 2010s

So the “step 0” was “find a retailer who didn’t follow the rules”, and they’d usually be a corner store selling handsets or SIM cards by the bucket load to all sorts of interesting characters

Re: Burner Phone 101

#64
post #52

If you need to communicate with people in your area and not be tracked; MeshCore software with LoRa hardware like the this https://lilygo.cc/en-ca/products/t-lora-pager is something to consider. Text only, completely offline

Yes!!! I've been wanting to make something like this for a long time. But unless the firmware is open source I wouldn't trust this for anything secure. But this looks like a dev kit so I can do whatever I want.

There are other alternatives https://meshtastic.org

Re: Burner Phone 101

#65
post #39

When I was working at EFF, I started writing (but never finished) a couple of essays along the lines of "the degree of trackability of mobile phones is an unfortunate accident, and we should fix it". It basically comes from routing requirements (especially to receive incoming phone calls) combined with billing requirements (to make people pay for their connectivity) combined with the empirical requirement to see whic…

Stellar reasoning.

Did you ever get to the point of hypothesizing good ways to align incentives to make this happen? It is hard to tell (having not thought much about it) whether this is a “smart well meaning engineers need to make new standards” problem, a “we need to harness the power of corporate greed problem,” or something else.

Re: Burner Phone 101

#66
eSim erodes privacy? Well, that sucks, because how long until Apple, Samsung, and Google decide the Sim slot should go the way of the 3.5mm headphone jack?

Re: Burner Phone 101

#67

If you need to communicate with people in your area and not be tracked; MeshCore software with LoRa hardware like the this https://lilygo.cc/en-ca/products/t-lora-pager is something to consider. Text only, completely offline

Except that your texts go out to everyone on the mesh network.

Re: Burner Phone 101

#68

If you need to communicate with people in your area and not be tracked; MeshCore software with LoRa hardware like the this https://lilygo.cc/en-ca/products/t-lora-pager is something to consider. Text only, completely offline

If you need to do this then start by figuring out why you need to do it, and adjust your approach too your threat model.

Because the most significant evidence we have lately is that in-person meetings or dead drops and other low tech means are how you avoid being tracked.

Turning on any sort of radio transmitter is just turning on a big flash light into the sky.

Turning on anything relatively uncommon is even worse: normal people have cellphones and use them. They don't use LoRa devices, there aren't a lot of LoRa devices and someone who only uses LoRa devices will stand out in any dataset.

Re: Burner Phone 101

#69
post #25
post #7

Earlier quoted context omitted.

Just track the hardware. A couple of days of normal usage and should be able to assign a 99% probability on you being the owner of that phone.

You should never turn on your burner in a place where you use your regular phone, duh.

And yet realistically you also probably don't turn it on except when you're within about 50 miles of your home.

And this is while you're flagging yourself heavily by (1) using a phone which is easily identified as a burner and (2) using it intermittently which means you're trying not to be tracked.

So you've already substantially identified yourself in any dataset.

Re: Burner Phone 101

#70
post #68

If you need to communicate with people in your area and not be tracked; MeshCore software with LoRa hardware like the this https://lilygo.cc/en-ca/products/t-lora-pager is something to consider. Text only, completely offline

If you need to do this then start by figuring out why you need to do it, and adjust your approach too your threat model. Because the most significant evidence we have lately is that in-person meetings or dead drops and other low tech means are how you avoid being tracked. Turning on any sort of radio transmitter is just turning on a big flash light into the sky. Turning on anything relatively uncommon is even worse:…

> Because the most significant evidence we have lately is that in-person meetings or dead drops and other low tech means are how you avoid being tracked.

How many cameras did you just go by? did you have your cell phone on you? how many networks did it connect too? how many bluetooth broadcasts did it passively send out? Not being tracked and being in public are slowly becoming an untenable duo.

Post reply on HN