9 karma · joined January 14, 2021
That being said, IMEIs are yet another identifier among many that could be used for tracking in the future. We've been working on ways to prevent this from happening while still allowing some common uses such as the stolen phone database that IMEIs are supposed to be used for to continue to work, but in a privacy-preserving manner. (Rolling this out will require cooperation from several large players, likely including Apple, Google, and mobile operators, so it's not an easy road.)
However, their use is to only gain IP connectivity - the equivalent of an allow list on the backend db (AUSF) which gives you IP connectivity. At that point you do billing and auth at the PGPP-GW using oblivious auth tokens.
Our fix changes the architecture to nullify an identity that has long been used to track users. The data has simply been available for them to sell as a byproduct of running a network.