SIM Card Forces All of Your Mobile Data Through Tor
motherboard.vice.com
motherboard.vice.com
Also with mobile phones data only or not all mobile phones must be able to call emergency services and provide their location data if you are so paranoid that you elect to use TOR for everything you might considering never touching a mobile phone again.
Could you elaborate? (On the second half, i.e. why you say so.)
Privacy is the agency you have over controlling your interactions and information, anonymity is the level of distance you have between a certain interaction and your identity.
A private conversation cannot be anonymous because you need to be able to establish and verify the identity of the parties involved and have trust in them not to dessiminate that information further.
TOR focuses on anonymity which means that if you use it to access things in private such as your gmail or bank account that anonymity goes out the window as you now can be tied to an identity.
Pushing everything through TOR can also include services that are not anonymous by definition which can expose your identity.
1. I am the only user of my logicallee front-end on a server somewhere. Nobody knows who I am. I'm also a shitty admin and don't have ssl enabled properly, everyone between me and the server can see everything between us.
2. Same thing but now I'm a good admin and the conversation with the server is private and nobody can break.
3. Same as 1 except this time instead of being the only user, 1.2 billion other users use it too. Google is a shitty web admin and anyone can decrypt my gmail session.
4. Same thing as 3 except this time Google is a great sys admin and so people can't decrypt session info.
Can you talk about the privacy and anonymity levels of these 4 scenarios? What about a scenario 5 where Google is the world's perfect possible admin and their servers are coded to be so secure, nobody at Google can access anyone's inbox or what mail they're sending in practice. Obviously they can in theory, but assume their practice is perfect and doesn't do that.
Really interested in your answers.
Your thinking is going in the right direction here, but you should consider some deeper analysis of your behavior ...
In your example, 1.2B people access gmail - so far, so good.
But how many people access gmail and HN ? How about gmail and HN and MeFi ? All during US timezone waking hours ? You can see where I am going with this.
Now let's look at a different angle - you only visit gmail, so you're safely back in the 1.2B herd, right ? But how many people visit gmail with OSX ? With OSX vX.Y ? With your screen resolution, your enabled fonts, and your patch level? You might be very surprised at how unique your web hit really is.[1]
The point being made here is that if you funnel all of your usage (traffic ?) everywhere, you create a usage "fingerprint" that can then be noticed or logged or tracked or correlated anywhere else you go.
It's not hopeless - you could spin up a throwaway VM that you would only use for gmail and nothing else, but again - there are opsec considerations there that can sink the whole operation, just like above, if you aren't very, very careful.
1. Only log in to tor to visit "get you killed.com" once you're ready to post the stuff that'll get you killed. No other tor usage.
2. Do all your usage through tor, including making your "get you killed.com" post but everything else too.
Then out of these two versions, the person who is doing (1) is safer than the person doing (2)?
Let’s think what privacy actually is, privacy in the broadest sense is your sovereignty over yourself.
What does privacy means? Privacy means that you control how you interact with the environment, how you think who you interact with, what do you do etc.
Let’s take the least private environment one can think of in the western world which is prisons.
Now prisons dont have privacy not because they monitor your calls that’s just one part of it, they lack privacy because prison requires you to surrender nearly all of your agency to a higher power.
Prisons take control over your entire daily routine, who you can talk to, when and how, what information you can access, anything you own can be searched and taken from you at any time and while you can still have confidential discussions with say a lawyer these discussion aren’t really private as they can only be had under predetermined conditions which you have no agency over.
Now let’s take a descrete case for example communications what properties do they need to exhibit to ensure privacy?
With email specifically you need to be able to establish an identity which is unique to you that can be used to establish trust with the party you communicate with.
You need to be fairly certain that the provider would deliver your correspondence to the intended recipient.
You need to be fairly certain that the email provider would not impersonate you or modify the contents of your correspondence.
You need to be fairly certain that the email provider would not access your correspondence.
You need to be fairly certain that the link betweeen you and your provider is secure and that 3rd parties can not intercept the communications between you and the email provider.
Now there can be a bunch of more requirements extrapolated form this but this will be too long.
Now again in the descrete case of email what are the technical controls needed to support these requirements?
So for the first one it would be mainly account control the provider need to support registration, account security they shouldn’t recycle inactive addresses.
The 2nd one is usually implied trust in the competency of the provider meaning that if you send an email to johnsmith@email.com it would go to that address and only to that address.
The 3rd and 4th ones are more complicated this can be solved with an implicit trust in the provider or if that trust is not sufficient then through other means like using PGP for your emails.
The 5th one is also “tricky” because it expands the model to involve more parties which some can be adversarial but in the most basic approach you need a private link between you and your provider if that private link is established over a public one for example the internet you need some sort of mechanism to validate the identity of your provider and ensure the confidentiality and integrity of the communications this is essentially what SSL/TLS does as it allows parties to prove that they are who they say they are and exchange keys securely.
Now in nearly all your cases there was some sort of a technical failure that adversely affected the ability of the email provider to allow you to communicate in private with another party.
However, privacy is often paired with authentication, which is the opposite of anonymity.
Keep in mind that anonymity isn’t Eve not knowing that Alice is talking to Bob but that Alice doesn’t know that it’s Bob who is talking to her regardless of what Eve knows.
It only becomes a problem if Alice can cross-reference that with some other data to narrow down Bob's identity.
If Bob wants to talk to Alice (regardless if it’s anonymous or not) but he doesn’t want Eve to know it’s a privacy issue.
Anonymity applies from the perspective and intention of the sender.
This is either a government honeypot, or it should be rebranded as “rusty trombone.”
I also had this impression, but on the other hand, I've had to call 911 a couple of times, and they've always asked me for my location, and denied that they have location data. What are the relevant statutes/regulations mandating that phones report location data?
For mobile phones RRLP (and its LTE descendant) has been in the GSM spec for years now.
https://en.m.wikipedia.org/wiki/Radio_resource_location_serv...
However they still ask for details because it’s more accurate and faster to ask and while they can get your location if the location is in a building with 200 apartments it doesn’t really help but denying they have the info when it’s an FCC mandate is a bit silly.
> Wireless network operators must provide the latitude and longitude of callers within 300 meters, within six minutes of a request by a PSAP. Accuracy rates must meet FCC standards on average within any given participating PSAP service area by September 11, 2012
As such the location provided by a barely-compliant mobile phone provider would only have a 50% chance (depending on distribution and what average means exactly in this context) of being within 300 meters of the actual location of the call. I don't know what the real world numbers look like, but it seems very reasonable that the emergency service personnel would need much more accurate location information than that in order to respond without a lot of searching.
I called 311 at 2am once, and had to give the address to the 911 operator because she had no data at all. This was from an AT&T phone, so it's a miracle I got through at all.
(AT&T, Verizon, and T-Mobile are all 1-bar for the 50,000 people near where I live, and they constantly complain about it on the neighborhood web sites. Only Sprint has a good signal, and that's because of old Nextel gub'mint contract towers.)
Emergency services would have your GPS coordinates these days, or at least could as its integrated into the spec.
You are arguing on lower levels the introduced solution does not aim at.
I overall share the sentiment "to be safe, just do not emit signals" but still think the SIM is a good start as it heightens the requirements for tracking on layers 4+.
On their website, they mention the following:
> Simply, your mobile device can't connect to the Internet, it can only communicate with a Tor Bridge within our closed network.
> Configure the Tor daemon on your device to use the bridge at 10.11.12.13:9000 and wait for the network to bootstrap.
This means they are hosting the Tor bridge themselves, but the device's traffic is still going through the carrier's network in plaintext (it's weakly encrypted over the radio link to the tower but unencrypted after that).
Technically the Tor daemon is still running on your device, but is forced to use their bridge with no other options. I'm not too familiar with Tor but surely this can't be good for security right? I can imagine an attacker on the other side of their bridge spinning up a fake Tor network pretending to be the real one (a "sybil attack" with tons of fake nodes).
Basically they're giving you the worst of both worlds. The inconvenience of using Tor with none of the security & anonymity benefits.
I am involved in the mobile industry and this kind of bullshit really makes me sad. They're eroding customer's trust not just in them but in the industry as a whole, making it more difficult for anyone that actually provides a good service.
The only traffic moving on this network will be encrypted traffic from the tor daemon.
>I'm not too familiar with Tor but surely this can't be good for security right?
The whole point of Tor is that this is perfectly fine.
The traffic is encrypted using the onion layering scheme on the device. The bridge node is the entry point for this traffic to the tor network.
>an attacker on the other side of their bridge spinning up a fake Tor network
The client creates the 'circuit', all the bridge node knows is who is connecting to it, it then unwraps its onion layer, finds an encrypted packet and a forwarding address and then sends it on.
You could have made the argument that allowing a single bridge makes it a bit easier to do traffic analysis attacks against users (instead of having to do DPI), but the ISP interception model is pretty much what Tor tries to protect you against, as long as that ISP isn't also (aided by) a global passive adversary.
[1] https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
When it comes to security I'd rather err on the safe side and call it insecure until proven otherwise.
In any case, even if we assume the Tor part is secure, this is still unnecessary at best, since it requires you to run a local Tor daemon. You can run one on a normal SIM, and probably end up better off since you're not putting yourself on a hypothetical watch-list by purchasing such a product.
Tor isn't the holy grail of anonymization the media makes it to be, it's just a tool that you still need to use correctly to protect yourself.
It actually got to the point where I installed a plugin in Firefox Mobile that autoredirects all AMP pages to their HTML counterpart. Life is better this way.