Skip to content

Comment on Why older tech is sometimes safer from hackers

Comments

It's incredible how far back the surveillance state goes - GSM mobile phones have an IMEI number that's tied to the handset - and the SIM is tied to the subscriber, and your phone broadcasts imei to neighboring towers constantly.

I haven't really gotten really into this, but from what I can tell, anything that has to do with mobile phones is strictly worse in terms of anonimity than Wifi.

At least anything that ties a Wifi connection to you you can change in an OS setting, but if you get into faking IMEI/SIM stuff, that can very quickly get you charged with an actual crime.

One of the things about mobile phone is that there's 2 OSes on the phone: one that handles the phone stuff and the other that you as a user actually interact with. What's really scary about it is that the OS we do not think about is often licensed to the manufacturer (Apple, Samsung, etc.), closed-source, and dated. There's a lot of security firms that sell fake cell towers to law enforcement and governments and that gives them access to all of the data you send over the network. In older formats like 2G there was no encryption on anything sent over the wire.

If you dig into the fake cell tower rabbit hole you'll find what you're talking about to be an even worse problem.

I think this how modern CPUs work also.

surveillance state

How do you suppose mobile phones are meant to work without subscriber info?

I haven't really gotten really into this

Clearly.

I think the argument is more the IMEI side of things, one might naively expect that they could could simply change SIM and that would change ones identity and that anything like an IMEI could be easily configurable like how a MAC is on a NIC is.

IMEI is needed to allow them to identify the device's capabilities, and know if it's been reported stolen.

Sure and of course surveil in general. To advertise capabilities one does not need a unique identifier it's clear that part of the rational for the development is to allow for control over the devices by telco's and/or the state, in a way that link layer for other networking technology did not. A while ago I brought a pixel second hand my intention to put a custom rom on it but it was locked by the carrier entirely and though unlocked the carrier simply decided to not allow their pixels to be flashed. All of that to say that obviously the decisions made where not entirely for simply because of the technical reality or for reasons beneficial to the users and lots of things that are hostile to privacy and real ownership of the device.

Doesn't the whole SIM architecture exist so that phones don't have to be trusted? I believe IMEI can be anything in practice, so long that there isn't a blatant duplicate nearby, a bit like Ethernet MAC address. I don't know if it's legal but phone nerds seem to be editing IMEI all the time for non-Apple phones as well, using those leaked vendor tools.

I believe IMEI can be anything in practice

It used to be that when the telco detects an IMEI change for your SIM, they send a configuration over the air so that you have access to the data network.

Anything billed by the second has good (-enough) cost attribution built in.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.