SamSuka
The Hated One
The Hated One

patreon


Episode 058 - Can you become invisible?

Links

Linddun: https://www.linddun.org/

About Linddun: https://www.linddun.org/linddun

Download Linddun Go tutorial here: https://www.linddun.org/_files/ugd/cc602e_f98d9a92e4804e6a9631104c02261e1f.pdf

Download Linddun Go cards here: https://www.linddun.org/_files/ugd/cc602e_cf7e4c6b1d894bdaabc3094c48b26869.pdf

Episode 058 - Can you become invisible?

Comments

Really enjoyed this podcast. In regards to repudiation and non-repudiation with mobile carriers (i.e, AT&T, Verizon, etc.) there is no way to deny/obfuscate your actions on their mobile network (e.g., calls, SMS text messages, etc.) and/or its relevant metadata (date and time of the event, etc.) because your IMEI and IMSI is unique to each user on the network and required to use their network. Not to mention your location at the time of the data event. Options For Better Privacy and non-Repudiation? 1 - Don't install a SIM card in your phone or use it for voice calls. You are not on the network and therefore no events will be recorded and linked to you. However, you also are not able to make or receive untrusted voice calls. You could use an app like Signal that was created with a burner phone number to make end-to-end encrypted calls with your trusted contacts only. Most people need the ability to make outgoing calls and receive incoming calls from a variety of sources. 2 - In order to receive and make voice calls to non-Signal users such as businesses, your doctor, ordering pizza, or anyone that can't or doesn't have signal, then you will have less privacy and give up your ability for non-repudiation. But, is there a reasonable way to make and receive calls knowing the cost to your privacy and inability to repudiate the call event? Option 1 - Use a GrapheneOS phone and enable LTE mode to make your location less accurate and lower your risk of known attacks that downgrade your signal to 3G/26. However, your carrier has all the metadata about the call event and there is no way around this. The only benefit was a less accurate location at the time of the event. Option 2 - Buy a cheap burner phone using cash and find a way to activate the service from a public phone. For example, buy a cheap $15 to $20 flip phone and get a pre-paid card for $30 that will allow calls/texts for up to 90 days. The goal is to trash this phone every month which makes this a good candidate for outgoing calls only. This is a reasonable way to achieve non-repudiation for outgoing calls so long as your actions don't create linkability back to your real identity. A nation-state or government could still determine it was you because you are most likely going to use the phone at home or your work, etc. The example above is based on an AT&T flip phone from Walmart. You can pretend you are blind or can't read and have no family. The associate at the store will most likely activate the phone for you. Go first thing in the morning when they open because they are less busy and more likely to help you. Option 3 - any other or better ideas for non-repudiation on mobile carrier networks?

Jose Vanduka


More Creators