sigmoid.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A social space for people researching, working with, or just interested in AI!

Server stats:

586
active users

#imei

0 posts0 participants0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://tweesecake.social/@adisonverlice" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>adisonverlice</span></a></span> even <em>if</em> an <a href="https://infosec.space/tags/MVNO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MVNO</span></a> isn't demanding any <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a> whatsoever (i.e. <a href="https://infosec.space/tags/prepaid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>prepaid</span></a> are offered OTC in most juristictions) it's <em>NOT</em> "<a href="https://infosec.space/tags/Anonymous" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Anonymous</span></a>" but merely <em><a href="https://infosec.space/tags/pseudonymous" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pseudonymous</span></a></em> as it's trivial for governments to utilize existing <em>and mandtory "<a href="https://infosec.space/tags/LawfulInterception" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LawfulInterception</span></a>" appliances</em> to create that <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PII</span></a> chain.</p><p><a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumber</span></a> &lt;=&gt; <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> (<a href="https://infosec.space/tags/SIMcard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIMcard</span></a>) &lt;=&gt; <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMSI</span></a> (SIM profile) &lt;=&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> (Phone/...).</p><p>So if <a href="https://infosec.space/tags/Anonymity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Anonymity</span></a> is important, <em>NONE</em> of these details have to be linked somehow even circumstantial.</p><ul><li><p>Bought/paid for the phone/SIM/ a single top-up with ec/CC/PayPal/SEPA/… = busted due to circumstantial connection.</p></li><li><p>Use the SIM in any device? Consider them <em>circumstantially connected</em> forever: <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> &lt;=&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>.</p></li><li><p>Same applies to <a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIM</span></a>|s: <a href="https://infosec.space/tags/EID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EID</span></a> &lt;=&gt; <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> &lt;=&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>.</p></li></ul><p>Add to the fact that most places have <a href="https://infosec.space/tags/CCTV" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CCTV</span></a>, and assume that they'll keep recordings for the <em>maximum permissible duration</em> if not longer and oftentimes even use questionable cloud services and you get the picture.</p><ul><li>I.e. in Germany the maximum permissible storage duration is 72 hours (<em>if nothing hapoens that warrants a longer storage i.e. burglary/theft/robbery/arson/...</em>) so anonymous top-ups would necessitate paying cash at a place one's not been known at (i.e. some kiosk) and waiting at least &gt;72 hours (and checking on the purchase location) before redeeming the top-up code (i.e. dialing <code>*104*1234567890123456#</code> )...</li></ul><p>So any <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a>-based service should <em>never ever &amp; under no circumstances</em> demand a Phone Number!</p><ul><li><p>Instead any privacy-focussed service should use <a href="https://infosec.space/tags/OnionServices" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnionServices</span></a>, host their own <a href="https://infosec.space/tags/OnionService" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnionService</span></a> or at least <a href="https://infosec.space/tags/DontBlockTor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DontBlockTor</span></a> and allow users to use it via <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tor</span></a> to use and signup. (But don't forget circumstantial connections there either!)</p></li><li><p>Also the less details they want or store and the least traffic they generate the harder it is to correlate traffic &amp; users.</p></li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://cloudisland.nz/@xssfox" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>xssfox</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@SnoopJ" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>SnoopJ</span></a></span> <span class="h-card" translate="no"><a href="https://cloudisland.nz/@pjf" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>pjf</span></a></span> really?</p><p>Is <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a> that cyberfacist?</p><ul><li><p>Like I know one's not supposed to have stuff or rather is not allowed to use it <em>for obvious reasons</em> but criminalizing mere possession is just absurd.</p></li><li><p>But then again <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a> also <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>-<a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" target="_blank">banned</a> devices due to <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> mandate and <a href="https://www.youtube.com/watch?v=r2h3iSA-Vac" rel="nofollow noopener" target="_blank">banned</a> <a href="https://www.youtube.com/watch?v=1OwUphqTBSw" rel="nofollow noopener" target="_blank">encrypted devices</a>…</p></li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@stman" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>stman</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@Sempf" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Sempf</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@LaF0rge" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LaF0rge</span></a></span> yes.</p><p>Because physical SIMs, like any <em>"cryptographic chipcard"</em> (i.e. <span class="h-card" translate="no"><a href="https://social.nitrokey.com/@nitrokey" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>nitrokey</span></a></span> ) did all that fancy public/private crypto on silicon and unless that was compromizeable (which AFAICT always necessistated physical access to the <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a>, espechally in pre-<a href="https://infosec.space/tags/OMAPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OMAPI</span></a> devices) the SIM wasn't <em>'cloneable'</em> and the weakest link always had been the <a href="https://infosec.space/tags/MNO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MNO</span></a> /.<a href="https://infosec.space/tags/MVNO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MVNO</span></a> issueing (may it be through <a href="https://infosec.space/tags/SocialHacking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SocialHacking</span></a> employees into <em><a href="https://infosec.space/tags/SimSwapping" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SimSwapping</span></a></em> or LEAs showng up with a warrant and demanding <em>"<a href="https://infosec.space/tags/LawfulInterception" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LawfulInterception</span></a>"</em>):</p><ul><li>These <em>"attack vectors"</em> were known and whilst <em>unfixable</em> they could at least be mitigated by i.e. <em>NEVER</em> using a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumber</span></a> for anything <em>and/or</em> using anonymously obtained <a href="https://infosec.space/tags/SIMs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIMs</span></a>. But more and more services like <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> did <a href="https://infosec.space/tags/regression" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>regression</span></a> demanding <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PII</span></a> <em>and</em> more and more nations <em>criminalized</em> <a href="https://infosec.space/tags/AnonymousSimCards" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AnonymousSimCards</span></a> under utterly <a href="https://infosec.space/tags/cyberfacist" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cyberfacist</span></a> &amp; <a href="https://infosec.space/tags/FalsePretenses" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FalsePretenses</span></a>!</li></ul><p>Add to that the <em>regression</em> in flexibility: </p><p>Unlike a <a href="https://infosec.space/tags/SimCard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SimCard</span></a> which was designed as a <em>vendor-independent, <a href="https://infosec.space/tags/MultiVendor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MultiVendor</span></a>, <a href="https://infosec.space/tags/MultiProvider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MultiProvider</span></a>, device agnostic unit to facilitate the the <a href="https://infosec.space/tags/authentification" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authentification</span></a> and <a href="https://infosec.space/tags/encryption" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>encryption</span></a> in <a href="https://infosec.space/tags/GSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSM</span></a> (and successor standards)</em>, <a href="https://infosec.space/tags/eSIMs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIMs</span></a> act to restrict <a href="https://infosec.space/tags/DeviceFreedom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DeviceFreedom</span></a> and <a href="https://infosec.space/tags/ConsumerChoice" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ConsumerChoice</span></a>, which with shit like <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a> per <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> (i.e. <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> demands it after 90 days of roaming per year) und <a href="https://infosec.space/tags/lMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>lMEI</span></a>-based <a href="https://infosec.space/tags/Allowlisting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Allowlisting</span></a> (see <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a>'s shitty <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> + <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> &amp; <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> shutdown!) are just acts to clamp down on <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> and <a href="https://infosec.space/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a>.</p><ul><li>And with <a href="https://infosec.space/tags/EID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EID</span></a> being unique per <a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIM</span></a> (like the <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> on top!) there's nothing stopping <a href="https://infosec.space/tags/cyberfacist" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cyberfacist</span></a> regimes like <em>"P.R."</em> <a href="https://infosec.space/tags/China" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>China</span></a>, <a href="https://infosec.space/tags/Russia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Russia</span></a>, <a href="https://infosec.space/tags/Iran" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Iran</span></a>, ... from banning <em>"<a href="https://infosec.space/tags/eSIMcards" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIMcards</span></a>"</em> (<a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIM</span></a> in SIM card form factor) or entire device prefixes (i.e. all phones that are supported by <span class="h-card" translate="no"><a href="https://grapheneos.social/@GrapheneOS" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>GrapheneOS</span></a></span> ), as M(V)NOs see the EID used to deploy/activate a profile (obviously they don't want people to activate eSIMs more than once, <em>unless explicitly allowed otherwise</em>.</li></ul><p>"[…] [Technologies] must <em>always</em> be evaluated for their ability to oppress. […] </p><ul><li>Dan Olson</li></ul><p>And now you know why I consider a <a href="https://infosec.space/tags/smartphone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>smartphone</span></a> with eSIM instead of two SIM slots not as a <em>real</em> <a href="https://infosec.space/tags/DualSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DualSIM</span></a> device because it restricts my ability to freely move devices.</p><ul><li>And whilst German Courts reaffirmed §77 TKG (Telco Law)'s mandate to letting people choose their devices freely, (by declarong <a href="https://infosec.space/tags/fees" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fees</span></a> for reissue of eSIMs illegal) that is only <em>enforceable towards M(V)NOs who are in <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Germany</span></a></em>, so <em>'good luck'</em> trying to enforce that against some overseas roaming provider.</li></ul><p>Thus <a href="https://infosec.space/tags/Impersonation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Impersonation</span></a> attacks in GSM-based networks are easier than ever before which in the age of <em>more skilled than ever</em> <a href="https://infosec.space/tags/Cybercriminals" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybercriminals</span></a> and <a href="https://infosec.space/tags/Cyberterrorists" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cyberterrorists</span></a> (i.e. <a href="https://infosec.space/tags/NSA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NSA</span></a> &amp; <a href="https://infosec.space/tags/Roskomnadnozr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Roskomnadnozr</span></a>) puts espechally the average <em><a href="https://infosec.space/tags/TechIlliterate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechIlliterate</span></a> User</em> at risk.</p><ul><li>I mean, anyone else remember the <a href="https://infosec.space/tags/Kiddies" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Kiddies</span></a> that <em>fucked around</em> with <a href="https://infosec.space/tags/CIA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CIA</span></a> director <a href="https://infosec.space/tags/Brennan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Brennan</span></a>? Those were just using their <em>"weapons-grade <a href="https://infosec.space/tags/boredom" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>boredom</span></a>"</em>, not being effective, for-profit cyber criminals!</li></ul><p>And then think about those who don't have <em>privilegued access</em> to <em>protection</em> by their government, but rather <em>"privilegued access" to prosecution</em> by the state <em>because their very existance is criminalized...</em></p> <p>The only advantage eSIMs broight in contrast is <em>'logistical' convenience</em> because it's mostly a <a href="https://infosec.space/tags/QRcode" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>QRcode</span></a> and that's just a way to avoid typos on a cryptic <a href="https://infosec.space/tags/LocalProfileAgent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LocalProfileAgent</span></a> link.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://chaos.social/@LaF0rge" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>LaF0rge</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@sysmocom" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>sysmocom</span></a></span> I do agree on that one.</p><p>The main problem with some mandate in that regard is that such regulations then get flexed against consumers.</p><p>Notable examples are the:</p><ul><li><a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>-Blocking in <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> after 90 days and subsequent demand for <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a> even for <a href="https://infosec.space/tags/Roaming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Roaming</span></a> devices.</li><li><a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a>'s IMEI-Firewall because some morons decided they wanted to axe <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> &amp; <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> despite millions of devices that can't do <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> still being in use.</li></ul><p>Now granted anyone who can manipulate the IMEI can circumvent that but that means 99,9% of all users aka. <em>"<a href="https://infosec.space/tags/TechIlliterates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechIlliterates</span></a>"</em> can't.</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://grapheneos.social/@GrapheneOS" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>GrapheneOS</span></a></span> <span class="h-card" translate="no"><a href="https://fedi.omada.cafe/@fluffery" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fluffery</span></a></span> <span class="h-card" translate="no"><a href="https://chaos.social/@maumau" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>maumau</span></a></span> <span class="h-card" translate="no"><a href="https://social.tchncs.de/@BryanGreyson" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>BryanGreyson</span></a></span> <span class="h-card" translate="no"><a href="https://mas.to/@fairphone" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fairphone</span></a></span> I.e. <span class="h-card" translate="no"><a href="https://mstdn.social/@BrodieOnLinux" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>BrodieOnLinux</span></a></span> could not use any of those because they don't support <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> (not just in <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a>) and thus would be blocked by the <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>-<a href="https://infosec.space/tags/Firewall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Firewall</span></a>!<br><a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=zIJavqEzEIw</span><span class="invisible"></span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://fedifreu.de/@cryptgoat" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>cryptgoat</span></a></span> ja, nur ist es quasi illegal <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> / <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> <a href="https://infosec.space/tags/anonym" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>anonym</span></a> (also faktisch nur <a href="https://infosec.space/tags/pseudonym" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pseudonym</span></a>, weil stets korrelierbar qua <a href="https://infosec.space/tags/Rufnummer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Rufnummer</span></a> -&gt; <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> -&gt; <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMSI</span></a> -&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> -&gt; <a href="https://infosec.space/tags/Location" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Location</span></a>) zu nutzen.</p><ul><li>Seit 07/2017 sind anonyme <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a>-Karten <em>faktisch illegal</em> und ne SIM mir Rufnummer ist ne <a href="https://infosec.space/tags/Paywall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Paywall</span></a> die faktisch teurer ist als nen <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>monocles</span></a></span> - Abo.</li></ul><p>Allein die notwendigen <a href="https://infosec.space/tags/Workarounds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Workarounds</span></a> sind so heftig paywalled dass es eher sinn macht 1h Hands-on - Training zu investieren...</p><ul><li>Von den <a href="https://infosec.space/@kkarhan/114234551915193036" rel="nofollow noopener" target="_blank">Problemen die Signal hat</a> ganz zu schweigen...</li></ul><p><a href="https://fedifreu.de/@cryptgoat/114705198216850106" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fedifreu.de/@cryptgoat/1147051</span><span class="invisible">98216850106</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.social/@derekmorr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>derekmorr</span></a></span> </p><blockquote><p>Let it go, already. No one uses MobileCoin. You can’t even find an exchange to buy it.</p></blockquote><p>Then why does <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> still have that shit in it? <span class="h-card" translate="no"><a href="https://mastodon.world/@Mer__edith" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Mer__edith</span></a></span> could've pulled that <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Shitcoin</span></a> yet refuses to do do!</p><blockquote><p>The Cloud Act is a non-issue. Signal doesn’t have data on users, so they can’t be forced to disclose it.</p></blockquote><p>That's literally wrong!</p><ul><li><a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> not only collects <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PII</span></a> in the form of a <a href="https://infosec.space/tags/PhoneNumher" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumher</span></a> but explicitly is <em>able and willing</em> to use that to dsicriminate against users and restrict app functionality based off their presumed juristiction. There is no <em>"legitimate interest"</em> for.doing so nor any legal mandate to do so (unless we excuse the ehole <a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MobileCoin</span></a>-<a href="https://infosec.space/tags/Scam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Scam</span></a>!)</li></ul><blockquote><p>It’s been 30 years, and no one uses xmpp. Let it go.</p></blockquote><p>Wrong again. Otherwise there wouldn't be thriving ecosystems and Apps to this day. It's just that corporate shills refuse to acknowledge that Signal - like all centralized, proprietary, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleVendor</span></a> and/or <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleProvider</span></a> kessengers before and after - will inevitably die as their business model is not sustainable. Sake with <a href="https://infosec.space/tags/ICQ" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICQ</span></a> really. The only exceptions are those that abolish <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> for <a href="https://infosec.space/tags/profit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>profit</span></a>, integrate <em>actually working payments</em> or sellout to a <a href="https://infosec.space/tags/cyberfacist" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cyberfacist</span></a> <a href="https://infosec.space/tags/government" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>government</span></a> (all those apply to <a href="https://infosec.space/tags/WeChat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WeChat</span></a>!)</p><blockquote><p>It’s shocking that people who claim to care about security and privacy push niche apps with terrible UX and no PFS like Delta or XMPP instead of the only private messenger with any real market share, Signal.</p></blockquote><p>You know what's shocking to me: People who are unable or rather unwilling.to acknowledge that Signal is garbage and it's requirement for a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumber</span></a> kills any <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> benefits it may have on paper by virtue of being at best pseudonymous (assuming the userd don't live in a juristiction that demands <em>"<a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a>"</em> for even prepaid <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a> cards (ime. <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Germany</span></a>) or god forbid even <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>|s (i.e. <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> has a literal allowlist that'll kick any device off it's MNOs after 90 days within 365 days.</p><ul><li>The <a href="https://infosec.space/tags/UScentric" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UScentric</span></a> approach to <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> and <a href="https://infosec.space/tags/threats" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>threats</span></a> makes Signal absolutely useless in many cases, and I do speak here from experience. </li></ul><p>I'd rather help people onboard <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OMEMO</span></a> like <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>monocles</span></a></span> and/or <span class="h-card" translate="no"><a href="https://fosstodon.org/@gajim" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>gajim</span></a></span> or <a href="https://infosec.space/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a>/MIME like <span class="h-card" translate="no"><a href="https://chaos.social/@delta" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>delta</span></a></span> &amp; <span class="h-card" translate="no"><a href="https://mastodon.online/@thunderbird" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>thunderbird</span></a></span> (incl. setting them up with <a href="https://infosec.space/tags/Orbot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Orbot</span></a> / <a href="https://infosec.space/tags/TorBrowserBundle" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TorBrowserBundle</span></a> / <span class="h-card" translate="no"><a href="https://venera.social/profile/tails_live" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tails_live</span></a></span> so their traffic gets through <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> and doesn't provide any useable IP addresses. </p><ul><li><em>I've literally been there and done that!</em></li></ul><p>As for <a href="https://infosec.space/tags/Sustainability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sustainability</span></a>, providers like <a href="https://monocles.eu" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">monocles.eu</span><span class="invisible"></span></a> finance themselves by subscriptions (starting at €2 p.m.) which people can pay <em>fully anonymous</em> using <a href="https://infosec.space/tags/CashByMail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CashByMail</span></a> and <a href="https://infosec.space/tags/Monero" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Monero</span></a> on top of common payment methods (i.e. SEPA wire transfer)...</p><ul><li>So even if you think <em>"<a href="https://infosec.space/tags/monocles" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>monocles</span></a> is a <a href="https://infosec.space/tags/honeypot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>honeypot</span></a>"</em> that is mitigateable ciz unlike with Signal you can <em>choose your own client, choose a different provider &amp; exervise self-custody of all tue keys!</em></li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@n_dimension" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>n_dimension</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@shaknais" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>shaknais</span></a></span> <span class="h-card" translate="no"><a href="https://beige.party/@maxleibman" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>maxleibman</span></a></span> what kind of facist policestate has it become?</p><ul><li>Oh nevermind, having an encrypted phone or using secure communications is also illegal, I guess... [1 - 5]</li></ul><p>And to enshure <em>"criminals"</em> can't just order something on ShitExpress, they now have an <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>-<a href="https://infosec.space/tags/Allowlisting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Allowlisting</span></a> / <a href="https://infosec.space/tags/Firewall" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Firewall</span></a> <a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" target="_blank">in place</a> that makes the <a href="https://infosec.space/tags/Turkish" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkish</span></a> Registration Demands look chill in comparison, [6 - 10] cuz they only yeet devices after 90 days and not <em>preemtively block them from any network!</em></p><ul><li>This wouldn't be such a proplem if Australia was like Germany where the furthest doctor away is 1hr by bike and the worst one could get is a bite from a rabid fox and having to get some post-exposure shots. So yeah tourists are not gonna be able to call for help in down under... </li></ul><p>Seriously, whoever came up with these ideas needs to touch grass, preferablzyin the outback on foot!</p><p><a href="https://www.wired.com/story/australia-encryption-law-global-impact/" rel="nofollow noopener" target="_blank">1</a> <a href="https://www.aljazeera.com/news/2022/4/5/australias-dangerous-encryption-law-in-works-in-2015-document" rel="nofollow noopener" target="_blank">2</a> <a href="https://astorlegal.com.au/are-cipher-phones-illegal-in-australia/" rel="nofollow noopener" target="_blank">3</a> <a href="https://www.kingstonfox.com.au/articles/what-are-dedicated-encrypted-criminal-communication-device-prohibition-orders" rel="nofollow noopener" target="_blank">4</a> <a href="https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications/data-encryption" rel="nofollow noopener" target="_blank">5</a> <a href="https://istanbul.tips/detailed-manual-on-how-to-unlock-imei-in-turkey/" rel="nofollow noopener" target="_blank">6</a> <a href="https://www.mcks.gov.tr/en/registration-and-matching" rel="nofollow noopener" target="_blank">7</a> <a href="https://ico.ku.edu.tr/resources/registering-mobile-phones/" rel="nofollow noopener" target="_blank">8</a> <a href="https://expatguideturkey.com/how-can-foreigners-register-imei-in-turkey/" rel="nofollow noopener" target="_blank">9</a> <a href="https://www.vartur.com/avoid-penalties-register-your-mobile-phone-in-turkey" rel="nofollow noopener" target="_blank">10</a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mstdn.jp/@landley" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>landley</span></a></span> <span class="h-card" translate="no"><a href="https://mstdn.social/@jschauma" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>jschauma</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@ryanc" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ryanc</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@0xabad1dea" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>0xabad1dea</span></a></span> yeah, the exhaustion problem would've been shoved back with a <a href="https://infosec.space/tags/64bit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>64bit</span></a> or sufficiently delayed by a 40bit number.</p><p>Unless we also hate <a href="https://infosec.space/tags/NAT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NAT</span></a> and expect every device to have a unique static <a href="https://infosec.space/tags/IP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IP</span></a> (which is a <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> nightmare at best that <em>"<a href="https://infosec.space/tags/PrivacyExtensions" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PrivacyExtensions</span></a>"</em> barely fixed.) </p><ul><li>I mean they could've also gone the <a href="https://infosec.space/tags/DECnet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DECnet</span></a> approach and use the <a href="https://infosec.space/tags/EUI48" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EUI48</span></a> / <a href="https://infosec.space/tags/MAC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MAC</span></a>-Address (or <a href="https://infosec.space/tags/EUI64" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EUI64</span></a>) as static addressing system, but that would've made <a href="https://infosec.space/tags/vendors" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vendors</span></a> and not <a href="https://infosec.space/tags/ISPs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ISPs</span></a> the powerful forces of allocation. (Similar to how technically the <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> dictates <a href="https://infosec.space/tags/GSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSM</span></a> / <a href="https://infosec.space/tags/4G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>4G</span></a> / <a href="https://infosec.space/tags/5G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>5G</span></a> access and not the <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> unless places like Australia ban imported devices.</li></ul> <p>I guess using a <a href="https://infosec.space/tags/128bit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>128bit</span></a> address space was inspired by <a href="https://infosec.space/tags/ZFS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ZFS</span></a> doing the same <em>before</em>, as the folks who designed both wanted to design a solution that clearly will outlive them (<em>way harder</em> than COBOL has outlived Grace Hopper)...</p><ul><li>Personally I've only had headaches with <a href="https://infosec.space/tags/IPv6" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPv6</span></a> because not only do I only have <a href="https://infosec.space/tags/IPv4only" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPv4only</span></a> <a href="https://infosec.space/tags/Internet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Internet</span></a> but my <a href="https://infosec.space/tags/ISP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ISP</span></a> refuses to allocate even a singe /64 to me (but has no problem throwing in a free /29 of <a href="https://infosec.space/tags/IPv4" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IPv4</span></a>'s in with my contract!)and stuff like <a href="https://infosec.space/tags/HurricaneElectric" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HurricaneElectric</span></a> / <a href="https://infosec.space/tags/HEnet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HEnet</span></a>'s <a href="https://infosec.space/tags/Tunnelbroker" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tunnelbroker</span></a> fail face first due to <a href="https://infosec.space/tags/Geoblocking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Geoblocking</span></a> and the fact that <a href="https://infosec.space/tags/ASNs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ASNs</span></a> get geolocated, not their <a href="https://infosec.space/tags/PoPs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PoPs</span></a>... </li></ul><p>If I was <span class="h-card" translate="no"><a href="https://social.bund.de/@BNetzA" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>BNetzA</span></a></span> I would've mandated <a href="https://infosec.space/tags/DualStack" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DualStack</span></a> and banned <a href="https://infosec.space/tags/CGNAT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CGNAT</span></a> (or at least the use of CGNAT in <a href="https://infosec.space/tags/RFC1918" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RFC1918</span></a> address spaces) as well as <a href="https://infosec.space/tags/DualStackLite" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DualStackLite</span></a>!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@bob_zim" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bob_zim</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@micahflee" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>micahflee</span></a></span> <span class="h-card" translate="no"><a href="https://social.heise.de/@heiseonline" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>heiseonline</span></a></span> <span class="h-card" translate="no"><a href="https://squeet.me/profile/golem" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>golem</span></a></span> Makes sense.</p><ul><li>After all, the whole <a href="https://infosec.space/tags/IMSIcatcher" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMSIcatcher</span></a> system can be detected by passive <a href="https://infosec.space/tags/SIGINT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIGINT</span></a> as it's an active attack on mobile networks.</li></ul><p>I wounder if I can get a compatible device in <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Germany</span></a> as well...</p><ul><li>Bonis points if that device has a freely reprogrammable <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> to allow hiding it's <a href="https://github.com/greyhat-academy/lists.d/blob/main/imei.devices.list.tsv" rel="nofollow noopener" target="_blank">identity</a>.</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.nz/@phlogiston" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>phlogiston</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> <span class="h-card" translate="no"><a href="https://social.librem.one/@guardianproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>guardianproject</span></a></span> at least <span class="h-card" translate="no"><a href="https://social.bund.de/@BNetzA" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>BNetzA</span></a></span> &amp; <span class="h-card" translate="no"><a href="https://social.bund.de/@Bundesregierung" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Bundesregierung</span></a></span> didn't cancel <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> / <a href="https://infosec.space/tags/GSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSM</span></a> / <a href="https://infosec.space/tags/EDGE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EDGE</span></a> with the <a href="https://infosec.space/tags/3Gshutdown" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3Gshutdown</span></a> like <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a> did recently.</p><ul><li>Seriously, the Ozzies <a href="https://infosec.space/@kkarhan/113866074599066600" rel="nofollow noopener" target="_blank">mandate</a> <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> and literally block <a href="https://infosec.space/tags/ImportPhones" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ImportPhones</span></a> based off <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://possum.city/@tauon" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>tauon</span></a></span> </p><p>1) <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudAct</span></a> is just <a href="https://infosec.space/tags/CyberFacism" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberFacism</span></a>, look it up!<br><a href="https://en.wikipedia.org/wiki/CLOUD_Act" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">en.wikipedia.org/wiki/CLOUD_Act</span><span class="invisible"></span></a></p><ul><li>And with <a href="https://infosec.space/tags/Trumpism" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Trumpism</span></a> ravaging the <a href="https://infosec.space/tags/USA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>USA</span></a> must be considered as <a href="https://infosec.space/tags/hostile" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hostile</span></a> as <a href="https://infosec.space/tags/Russia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Russia</span></a> and the <em>"P.R."</em> <a href="https://infosec.space/tags/China" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>China</span></a> by anyone who takes <a href="https://infosec.space/tags/OpSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpSec</span></a>, <a href="https://infosec.space/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> &amp; <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a> seriously!</li></ul><p>-</p><p>2) <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> 's <a href="https://infosec.space/tags/Server" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Server</span></a> code is proprietary and since it's centralized we can't trust that the code they release is what's running on their backend! </p><ul><li>Plus their <a href="https://infosec.space/tags/App" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>App</span></a> doesn't allow <a href="https://infosec.space/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a> (if Signal was <a href="https://infosec.space/tags/FLOSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FLOSS</span></a> it would be on <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fdroidorg</span></a></span> / <a href="https://infosec.space/tags/Fdroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fdroid</span></a>) but alas it isn't!</li></ul><p>-</p><p>3) <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> still demands <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumbers</span></a> which are <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PII</span></a> either by association (<a href="https://infosec.space/tags/Number" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Number</span></a> =&gt; <a href="https://infosec.space/tags/ICCID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ICCID</span></a> = <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a> = <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMSI</span></a> =&gt; <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> =&gt; Location Data <a href="https://infosec.space/@kkarhan/113467346741876822" rel="nofollow noopener" target="_blank">as I explained before</a><a href="https://infosec.space/@kkarhan/113878565911126519" rel="nofollow noopener" target="_blank">twice</a>) or mandatory <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a> / <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ID</span></a> requirements (even on prepaid cards), which an increasing amount of juristictions <em>do</em>...</p><ul><li>They have no <em>"<a href="https://infosec.space/tags/LegitimateInterest" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LegitimateInterest</span></a>"</em> demanding said <a href="https://infosec.space/tags/PersonallyIdentifyingInformation" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PersonallyIdentifyingInformation</span></a> to begin with! </li></ul><p>-</p><p>But don't take my word for it.<br><a href="https://www.youtube.com/watch?v=tJoO2uWrX1M" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=tJoO2uWrX1M</span><span class="invisible"></span></a></p><ul><li>Ask yourself if you'd trust someone <a href="https://www.youtube.com/watch?v=0DSGq9FQKU4" rel="nofollow noopener" target="_blank">peddlibg</a> <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Shitcoin</span></a> <a href="https://infosec.space/tags/Scams" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Scams</span></a> like <a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MobileCoin</span></a> with your data!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://hachyderm.io/@lucasmz" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>lucasmz</span></a></span> <span class="h-card" translate="no"><a href="https://ioc.exchange/@Avitus" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Avitus</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@david_chisnall" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>david_chisnall</span></a></span> the benefit of <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OMEMO</span></a> is that there are <a href="https://github.com/greyhat-academy/lists.d/blob/main/xmpp.servers.list.tsv" rel="nofollow noopener" target="_blank"><em>several providers</em>, including free options</a>...</p><ul><li><span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>monocles</span></a></span> also supports <a href="https://infosec.space/tags/Monero" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Monero</span></a> and <a href="https://infosec.space/tags/CashByMail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CashByMail</span></a> for those that can't use <a href="https://infosec.space/tags/PayPal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PayPal</span></a>, <a href="https://infosec.space/tags/Stripe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Stripe</span></a> or <a href="https://infosec.space/tags/SEPA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SEPA</span></a>.</li></ul><p>All <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PII</span></a> incl. <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumbers</span></a> can and will be abused by existing governments and <em>if users don't pay, then they are the product and their data is the one to be sold</em>.</p><ul><li><a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a> <em>IS</em> THE <a href="https://infosec.space/tags/IllicitActivity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IllicitActivity</span></a> WHEN IT COMES TO <a href="https://infosec.space/tags/ComSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ComSec</span></a>!</li></ul><p>After all, you have the same <em>cost problem</em> with phone numbers. Even if one doesn't pay per line/number and never pay for calls and texts, they still have to top it up to extent validity.</p><ul><li>And again: It's way easier for a government to demand an ID for a <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a> that works in networks around their country (i.e. <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> demands registration on a per-<a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> - basis *with <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ID</span></a>) than to tunnel XMPP+OMEMO through <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> over <a href="https://infosec.space/tags/EDGEland" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EDGEland</span></a>-speed <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> networks.</li></ul><p>Plus you relying an <em>unfixably insecure</em> <a href="https://infosec.space/tags/Telephony" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Telephony</span></a> makes a system inherently unsafer than it needs to be...</p><ul><li>This is how people get caught!</li></ul><p>Also <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> is <em>able and willing</em> to use said PII to <em>restrict and ban users</em> and if I were some dissident in Cuba or North Korea or even just Eritrea or Yemen I'd not rely on non-enforcement of <a href="https://infosec.space/tags/OFAC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OFAC</span></a> / <a href="https://infosec.space/tags/USML" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>USML</span></a> / <a href="https://infosec.space/tags/ITAR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ITAR</span></a> since Signal can obviously distinguish &amp; identify accounts by virgue if their <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumber</span></a>! </p><ul><li>Always think <em>"How can this be weaponized against someone?"</em> when it comes to <a href="https://infosec.space/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a>!</li></ul>
Kevin Karhan :verified:<p>And don't even get me started on <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> <a href="https://www.youtube.com/watch?v=Q6qb9dml6So" rel="nofollow noopener" target="_blank">support</a>...</p><ul><li>Like <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a> had <em>the glorious idea</em> of shutting down <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> <em>AND</em> <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> as well as <em><a href="https://infosec.space/tags/allowlisting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>allowlisting</span></a></em> <a href="https://www.youtube.com/watch?v=RPlTz-3estM" rel="nofollow noopener" target="_blank">only specific</a> <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>|s, <a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" target="_blank">banning &gt; 500k devices</a> for no good reason.</li></ul><p>Also <em>most</em> <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> / <a href="https://infosec.space/tags/Vo5G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Vo5G</span></a> - devices *explicitly use <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> / <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> for <a href="https://infosec.space/tags/EmergencyCalls" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmergencyCalls</span></a>!</p><ul><li>Which is <em><a href="https://infosec.space/tags/funfuckingtastic" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>funfuckingtastic</span></a></em> in a place like Australia where <em>basically everything in nature conspires to hurt or kill humans</em>!</li></ul><p><a href="https://infosec.space/tags/DownUnder" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DownUnder</span></a> <a href="https://infosec.space/tags/AUSpol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AUSpol</span></a> <a href="https://infosec.space/tags/AUpol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AUpol</span></a> <a href="https://infosec.space/tags/tech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tech</span></a> <a href="https://infosec.space/tags/2Gshutdown" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2Gshutdown</span></a> <a href="https://infosec.space/tags/3Gshutdown" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3Gshutdown</span></a> <a href="https://infosec.space/tags/EmergencyCalling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmergencyCalling</span></a></p>
Kevin Karhan :verified:<p>[<a href="https://infosec.space/tags/TLDR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TLDR</span></a>: JUST TELL ME <em>IF</em> YOUR TABLET CAN DO <a href="https://infosec.space/tags/CALLS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CALLS</span></a>!]</p><p><a href="https://infosec.space/tags/DearVendors" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DearVendors</span></a> of <a href="https://infosec.space/tags/Android" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Android</span></a>-<a href="https://infosec.space/tags/Tablets" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tablets</span></a>:</p><p>Off all the <a href="https://infosec.space/tags/Functions" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Functions</span></a> you can put into a <a href="https://infosec.space/tags/Specifications" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Specifications</span></a> Sheet of your Devices there's one you should <em>ALWAYS answer clearly</em> on your <a href="https://infosec.space/tags/Website" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Website</span></a>:</p><p><em>DOES YOUR TABLET [with <a href="https://infosec.space/tags/4G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>4G</span></a> / <a href="https://infosec.space/tags/5G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>5G</span></a> / …) SUPPORT MAKING PHONE CALLS?</em></p><ul><li><p><em>NOT</em> "It can run <a href="https://infosec.space/tags/WhatsApp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WhatsApp</span></a>" (or <em>whatever shitty <a href="https://infosec.space/tags/CCSS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CCSS</span></a> for <a href="https://infosec.space/tags/VoIP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoIP</span></a></em> you think of)...</p></li><li><p><em>NOT</em> "It can do <a href="https://infosec.space/tags/CSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CSD</span></a> / <a href="https://infosec.space/tags/HSCSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HSCSD</span></a> / <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> / <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> /..."</p></li><li><p><em>But</em> DOES IT SUPPORT <a href="https://infosec.space/tags/GSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSM</span></a>-<a href="https://infosec.space/tags/Calls" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Calls</span></a> (and/or <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a>)??</p></li></ul><p>Like: <em>IS IT TOO MUCH TO ASK TO HAVE THAT INFO IN THE SPECSHEETS?</em></p><p>You're obviously able to list all the <a href="https://infosec.space/tags/Codecs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Codecs</span></a> natively supported and the user-available storage as well as supported Frequency Bands, WWAN modes, WiFi channel width and the Display Glass vs. Panel dimensions including DPI of the latter and whether or not it has a hall effect sensor to detect your overpriced 1st party tablet covers!</p><p>Now some folks may ask: <em>"WHY does this matter?"</em> or outright dismiss this as a problem.</p><p>Listen: <br>Not everyone is able or willing to carry <em>two</em> devices when 1 <em>SHOULD BE ENOUGH</em> and also some places (i.e. <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a>) have <a href="https://infosec.space/tags/ImportRestrictions" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ImportRestrictions</span></a> re: <a href="https://infosec.space/tags/MobileDevices" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MobileDevices</span></a>, so having more than 1 <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> is already a <em>"NOPE!"</em> by the authorities.</p><ul><li>Also this isn't something one can <em>"fix"</em> post-purchase like installing <a href="https://infosec.space/tags/VLC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VLC</span></a> to decode some obscure file format in Software: Either <em>the <a href="https://infosec.space/tags/Baseband" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Baseband</span></a> and <a href="https://infosec.space/tags/ROM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ROM</span></a> support <a href="https://infosec.space/tags/PhoneCalls" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneCalls</span></a> or they don't!</em></li></ul><p>So why do <em>NONE</em> of the <a href="https://infosec.space/tags/Tablet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tablet</span></a> manufacturers allow to <a href="https://infosec.space/tags/search" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>search</span></a> or <a href="https://infosec.space/tags/filter" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>filter</span></a> for that???</p><ul><li>Bonus points if you have lazy fucks like <a href="https://infosec.space/tags/HMD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HMD</span></a> (aka. <a href="https://infosec.space/tags/Nokia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nokia</span></a>) who literally copy the <a href="https://infosec.space/tags/Safety" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Safety</span></a> &amp; <a href="https://infosec.space/tags/Useage" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Useage</span></a> information for all <a href="https://infosec.space/tags/Smartphones" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Smartphones</span></a> and <a href="https://infosec.space/tags/Tablets" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tablets</span></a> and don't even bother to change <em>"Mobile Phone"</em> for <em>"Tablet"</em>.</li></ul><p><em>NO</em>, instead one has to download an <em>obscenely huge <a href="https://infosec.space/tags/PDF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PDF</span></a></em> just to then <a href="https://downloadcenter.samsung.com/content/UM/202410/20241010132004137/SM-X11X_X21X_UM_Open_UU_Ger_Rev.1.2_240925.pdf" rel="nofollow noopener" target="_blank">read on page 34</a> that for any <em>"<a href="https://infosec.space/tags/telephony" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>telephony</span></a>"</em> function you <em>NEED YET ANOTHER DEVICE FROM THE SAME MANUFACTURER AND HAVE TO SIGNUP WITH AN ACCOUNT</em> and even that level of <a href="https://infosec.space/tags/abuse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>abuse</span></a> WON'T GUARANTEE THAT IT WORKS...</p><ul><li>I mean, come on, this <em>ain't</em> some <em>obscure functionality</em> like <a href="https://infosec.space/tags/OMAPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OMAPI</span></a> to do some <em>"evil sourcery"</em> like <em>managing an <a href="https://infosec.space/tags/eSIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eSIM</span></a> that is in a <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a>-Card form factor</em>!</li></ul><p>Pretty shure <em>A LOT</em> of other folks have the same question and ain't willing to get <em>yet another device &amp; <a href="https://infosec.space/tags/SIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SIM</span></a></em> just to recieve <em>the occasional call</em> because <a href="https://infosec.space/tags/TechIlliterates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechIlliterates</span></a> can't be assed to send an <a href="https://infosec.space/tags/eMail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>eMail</span></a> or learn <a href="https://infosec.space/tags/XMPP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>XMPP</span></a>+<a href="https://infosec.space/tags/OMEMO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OMEMO</span></a> to message one...</p><ul><li>Obviously they same manufacturers are <em>able and willing</em> to specify <em>f-stops</em> of the built-in cameras and list <em>EVERY SINGLE <a href="https://infosec.space/tags/WEARABLE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WEARABLE</span></a></em> they made and certify as <em>'compatible'</em> with, as if <em>anyone</em> is gonna take their non-<a href="https://infosec.space/tags/waterproof" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>waterproof</span></a> <a href="https://infosec.space/tags/Tablet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tablet</span></a> for a marathon or god forbid triathlon...</li></ul><p><a href="https://infosec.space/tags/Rant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Rant</span></a> <a href="https://infosec.space/tags/TechSupport" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechSupport</span></a> <a href="https://infosec.space/tags/Technology" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Technology</span></a> <a href="https://infosec.space/tags/Support" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Support</span></a> <a href="https://infosec.space/tags/Sysadmin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sysadmin</span></a> <a href="https://infosec.space/tags/Procurement" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Procurement</span></a> <a href="https://infosec.space/tags/IT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IT</span></a> <a href="https://infosec.space/tags/SpecSheet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SpecSheet</span></a> <a href="https://infosec.space/tags/Tech" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tech</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://infosec.space/@ada" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>ada</span></a></span> yeah, but then again Oz is ruled by <a href="https://infosec.space/tags/TechIlliterate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechIlliterate</span></a> <a href="https://infosec.space/tags/Wankers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Wankers</span></a> who decided to not only shutdown both <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> &amp; <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> but <a href="https://www.youtube.com/watch?v=RPlTz-3estM" rel="nofollow noopener" target="_blank">literally</a> <a href="https://infosec.space/tags/ban" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ban</span></a> <a href="https://infosec.space/tags/importPhones" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>importPhones</span></a> and basically lock-out any device that desn't do <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a> <em>their way</em>...</p><p>And yes, they enforce that like <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> enforces people to register imported devices 30 days after import:</p><ul><li><a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" target="_blank">With</a> an <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> - <a href="https://infosec.space/tags/BanList" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BanList</span></a>!</li></ul><p>So if you are i.e. a <a href="https://infosec.space/tags/Tourist" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tourist</span></a> in <a href="https://infosec.space/tags/DownUnder" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DownUnder</span></a> and you got some serious issue, you can't even call their emergency services on 000 cuz your devices got yeeted off the network through no fault of your own!</p>
Kevin Karhan :verified:<p>Seriously, <a href="https://infosec.space/tags/Australia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Australia</span></a>'s <a href="https://infosec.space/tags/2G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2G</span></a> &amp; <a href="https://infosec.space/tags/3G" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3G</span></a> <a href="https://infosec.space/tags/Shutdown" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Shutdown</span></a> <a href="https://www.youtube.com/watch?v=zIJavqEzEIw" rel="nofollow noopener" target="_blank">and</a> <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a>-based <a href="https://infosec.space/tags/Blocklisting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Blocklisting</span></a> <em>WILL inevitably kill people</em> </p><p>And the only <em>"tool"</em> there is is <a href="https://infosec.space/tags/Telstra" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Telstra</span></a>'s <a href="https://www.telstrawholesale.com.au/3G-Network-Closure-Blocked-Devices-Checker.html" rel="nofollow noopener" target="_blank">Website</a> and just <a href="https://github.com/greyhat-academy/lists.d/blob/main/imei.devices.list.tsv" rel="nofollow noopener" target="_blank">teting random IMEIs</a> only yields two possible results:</p><ol><li><p><em>'We don't know this device at all'</em></p></li><li><p>"'We've not blocklisted it'*</p></li></ol><p>Even when testing it with obvious <a href="https://infosec.space/tags/2Gonly" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>2Gonly</span></a> &amp; <a href="https://infosec.space/tags/3Gonly" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>3Gonly</span></a> devices that certainly don't support <a href="https://infosec.space/tags/VoLTE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VoLTE</span></a>... </p><p><a href="https://infosec.space/tags/GreatFirewallOfAustralia" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GreatFirewallOfAustralia</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://labyrinth.zone/users/halva" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>halva</span></a></span> <span class="h-card" translate="no"><a href="https://a.bloodyno.se/users/lynn" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>lynn</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>signalapp</span></a></span> <span class="h-card" translate="no"><a href="https://tech.lgbt/@deilann" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>deilann</span></a></span> </p><p>The problem is one needs to literally acquire a phone number and have access to it, and the demand of a phone number itself is bad. This makes it unnecessarily complex and expensive compared to using <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>monocles</span></a></span> / <a href="https://infosec.space/tags/monoclesChat" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>monoclesChat</span></a>. <br>(Cuz if I've to pay to communicate, I might just choose a provider that isn't a <a href="https://infosec.space/tags/VC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VC</span></a> <a href="https://infosec.space/tags/MoneyBurningParty" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MoneyBurningParty</span></a> but a long-term sustainable solution based off <a href="https://infosec.space/tags/OpenStandards" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenStandards</span></a>!)</p><ul><li>I'm sorry for your location. My sincere condolences!</li></ul><p>Still, <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> doesn't allow <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SelfCustody</span></a> of all the keys &amp; <a href="https://infosec.space/tags/SelfHosting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SelfHosting</span></a>, which makes it vulnerable as a <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>proprietary</span></a> <a href="https://infosec.space/tags/centralized" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>centralized</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleVendor</span></a> &amp; <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SingleProvider</span></a> solution.</p><ul><li>Just because <span class="h-card" translate="no"><a href="https://mastodon.world/@Mer__edith" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Mer__edith</span></a></span> isn't having <a href="https://infosec.space/tags/Roskonmadnozr" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Roskonmadnozr</span></a> pointing a gun at her head doesn't mean <a href="https://web.archive.org/web/20220112020000/https://twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener" target="_blank">she'd risk jail for a user</a> when push comes to shove.</li></ul><p>And with <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudAct</span></a> on one hand and <a href="https://infosec.space/tags/Trump" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Trump</span></a> wanting to <em>"Speedrun Hitler"</em>, I'd not rely on Signal.</p><ul><li>The <em>"Metadata"</em> <a href="https://infosec.space/tags/FUD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FUD</span></a> is just a marketing bs because Signal <em>will comply</em> with warrants, whereas nothing prevents me from buying a Thin client, setting up an <a href="https://infosec.space/tags/OnionService" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnionService</span></a> to tunnel everything over <span class="h-card" translate="no"><a href="https://mastodon.social/@torproject" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>torproject</span></a></span> / <a href="https://infosec.space/tags/Tor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Tor</span></a> and rig it to disconnect power if tampered with or upon command.</li></ul><p>I have setup comms for critical operations (incl. helping people flee Russia!) and I'd rather choose <a href="https://infosec.space/tags/OnionShare" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OnionShare</span></a> over <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Signal</span></a> if <a href="https://infosec.space/tags/Metadata" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Metadata</span></a> is a real concern.</p><ul><li>Internet Access, even in <em>"P.R."</em> <a href="https://infosec.space/tags/China" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>China</span></a>, is something feasible to workout given the massive prevalence of public <a href="https://infosec.space/tags/WiFi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WiFi</span></a>. Also it's easier to spoof/anonymize a MAC than an <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> or even <a href="https://infosec.space/tags/IMSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMSI</span></a>, so making one dependent on <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PhoneNumbers</span></a> to even sign up is inherently bad!</li></ul>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mastodon.au/@quokka1" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>quokka1</span></a></span> <span class="h-card" translate="no"><a href="https://grapheneos.social/@GrapheneOS" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>GrapheneOS</span></a></span> I sincerely doubt the <a href="https://infosec.space/tags/regulators" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>regulators</span></a> will do much about it and I assume that like with <a href="https://infosec.space/tags/Turkey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Turkey</span></a> (aka. <a href="https://infosec.space/tags/T%C3%BCrkiye" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Türkiye</span></a>):</p><p>Restricted imports of one Device (as per IMEI!!!) per person and year (every entry is counted even if you leave with the device!) and automatically bans them after 30 days of <a href="https://infosec.space/tags/Roaming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Roaming</span></a> across all networks until one <a href="https://infosec.space/tags/KYC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>KYC</span></a>'s with a Turkish National ID at a <a href="https://infosec.space/tags/T%C3%BCrkcell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Türkcell</span></a> Store in person results in a literal <em>"<a href="https://infosec.space/tags/BlackMarket" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BlackMarket</span></a>" for domestically sold, cheap prepaid phones by said carriers</em> just to take their <a href="https://infosec.space/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> and flash it onto the <a href="https://infosec.space/tags/Baseband" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Baseband</span></a> of an <a href="https://infosec.space/tags/imported" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>imported</span></a> <a href="https://infosec.space/tags/Smartphone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Smartphone</span></a> to circumvent that garbage.</p><ul><li>Basically the inverse of what people do in places like <a href="https://infosec.space/tags/Thailand" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Thailand</span></a> and <a href="https://infosec.space/tags/Germany" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Germany</span></a> where KYC is mandated even for <a href="https://infosec.space/tags/Prepaid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Prepaid</span></a> cards and they just import a SIM from neighbouring countries.</li></ul>
Debacle<p>I don't plan to do that, but I'm curious: Can users change the <a href="https://framapiaf.org/tags/IMEI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IMEI</span></a> of their <a href="https://framapiaf.org/tags/PinePhone" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PinePhone</span></a> using <a href="https://framapiaf.org/tags/Mobian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Mobian</span></a>?</p><p>Also: What happens (if anything), if multiple devices in the <a href="https://framapiaf.org/tags/mobile" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mobile</span></a> network show up with the same IMEI?</p><p>And: What happens to a user who accidently sets their IMEI to the same as one of those people? 😉</p><p><a href="https://eumostwanted.eu/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">eumostwanted.eu/</span><span class="invisible"></span></a></p><p><a href="https://framapiaf.org/tags/EU" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EU</span></a> <a href="https://framapiaf.org/tags/Europol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Europol</span></a> <a href="https://framapiaf.org/tags/ENFAST" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ENFAST</span></a> <a href="https://framapiaf.org/tags/MostWanted" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MostWanted</span></a> <a href="https://framapiaf.org/tags/mobileLinux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mobileLinux</span></a> <a href="https://framapiaf.org/tags/GSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GSM</span></a></p>