Is it possible to create a private and secure mobile carrier? Cape Mobile thinks so! In this video I sat down with Ruddy Wang, Head of Consumer at Cape who answered some questions I had about the service and dove how the privacy & security features work.
As I understood when listening to the interview it seemed that the tower receiving can see the IMEI of the connecting device. Since this is unchanging, wouldn’t it make a feature like IMZ rotation redundant because the IMEI is another identifier that that tower can use to track but is not being rotated?
The secondary phone numbers seem really useful. I imagine tying them in to “personas” as in what accounts you want to be connected would be useful. As I understand it the tower operators would only be the main number. So, you could keep that number tied to people / accounts associated with the physical persona. Then, the other two for other online activities you would rather not be connected to your actual self (for example, services you need a phone number to sign up for but are basically throwaways).
There’s three things going on here:
-
Your IMSI can be seen by anyone in the local area. This is the primary way things other than your carrier, such as MITM/Stingray devices, track people. Your IMEI, on the other hand, can only be seen by the carrier after mutual authentication is performed.
This is a legitimate protection that IMSI rotation provides, where the IMEI doesn’t matter, and IMO it’s the main protection most people should be thinking about.
-
Your IMSI is used by attackers to perform SS7 (or similar) attacks, they need it to hijack your connection via a compromised carrier. Because your IMSI changes very infrequently with most carriers, attackers will sometimes/usually store people’s IMSI numbers for months/years before they perform an attack. IMSI rotation renders this nearly impossible because the window to attack is very small.
This is a legitimate protection IMSI rotation provides as well, but IMO less useful to most people simply because you probably will not be targeted by this sort of attack. If you are a target though, IMSI Rotation and Network Lock are both very useful tools.
-
Cape’s general thesis is that most carriers are tracking people and/or monetizing their data only using IMSI numbers, because they are per-user identifiers they control, whereas your IMEI can theoretically change for any reason (like, you change your phone) or be shared amongst multiple users (if you give your phone to a family member or someone later). So throwing IMSI rotation into the mix (see 20:02 in the interview I think) kind of makes tracking uneconomical. Since AT&T can track the 99.9% of people who aren’t using Cape much more accurately with IMSI numbers, they simply haven’t really built the tools to track people via IMEI in the same way.
This might be true tbh, but obviously it is not a technical protection like the other two points, since they can track people using their IMEI as you said, they just “don’t.”
The long story short is that IMSI rotation has legitimate protections against attackers other than your carrier, but IMSI rotation is not enough to protect you from the carrier itself.
Also, note that #3 only applies to AT&T/T-Mobile when you connect to Cape using their towers. Cape themselves basically have full access all of your carrier activity, the only protections from Cape are basically their logging policy and the fact that they collect very limited billing data, but defending yourself from Cape is not the primary use-case for this carrier.
Yes. I am also told at some point they want to protect the main number in the same way secondary numbers are protected, so that any primary number usage goes directly through their servers, but that hasn’t been built yet.
I understand that Cape has certain security benefits, my concern is more with it being a potential honeypot. The CEO of cape is (self admitted) former Palantir, recruited from the special forces, and the point of the company is to make cell phone services (an extremely insecure service) more resistant. This has the potential to give someone false security when using a (still insecure) service. What’s more, its marketed towards people with a very high threat model (its on accresent and donates to grapheneos and other similar services. People with high threat models like this are very appealing to trigger-happy law enforcement agencies.
I am absolutely not saying this as an insult or as if it is complete fact, this is speculation. I only mean that we must be careful about trust, and things like this need to be brought up when talking about services we use.
Since IMEI is still visible to the host carrier after mutual authentication, is there any roadmap discussion of pairing Cape with IMEI randomization at the OS level (e.g., GrapheneOS), or does the network reject devices whose IMEI changes?
Thank you for the thorough response. It was very helpful.
Honestly that was one of the most interesting talks in the recent weeks!
It is kinda crazy to go into this crappy, legacy, proprietary telco ecosystem full of proprietary nonsense, weird regulations and nonexistent privacy and security and change it.
Obvious issues
- Only in the US, which is kinda ironic as the US is a privacy hellscape in many other regards (excluding privacy.com and visa gift cards, both dont exist in europe)
- Requires ESIMs (afaik?), is there support for EasyEUICC? OpenEUICC requires privileged OS integration, iodéOS is the only one I know integrating it. GrapheneOS actively decided against it, there was some crazy drama.
It is surprising how expensive it is to create a new carrier. I mean, I pay 5€ for 10GB. Nonetheless, I want this in the EU!
There are some EU countries left without KYC, and EU roaming works flawlessly. Still, I guess there are some things in the wild west making this easier.
Here is some worldwide map
I will say I have have had thoughts in the past that whoever improves cellular privacy and security would be a huge blessing to privacy and I thought it would be impossible without creating a new MNO, but Cape has made improvements.
On that note, a GrapheneOS developer was recently working on an eSIM app/LPA, so proper open source eSIM support in the OS may be coming in the not too far future (to replace the togglable proprietary Pixel app integration, which already allows you to manage eSIMs privately on GOS).
GrapheneOS isn’t gonna include OpenEUICC because it’s now GPLv3 (which they don’t want in the base OS to keep it usable as a drop-in AOSP replacement) and it also uses a lot of memory unsafe (C) code.
My understanding (from 22:32 and 24:42 in the interview) is that a hardware OEM partnership is required, not an OS partnership. Well, actually you probably need both, but it’s not something they could do with GrapheneOS on their own.
I believe on Pixels I think there is a way to change the IMEI with root? So theoretically is it technically possible for GrapheneOS or another Pixel ROM to add support for that? I suppose… But just changing the IMEI to any random number is illegal, you have to actually own the IMEI numbers you’re using. Therefore they’d need a partnership with someone like Motorola who lets them use Motorola registered numbers, not just with GrapheneOS.
IMEI numbers are also a finite resource, as opposed to IMSI numbers which are carrier-specific, so they can kind of do whatever they want with them on their own network.
Hope this company is not a play on words and is related to Kape just like how Incogni the DataBroker removal service is.
