Imagine a pawn shop that loans money on cell phones. Now imagine someone comes in and pawns their phone. It still has service and all, but he thinks he will come back next week and redeem it. A few months pass and he never comes back. Now the phone is legally (the pawn contract says one must completely own the collateral, so carrier subsidies etc. shouldn't be a problem) the pawn shop's property. Mr. Defaulter calls…
California Law to Require Antitheft Technology in Cellphones
81–90 of 104 posts
Re: California Law to Require Antitheft Technology in Cellphones
#82Earlier quoted context omitted.
You're probably right - I think that's more valuable to coordinate rather than a mandatory kill switch.
But how? I can't see any realistic chance of a broad international agreement. Remember that it works both ways, too. What would you do if your phone stopped working because a telecoms company in (say) Nigeria accidentally asserted that your IMEI was stolen? Saying "wouldn't it be great if the world could co-ordinate" is not the answer as it isn't realistic. It's avoiding the problem and the need to come up with pract…
However, that results in carriers needing to assert ownership over an imei, which would be come quite a mess - so it very well could not be done.
I do believe national blacklisting registers of imeis, as already done for many years in certain european countries is much better than not doing it though.
Re: California Law to Require Antitheft Technology in Cellphones
#83Kill switches are never the right choice to solve this. Once this technology exists and is widespread (as the article points out, manufacturers are unlikely to maintain two models, with and without this unless legally required), what stops oppressive countries from using this feature from disabling the phones of people legitimately protesting like those in the Ukraine right now?
Re: California Law to Require Antitheft Technology in Cellphones
#84I just wrote a blog post about it: (https://news.ycombinator.com/item?id=7198054)
Re: California Law to Require Antitheft Technology in Cellphones
#85Re: California Law to Require Antitheft Technology in Cellphones
#86Earlier quoted context omitted.
It would be a dumb idea to take your device to a revolution in the first place.
Information, organization, and gathering evidence are fundamental to human rights, let alone to a revolution. Authoritarians naturally wish to ensure it becomes a "dumb idea."
Re: California Law to Require Antitheft Technology in Cellphones
#87From what I understand, the mechanisms for this law are already in place and aren't much of a problem; any Apple customer already has this with the "Activation Lock" feature, and any carrier can already deny service based on a blacklisted ESN. The proposed law, at least in spirit, would require carriers and phone makers to honor your request to make your device unusable when you report it as stolen. It isn't so much…
Re: California Law to Require Antitheft Technology in Cellphones
#88Cross-posting from the other discussion on this topic ( https://news.ycombinator.com/item?id=7197416 ): Actual draft of the bill is here: http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?... Relevant portions: (1) Any advanced mobile communications device that is sold in California on or after January 1, 2015, shall include a technological solution that can render the essential features of the device inope…
The way that I'm reading this, a limit to what a "hard reset" can be is being set by (1). It's saying: Any process that you have in order to return a phone to factory condition must not remove the ability for it to be remotely bricked by the State of California.
It's labeling whatever that process is as a "hard reset" but they only care about the we can still brick the phone part.
That is the diametric opposite of (2), though. Unless the "disabling of the technological solution" is expected to be through software.
In order to enforce (1) and (2), California is going to have to:
a) Start certifying operating systems, and approving of their solutions for the remote bricking disabler.
and
b) Implement the remote bricker in hardware.
This is actually a really scary bill.
edit: The "rightful owner" requirement could be interpreted as really hard to satisfy, especially combined with an inability for the "retail seller" to do it. That may mean that you have to get a code, connect to the manufacturer's server, etc. to get the app to disable the bricking chip unlocked or downloaded, and the additional security theater that would entail - and the bitrot that would happen for older model phones when you had to download it (after a "hard reset") and the manufacturer is either defunct or doesn't care anymore.
This bill has too many goodies for too many entrenched interests not to pass.
edit2: "Rightful owner" is really creeping me out. That might be seen as insuring that the State must be the one with the killswitch. Who can determine a rightful owner? It could be that you are the one who knows the PIN, or it could be that you file a police report, and they kill the phone from the station.
Re: California Law to Require Antitheft Technology in Cellphones
#89There's already an easy way to do this (that I remember reading somewhere is already being done in Australia). When a phone is reported stolen the carriers just need to blacklist the IMEI so it doesn't work - removes the incentive to steal devices. I don't remember where I originally read this (probably here), but the US carriers were not interested in doing this because they don't see stolen phones as a problem that…
IMEI blocking hasn't stopped phone thefts in Europe. Possible reasons: 1. IMEI numbers can be changed. 2. Thief can still use phone for many hours until block. 3. Stolen phones can be shipped to countries that don't implement block. 4. A blocked phone can still be used to run apps, play games, make VOIP calls on wifi etc. The Apple system seems much more sensible. You can't use an iPhone without the pincode, and even…
Re: California Law to Require Antitheft Technology in Cellphones
#90There's already an easy way to do this (that I remember reading somewhere is already being done in Australia). When a phone is reported stolen the carriers just need to blacklist the IMEI so it doesn't work - removes the incentive to steal devices. I don't remember where I originally read this (probably here), but the US carriers were not interested in doing this because they don't see stolen phones as a problem that…
I lost my iphone some time back so when I called AT&T to report it, they kept on insisting me - please wait for few days as you may find it. They also told me once we report the phone as lost and block it using IMEI then this change can't be undone incase you find your phone then it can't be activated again. And, the block using IMEI does not work across carriers which means if its blocked in AT&T then the person car…