PGPP (Pretty Good Phone Privacy) Beta Launch
invisv.com
invisv.com
This is a bit like calling your company "Red Cross Pharmaceuticals" despite not being affiliated with them.
In fact atleast over here in Finland naming one's company is specifically reviewed by the patent and registry bureau to make sure it doesen't resemble any existing companies. It costs around 100-450€ and is mandatory for any new company
> It was this bill that led me to publish PGP electronically for free that year [1991]
https://www.philzimmermann.com/EN/essays/WhyIWrotePGP.html
> It was on this day in 1991 that I sent the first release of PGP to a couple of my friends for uploading to the Internet. First, I sent it to Allan Hoeltje, who posted it to Peacenet, an ISP that specialized in grassroots political organizations, mainly in the peace movement. [...] Then, I uploaded it to Kelly Goen, who proceeded to upload it to a Usenet newsgroup that specialized in distributing source code.
https://www.philzimmermann.com/EN/news/PGP_10thAnniversary.h...
Symantec later bought it and things changed, but thanks to there being an open standard (OpenPGP) and RFCs, people can and did write compatible software. With varying degrees of compatibility, admittedly.
Also wanted to add, since this is a common question: does PGPP protect all identifiers or just some? As with most privacy systems, just some. Our aim is twofold: 1) to decouple a user's human identity from their network identities (mobile and Internet) and 2) randomize their network identities. We view decoupling as pretty fundamental to practical privacy -- to decouple who you are from what you do. Who you are in the context of the network is your human identity, often associated with the main point of contact you have with the network and billing -- your subscription and SIM, your broadband connection and its IP address and your home address, etc. That information has been used as the key upon which datasets can be attached. The goal then is to decouple across entities -- the different parties who have data -- and across uses -- the different mechanisms of a network protocol, such as authentication and connectivity.
Other identifiers such as hardware identifiers aren't inherently attached to a person and aren't always used by networks, but even when they are, removing them is insufficient -- as our colleagues at UCSD found in recent work, phones can be identified at the PHY, without even using a unique hardware identifier.
Seems like if the same IMEI shows up over and over again with a different rotating IMSI then the jig is up.
How widespread is this practice? Do the major US carriers know my IMEI?
I tend to believe that they do from what I've seen in their web interfaces, and that IMSI rotation alone is basically pointless from a privacy standpoint.
IMEIs can be queried by a network core (not the tower) and US carriers probably do this every once in a while to check against their stolen phone database. It can be changed on some devices but not others. It's not inherently tied to you as a person but of course it is tied to that device.
For those who don't need mobile data service of any sort, I think that PGPP Relay does what's needed -- decouples your IP from your identity -- and you can use WiFi networks without revealing anything.
It's also linked to the rotating IMSI, so all of the rotating IMSIs that are used at the times the IMEI is interrogated are linked together from a metadata standpoint.
They're also all linked to every other IMSI that was ever used with that IMEI (at the times the IMEI is interrogated).
> US carriers probably do this every once in a while to check against their stolen phone database
Hourly? Daily? Monthly? Only on first-time seeing a new IMSI?
I would be shocked if there were real consequences for IMEI spoofing in the U.S. absent any crime (like stealing lots of phones and changing the IMEIs).
Edit: the FCC isn't specific about it but I'd imagine it falls under existing fraud regulations which may or may not be a federal thing.
A cursory Google suggests:
A bill was introduced in the United States by Senator Chuck Schumer in 2012 that would have made the changing of an IMEI illegal, but the bill was not enacted.
So in the USA specifically it is not a crime but in many places it is due to the aforementioned life at risk issue.
As devices are made for global .markets in general, the above does not apply anyway as you cannot change it without manufacturer tools anyway, at which point different regulation applies.
IMEI changes also have limited effect when fingerprinting is relatively easy.
This would mean that, in sensible societies, failing to carry a phone on your person is a criminal offense. It is a position only a true idiot could even articulate.
This is not difficult.
And a hint--I believe it's actually quite easy using an edXposed module if you want to root your Android phone.
Of course, then you've got a rooted phone, which is less secure.
This is incorrect. Changing your IMEI it is illegal in the USA under the Wireless Telephone Protection Act of 1998:
"Amends the Federal criminal code to prohibit knowingly using, producing, trafficking in, having control or custody of, or possessing hardware or software knowing that it has been configured to insert or modify telecommunication identifying information associated with or contained in a telecommunications instrument"
https://www.congress.gov/bill/105th-congress/senate-bill/493
That's nice. The courts think differently.
There are lots and lots of laws, though, that are either unenforceable because they're badly written or just not enforced. The sibling comment pointing out the part you left out is on point, and I would be surprised if any sort of prosecution would ever happen. I'm paying my phone bill and I want to change my IMEI, so what? I'm not defrauding anyone. I am inclined to believe two things:
1) Nobody would ever bother me about this, and
2) Courts would agree with me if push came to shove
They may not be doing it right now, but if this sort of thing catches on, it is likely that they will start trying to do it.
Could I pick up an eSIM compatible Android tomorrow for cash at the local pawn shop, and get service using your system without handing over anything identifiable?
It seems like you're misreading a key market segment if you don't offer cryptocurrency payments (particularly Monero).
The answer is no, you cannot. Payment cards are PII.
I understand that revealing that information to Stripe may not be acceptable -- not sure what to say to that. We've gotten requests for other forms of payments and we can consider it, but we don't support anything other than credit cards at the moment. (There are credit cards that aren't linked to a person, if that's a better option.)
My desire to know more intensifies.
Go to the grocery store, buy with cash, you're good to go.
No. Gift cards can be purchased in-person in the US, with cash. Said gift cards are activated at the register upon purchase. These can then be gifted to someone else, and further activation (or registering your personal information with the card) is not required.
Edit: I just checked the Visa gift card issuer's site for a card I have (and never had to activate or provide personal information to), and for shopping online it just says:
>In the Payment Method section, enter the Card information as you would a credit or debit card. In the Billing Address section, fill in your name and address.
So when I check out online, I can enter any information that I like, presumably as long as it ties back to a valid address of some kind - there is zero effort on the part of the card issuer to verify that I am who I say I am. I would only need a PIN when making purchases with it as a debit card in-person. I should make it clear that I'm not saying that providing false information is legal, just that the point about being required to provide "strong government identity" to activate gift cards has been false for a long time.
You said this with remarkable confidence and were dead wrong. You should reflect on that.
I imagine many others will be in the same position.
Obviously taking crypto will mean upfront prepayment of accounts (like prepaid mobile credit) instead of monthly billing and will require some reworking.
For a privacy product this should have been there at the start.
Obscuring traffic patterns without stupendous amounts of dummy traffic is quite difficult. That someone is connected to your network at all is already a huge giveaway. I have trouble seeing how something like this can work without a very big operator (think Cloudflare or AWS) being involved, and anything that size would have to get in bed with regulators. It's a lot easier if you're only trying to do low bandwidth text.
Does anyone have a copy of it? I can't find it ANYWHERE. Actually used it way back when, it worked surprisingly OK and was the first softphone I used.
- Given that your Android app is security-critical for its users, are you planning on open-sourcing it in the near future?
- How exactly does your app work on Android? How does it rotate the IMSI? (I don't know a lot about eSIMs but I would have thought a regular app can't easily change the carrier/network settings.)
- As for the relay functionality, I suppose on Android this "simply" sets up a VPN once the network connection is established?
[0]: https://www.usenix.org/conference/usenixsecurity21/presentat...
Your claim "we don't learn which eSIM your phone gets" is false. The eSIM update protocol, which is implemented in firmware which you do not control, will send you (the carrier) the eSIM's permanent ID (the EID), and you can't stop this. https://news.ycombinator.com/item?id=32416373
Moreover, you provide no protection whatsoever against IMEI tracking, which all carriers implement. IMEIs are reported to the carrier immediately after authentication/attach (AKA), and many will block invalid/unexpected IMEIs. You can't prevent this. Without a solution to IMEI tracking your work on IMSI tracking isn't much use. This won't protect anybody from the telcos. At best it might stop people using a stingray without assistance from the telco (i.e. almost nobody). https://news.ycombinator.com/item?id=32416308
Doesn't signal require a phone number to use? Or did they fix that?
1) You should explicitly test with privacy-respecting Android flavors like GrapheneOS. I assume it would work using the sandboxed play services hack, but I'm not sure.
2) You need another exit aside from London. U.K. has weak data protections, facilitates U.S. spying, doesn't even offer access to the real internet any more (they run a firewall and mandate various other kinds of nannying), and, generally, seems like it's sliding down the path towards some sort of oppressive surveillance state.
3) I need to be able to pay with cryptocurrency, ideally Monero.
1) we have tested with GrapheneOS and it does work. Relay works well with GrapheneOS. With some amount of configuration, the mobile plans also work, though it can be a bit tricky to set up.
2) We have many egresses (via Fastly) -- across North America, South America, Europe, and Asia -- and more planned. The London egress is used when you're on mobile data by default, but if you're on WiFi then you can egress elsewhere.
3) Not sure about that at the moment, but we've gotten the request from multiple folks.
Much much more discussion on this here: https://github.com/GrapheneOS/os-issue-tracker/issues/159
What? No such thing exists, stop
"UK mobile phone operators began filtering Internet content in 2004[9] when Ofcom published a "UK code of practice for the self-regulation of new forms of content on mobiles".[107] This provided a means of classifying mobile Internet content to enable consistency in filtering. All major UK operators now voluntarily filter content by default."
It's Wikipedia, so take it with a grain of salt, but...
Actually to save everyone else's time I'll explain the actual real world implications:
The "big 4" (over x customers) must implement "best effort" blocking, which varies between network (it's all useless because DNS is easy and satisfied the law), however unlike the USA, the UK has 100s if not 1000s of ISPs who are not subject to said regulation and can do what they want. This is because in the UK we do not stomp on competition which means independent ISPs are allowed to exist and pay the same price as everyone else for the same access.
While I'm here, there has never and never will be a "firewall" - the free market design of UK telecoms does not allow it to happen and there are no central points to filter, anyone who disagrees otherwise is a genuine moron or willfully ignorant, it doesn't matter the result is the same, since the reality trump's opinion.
If you'd like to discuss these things in real detail I have contact ability so message me instead of absolute nonsense on here - there is no excuse to be ignorant we live in an informational society.
If it's contained locally, it's likely you could make more in volume than with a higher price.
Also, it's deceptive/leaves a bad taste in mouth with having the Play Store show an "Install" button rather than purchase, only to open the app to a paywall. Using this dark pattern could end up hurting user perception/the app's reviews.
The $90/month price is for unlimited mobile data, so it would in theory replace your phone bill entirely.
I still do find it disingenuous to omit it entirely as it implies that all possible issues are averted which they absolutely are not, even if IMEI wasn't a factor.
Every time anybody points out the severe technical flaws in this scheme he either waves it away with happytalk or ignores it.
Was this relevant to making the "likelihood of confusion" low enough that there's no risk of needing to rename the Pretty Good Phone Privacy product?
How does this protect against IMSI catchers and Stingrays if they are done local to you? Local cell tower spoofing?
Also, this is just for data? So if you have another SIM for voice/SMS this is completely negated?
I seen this happen before. I used to use the "Private Buyer" Payment service to anonymously pay for services privately. They had issues with payment processors preventing their payments from going through. I gather largely due to the privacy aspects of the service. That was in the early 2000 and I think the went out of business after 3-5 years.
So no, make a different solution.