If your threat model includes targeted attack by a major intelligence agency, just accept that you are likely screwed.
If your threat model includes targeted attack by a major intelligence agency, just accept that you are likely screwed.
I was recently asked how to make an anonymous post to a local news organization where all they wanted to do was hide their IP. I said if their only worry is the news organization then a VPN would be enough... Now that I'm reading your comment I'm having second thoughts whether it was right.
Varies by country I’m sure, but I was surprised how difficult it was to buy a SIM in Indonesia and Malaysia without an ID. Even little shops wanted an ID or passport number to type in to activate it.
This is near impossible now. I tried a few years ago to get an anonymous phone to activate an anonymous twitter account and you have to provide too much information to activate the sim card across the major providers and other companies that use their infrastructure.
I was driving home today and the satnav warned us about driving over speed limit (74 mph on UK motorway). Ok. But the solution to that is technology - and organisation. There are speed cameras on this road. But most of the time they don't take images or don't trigger an action. If every road camera triggered a warning / fine on every violation then speeding would stop in a few months.
Is that something socially beneficial ? Probably. Would it be disruptive and cause great anger and political resentment? Yes.
That is one tiny example but I think that pretty much every criminal act can be detected with technology - it's going to become which one we care enough about to prosecute and which we give up and decriminialise?
Or governments will continue to have those laws on the books and prosecute them with discretion (which is what happens today). It is very convenient for those in power when every person is already guilty of something.
If society is not free or fair, that's the problem to fix first.
Location can be determine with sufficient accuracy for this purpose from cell-tower connections. More so as 5G, with its greater tower density and shorter range, is rolled out.
(An actual 5G threat you can get behind.)
If you add a VPN to the stack, the VOIP service doesn't know your IP (though I wonder if a VOIP service would work well through a VPN, due to added latency).
If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.
The notion of having short-lived individually-attributable 5G connection history, perhaps through a dongle- or tether-swapping system, in which many individuals utilise devices for a short period of time, might work. With a sufficient budget, disposable devices might also be an option. (As the cost of SBCs / SOCs falls through $0.10/device, the disposable option might be tractable, leaving SIM card provisioning as the bottleneck.)
The tether is connected over WiFi (the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level), giving a two-stage connection to the actual mobile network itself. Frequently-relocating (via a swap) or short-lived / previously unknon tethers, as identified through IMEI is required for mobile connections to work, would still be possible, but at a much greater workload. (I'm very sketch on how 5G identifies specific devices, take what I'm saying here with a few kilos of salt.)
I'd still have concerns with a VOIP device that itself has access to information and computing capabilities, but at least the degree of tracking that's possible over a PSTN direct-dialed mobile handset on a 4G/5G network would be sharply reduced. Other threat vectors remain.
Burner phones on a one-use / short-use cycle would probably be preferable.
If by "two problems" you mean that VOIP adds an additional problem, I don't quite grok it. It isn't a panacea, as you point out, but seems like a clear improvement.
Another advantage of VOIP is that you can easily obtain throwaway phone numbers.
> If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.
Good point. They still don't know who I talk to and when, but they certainly can figure out who I am. I wonder how expensive the latter is, which I'd guess it depends on whether that analysis and the sharing of it is done automatically or takes a special request.
> The tether is connected over WiFi
I'm not sure that helps privacy: Wifi networks are likely shorter range than 5G cells, and the networks are well mapped. I suppose it does require involvement of someone with the map, but that might be easy to obtain.
> the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level
I think iOS and Android randomize MAC addresses these days ?
> Burner phones on a one-use / short-use cycle would probably be preferable.
Yes, but a single burner phone, between the hardware and a one month plan, can cost $75-100. Using lots of them is out of reach for many people.
On connecting to the tether over WiFi, the advantages over cellular data or Bluetooth is that a WiFi identity (MAC address, SSID) can be arbitrarily changed, and in fact are in consumer-grade hardware (yes, iOS uses a distinct MAC per connected network AFAIU, not positive of Android). This could be modified on every network connection, or even within a single session (requiring periodic reconnects). Other means of specific host identification via TCP/IP and 802.11 protocols are fairly limited.
On increasing workload, much surveillance is done via mass-produced hardware and software, and targets frequently-encountered devices (e.g., stock mobile phones, iOS, and Android systems). Adopting measures and methods other than these ... leaves a signature, but also means that specific new surveillance methods need to be devised for a specific target.
Also: in case anyone mistakes me for an expert on this area, I'm not. I've general familiarity with methods, techniques, protocols, devices, and operating systems.