The IMEI Code: Your phone’s other number
tedium.co
tedium.co
> The combination of the ICCID and the IMSI basically tells the mobile network, “hey, this person paid for a plan.”
As far as I remember, the ICCID never actually appears in standard network messaging. It might be possible for the network to request it, but it's not part of a standard 2/3/4/5g attach.
The piece seemed to miss two major uses for the IMEI (or I missed it when reading), which were working around vendor bugs and allowing emergency calling.
Radio firmware and state machines have always had weird bugs, and even when it conforms to standards (some of which are extremely interpretable), does very weird things in the real world. Pre-smartphone, being able to update phone and radio firmware was extremely rare, so it was common for the networks instead to implement workarounds on a manufacturer or handset basis. Having a hardware ID that identified this was extremely useful.
GSM (and onward) actually supports a handset attaching to a network, even without a SIM card, for the sake of emergency calling. It needs some form of unique identifier for this to work. As much as it could (potentially, entirely redefining the stack) generated UUIDs, it makes some sense for these unique IDs to persist across roaming/sessions/reboots.
Yeah, that would be the IMSI (which a given SIM card can have multiple of, e.g. for switching to a more beneficial home network while roaming!)
The ICCID is useful for identifying a given physical SIM card (e.g. so that the phone can link a given user-selected profile name to it/the associated phone line for a "preferred line for contact" indicator in dual-SIM phones), and probably also as an identifier when dynamically assigning a new IMSI over the air.
> for the sake of emergency calling
The IMEI can indeed be an identifier of last resort for emergency calls. I wonder if some countries use it to block abuse/spam calls to emergency services, or more importantly, why some others aren't?
In Germany, for example, SIM-less emergency calls are no longer possible, supposedly due to many people calling the local emergency number to test whether a used phone is in working condition without inserting a SIM card... I don't know what they're doing with the IMSI in that case, and if it's locking these callers out, why they can't do the same for the IMEI.
In older systems, your caller ID is sent using in-band DTMF tones, which are decoded by the dispatch computer.
On newer E-911 systems they get some additional digital address data from the telephone network, but the record format wasn't designed with VoIP or cellular in mind. So in those cases, the telephone network sends a virtual number and the dispatch computer does a seperate out-of-band lookup with the VoIP/cellular company using that number as a key to get your location.
The whole emergency calling system is layers upon layers of hacks. While they can bolt additional functionality on if they're creative, it's more likely a given feature is _not_ implemented. There's a good chance that by the time the call gets to dispatchers, the IMEI/IMSI isn't displayed anywhere and they just see a random virtual number.
The PSAP (E911 end point) likely will receive an MDN/MSISDN (10 digit number you dial for NANP networks) - this is so they can call back if the call is dropped.
E911 is a special service, so in the case of deactivated/missing SIM cards, the carrier assigns a temporary MSISDN for duration of the call when the UE exits E911 mode - there are actually of regulatory and carrier requirements around E911 mode.
E911 Phase 2 required not only the DN, but also if possible the location of the device - whether thru Cell Base Station Triangulation (if possible) or GNSS with a LAT/LONG based on coarse/fine location info.
In any case, as @tjohns mentions, IMSI/IMEI are not typically used outside of the servicing network.
But then I wonder why having an IMSI (as far as I understand, the SIM can be deactivated, foreign etc., i.e. it doesn't need to actually register to the network) improves this in Germany?
Maybe German authorities just hope that having to insert a SIM might deter people, since SIMs are perceived as being personally identifiable more than just phones without a SIM?
Technology under pressure looks a lot like biology.
Always thought it would make more sense to have a dedicated "test number" for this purpose. Probably with some rate limiting.
Now that it’s common for devices to be updated regularly, they will typically send an extended form of the IMEI to the network called the IMEISV, which is the same as the IMEI except the final check digit is replaced with a two-digit code indicating the current software version (SV = Software Version).
These people are not trying to do anything particularly nefarious but they do it so that they can use a phone or tablet plan in a router. Unlimited or high GB plans for routers and hotspots are expensive and there are not many options.
There are lots of reasonably priced, easy to get unlimited phone and tablet plans but if you put a phone SIM in a router it might work for while until the carrier detects that you have the SIM in an unauthorized device. The "solution" to that is to activate on a spare phone and then change the router IMEI to match the phone. Don't use both devices at the same time. The carrier now thinks the router is a phone.
The legally of it is somewhat unclear so it's talked about quietly on various forums using words like "magic configuration", "giving your router an identity crisis" etc.
It's a bit of a cat and mouse game because IMEI is probably not the only way to identify an unauthorized device but so far it seems to be the main way.
reminds me of changing mac address to get around data caps in the student dorm network
Buying an unlocked phone of a model AT&T didn't sell seemed to never trigger the "you're using a smartphone" check. Fun times with some cheap 3G back in the day.
Anything from https://thewirelesshaven.com. I have an old one of their routers and the latest firmware literally has IMEI as a textbox in the admin.
This said, I find it insane that there are such plans. The cost of a connection should be the same whatever the device behind is.
Something interesting might happen next week. T-Mobile Home Internet is not supposed to be moved from the registered address but until now that has not been enforced. It's quite popular with RVers. They just announced a new "Away" plan for $160/mo that you are allowed to move compared to $60 for the normal home plan and, not surprisingly, it seems like they're about to start enforcing the geo-restriction on the home plan. This apparently uses GPS in the device. I hear that a lot of people are using the home internet SIMs in other devices with the IMEI set. This is because there are much better devices with external antenna ports etc. These might be in trouble if they don't respond to the GPS request.
That might have legal implications (wiretap laws, they would be basically intercept your communication). But perhaps TCP/IP fingerprinting too, not sure... On the other hand, with providers that were even injecting code in web pages when HTTPS was not ubiquitous... maybe they don't care too much.
IMEI - we only really cared about the TAC prefix, as this identifies the device type, which is mapped to capabilities for services.
IMSI - this is usually in the SIM card (UICC), and mapped out specifically within the uSIM/SIM application inside the card. This is aligned with the Billing/Rate Plan for services that the subscriber is set up with.
TMSI - this is usually what the network uses to page you and also deliver singaling over the NAS via the SGs interface for devices that do not support IMS/VoLTE
ICCID - this ID's the card itself, for SIM cards, it always starts with 89 as this designates the card as telephony related as a physical UICC - remember, there are other types of UICC's such as CHIP based Credit Cards, which start with a different number.
MSISDN - this is the number that you dial and send SMS to - in legacy systems, it can also be referred to as the MDN
Fun Fact that was skipped in the article - IMEI's that start with 99 are special, as these indicate that the Device is both GSM/UMTS/LTE and CDMA/EVDO capable, and generally those IMEI's will align closely with the CDMA MEID's, but they were not required to. The "99" range wasn't just Apple, but was used in the early days of dual-mode across most vendors as it helped facilitate session handovers from C2K to any 3GPP based service. For C2K, on the IMSI front, most devices would use IMSI_T (True IMSI based on the SIM card IMSIef) but some used IMSI_M which was based on the legacy MIN.
Legacy - there is the ESN in CDMA, but this is very legacy, and was largely superseded by MEID - for Legacy Support, pESN could be derived from MEID, however at the high risk of collisions...
> SUPL is used as part of the A-GPS (Assisted GPS) system to get a faster Time to First Fix. The problem is that Android's implementation automatically sends the IMSI (ID of the SIM card) to the SUPL provider for no apparent reason. And because Google is the default provider it's a big breach of privacy.
If you happen to buy one from another country, it will be locked after 60 days of use and no carrier will connect it after that. You can use your passport to to prove that it was not imported commercially but you brought it with you and register it. For $1000 (yeah). And it is locked to your ID. Can't transfer it to someone else.
IMEI cloning from an already registered donor phone was a thing and maybe it still is but as far as I can tell, high end phones pretty much lock it tightly.
BTW, this also affects a lot of other stuff. Can't buy a gps dog tracker from amazon. Can't buy a gsm module for your arduiono etc...
My car has a connectivity system where it provides internet to the in car infotainment system and also allows me to open doors etc remotely. It only recently became operational when the distributor finally managed to register the IMEI numbers. A lot of companies do not bother (Mercedes, BMW etc are equipped with similar systems, not operational)
What do you mean by that? Ostensibly I can.
https://www.adafruit.com/product/2687
Note: it’s on back order, but in theory I would be able to buy a GSM module for my Arduino.
My native Turkish might be seeping through though. Thanks for the heads up.
Just let people edit it. Then I can be someone new every day and nobody can track me.
Mac address randomization does that for wifi. Now do the same for mobile networks.
And while we are at it stop tunneling my data back "home" when I travel. I don't want increased latency.
The phone could pop up a menu saying "Here are the available networks", and you pick one, connect and it says "Welcome to AT&T, enter credit card number here", and you type a number and hit OK and you're connected.
Oh wait - just like Wifi!! Why are mobile networks so far behind?
Not if you need to send a message to $thatUniquePhone.
Over simplifying considerably, but if a land line places a call to a mobile, the "220-1234 calling for 220-7890" message enters the network. The `220-7890` phone number needs to map to the unique modem address so you can look up which tower the call setup data should be sent to. If - by sheer coincidence - I also have your MAC address and am attached to a tower 3 states away... which tower(s) do you forward the call setup data to?!
Whichever one has most recently communicated with the user in question (based on the credentials or certificate provided, in the original example)
If you have a wired connection, this makes the MAC completely superfluous. The concept is sort of still valid for wireless connections (or of course for "wired" connections where you have multiple devices physically connected by the same wire, a bus, where the concept originated). It should be rethought.
Note that this is only about last-mile/first-hop. Once you scale past a single LAN segment, routing is mostly layer 3 until you get to core Internet infrastructure which uses ASNs and BGP. At the very least, it is probably sufficient to say that routing across a WAN is all about IP, but if you zoom in on parts of that network of networks, the underlying technologies often use other routing mechanisms internally that don't get exposed to the other parts of the WAN.
It’s also worth mentioning SLAAC does not strictly require a hardware address to function. For example, Apple devices implement newer standards from IETF to generate random but stable addresses that don’t reveal information about the hardware addresses (https://support.apple.com/guide/security/ipv6-security-seccb...)
Oddly enough, I found this to be a plus when I traveled to China for work. My data was unmolested by the Great Firewall of China. I was able to get on websites with my mobile data that I couldn't when using wifi in the hotels.
You might not, but a whole lot of customers who aren't as technically sophisticated did. When T-Mobile first started doing included international data roaming, they didn't tunnel back. That caused a lot of confusion from customers who didn't realize why stuff they expected to work, like checking their bank balance, didn't. (It also made throttling speeds a lot more difficult.)
So to fix that, T-Mobile tunnels you back to a few endpoints in the States. Banking apps are generally happy, as are Netflix and Spotify. Most customers are happy because their phone "just works" the same as it "always has".
For those of us who want to avoid the latency, we get a local SIM for data (if possible).
The only thing I can think of, assuming they tunnel as you describe, is maybe I first loaded the site from local WiFi instead of mobile data, at which point I was redirected (to a localized subdomain that doesn't redirect back) or got a cookie or something, which lingered as I continued without WiFi.
On the other hand, the IMEI in principle makes tracking and disabling of stolen devices easy.
By the way, in the UK it is actually an offence to change the IMEI [1]
The network operator does NOT need to know who you are, even if you live in a repressive country that mandates tying ID to mobile phone lines. Get a SIM card in person and top up in cash, or use a virtual credit card, or pay in cryptocurrency for an eSIM, or get a subscription in a less oppressive country and roam.
Invisv is a great suggestion.
There are people that for various reasons do cycle out their SIM card frequently as a means to avoid tracking. This is ineffective. Changing the IMEI/discarding devices entirely is more effective.
I wouldn't be surprised if there were some 'ghost'/virtual profiles associated to an imei similar to how Facebook would do with the like button
Existing privacy level is adequate for members of the public. Anyone who actually, really requires more either has state agencies resources available or is being wanted by state agencies...
https://invisv.com/pgpp/ for IMSI (not available worldwide)
https://github.com/srlabs/blue-merle for IMEI, a nice guide written by them explaining how it works https://raw.githubusercontent.com/srlabs/blue-merle/main/Doc...
You can follow this thread for more info https://discuss.privacyguides.net/t/cell-towers-tracking-net...
I should have been well positioned for early retirement during the early smart phone gold rush but was just so put off by the Ma Bell feeling of the mobile industry that I had exited before most people had even entered.
Maybe once upon a time, but I'm pretty sure stolen devices can be blacklisted from networks these days.
Australia had been doing it since 2003. IMEIs have been around for 30 years? Everyone having a cellphone is still a relatively recent phenomenon, but according to Pew 80% of American adults had cellphones for several years already before carriers were forced to deal with stolen ones.
It's like when your apple laptop gets stolen and then starts using your applecare support and apple won't help you get it back.
Of course, if you decided not to pay your phone bill I'm sure that device would get blackslisted real fast.
No other sim will work in it until you take that photo ID/passport to the mobile companies office to have it unlocked. The photo id (even if expired) becomes the unlock code for the phone.
Made phone theft drop to pretty much zero.
Use a nuke to kill a fly?
You continually use the present tense when the argument... just doesn't apply anymore.
> I think I’m more concerned with the fact that the carriers know the IMEI of phones and claim that they can do nothing about stolen phones.
This is not a fact anymore.
GSM, SS7, etc. are massive privacy holes _by design_.
Not sure where you get your information, but these are routinely used by police to covertly track targets.
By sending one that clears all of them in a network that doesn't use them (or sending one equivalent to the current state for one that does), you can achieve the outcome of initiating SMS-MT (mobile-terminated) delivery to a given ME (phone) without any user notification.
SMS delivery by necessity involves paging the device, revealing its location at a finer level (base station instead of paging area).
So I wouldn't say silent SMS were designed as a spying tool, but they're one out of several ways to silently "ping" a phone and force it to communicate with the network without having to wait for it to cross location area boundaries, get or make a call etc.
Many carriers implement this via "silent SMS" + IMAP (the same IMAP as for emails). The device will send an activation or status message to the carrier's visual voicemail number and the carrier will respond with an SMS containing the IMAP credentials.
The version of this I'm familiar with is T-Mobile's old CVVM protocol. During initial setup, the device will send a text message containing "Activate:dt=6" to the number 122 and T-Mobile will reply with (in decoded form):
pw_len=4-9
vs_len=10
u=<IMAP username>
pw=IMAP password>
rc=0
st=R
ipt=148
srv=e7.vvm.mstore.msg.t-mobile.com
lang=1|2|3|4
g_len=180
If visual voicemail is already enabled, then sending the "Status:dt=6" SMS to 122 will also result in the same reply. Putting the credentials in an IMAP client will work and it doesn't have to go over the phone's cellular connection. You can even use curl: curl -v imaps://<USERNAME>:<PASSWORD>@e7.vvm.mstore.msg.t-mobile.com/
T-Mobile has deprecated this protocol though. New activation messages will fail with a blocked status: rc=0
st=B
srv=vvm.mstore.msg.t-mobile.com
T-Mobile replaced this CVVM protocol with two HTTP based protocols: "mstore" (used by OEMs like in the dialer app on Google Pixels and OnePlus devices) and "cpaas" (used by T-Mobile's first party visual voicemail app). I've been working on an open source client for mstore for use with open source Android OS's, like GrapheneOS.In case anyone is interested, the vvmd wiki (visual voicemail implementation for Linux phones) has information on how several carriers implement VVM: https://gitlab.com/kop316/vvmplayer/-/wikis/Visual-Voicemail.... AT&T's is especially nasty.
The whole purpose of mobile networks is to track a devices location (so you can route data to/from it!). Of course its easy to do it if your the operator or someone who has compromised it.
When these things were designed, privacy wasn't really a concern and wasn't really thought about in the way it is now. The assumptions were very different, it was assumed that only large and trusted companies could get on SS7 and those would play by the rules, or else face the wrath of the government. Now, a small carrier in a third-world country that routinely violates human rights can get that access.
And smartphones 10 times more (or more, depends on how many apps you installed, almost all of them include some sort of trackers).
IMEI is (almost) the last of my privacy problems.
To increase privacy, either randomize it (but make it much longer at the same time to avoid collisions) and/or remove it from as many signalling contexts as possible and keep it as a device-local identifier only (which then probably also doesn't have to be unique across manufacturers).
The HTC phones had a Qualcomm radio that, with the right tooling, one could write all 0s to the IMEI (or the CDMA equivalent) register. Then you could write any IMEI to the register. That worked well for a few years.
HTC got into a bit of trouble with the carriers on the whole IMEI/MEID rewrite mess at the end of the day. With Qualcomm, that was an NVITEM that was supposed to be read-only.
EDIT: "Over 13,000 Vivo phones found to be using same IMEI number"
https://www.techradar.com/news/over-13000-vivo-phones-found-...
Unfortunately, neither IMEI, Serial Number or a combination of both can assert this.
I bought a Samsung S24 a week ago off Facebook Marketplace. It was in the box and everything. I cross checked both the IMEIs and also the Serial Number with the #06# test. I even checked them online. Did all the tests, #0# and even downloaded Samsung members. Paid for the phone, convinced it was a genuine one.
Upon registering it and using it, it becomes very clear the phone is fake and is at best a clone. The camera is nowhere near the S24 and does not have the features. It heats up after charging and does not keep charge. It runs slower than a 10 year Android once you are signed it.
when you run diagnostics, it shows all the specs of an S24 Ultra. How do I know this? I went and got another S24 Ultra from the store and they are worlds apart.
So my question is, if you are buying a phone from a reseller or someone, is there any way of definitely asserting whether it is authentic?
You need to price in the risk factor when purchasing where such legislation doesn’t apply or isn’t easy to enforce.
You could set how much RAM you wanted, how much storage, what CPU and so on, and then that info would be shown in all the "about" screens. They went to a few Tb of ram if I remember correctly.
Changing any of these parameters didn't have an impact on what the phone could actually do, just to be clear.
it will generally start with a 35, which is unused as a country calling code
It's "unused" because several country codes start with 35: Ireland, Portugal, Luxembourg, Iceland... (This doesn't mean that phones are actually manufactured there... I have a phone with an IMEI starting in 354 and it's definitely not manufactured in Iceland...)Based on what other commenters have already pointed out, this seems to be a quite sloppily researched article.
The ICCID starts 8944 - not sure of the significance of the 89, but 44 is the UK, where my SIM card (and me) comes from.
We always wondered if you could crash part of a cell network by dropping in 8192 phones with the same IMEI. Everyone needs to deal with non unique identifiers, but the question is how many do they expect?
FYI this is a problem on Ethernet, when you get boards that haven’t been initialized. Things don’t like multiple MAC addresses with 0s.
> Check digit: The final digit is essentially used to validate the prior 14 digits with an algorithm. Similar digits exist in other types of identifier codes, such as the Universal Product Code (UPC) and the International Standard Book Number (ISBN). The algorithm that the mobile industry uses, the Luhn algorithm, is also used for social security numbers and credit card numbers.
No, just no. SSNs (in the US) don't have check digits.
Also:
> Then there are network identifier numbers—the MAC address bestowed upon you by your WiFi network or mobile provider
Huh? This nonsense ("bestowed upon") serves only to confuse. This is bad tech journalism: it fails to inform the masses, and is transparently worthless to experts.
Digging into it, it seems they've been IMEI blocked – i.e. reported stolen. Sending them back to Amazon is always such a pain because it means a visit to the post office.
>The blue-merle software package enhances anonymity and reduces forensic traceability of the GL-E750 / Mudi 4G mobile wi-fi router ("Mudi router")
>Mobile Equipment Identity (IMEI) changer
>Media Access Control (MAC) address log wiper
>Basic Service Set Identifier (BSSID) randomization
>MAC Address randomization
I realize that there are some Modem OEM's that might allow the IMEI to be "adjusted", but proper modem vendors will not allow that AT command.
Follow up, does the IMEI number get broadcast when you connect, or is it a searchable bit of information accessible by apps, et al?
Im wondering how anonymous you can be if youre making all the right privacy moves, but your phone is still essentially giving you up because your IMEI number is traceable back to you.
Say... to help identify if a specific phone comes around, or what phone/s were around when a break in occurred?
Phones seem to switch off wifi regularly for energy savings, so not particularly useful for detecting iphones at home for home presence automations
Even the IMSI is only used when absolutely necessary, i.e. for the initial attachment procedure when cold starting a device or entering a new routing area; after that, it's replaced by an alias called TMSI to make tracking phone users a bit harder.
New Android versions will supposedly have a switch in their settings to show a warning every time the IMEI or IMSI is transmitted in plantext [1].
[1] https://cs.android.com/android/platform/superproject/main/+/...
The U.S. Gun Control Act of 1968, among other things, requires traceable serial codes on guns, something that has become a key element of forensic ballistics. In some circles, this is seen as controversial, as highlighted by a case involving “ghost guns” that the Supreme Court is hearing this session.
First of all, serial numbers don't have much to do with forensic ballistics. Generally, in forensics, investigators are comparing items in their actual possession -- shell casings, bullet fragments, and weapons recovered from the scene of a crime or from a suspect. Serial numbers don't help with that.
Serial numbers are useful in investigating gun trafficking -- it's actually very similar to the example of car theft that the author presents early in the article.
Regarding the "this is seen as controversial", that is a claim that is absurd beyond belief. What is at issue in the case is when the requirement to serialize adheres and to what it adheres. That is a complex issue. A gun is made of dozens of components. Many are tiny with small surface areas, like springs and pins, and many are replaced over the life of a gun, so serializing them would (a) be ineffective and impractical and (b) could actually confuse the identity of the gun.
So when do we serialize and what do we have to serialize? For a long time, the settled practice in the industry has been that there is one component that is "the firearm". This part generally is large, is subject to low mechanical stresses, and can be expected to last the life of the gun. This is generally a part called the "receiver" or "frame".
If the receiver is ever damaged beyond repair, regardless of the state of the other parts, then a "new" firearm has to be created and serialized. Although the barrel, trigger, &c, are all the same, it is a different gun now.
This system has actually worked pretty well and has allowed for relatively robust tracing of stolen guns and guns found in investigations of international arms trafficking.
Collections of parts that make up an incomplete gun are of two kinds -- if the receiver is in that collection, the collection of parts is a firearm and has to be sold according to the rules governing transfer of a firearm; if not, it isn't.
A receiver or frame starts life as a large block of metal or plastic. So what if we sell people a parts kit where we have every part of the gun except the receiver, and also an appropriately sized block of metal or plastic? Nothing in this combination has to be serialized and it is not a firearm.
Until recently, this was not really an area of much activity because, while a receiver is subject to low mechanical stresses, that is in relative terms -- relative to other parts of the gun. It is nevertheless a component that takes a fair amount of machining and finishing to get made. What brings us to the "ghost guns" discussion and the Supreme Court case linked in the article, is the degree to which home manufacturing with light tools has improved in recent years. It is actually possible now to make a pretty good receiver without a machine shop. Some people came up with a business of selling people almost complete guns, with a block of plastic or metal and some jigs that allowed them to readily complete the receiver. This is an edge case and it will take some thought to establish when, exactly, we apply the rules regarding serialization. The people making blocks of plastic probably will not be required to serialize all blocks of plastic simply because they are potential firearms (along with potentially being many other things); but the people buying the blocks of plastic to put into kits that they then sell to others in order to make guns probably will be seen to have created a "constructive firearm" and so will be required to serialize them.