Live data from Hacker News

California Law to Require Antitheft Technology in Cellphones

bits.blogs.nytimes.com

81–90 of 104 posts

Re: California Law to Require Antitheft Technology in Cellphones

#81
post #65

Imagine a pawn shop that loans money on cell phones. Now imagine someone comes in and pawns their phone. It still has service and all, but he thinks he will come back next week and redeem it. A few months pass and he never comes back. Now the phone is legally (the pawn contract says one must completely own the collateral, so carrier subsidies etc. shouldn't be a problem) the pawn shop's property. Mr. Defaulter calls…

You're missing the part where the pawn shop, knowing people do stuff like this, will collect the Name / Phone # of the person pawning the cell phone and can call the authorities and get said person arrested.

Re: California Law to Require Antitheft Technology in Cellphones

#82

Earlier quoted context omitted.

You're probably right - I think that's more valuable to coordinate rather than a mandatory kill switch.

But how? I can't see any realistic chance of a broad international agreement. Remember that it works both ways, too. What would you do if your phone stopped working because a telecoms company in (say) Nigeria accidentally asserted that your IMEI was stolen? Saying "wouldn't it be great if the world could co-ordinate" is not the answer as it isn't realistic. It's avoiding the problem and the need to come up with pract…

Surely carrier A wouldn't let carrier B be able to block an imei belonging to their customers. If carrier B did block it though, you, customer of carrier A, wouldn't be able to roam in the network of carrier B - but still work fine in your home network of carrier A.

However, that results in carriers needing to assert ownership over an imei, which would be come quite a mess - so it very well could not be done.

I do believe national blacklisting registers of imeis, as already done for many years in certain european countries is much better than not doing it though.

Re: California Law to Require Antitheft Technology in Cellphones

#83
A bill that requires manufacturers to offer phones that have this feature and phones that don't have this feature I could see as being okay, but to require all phones to have it and leave the user no choice (fwiw, being able to disable it after purchase is a false choice) is ridiculous.

Kill switches are never the right choice to solve this. Once this technology exists and is widespread (as the article points out, manufacturers are unlikely to maintain two models, with and without this unless legally required), what stops oppressive countries from using this feature from disabling the phones of people legitimately protesting like those in the Ukraine right now?

Re: California Law to Require Antitheft Technology in Cellphones

#85
This is a cellphone carriers' lobbyist work at its finest! This law is not about the customers; its about those rare examples where customers are screwing the carriers when the phone is being stolen and the police report is good enough to get out of a lengthy & expensive contracts.

Re: California Law to Require Antitheft Technology in Cellphones

#86
post #40
post #12

Earlier quoted context omitted.

It would be a dumb idea to take your device to a revolution in the first place.

Information, organization, and gathering evidence are fundamental to human rights, let alone to a revolution. Authoritarians naturally wish to ensure it becomes a "dumb idea."

For revolutionaries to assume they can rely on a system that authoritarians control is inherently a dumb idea, and the lack of any good alternatives doesn't change that.

Re: California Law to Require Antitheft Technology in Cellphones

#87

From what I understand, the mechanisms for this law are already in place and aren't much of a problem; any Apple customer already has this with the "Activation Lock" feature, and any carrier can already deny service based on a blacklisted ESN. The proposed law, at least in spirit, would require carriers and phone makers to honor your request to make your device unusable when you report it as stolen. It isn't so much…

There's a huge ethical problem with a vendor imposing limits on the relationship between a human being and their tools. Apple customers are self-selected for being okay with this.

Re: California Law to Require Antitheft Technology in Cellphones

#88

Cross-posting from the other discussion on this topic ( https://news.ycombinator.com/item?id=7197416 ): Actual draft of the bill is here: http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?... Relevant portions: (1) Any advanced mobile communications device that is sold in California on or after January 1, 2015, shall include a technological solution that can render the essential features of the device inope…

>* The hard reset definition is sort of dumb. When a device leaves the factory, it obviously doesn't have any knowledge of whom its proper owner is. A hard reset, by definition, has to nullify any owner-verification system and no technological solution can withstand it.

The way that I'm reading this, a limit to what a "hard reset" can be is being set by (1). It's saying: Any process that you have in order to return a phone to factory condition must not remove the ability for it to be remotely bricked by the State of California.

It's labeling whatever that process is as a "hard reset" but they only care about the we can still brick the phone part.

That is the diametric opposite of (2), though. Unless the "disabling of the technological solution" is expected to be through software.

In order to enforce (1) and (2), California is going to have to:

a) Start certifying operating systems, and approving of their solutions for the remote bricking disabler.

and

b) Implement the remote bricker in hardware.

This is actually a really scary bill.

edit: The "rightful owner" requirement could be interpreted as really hard to satisfy, especially combined with an inability for the "retail seller" to do it. That may mean that you have to get a code, connect to the manufacturer's server, etc. to get the app to disable the bricking chip unlocked or downloaded, and the additional security theater that would entail - and the bitrot that would happen for older model phones when you had to download it (after a "hard reset") and the manufacturer is either defunct or doesn't care anymore.

This bill has too many goodies for too many entrenched interests not to pass.

edit2: "Rightful owner" is really creeping me out. That might be seen as insuring that the State must be the one with the killswitch. Who can determine a rightful owner? It could be that you are the one who knows the PIN, or it could be that you file a police report, and they kill the phone from the station.

Re: California Law to Require Antitheft Technology in Cellphones

#89

There's already an easy way to do this (that I remember reading somewhere is already being done in Australia). When a phone is reported stolen the carriers just need to blacklist the IMEI so it doesn't work - removes the incentive to steal devices. I don't remember where I originally read this (probably here), but the US carriers were not interested in doing this because they don't see stolen phones as a problem that…

IMEI blocking hasn't stopped phone thefts in Europe. Possible reasons: 1. IMEI numbers can be changed. 2. Thief can still use phone for many hours until block. 3. Stolen phones can be shipped to countries that don't implement block. 4. A blocked phone can still be used to run apps, play games, make VOIP calls on wifi etc. The Apple system seems much more sensible. You can't use an iPhone without the pincode, and even…

5. The stolen phone can be sold to a hapless buyer shortly after it is stolen, before the theft is realized or reported and therefore before the IMEI is blocked.

Re: California Law to Require Antitheft Technology in Cellphones

#90

There's already an easy way to do this (that I remember reading somewhere is already being done in Australia). When a phone is reported stolen the carriers just need to blacklist the IMEI so it doesn't work - removes the incentive to steal devices. I don't remember where I originally read this (probably here), but the US carriers were not interested in doing this because they don't see stolen phones as a problem that…

I lost my iphone some time back so when I called AT&T to report it, they kept on insisting me - please wait for few days as you may find it. They also told me once we report the phone as lost and block it using IMEI then this change can't be undone incase you find your phone then it can't be activated again. And, the block using IMEI does not work across carriers which means if its blocked in AT&T then the person car…

That situation seems a bit poorly implemented to me. The irreversible block only applies to AT&T's network, and is under AT&T's control... Wouldn't it make sense for AT&T to simply place the IMEI on watch, so that the next time AT&T's network sees it come online, an "alert" is triggered and AT&T can contact the owner to confirm whether or not it's in their possession?
Post reply on HN