Over 13k Vivo phones found to be using same IMEI number (2020)
techradar.com
techradar.com
It would not surprise me if some apps still use IMEI (or MAC address) for similar purposes…
https://developer.android.com/about/versions/10/privacy/chan...
It still works fine if your intent is to stalk users, though.
51%. Super strong argument there.¨
TelephonyManager tm = (TelephonyManager) getSystemService(Context.TELEPHONY_SERVICE);
IMEIs must be registered before sold. If you buy mobile phone from abroad you can use it for few months without registering the IMEI. Then the mobile networks do not respond to the mobile phone, even if you change the SIM. Registering a phone requires a passport, that proves you have visited abroad in that last 6 months. If longer, you cannot register. And the IMEI gets tied to the SIM. Plus, it is very expensive, like half minimal salary.
Are there large chunks of the population that just use wifi-only phones?
There is no wifi only phone or wifi network, if you really mean wifi. There are "only data" plans but for that you also need to register the IMEI.
Last time I visited Turkie, I didn't had any trouble using the phone (except eye-watering 3G tariffs and somewhat spotty reception out of the main areas), bu the moment I tried to use a WiFi network in the mall it requested a SMS confirmation.
I've heard some people clone IMEIs from the old phone when getting a new phone from abroad and that it does reduce the cost significantly.
The slight extra hassle this will create for law enforcement isn't worth the massive risk of disadvantages that duplicate IMEIs have.
I guess it might have worked for a while, but it was not a great idea...
I wonder if operators will block those IMEI, because in some countries, they might just refuse to block them...
Not necessarily. It could also have been an employee who knew about the dangers of surveillance.
In the same way that not wearing a tracking collar is a security concern, because it makes it harder for the police to spy on you? We really should invent a new word for "security" that is actually "security against the user".
Surveillance state, digital restrictions management, treacherous computing appliances, "two factor authentication", airport searches, totalitarian schools, prohibitions on mobile phones or pocket knives, no outside food or drink, etc. These are all instances of making some central entity's position more secure, while running roughshod over the ability for individuals to make ourselves secure.
and sometimes people who are used to being treated like an authority say “if you won’t respect me I won’t respect you” and they mean “if you won’t treat me like an authority I won’t treat you like a person”
and they think they’re being fair but they aren’t, and it’s not okay.
— https://flyingpurplepizzaeater.tumblr.com/post/115216522824/...
For example, in the United Kingdom, under the Mobile Telephones (Re-programming) Act, changing the IMEI of a phone, or possessing equipment that can change it, is considered an offence under some circumstances. - https://en.wikipedia.org/wiki/International_Mobile_Equipment...
Sorry for the car analogy, I had to ;)
On most pixel phones, the "equipment" is any computer with a usb cable and a copy of android SDK (adb). Better arrest every owner of said equipment...
No, it's not. If only people who require protection will try to have privacy, it will be very easy to target them. Everyone should have privacy to protect them. See also: https://news.ycombinator.com/item?id=31695383.
We survived because lots of services and relationships didn't rely on people having a mobile phone.
I mean in the US IMEI aren’t linked to a person, at least not required.
Neither are SIMs.
So if one really wanted an anonymous cell phone it’s not hard to do.
What IMEI gives you is the ability to track the same phone across SIMs.
The main scenarios where IMEI should be interesting to law enforcement are: stolen phone situations, criminals that keep getting getting new burner sims while continuing to use the same phone, or people that keep prank calling emergency services without having a SIM installed.
In nearly all other cases, the ISMI is far more useful identifier. And obviously the phones in question all have unique ISMIs or the network would be having, err.... great difficulty with all of those phones having the same phone number, and being able to route calls.
Sims same, they are immediately tied to your account and if you are post paid, there you go.
Anonymous cell phones also aren't entirely possible anymore because of network effect and the convenience factor.
1. Network effect, who you know, who you call, when they call you - pattern. 2. Internet usage, where do you go? 3. Geolocation - GPS, proximity with other cell phones, and then internal measuring devices. You can disable reporting completely, sure, but triangulation is user carrier side data, and with 5g roll outs and other potential signal repeaters and cell phones, it's still very accurate. 4. Sideline recording of this data is possible, same as a heat map in googlemaps - just looking for repeatable patterns of usage, where you go, etc.
It's not only hard, cell phones nowadays are not designed for anonymous usage. And this is before we even get into adtech, app tracking and other layers of interaction.
But there is no ID requirement in the US. You can buy a SIM for cash, buy a phone for cash.
This is unlike many other countries. Singapore links all SIMs to your ID at purchase. There is a black market for anonymous SIMs (linked to random people's IDs), but the police actively crack down on those.
Sure, you can "walk" to the store, browse to the phone aisle, pick up a prepaid phone, wait in line, ring out and pay in cash and walk out - but that all creates a foot print, geographically at a minimum.
You can try a smaller store, franchised sure - but there will be recording of the transaction. Then the activation itself. Then the recurring topping up of credits to use the service.
As with Singapore/Japan/Indonesia and China, yes - pre-activated sims still are sold w/ government intervention and seizing information and terminating the sim in use - but another thing to note is that the telecom in those countries are also state enterprises. In the USA, they are not - not yet.
But, "effort" into being anonymous, is friction - and the more friction you need to overcome, the more opsec you need to execute to maintain a hygenetic environment. That's where it becomes impossible to maintain.
State level actor? Well then yeah, you’re screwed.
I have two phones - an iphone I purchased with cash at an Apple store and a Pixel 4 that I purchased from Amazon. My Amazon account is not connected to any individual person or personal address ...
The former IMEI ... recorded by Apple as "dude with cash" and the latter recorded by some fly-by-night Amazon third party seller as (dude with Amazon pseudonym) ?
"1. Network effect, who you know, who you call, when they call you - pattern. 2. Internet usage, where do you go? 3. Geolocation - GPS"
Yes - very appropriate to be thinking about these things and their impact on ones ability to pseudonymously participate on the mobile network.
I've been thinking of a raspberry pi access point that advertises a collection of SSIDs that exist elsewhere ... which is to say, I would record my network scan of unique SSIDs next time I am in downtown Denver and then recreate all of them in my office in San Francisco at the push of a button ... I wonder if there is a collection of SSIDs that would transport my phone to a different geography ...
Except your card and the delivery address? Along anything other you ordered on this account?
I mean, come on - that's like a "must be this tall to ride" minimum for these kind of efforts, right ?
Card number ... sure, if Amazon wants to break every single PCI compliance[1] (and many other) rule in the book and compare my un-hashed credit card number with (card numbers from other vendors and suppliers) then, yes, they could start to paint a picture there ... but in reality, nobody wants CC information - it's radioactive and there is no upside to storing/viewing/comparing it.
There are, indeed, non-mobile numbers and they are second class citizens with regard to shortcodes and SMS 2FA, etc. You will have difficulties, for instance, if you try to adopt a Twilio number (or similar) as your primary phone number.
But it has nothing to do with identification, per se - the most anonymous, cash-bought, found on the street SIM card is a real mobile number and will work perfectly ...
... and the most fully ID checked, personally identifiable VOIP number will work very poorly with 2FA (and not work at all with shortcodes).
I am not sure about your specific anecdote - what carrier are you using and is your "number" the number on your physical SIM card ?
They are in most of Europe though. Since the terrorist attacks a few years ago, it became mandatory to link an ID to any new and existing SIM cards.
Weirdly, Orange will sell anyone a "Orange Holiday Europe" SIM card that has no identity attached to it whatsoever.
I am using it now - purchased from Amazon for $40 - and it is an insta-connect SIM with talk/text/data that auto provisions a number and brings up service immediately upon insertion.
And yes, my Amazon account is indeed pseudonymous and has no connection to my name or physical address. That has always been the case.
How did you manage that? Credit cards, shipping addresses?
Visa and MasterCard don’t verify cardholder name - you can enter any name you want when checking out with a credit card. Our current “bullshit online retailer” nym is a character from Dune.
Network cards do run into extremely uncommon MAC collisions because they just generate a random MAC on first start, which is then read, and printed after manufacturing.