1
00:00:00,020 --> 00:00:01,840
Even with lockdown mode, even with a VPN,

2
00:00:02,360 --> 00:00:04,500
you've protected the data at the application layer.

3
00:00:04,740 --> 00:00:07,400
The whole cellular side is still left wide open.

4
00:00:09,060 --> 00:00:11,720
Welcome to what I think is one of the most groundbreaking interviews

5
00:00:11,940 --> 00:00:13,340
we've ever done on Techlore Talks,

6
00:00:13,340 --> 00:00:15,820
because we are going to pretty much expand on something

7
00:00:15,960 --> 00:00:18,780
that has very little to no information on the internet,

8
00:00:18,920 --> 00:00:22,100
especially in a centralized place, which is cellular privacy.

9
00:00:22,500 --> 00:00:24,580
What does it look like? Why is it not private?

10
00:00:24,860 --> 00:00:26,620
What can all of you do about it?

11
00:00:26,860 --> 00:00:29,280
I'm really excited to have Cape on to discuss this,

12
00:00:29,600 --> 00:00:33,140
and they're going to be covering how everything works behind the scenes, what your typical

13
00:00:33,520 --> 00:00:37,040
provider can see and can't see about your information, the security vulnerabilities

14
00:00:37,470 --> 00:00:41,660
in each step of the process, what this looks like for protesters, what this looks like between

15
00:00:42,100 --> 00:00:47,180
iOS and Android, the features that you can customize. It's a really big deep dive, and

16
00:00:47,400 --> 00:00:51,760
hopefully we take these technical concepts and make them accessible to all of you. And of course,

17
00:00:52,080 --> 00:00:56,280
he will touch on what CAPE does a little bit differently and how they try to add privacy

18
00:00:56,280 --> 00:01:01,480
into the mix. So without further ado, let's get into the interview. I just wanted to start by

19
00:01:01,740 --> 00:01:09,840
asking what does a typical cellular carrier actually see about their customers? Yeah, there's a lot that

20
00:01:09,900 --> 00:01:15,520
they see ranging from both what they collect on the business side and what's needed on the technical

21
00:01:15,760 --> 00:01:20,740
side. And a lot of times those are kind of intermixed with each other. So a lot of times you sign up for

22
00:01:20,980 --> 00:01:26,260
postpaid service, they'll collect your name, your address, your social security number, sometimes

23
00:01:26,280 --> 00:01:27,340
You need to run a credit check.

24
00:01:28,090 --> 00:01:30,600
Those types of things are pretty standard for like the signup process.

25
00:01:31,560 --> 00:01:39,280
And then there's all the things that you sort of need to run the telco itself, to run your

26
00:01:39,450 --> 00:01:39,580
service.

27
00:01:40,600 --> 00:01:45,640
And there's going to be different identifiers that go in there, like most notably starting

28
00:01:45,640 --> 00:01:48,960
at the device, like they can see your IMEI when you register.

29
00:01:49,240 --> 00:01:52,820
That's your equipment identifier that identifies your specific phone.

30
00:01:53,500 --> 00:02:01,240
They'll be able to see the service and information about your subscriber that you have, most correlated with what's called an IMSI or subscriber identifier.

31
00:02:02,680 --> 00:02:04,580
Those tend to follow your SIM card.

32
00:02:05,090 --> 00:02:10,039
And so they can kind of tell where you are at different points in time and what services you subscribe to.

33
00:02:10,800 --> 00:02:19,440
And then there's, how do I actually get communication on a cellular network is all, how do I get radio waves from a tower to you?

34
00:02:19,530 --> 00:02:22,840
And so they clearly need to know some degree of where you are.

35
00:02:23,260 --> 00:02:24,860
So they can send it out over the right tower.

36
00:02:25,520 --> 00:02:37,920
Or if you're, you know, in another country and you're roaming, you know, what other operator do I need to send information to, you know, to correspond with how I actually hand this off to someone else to send that information to you?

37
00:02:38,460 --> 00:02:49,020
So there's, you know, there's kind of good bit ranging from things you actually need for your service to work all the way to like, how do I, you know, product ties and how do I make money off of this system?

38
00:02:50,400 --> 00:03:01,500
Yeah. And then what are the general concerns that you've seen as a result of this tracking? I mean, one could just say that this is, you know, just part of running the service. So what's actually the issue with all this kind of data?

39
00:03:02,420 --> 00:03:08,160
Yeah. And a lot of it comes from, there was sort of like this implicit trust that occurs with,

40
00:03:08,340 --> 00:03:11,880
you know, a lot of these different networks. And, you know, I think a lot of it was designed with

41
00:03:12,080 --> 00:03:16,420
best intentions in mind. But when you start to, you know, kind of put more of an adversarial

42
00:03:16,840 --> 00:03:22,160
kind of spin on it or a lens, you start to think, hey, if I know where, you know, someone is at all

43
00:03:22,320 --> 00:03:27,020
times, is that information that could be like tracked, collected and sold to someone else?

44
00:03:27,720 --> 00:03:31,740
If my system is exploited, can someone pull that information without me knowing?

45
00:03:32,680 --> 00:03:38,040
all the way down to things like, hey, if I can reroute someone's traffic from point A to point B,

46
00:03:38,740 --> 00:03:44,060
and they're not actually at point B, could I intercept it, get their two-factor authentication

47
00:03:44,520 --> 00:03:51,340
code? Could I pretend to be them? Could I spoof something? And so these networks had this trust

48
00:03:51,540 --> 00:04:00,359
in mind, but they can be abused, and sometimes by design and sometimes by unintended consequences of

49
00:04:00,920 --> 00:04:06,140
the time period we're in now where information and data is more valuable than ever.

50
00:04:07,800 --> 00:04:12,280
Yeah. And have there been stories and incidents that you guys can cite

51
00:04:12,620 --> 00:04:15,540
where this data has very clearly been abused in your view?

52
00:04:16,640 --> 00:04:23,180
Yeah. I mean, there's lots of different stories towards, I think there's a classic one where,

53
00:04:23,180 --> 00:04:25,280
I forget the name of the story. It's like, I paid a bounty hunter,

54
00:04:25,900 --> 00:04:28,120
They're like $100 or $500 to locate me.

55
00:04:28,140 --> 00:04:30,360
And they did it within like, you know, X number of minutes.

56
00:04:31,160 --> 00:04:34,640
And so, you know, this data is readily available.

57
00:04:34,980 --> 00:04:40,360
And there's, you know, lots of different, you know, flaws in the system, you know, ranging from, you know, social engineering.

58
00:04:40,840 --> 00:04:45,560
Maybe it's support, you know, customer support person who's tricked or maybe someone is compromised.

59
00:04:46,640 --> 00:04:51,620
And, you know, especially now when you start to think about like, you know, people for who they are or what they're doing,

60
00:04:52,100 --> 00:04:55,880
Disinformation can be very valuable and very dangerous and put into the wrong hands.

61
00:04:56,440 --> 00:05:03,580
Think like a journalist trying to tell a story who might be targeted or a victim of domestic abuse who may be trying to escape.

62
00:05:03,770 --> 00:05:06,280
And there's very tangible consequences to what this looks like.

63
00:05:06,730 --> 00:05:17,120
And when so readily available, and another thing I'll note is that even if you kind of do your best effort, a lot of times this information passes through many systems you may or may not have control over.

64
00:05:17,820 --> 00:05:28,400
And so whether it goes into another billing system or whether it goes through a roaming network, you know, it's the lineage of this data can be hard to track and therefore can leak out in all kinds of ways.

65
00:05:29,680 --> 00:05:36,740
Did you watch the Linus Tech Tips video where I think they did a SIM swap attack to hack into his channel using cell tower issue?

66
00:05:36,740 --> 00:05:39,160
Yes, I remember watching that happen live.

67
00:05:39,210 --> 00:05:39,340
Yeah.

68
00:05:40,100 --> 00:05:40,960
Can you speak to that?

69
00:05:42,820 --> 00:05:47,360
Yeah, I forget a while ago when I watched, I think right at the beginning of the company,

70
00:05:47,680 --> 00:05:51,500
a lot of the, you know, like a SIM swap attack carried out in a number of ways,

71
00:05:51,840 --> 00:05:56,840
a lot of times handled through customer service or bribes or any of those types.

72
00:05:56,910 --> 00:06:00,640
I forget exactly what they did in the video.

73
00:06:02,420 --> 00:06:04,860
I think it was an SS7 exploit or something.

74
00:06:05,280 --> 00:06:06,340
I think it was SS7.

75
00:06:07,220 --> 00:06:07,300
Yeah.

76
00:06:07,750 --> 00:06:11,060
And SS7, you know, it's always been like a sort of a lingering problem.

77
00:06:11,860 --> 00:06:15,380
And less so now with kind of sunsetting of 3G networks.

78
00:06:15,840 --> 00:06:19,980
But no matter how much you sunset a network, it still exists in the global scale.

79
00:06:20,260 --> 00:06:23,560
I haven't had to deal with it with as much staying in the 4G and 5G world.

80
00:06:24,220 --> 00:06:30,040
But yeah, you can quite easily trip phones and tech networks into thinking,

81
00:06:30,670 --> 00:06:32,840
hey, this device is actually somewhere else.

82
00:06:33,280 --> 00:06:36,000
This is a bit of a broad question, but can you walk me through what happens

83
00:06:36,210 --> 00:06:37,720
if I make a call to somebody else?

84
00:06:38,080 --> 00:06:42,540
just on a regular cell network, not via a messenger or signal or anything like this?

85
00:06:42,760 --> 00:06:44,620
What does it look like behind the scenes when I make a call?

86
00:06:45,560 --> 00:06:50,540
Yeah. So typically it starts with your phone connecting to the network. Let's say you power

87
00:06:50,540 --> 00:06:57,080
your phone on. Your phone will start to look for different networks to connect to. That's informed

88
00:06:57,300 --> 00:07:01,480
by your SIM card. Your SIM card has programmed in different identifiers and different preference

89
00:07:01,780 --> 00:07:05,880
lists for different networks to connect to, whether to treat them as roaming or not roaming.

90
00:07:06,560 --> 00:07:15,260
And a lot of times your phone will kind of prolifically try to connect to whatever network, you know, seems the strongest or based on what its preferences are.

91
00:07:16,160 --> 00:07:23,000
And usually part of that, you know, depending on whether you're in the 4G or 5G world is you, you know, you tell the network, here I am.

92
00:07:23,720 --> 00:07:26,420
This is my identifier. Can I connect to your network?

93
00:07:26,720 --> 00:07:30,760
You know, the network, depending on whether you're kind of a native subscriber of that network,

94
00:07:31,460 --> 00:07:36,140
or if you're roaming on that network, will then kind of query whoever's the, you know,

95
00:07:36,210 --> 00:07:41,100
quote unquote, owner of the subscriber, go back and pull an authentication challenge.

96
00:07:42,220 --> 00:07:47,020
The device and the network in 4G and above will mutually authenticate each other. So,

97
00:07:47,640 --> 00:07:51,700
hey, like, yes, I am the network you claim to be trying to connect to. And yes, you are the user

98
00:07:52,200 --> 00:07:56,560
that is trying to connect. And then once that's established, they'll frequently establish what

99
00:07:56,580 --> 00:08:13,620
It's called security context, you know, exchange based on key material, which is kind of pre-distributed in your SIM card and on the backend system that already exists to create a secure tunnel, secure being on certain different parts of the network of different types of security.

100
00:08:14,060 --> 00:08:19,920
This part is on the control, what's called the control plane, sort of how you do authentication and mobility management, that aspect.

101
00:08:20,860 --> 00:08:30,620
And then typically what will happen is also an exchange of other identifiers, like your IMEI, will then get sent to the network you're connecting to.

102
00:08:30,980 --> 00:08:36,099
They'll frequently use that to check for whether your device is stolen or there's some sort of restriction on your device.

103
00:08:36,820 --> 00:08:43,620
You know, you and the network will exchange what capabilities you have and kind of negotiate as to what services I should have.

104
00:08:43,740 --> 00:09:11,300
And then if you're working on a network that's, you know, again, 4G and 5G, like a packet switched kind of network, so you're no longer dealing with the circuit switched part of 3G, you'll also, and you're using things like called voiceover, voiceover LTE or voiceover new radio for the 5G standalone equivalent, you will also register to effectively like a SIP server, sending over, you know, your identifiers and authenticating on the SIP side before you subsequently make a phone call.

105
00:09:11,760 --> 00:09:18,780
where you will kind of change your path depending on whether it's a local, you're calling someone

106
00:09:18,810 --> 00:09:23,280
else on your network, or if your network needs to go find the other person wherever they are in the

107
00:09:23,460 --> 00:09:28,340
world and kind of hand it off to someone else. So there's kind of multiple layers of kind of

108
00:09:28,600 --> 00:09:33,240
registering, authenticating, sending different types of identifiers and information, all before

109
00:09:33,250 --> 00:09:38,199
you even get to making a phone call. And then once you make the phone call, you're kind of sending

110
00:09:38,220 --> 00:09:43,700
your intent to make a phone call to your own network. Your network finds out who this person

111
00:09:43,860 --> 00:09:49,520
is, whether they belong to you, your home network, or they belong somewhere else. And then we'll route

112
00:09:49,660 --> 00:09:56,540
your kind of negotiate on the call side and then start sending media traffic. And which part of that

113
00:09:56,960 --> 00:10:00,520
kind of process or multiple parts of that process do you guys see as problematic,

114
00:10:01,680 --> 00:10:04,360
maybe from a privacy and or security standpoint?

115
00:10:05,460 --> 00:10:08,120
Yeah, I mean, a lot of it is of concern,

116
00:10:09,040 --> 00:10:10,560
you know, ranging from, you know,

117
00:10:10,560 --> 00:10:12,460
kind of implicit channels where, you know,

118
00:10:12,680 --> 00:10:14,700
where information is leaked or, you know,

119
00:10:14,820 --> 00:10:17,360
things that are kind of by design that can be used to track.

120
00:10:17,720 --> 00:10:20,280
So example, you connect to your network

121
00:10:20,800 --> 00:10:22,300
and just during the normal attach process,

122
00:10:22,600 --> 00:10:25,360
you're sharing your IMSI and your IMEI.

123
00:10:26,020 --> 00:10:29,160
IMSI is tied to your subscriber identifier,

124
00:10:29,440 --> 00:10:31,160
it's tied to like your SIM card and your subscription.

125
00:10:31,660 --> 00:10:35,740
your IMEI, your equipment. So those are shared with whatever network you're attaching to.

126
00:10:36,230 --> 00:10:41,980
Those are typically mostly static for most people, unless you're switching SIM cards and switching

127
00:10:42,140 --> 00:10:47,560
devices on a regular cadence. And so that can be used to track you as an individual subscriber or

128
00:10:48,190 --> 00:10:54,180
the kind of owner in possession of device, which can be really big for tracking a very specific

129
00:10:54,450 --> 00:10:59,619
person all over the world down to like what your phone number, because typically you want to give

130
00:10:59,640 --> 00:11:05,180
your phone number out to your friends, to your family, so they have a unique address on how to

131
00:11:05,390 --> 00:11:11,320
contact you that stays the same. But that's also seen in both the control plane traffic that you see

132
00:11:11,520 --> 00:11:16,120
during your authentication process as part of your subscriber data profile, as well as when you're

133
00:11:16,240 --> 00:11:21,700
registering to make a phone call. And so that can be subsequently correlated to other identifiers.

134
00:11:21,920 --> 00:11:27,980
Say you transfer your service from one SIM to another, or one carrier to another carrier,

135
00:11:28,080 --> 00:11:29,180
or bring your phone number with you,

136
00:11:29,680 --> 00:11:31,200
that phone number is still following you

137
00:11:31,540 --> 00:11:32,820
in all the traffic that can be seen

138
00:11:32,890 --> 00:11:33,720
and they can then correlate,

139
00:11:33,910 --> 00:11:35,080
okay, you have this device,

140
00:11:35,320 --> 00:11:36,180
now you have the other device.

141
00:11:36,820 --> 00:11:39,040
So all those pieces are these breadcrumbs

142
00:11:39,040 --> 00:11:41,160
that you can follow without too much difficulty

143
00:11:41,460 --> 00:11:42,780
if you're in the telco space.

144
00:11:43,920 --> 00:11:45,220
Yeah, I think people just assume,

145
00:11:45,480 --> 00:11:48,620
if I have an Android phone right now

146
00:11:48,920 --> 00:11:51,600
and I have Verizon as my carrier

147
00:11:52,140 --> 00:11:54,800
and I'm gonna switch over to both AT&T

148
00:11:55,300 --> 00:11:56,280
and get an iPhone,

149
00:11:56,980 --> 00:12:00,380
It feels like a fresh start, but if you port your phone number over, what you're implying

150
00:12:00,520 --> 00:12:03,260
is that there's still a very direct link there between the two devices.

151
00:12:04,720 --> 00:12:04,980
Exactly.

152
00:12:05,200 --> 00:12:08,320
It's like, you know, your phone number is your name on the network.

153
00:12:08,700 --> 00:12:13,180
It's, you know, you change your clothes, but, you know, people can still see your face and

154
00:12:14,020 --> 00:12:15,300
identify you in that way.

155
00:12:16,420 --> 00:12:20,760
It's a very hard thing to break, you know, to break your identity and all the services

156
00:12:21,020 --> 00:12:25,300
and usefulness you get by having a static phone number with, you know, all the downsides

157
00:12:25,400 --> 00:12:26,300
that also comes with it.

158
00:12:26,880 --> 00:12:30,120
Got it. Okay, now, you know, I want to get a little bit more into the tracking methods

159
00:12:30,540 --> 00:12:35,180
specifically, and because you guys cite a lot of stuff on your blog. And I feel like even some of

160
00:12:35,180 --> 00:12:40,440
these attacks go well, well beyond my technical understanding. And so I like to ask someone who's

161
00:12:40,580 --> 00:12:44,640
definitely more of an expert on this. I have a very basic understanding of cell tower triangulation

162
00:12:44,760 --> 00:12:50,500
and geofencing. My overall concept of this is my phone wants to always connect to the fastest cell

163
00:12:50,640 --> 00:12:55,459
towers, that's the most reliable. And so it's constantly pinging. But that constant pinging

164
00:12:56,220 --> 00:13:01,320
allows, you know, someone with the full access to that network of the cell towers to see like,

165
00:13:01,420 --> 00:13:05,660
oh, this person is moving throughout here because it's stronger over here right now.

166
00:13:05,740 --> 00:13:09,980
And there's this triangulation aspect. Is that an overall good summary of how that works? Or am I

167
00:13:10,460 --> 00:13:13,900
making this a little bit too simplified? And how can that process be abused?

168
00:13:14,700 --> 00:13:19,140
Yeah. I mean, you can follow the rabbit hole all the way down. It gets, it can get very,

169
00:13:19,320 --> 00:13:24,000
very complicated down to like the physics behind it. You know, at a rough level, that's about right.

170
00:13:24,220 --> 00:13:31,920
I mean, not only can you track on the application layer, like, you know, if I'm going from tower A to tower B, my session state is handed off from tower A to tower B.

171
00:13:32,080 --> 00:13:36,540
So now I know, like, at a very rough level, like, hey, I'm within the purview of this tower.

172
00:13:36,800 --> 00:13:38,220
Now I'm within the purview of that tower.

173
00:13:38,980 --> 00:13:46,760
But the way that you actually establish your connections to the tower, you know, involves, you know, very, like, precise calculation and timing.

174
00:13:47,400 --> 00:13:51,440
And that timing with how long it takes a signal to get from A to B can be used.

175
00:13:51,900 --> 00:13:58,240
And if you look at like the tower information to kind of get a much more accurate picture of where, you know, of where you actually of where you are.

176
00:13:58,620 --> 00:14:04,000
Because the coordination with the tower is, you know, is very is very important to make sure everyone's on the same page,

177
00:14:04,120 --> 00:14:11,000
to make sure all the users within that are all served by the same cell are getting the right signals to each other and that I can connect.

178
00:14:11,880 --> 00:14:17,340
So it goes down from both the high level and moving from tower A to B, but also, again, you said relative signal strength,

179
00:14:17,700 --> 00:14:21,820
the time it takes, and the coordination effort between the two, you can kind of measure delays

180
00:14:21,980 --> 00:14:27,960
and do a little bit of math and get a fairly accurate understanding of where people are.

181
00:14:29,100 --> 00:14:33,380
And how accurate is this? Is this like within a mile or is it like within 10 feet?

182
00:14:33,880 --> 00:14:37,740
I mean, I think you can, you know, with the right access to information, you can get it down to

183
00:14:37,840 --> 00:14:42,740
within meters, you know, a handful of meters is what I've been told. That one I don't know for sure.

184
00:14:43,360 --> 00:14:45,500
But, you know, it's kind of scary to think.

185
00:14:45,640 --> 00:14:52,600
And, you know, especially, I'll note, as we're kind of spinning up more and more radios,

186
00:14:53,080 --> 00:14:57,520
you know, we're not in the world, especially if you live in a city where you have radios

187
00:14:57,680 --> 00:14:58,620
that are covering miles.

188
00:14:59,120 --> 00:15:02,260
You might have radios that are covering very, very specific areas.

189
00:15:03,000 --> 00:15:06,020
You could have a radio that's covering just the entrance of a stadium.

190
00:15:06,640 --> 00:15:10,380
You could have, you know, a small cell radio that's covering, you know, a New York City

191
00:15:10,600 --> 00:15:10,720
block.

192
00:15:11,300 --> 00:15:18,240
If you think about how those can differ, I mean, you can also have a radio tower like I have outside my window here that covers the span of a mile.

193
00:15:18,580 --> 00:15:23,720
You can have one that covers, like I have in my office here in my lab, just 20 feet in all direction.

194
00:15:24,679 --> 00:15:29,560
And you can really start to narrow it down even by what tower you're connected to based on the signal strength.

195
00:15:30,860 --> 00:15:38,740
Got it. And I also want to maybe clear this up because I think a lot of people think if they turn off the location services on their phone,

196
00:15:39,360 --> 00:15:41,220
that where they go can't be tracked.

197
00:15:41,340 --> 00:15:44,340
But this is all entirely independent of that, correct?

198
00:15:45,040 --> 00:15:45,380
Correct.

199
00:15:45,540 --> 00:15:48,560
This is all at the kind of cellular connectivity level.

200
00:15:49,280 --> 00:15:53,060
You know, a lot of the location services, you know, use your GPS and can use your Wi-Fi

201
00:15:53,540 --> 00:15:55,520
access points that you're connected to to figure this out.

202
00:15:56,140 --> 00:16:01,180
This is all just information that's needed by the cell towers to, you know, connect you

203
00:16:01,280 --> 00:16:01,600
to it.

204
00:16:02,579 --> 00:16:04,480
And some of those can be manipulated.

205
00:16:05,200 --> 00:16:08,340
Some of those can not be manipulated due to physics,

206
00:16:08,780 --> 00:16:12,060
but all of this is happening just to maintain your cellular connection.

207
00:16:13,620 --> 00:16:13,880
Got it.

208
00:16:14,840 --> 00:16:16,980
And then I'll talk about, or I'll not talk about,

209
00:16:17,060 --> 00:16:20,020
but I'll ask you about threats later on and how to address those.

210
00:16:20,460 --> 00:16:22,920
But I still want to clear through a bit more of the tracking methods here.

211
00:16:23,140 --> 00:16:26,000
So another thing that I saw online a lot was call data records.

212
00:16:26,270 --> 00:16:31,560
And so what are kind of the concerns around how a typical carrier might handle call records?

213
00:16:32,120 --> 00:16:34,720
And I guess we can throw in SMS records as well.

214
00:16:34,860 --> 00:16:35,580
Yes, similar.

215
00:16:36,580 --> 00:16:36,720
Yeah.

216
00:16:36,840 --> 00:16:42,200
And so, I mean, typically call data records or CDRs as their acronym, because everyone

217
00:16:42,280 --> 00:16:42,940
loves acronyms.

218
00:16:43,140 --> 00:16:45,340
The intent behind them is around billing and accountability.

219
00:16:45,640 --> 00:16:52,140
The problem is that these are stored for potentially very long periods of time, potentially years.

220
00:16:52,500 --> 00:16:54,800
And there's some good intent around them.

221
00:16:55,080 --> 00:16:57,360
Originally, it's like, hey, I'm using the network.

222
00:16:57,480 --> 00:17:00,580
I need to piece together who did what so I can build them for the right information.

223
00:17:01,160 --> 00:17:02,780
Or I was on a roaming network.

224
00:17:03,040 --> 00:17:04,520
And so they sent me the CDRs.

225
00:17:04,800 --> 00:17:06,339
So I can build my user accordingly.

226
00:17:06,900 --> 00:17:11,240
Another part of it is these are kind of my proof of this user did use the network this

227
00:17:11,400 --> 00:17:11,520
amount.

228
00:17:11,680 --> 00:17:15,980
So like as an, you know, as an MVNO or as a roaming agreement, if they send you a bill

229
00:17:16,100 --> 00:17:21,140
and say, Hey, this person used 10 gigabytes by CDRs are my proof of whether they did or

230
00:17:21,220 --> 00:17:21,480
didn't.

231
00:17:21,660 --> 00:17:23,880
If they did not and we disagree, we can mediate.

232
00:17:24,560 --> 00:17:27,560
And this is my proof of like, look, they only had, they only use this amount.

233
00:17:27,720 --> 00:17:28,780
This is how I can account for it.

234
00:17:29,280 --> 00:17:33,819
So there's, you know, some legitimate use, you know, for these, but they can be fairly

235
00:17:33,840 --> 00:17:40,120
invasive because the content of them can vary from carrier to carrier. So things like your subscriber

236
00:17:40,260 --> 00:17:45,260
ID, your IMSI, things like your IMEI can make it in there. Maybe they don't actually need your IMEI

237
00:17:45,300 --> 00:17:49,700
because they know it's tied to your subscriber. So there can be data leaks that occur here. Not to

238
00:17:49,960 --> 00:17:54,360
mention that you mentioned SMS, all the SMS that you send through traditional SMS protocols, not

239
00:17:54,540 --> 00:17:59,299
counting any over the top app, those are all visible to your network provider. And those can

240
00:17:59,320 --> 00:18:04,380
make their way into data sets that you don't want to know. I don't know if you've ever logged into

241
00:18:04,500 --> 00:18:08,720
your cellular provider service portal. Sometimes you can actually see the record and content of

242
00:18:08,960 --> 00:18:13,460
every single message you've sent. I remember as a kid, when I found out my parents could see that,

243
00:18:13,480 --> 00:18:18,260
I was like, oh, maybe I should think twice about what I'm sending to my best friend across the

244
00:18:18,880 --> 00:18:24,060
room during school hours. But I think the real thing comes from, one, a lack of people knowing

245
00:18:24,260 --> 00:18:29,280
what's in these, because there can be legitimate use cases. And two, obviously you have to kind of

246
00:18:29,300 --> 00:18:35,580
defend yourself if you care about what's stored there. But the other side of this is the longevity

247
00:18:35,900 --> 00:18:43,580
of these records. Some places may store these for five plus years. And if you think like,

248
00:18:44,100 --> 00:18:48,220
hey, someone can go kind of back in the time machine and see what I was doing at a different

249
00:18:48,380 --> 00:18:53,480
period of time, that's kind of a scary thought that they can kind of reconstruct what you were

250
00:18:53,560 --> 00:18:58,140
doing. A lot of times these will contain potential information about where you were at the time,

251
00:18:58,360 --> 00:19:03,840
like the cell tower you're connected to. And so it's kind of scary when you think that there's a

252
00:19:04,020 --> 00:19:08,260
long period of time in which these can be connected to that's just sitting there that someone could

253
00:19:08,420 --> 00:19:16,120
take or steal or could be subpoenaed or any of those options. Yeah. And I think what's fascinating

254
00:19:16,300 --> 00:19:23,659
here is it's a bit of a myth, actually. I think I've heard this at least five times in my life

255
00:19:23,680 --> 00:19:26,660
from people where they go, oh, let's not email this.

256
00:19:26,840 --> 00:19:27,660
Let's text this.

257
00:19:28,140 --> 00:19:33,660
So there's this odd myth out there that SMS is more secure than email.

258
00:19:33,940 --> 00:19:35,260
And it's not like email is secure either.

259
00:19:35,380 --> 00:19:38,800
These are both, to their core, they seem like inherently insecure protocols.

260
00:19:39,560 --> 00:19:43,660
But I would argue in some ways email is actually a little bit better for most people.

261
00:19:43,900 --> 00:19:46,880
I don't know if you guys have a view on which one is worse than the other.

262
00:19:47,840 --> 00:19:53,500
Yeah, I mean, I can tell you what can be seen and how easy it can be.

263
00:19:53,540 --> 00:19:58,500
of, you know, it all depends on the choices that you're making at the time, the threat model of

264
00:19:58,500 --> 00:20:02,120
what you're, when you're acting. You know, well set up email server can be secure or it can be

265
00:20:02,280 --> 00:20:08,100
insecure. I can definitely tell you that a telco can see every SMS that you're sending. I don't

266
00:20:08,100 --> 00:20:12,620
know, like, I know, I know I can readily, you know, readily access that information and we have to

267
00:20:13,040 --> 00:20:18,000
actively work to design systems where we can't do that. Or it's very, very, very hard to do that

268
00:20:18,000 --> 00:20:21,880
and encourage people to not use that. Pick and choose where you want to put your fate if you're

269
00:20:21,900 --> 00:20:28,780
either of them. So the next threat I have here is sim swaps and IMSI catchers. So this is a very

270
00:20:28,940 --> 00:20:33,240
common one, especially in light of protests, which I know are quite common right now in the US. So

271
00:20:33,480 --> 00:20:41,320
what can people kind of, what would you overall explain to someone who's new to the idea of sim

272
00:20:41,440 --> 00:20:46,480
swaps and IMSI catchers and also where the cell company kind of has a role in this?

273
00:20:46,700 --> 00:20:54,440
When it comes to, you know, I think in a cellular company's role, like the SIM swaps, I think they'll play a much larger role in.

274
00:20:54,800 --> 00:21:02,560
Because typically, especially in 4G and 5G, that comes to typically issuing a new SIM, you know, to someone else.

275
00:21:02,920 --> 00:21:13,600
A lot of times through social engineering, hey, I contact customer support and I say, hey, hit me up at this WhatsApp, my WhatsApp number, my signal number, and I'll give you 50 bucks for something.

276
00:21:13,680 --> 00:21:19,100
and they can reactivate a SIM, give you a QR code to download and go that way.

277
00:21:20,100 --> 00:21:22,800
Or porting someone's number from A to B if there's not protection.

278
00:21:22,980 --> 00:21:28,180
So the carrier plays an active part based on their security principles that they follow.

279
00:21:28,460 --> 00:21:33,420
How readily am I willing to transfer someone's number or give someone a new SIM or deactivate

280
00:21:33,420 --> 00:21:34,220
their old SIM?

281
00:21:34,660 --> 00:21:38,680
A lot of that is control of the cellular provider for the user.

282
00:21:39,740 --> 00:21:55,120
Now, IMSI catchers are kind of a different story because, you know, despite what a carrier might do, it's very hard to stop someone malicious who's on the ground with a radio from setting up their own IMSI catcher.

283
00:21:55,660 --> 00:21:57,620
And a lot of that has nothing to do with the operator.

284
00:21:58,240 --> 00:22:02,600
It has to do with the protocols that exist within cellular space.

285
00:22:03,580 --> 00:22:17,600
And that, like, for example, in 4G with an IMSI catcher, by definition, the protocol has a flaw where you can request your IMSI, which is typically static for people unless they're changing it, which is not a common feature to just trick someone's phone into attaching.

286
00:22:17,930 --> 00:22:29,000
You know, pretty early on in my time at working in telecom space, I, you know, I bought a cheap software defined radio and I did an IMSI catcher on myself and I was able to, you know, get that done.

287
00:22:29,320 --> 00:22:33,520
And you can watch YouTube videos and how you get that done in like an hour or a couple hours.

288
00:22:34,080 --> 00:22:39,960
And a lot of that is, you know, between, you know, the equipment, the phone and the device itself.

289
00:22:40,660 --> 00:22:44,880
And I mean, there are probably ways, there are lots of ways you can go about like detecting if these things are happening.

290
00:22:45,200 --> 00:22:50,520
A lot of times you can be like, hey, can the device, you know, you see you lose service or blip in service you didn't expect.

291
00:22:51,120 --> 00:22:55,620
Might be you attempted to connect to, you know, a rogue base station, MZ Catcher.

292
00:22:56,060 --> 00:22:58,080
Because a lot of times these are going to be service disrupting.

293
00:22:58,500 --> 00:23:02,260
your phone's going to be scanning, it's going to attempt to attach to something, and it's going to keep going.

294
00:23:03,120 --> 00:23:07,760
And, you know, I think looking for ways to, you know, mitigate, you know, those types of things,

295
00:23:08,110 --> 00:23:14,600
you know, either by changing those identifiers or, you know, ideally in, like, the technology and the standards themselves,

296
00:23:14,980 --> 00:23:21,080
so, like, moving to something like, you know, 5G standalone, where the IMSI is significantly less readily accessible,

297
00:23:21,680 --> 00:23:26,440
it's, you know, encrypted and exchanged securely, helps to patch some of these things.

298
00:23:26,680 --> 00:23:30,000
And being cognizant of the situation you're in,

299
00:23:30,600 --> 00:23:32,520
and maybe it's like, hey, I'm at a protest

300
00:23:32,720 --> 00:23:34,440
and I think I might be tracked here.

301
00:23:35,299 --> 00:23:36,720
Thinking through, do you need a solution

302
00:23:36,900 --> 00:23:38,160
that can change these identifiers?

303
00:23:39,160 --> 00:23:40,660
Do I want to turn my phone off?

304
00:23:41,260 --> 00:23:43,060
Do I want to take my SIM card out?

305
00:23:43,080 --> 00:23:44,920
Do I want to have a different SIM card

306
00:23:44,960 --> 00:23:45,940
that I use completely?

307
00:23:46,380 --> 00:23:49,160
Ranges from being not very sophisticated

308
00:23:49,700 --> 00:23:51,160
to ultra sophisticated.

309
00:23:51,780 --> 00:23:52,980
Yeah, and I guess on that note,

310
00:23:53,100 --> 00:23:55,140
I'd love to start talking about some of the solutions.

311
00:23:55,400 --> 00:24:01,280
I want to start by just going through solutions that anyone can pursue, regardless of what phone or cell carrier they use.

312
00:24:01,720 --> 00:24:09,340
And then, of course, I want to get into how you guys change that and what you deal with on a root level, because I know you guys are quite different from an MVNO, and we'll touch on that in a second.

313
00:24:09,620 --> 00:24:14,120
To start with maybe something like I'm going through the list here, cell tower triangulation and geofencing.

314
00:24:14,800 --> 00:24:18,740
What are kind of the go-to solutions for a regular person to help navigate that?

315
00:24:19,580 --> 00:24:23,400
Maybe from like easiest and like less effective to the most effective?

316
00:24:24,260 --> 00:24:38,760
Yeah. I mean, there's very not sophisticated things like turning your phone off, putting it in a Faraday bag, any of those options that prevents cellular radiation or you attempting to connect to networks.

317
00:24:39,500 --> 00:24:47,120
As everything is sort of working on normal function, your phone is going to be constantly trying to stay connected.

318
00:24:47,180 --> 00:24:49,080
That's what its job is.

319
00:24:49,690 --> 00:24:59,680
And so kind of eliminating the ability for it to present any signal to the world is like the most kind of naive way to stop yourself from being tracked.

320
00:24:59,750 --> 00:25:03,260
But it comes at a downside of you don't have connectivity.

321
00:25:04,050 --> 00:25:11,580
So it can be a little bit tough if you need to stay portable, use your GPS and maps, whatever, as you're moving from A to B.

322
00:25:11,900 --> 00:25:13,900
Then you can get ultra sophisticated.

323
00:25:13,980 --> 00:25:17,880
some of these things that are used to track, you know, like, you know, things like, you know,

324
00:25:18,020 --> 00:25:24,320
geofences and triangulation and things like that. They can be a tougher, you know, a tougher nut to

325
00:25:24,500 --> 00:25:28,840
crack simply because it has a lot to do with timing and it has a lot to do with your modems.

326
00:25:29,050 --> 00:25:34,960
And those are not, you know, necessarily easy and approachable things to do. You know, there are,

327
00:25:35,420 --> 00:25:39,700
there are features that can be developed that can, you know, tweak these items. But for the most part,

328
00:25:39,800 --> 00:25:44,900
I think they're not going to be very approachable except by, you know, different OEMs, things like that.

329
00:25:45,080 --> 00:25:48,860
I'm not saying someone in the right hackerspace couldn't get it to work.

330
00:25:49,020 --> 00:25:54,340
But I think a lot of those basics with how they function are going to be not overly approachable.

331
00:25:54,640 --> 00:26:00,880
But the other side of that is, you know, carrier changing could also be, you know, sort of an effective thing,

332
00:26:01,500 --> 00:26:05,520
which is, you know, spreading out the data to different groups of people.

333
00:26:06,260 --> 00:26:13,740
And so, you know, if I'm, you know, on carrier A and then switch to carrier B, you know, you're splitting your story between A and B.

334
00:26:14,320 --> 00:26:20,000
And now, you know, if you're assuming if you're assuming compromise, you have to compromise both A and B, which might be hard.

335
00:26:20,220 --> 00:26:25,440
Or, you know, if you're if this data is being brokered or sold, maybe it gets put into different buckets.

336
00:26:25,700 --> 00:26:37,580
And so, you know, those are probably the most tangible ways for, you know, kind of those lower level type attacks to try to prevent against them, minus, you know, significant investment on the equipment side and coordination with the network.

337
00:26:38,120 --> 00:26:42,040
Got it. And then what about something like call data records and SMS messages?

338
00:26:42,720 --> 00:26:46,579
Typically the easiest thing to do, and, you know, like there are multiple types of CDRs.

339
00:26:47,520 --> 00:26:52,700
So CDRs are collected, you know, hit on every single major service like voice messaging and data.

340
00:26:53,700 --> 00:27:00,620
all three of them create CDRs, a different value. So when you use normal telephony channels,

341
00:27:01,260 --> 00:27:07,040
so I use voiceover LTE, I'm using my native carriers call, avoiding doing that is going to

342
00:27:07,040 --> 00:27:12,620
be a way to prevent CDRs from being generated by your voice call. Same thing for SMS. So using

343
00:27:12,960 --> 00:27:18,259
an over-the-top app, like Signal, like a WhatsApp, anything that takes it out of the normal telephony

344
00:27:18,260 --> 00:27:24,140
channels and moves it into the data channel is going to be pretty effective at stopping

345
00:27:24,660 --> 00:27:26,540
CDRs from being generated for those activities.

346
00:27:27,300 --> 00:27:33,100
And instead, you'll move it from a highly specific CDR, like, you know, I'm number A and

347
00:27:33,100 --> 00:27:39,180
I called number B at this time, and instead move it to a more broader CDR, which is I had

348
00:27:39,180 --> 00:27:40,520
a data session at this time.

349
00:27:40,920 --> 00:27:44,700
And the contents of that data session don't make it into a CDR because, you know, people

350
00:27:44,700 --> 00:27:46,680
are sending gigabytes of data over.

351
00:27:47,060 --> 00:27:52,600
It's mostly meant for like a billing practice, not really showing what you did, just that you use the network.

352
00:27:53,340 --> 00:27:58,720
And so kind of shifting your practice to using those over the top item apps can be very effective.

353
00:27:59,350 --> 00:28:06,920
But I will note it comes at, you know, a downside in the sense of, you know, there are certain things that networks are that prioritize.

354
00:28:06,980 --> 00:28:27,700
So, for example, when you make a voice over LTE call or Volte call, normal call in 4G, you're getting specific types of connections that are guaranteeing bandwidth, that are guaranteeing latency, that are set up specifically to optimize your voice call that you might not get, you know, from a data channel session or something like Signal.

355
00:28:27,760 --> 00:28:32,440
I think we've gotten to the point where cellular networks are powerful enough to be able to support all of those.

356
00:28:33,040 --> 00:28:36,520
But in a pinch and low connectivity, maybe those apps don't work.

357
00:28:36,880 --> 00:28:41,420
You still might want to consider, depending on your situation, if it's an emergency or not, using those channels.

358
00:28:41,680 --> 00:28:47,080
And so you don't get to take advantage of those designs of the network, but those are becoming less and less relevant as time goes on.

359
00:28:47,560 --> 00:28:50,980
Got it. And then a question I've always had, actually, is Wi-Fi calling.

360
00:28:51,160 --> 00:28:55,860
What are the implications of opting into something like Wi-Fi calling instead of just not touching it at all?

361
00:28:55,980 --> 00:29:01,400
Wi-Fi calling can shift the sort of where the information flows.

362
00:29:02,040 --> 00:29:04,760
So effectively what happens, you go and click on Wi-Fi calling,

363
00:29:04,960 --> 00:29:07,120
and now it says your carrier and Wi-Fi,

364
00:29:07,720 --> 00:29:10,140
is you're basically setting up like an IPsec connection,

365
00:29:10,460 --> 00:29:14,880
so a secure VPN tunnel to an endpoint hosted by your cellular service,

366
00:29:15,320 --> 00:29:17,260
and you're putting your registration over that.

367
00:29:17,460 --> 00:29:20,720
And so your data goes over a non-secured,

368
00:29:20,990 --> 00:29:22,980
I think a kind of not trusted channel,

369
00:29:23,100 --> 00:29:26,720
which is like open Wi-Fi over an IPSec tunnel to the back end.

370
00:29:27,330 --> 00:29:30,000
From there, everything else is the normal flow.

371
00:29:30,150 --> 00:29:35,440
You know, you may accept, you know, more of your carrier sees more information or all the information.

372
00:29:35,640 --> 00:29:37,260
Well, intermediaries don't.

373
00:29:37,260 --> 00:29:42,780
So if I'm roaming and I have voiceover Wi-Fi, I'm still connecting back to my home network

374
00:29:42,950 --> 00:29:46,020
and I'm skipping the visited network that I'm roaming on along the way.

375
00:29:46,110 --> 00:29:51,580
But I will note that there are certain functionality that does glean information about like,

376
00:29:51,660 --> 00:29:56,500
do you have Wi-Fi calling on or established? Think about the cases of handovers. I'm in the

377
00:29:56,540 --> 00:30:01,880
middle of a Wi-Fi call in my hotel room and I walk out of my hotel room and my call continues to work

378
00:30:02,220 --> 00:30:06,020
even though I'm outside of Wi-Fi range. Those are still coordinated with the cellular network.

379
00:30:06,480 --> 00:30:11,700
You have to tell the network that you're leaving Wi-Fi so they can transfer the call over and now

380
00:30:11,780 --> 00:30:16,860
it's following a different channel. So, you know, Wi-Fi calling, you know, can help change the

381
00:30:17,060 --> 00:30:21,480
adversarial model and who can intercept. But there are ways, especially in these transition cases,

382
00:30:21,580 --> 00:30:23,780
where you can still provide certain information

383
00:30:24,030 --> 00:30:26,280
and still find yourself in a situation

384
00:30:26,510 --> 00:30:27,760
where that information can be collected

385
00:30:28,340 --> 00:30:30,440
because you as a person are moving

386
00:30:30,590 --> 00:30:31,400
as you're making that call

387
00:30:31,460 --> 00:30:32,620
and going in and out of Wi-Fi.

388
00:30:33,270 --> 00:30:34,460
And those networks need coordination

389
00:30:34,800 --> 00:30:36,060
to move your data session over

390
00:30:36,580 --> 00:30:39,260
and to make sure they land on the same gateways

391
00:30:39,460 --> 00:30:40,120
that they were on before

392
00:30:40,700 --> 00:30:41,820
so you don't have your call dropped.

393
00:30:42,280 --> 00:30:45,140
So it's a nice way to provide coverage.

394
00:30:45,360 --> 00:30:47,180
It's a nice way to provide higher bandwidth,

395
00:30:47,800 --> 00:30:49,140
but there are still kind of side channels

396
00:30:49,260 --> 00:30:51,540
of how that information makes its way

397
00:30:51,560 --> 00:30:53,740
different carriers if you aren't thinking about it.

398
00:30:53,910 --> 00:30:54,140
Got it.

399
00:30:54,240 --> 00:30:56,220
And then what about like an SS7 signaling attack?

400
00:30:56,490 --> 00:30:59,260
What are some of the things that people can do to help protect themselves from that?

401
00:31:00,280 --> 00:31:02,980
Yeah, a great thing is don't choose a network that has 3G.

402
00:31:03,290 --> 00:31:06,960
A lot of carriers have, you know, deprecated their 3G networks.

403
00:31:07,350 --> 00:31:08,080
They don't have them around.

404
00:31:08,820 --> 00:31:12,280
So sticking to something that's, you know, 4G or 5G only.

405
00:31:12,960 --> 00:31:13,640
How do you do that?

406
00:31:13,900 --> 00:31:15,060
Like, is that a setting for people?

407
00:31:15,440 --> 00:31:15,560
Yeah.

408
00:31:15,610 --> 00:31:18,840
And so a lot of it has to do with the network operator themselves.

409
00:31:19,220 --> 00:31:20,400
So you can do some background research.

410
00:31:20,900 --> 00:31:32,500
I think most major U.S. carriers have sunset their 3G networks and 2G network platforms at this point, but not all of them or depending on certain use cases, they can still see that.

411
00:31:33,000 --> 00:31:37,060
And a lot of the SS7 pieces are all occurring on the back end.

412
00:31:37,650 --> 00:31:42,020
So, you know, whatever you set your phone to do doesn't play the finalized role.

413
00:31:42,280 --> 00:31:49,480
So choosing a carrier that doesn't have those components to their network, which, again, is becoming rarer and rarer, is a great way to prevent it.

414
00:31:49,720 --> 00:31:59,900
And also being cognizant of like, hey, if I go to a country that still has 3G and what network operator I'm on, knowing there are still some vulnerabilities that can exist there.

415
00:32:00,080 --> 00:32:05,720
But picking a network that's on 4G and 5G is probably the most approachable way.

416
00:32:06,160 --> 00:32:11,900
Ones that have published articles about them sunsetting or not having it anymore is probably the most attainable way to do that.

417
00:32:12,180 --> 00:32:15,200
And then just being cognizant when you do travel

418
00:32:15,640 --> 00:32:19,080
that you could be changing your risk portfolio a little bit,

419
00:32:19,160 --> 00:32:21,040
especially if you're getting a SIM

420
00:32:21,200 --> 00:32:22,340
from a native carrier over there.

421
00:32:22,960 --> 00:32:23,180
Got it.

422
00:32:23,340 --> 00:32:25,240
And then something I've been curious about,

423
00:32:25,480 --> 00:32:27,160
because there is a little bit of granularity

424
00:32:27,280 --> 00:32:28,720
that at least iOS gives you,

425
00:32:28,720 --> 00:32:30,140
and I believe Android devices as well,

426
00:32:30,340 --> 00:32:32,660
that at least iOS, like everything is bizarre

427
00:32:33,100 --> 00:32:35,720
in the way that they tell you settings,

428
00:32:35,940 --> 00:32:36,700
like nothing's clear.

429
00:32:36,740 --> 00:32:38,060
It's like, we'll automatically decide

430
00:32:38,200 --> 00:32:40,140
based on unknown contexts,

431
00:32:40,420 --> 00:32:43,440
but you can do like automatic 4G, 5G switching,

432
00:32:43,680 --> 00:32:45,200
or you can do forced 5G switching.

433
00:32:45,380 --> 00:32:48,680
But I know the forced 5G can use a lot more battery life on iOS devices.

434
00:32:49,320 --> 00:32:51,900
But is there a meaningful privacy or security difference

435
00:32:52,580 --> 00:32:53,620
if a user is trying to maximize?

436
00:32:53,820 --> 00:32:56,400
So I know lockdown mode and now Android devices

437
00:32:56,560 --> 00:32:58,820
just straight up disable 2G now automatically

438
00:32:59,220 --> 00:33:02,680
to help, I think, the MZ situation we already talked about.

439
00:33:02,700 --> 00:33:03,840
I think that's the main thing.

440
00:33:04,220 --> 00:33:07,700
And you're eyeing in some cases, depending on which protocol you're in.

441
00:33:08,620 --> 00:33:08,900
Got it.

442
00:33:09,040 --> 00:33:12,940
So yeah, is there a difference between like, you know, if someone's trying to maximize,

443
00:33:13,260 --> 00:33:14,480
should they only opt for 5G?

444
00:33:14,920 --> 00:33:20,000
A lot of it kind of boils down to exploitation of the device itself, which can be done, you

445
00:33:20,000 --> 00:33:20,920
know, with radios.

446
00:33:21,500 --> 00:33:26,420
And so just like how in 4G, I can force someone to send me their IMSI.

447
00:33:27,040 --> 00:33:28,220
And that's just in the protocol.

448
00:33:28,580 --> 00:33:32,220
Like, hey, if I connect to this thing, I can say, oh, send me your IMSI in the clear and

449
00:33:32,220 --> 00:33:32,920
it will just do it.

450
00:33:33,440 --> 00:33:34,840
You know, it's kind of a bootstrapping problem.

451
00:33:35,020 --> 00:33:38,180
The first time you connect, you have to send it in the clear so they know who you are.

452
00:33:38,260 --> 00:33:40,620
and then you switch to a more ephemeral identifier.

453
00:33:41,120 --> 00:33:43,280
But it's baked into the protocol so you can force it.

454
00:33:43,700 --> 00:33:48,020
In 3G and in 2G, the vulnerabilities in those protocols still exist

455
00:33:48,160 --> 00:33:51,620
because those protocols weren't updated and fixed to do that.

456
00:33:51,700 --> 00:33:55,520
Instead, they upgraded to the next technology.

457
00:33:56,000 --> 00:33:59,600
So disabling those on your devices will prevent your phone

458
00:33:59,720 --> 00:34:03,720
from responding with 2G or 3G protocols, which are known to be vulnerable,

459
00:34:04,240 --> 00:34:07,200
where you can grab like in 2G, you know, MZs and IMIs

460
00:34:07,200 --> 00:34:11,760
and, you know, in 4G, you can definitely still grab your IMSI, you know, having your phone

461
00:34:12,120 --> 00:34:17,940
kind of locked down to not kind of accept those protocols will prevent your phone from responding

462
00:34:17,960 --> 00:34:24,700
in those cases. And, you know, also note, like your phone tells the network what it's capable of

463
00:34:24,820 --> 00:34:29,780
doing. And so it's another kind of interesting, you know, interesting point is that like that

464
00:34:30,020 --> 00:34:34,120
information, not only about like, you know, what your IMEI is, but the device capabilities like,

465
00:34:34,179 --> 00:34:37,080
hey, I support 4G, I support 5G, I support these bands.

466
00:34:37,620 --> 00:34:41,200
All of that information does and can make its way back to the network.

467
00:34:41,409 --> 00:34:47,879
And so as you change those settings, the network actually sees that you're not advertising those capabilities as well.

468
00:34:48,320 --> 00:34:54,139
And so you can kind of think of that as another side channel of like, oh, there's these devices that can be exploited in this way.

469
00:34:54,260 --> 00:34:55,500
They're out in the wild in this area.

470
00:34:56,120 --> 00:35:00,220
Now, if you really want to go down the rabbit hole, it's all about the device that can be exploited.

471
00:35:00,720 --> 00:35:01,900
Who knows about it?

472
00:35:02,240 --> 00:35:04,080
How can they cast their net?

473
00:35:04,100 --> 00:35:10,160
you can go forever on, you know, complexity and whether you think it's, you know, what the

474
00:35:10,380 --> 00:35:16,420
adversary model is, which I think makes it very interesting. What you just described sounds a lot

475
00:35:16,480 --> 00:35:22,020
like a fingerprinting attack, like via web browsers, you know, where if you're the only user using a

476
00:35:22,110 --> 00:35:26,680
certain VPN with a DNS provider, it actually makes you stand out, even though you are getting some

477
00:35:26,760 --> 00:35:30,820
privacy and security protections along the way. Is that like a pretty similar concept there where

478
00:35:31,180 --> 00:35:35,860
you're advertising that you're a different phone. Exactly. And so, you know, if you want to talk

479
00:35:36,020 --> 00:35:41,700
about like, you know, information that phones leak, it's all over the place, ranging from like user

480
00:35:42,000 --> 00:35:48,780
agent information. So like, hey, I'm an Android or I'm an iOS device, or, you know, here's Chrome,

481
00:35:49,180 --> 00:35:53,180
here's, you know, you know, a soft phone application, you know, all of those types of

482
00:35:53,380 --> 00:35:58,300
things that use certain channels can be leaked. And that's why it's important, you know, it's like,

483
00:35:58,840 --> 00:36:03,520
it's death by a thousand cuts. And when you, when you want to, you know, target something,

484
00:36:03,800 --> 00:36:08,440
there's a lot of information that the network can have about it beyond just your normal identifiers.

485
00:36:09,200 --> 00:36:12,480
And if you're changing those identifiers, keeping them all in line is, you know,

486
00:36:12,700 --> 00:36:17,080
an important thing to do. Otherwise you may be, you're breaking your facade that you want to put

487
00:36:17,160 --> 00:36:21,880
up for the world. And so if you want to like, you know, correlate all of those, or, you know,

488
00:36:21,960 --> 00:36:26,360
can more easily identify, you know, someone based off of where they are, what they're doing and the

489
00:36:26,380 --> 00:36:32,660
capabilities advertised, user agent, you can follow that and pull that thread all the way.

490
00:36:34,060 --> 00:36:38,240
Got it. And is the user agent specific enough? Because I know we can say iOS or Android,

491
00:36:38,340 --> 00:36:42,340
I'm sure we don't even talk about operating systems. It can just see this is an iPhone 17,

492
00:36:42,660 --> 00:36:46,500
this is a Pixel 6, etc. But what about like specific custom ROMs? I know a lot of

493
00:36:46,940 --> 00:36:50,720
people who use privacy respecting custom ROMs might not know if their carrier is aware that

494
00:36:50,800 --> 00:36:53,560
they're using them. So is that some insight that a carrier would have?

495
00:36:54,500 --> 00:37:01,460
It depends. A lot of it is like, you know, these strings get to be chosen by the libraries and the ROMs that you're using.

496
00:37:01,780 --> 00:37:08,820
So as long as someone's conscious about, you know, what they're selecting or, you know, if it's a privacy conscious designer of the ROM,

497
00:37:09,480 --> 00:37:12,720
they might know this and they might know the appropriate strings to set.

498
00:37:12,960 --> 00:37:20,060
Or if they forked it from a particular library or community, you know, they follow the initial thread from where it came from.

499
00:37:20,380 --> 00:37:22,560
So it can kind of depend based on the implementation.

500
00:37:24,000 --> 00:37:25,980
Yeah, I'm sure a lot of our audience would be curious about Graphene.

501
00:37:25,980 --> 00:37:29,140
I don't know if they actively address that issue.

502
00:37:30,180 --> 00:37:30,300
Yeah.

503
00:37:30,940 --> 00:37:35,520
And it can also get really complicated, too, in that, you know, depending on what libraries

504
00:37:35,780 --> 00:37:39,680
you're using, you know, for what, like, you know, particularly for, you know, like for

505
00:37:39,780 --> 00:37:45,200
voice calls and messaging that use, you know, like IMS or which is like this multimedia subsystem.

506
00:37:45,680 --> 00:37:47,820
You know, are they writing their own library?

507
00:37:48,280 --> 00:37:49,280
Do they have another library?

508
00:37:49,860 --> 00:37:51,580
Are you inheriting debt from something else?

509
00:37:51,880 --> 00:37:53,960
Is it like querying the OS and pulling something?

510
00:37:54,260 --> 00:37:56,620
So it can all depend on the implementation

511
00:37:56,940 --> 00:37:58,240
of how these things get set up.

512
00:37:58,420 --> 00:38:00,340
But those are all like testable things

513
00:38:00,600 --> 00:38:02,200
that you can like look at, you know,

514
00:38:02,320 --> 00:38:04,040
on the device side and on the network side,

515
00:38:04,200 --> 00:38:06,220
which is, you know, what we spend a lot of time doing,

516
00:38:06,440 --> 00:38:09,300
which is, can I, you know, what can the network see?

517
00:38:09,580 --> 00:38:10,460
What can the device see?

518
00:38:10,520 --> 00:38:11,180
What is it sending?

519
00:38:11,900 --> 00:38:13,440
And then what can we do that's better than that?

520
00:38:13,640 --> 00:38:15,080
I guess, okay, so if I'm a cell carrier

521
00:38:15,759 --> 00:38:17,200
and I get a new pixel

522
00:38:17,300 --> 00:38:18,660
because I want to flash graphene on it,

523
00:38:19,539 --> 00:38:21,840
and a lot of times they still require you

524
00:38:21,860 --> 00:38:24,860
connect to Wi-Fi before you can unlock the bootloader and this stuff. But let's say I set

525
00:38:24,940 --> 00:38:28,460
it up on my cell carrier instead for whatever reason. The cell carrier will see, you know,

526
00:38:28,720 --> 00:38:32,960
the MZ, it'll get all the basic information that the phone sends off by default. And it'll probably

527
00:38:33,120 --> 00:38:38,940
see, oh, this person's running a Pixel 10, whatever, running Android. But then let's say

528
00:38:38,940 --> 00:38:44,360
I flash graphene on it and then I just resume. Will a carrier notice a difference between those two

529
00:38:44,540 --> 00:38:50,340
things? Or are you guys not aware of that? Specifically for graphene on the Pixel, I don't

530
00:38:50,360 --> 00:38:55,520
I don't know offhand, but I can imagine that it might advertise itself differently.

531
00:38:55,870 --> 00:39:00,400
And so they might be able to tell something changed, like maybe user agent string changes,

532
00:39:00,690 --> 00:39:04,960
maybe the capabilities broadcast change, which could be, you know, I've changed ROM and I've

533
00:39:05,120 --> 00:39:09,340
disabled 3G. It could be someone went in and changed the setting. So they may be able to infer

534
00:39:09,860 --> 00:39:14,820
something itself has changed. And kind of depending on the implementation, they might be able to,

535
00:39:15,060 --> 00:39:16,500
you know, tie it to one versus the other.

536
00:39:17,520 --> 00:39:21,180
It's all going to vary, you know, based off a phone.

537
00:39:21,620 --> 00:39:25,480
But one thing that will remain, you know, static is like your IMEI.

538
00:39:25,580 --> 00:39:27,920
So they'll still be able to tell like, hey, I'm on, you know,

539
00:39:28,000 --> 00:39:30,740
this specific model of, you know, Pixel 7.

540
00:39:31,720 --> 00:39:34,640
And so that's primarily what they'll probably, you know,

541
00:39:34,840 --> 00:39:38,060
gauge on to like to kind of determine who's using our network,

542
00:39:38,640 --> 00:39:42,780
because it's kind of the easiest, most tractable one in many cases.

543
00:39:44,180 --> 00:39:49,040
So what you're saying is that this isn't a, it's not like my phone just sends to a cell tower,

544
00:39:49,260 --> 00:39:56,660
hey, I'm running iOS, you know, 26.2. What you're saying is more so the user agent is just various

545
00:39:56,940 --> 00:40:02,860
pieces of metadata that someone can use to maybe infer what someone is running on their devices.

546
00:40:03,090 --> 00:40:08,900
And so theoretically, if there was like Lineage OS, maybe, you know, implemented something in a

547
00:40:08,920 --> 00:40:14,340
very unique way, it could unintentionally let cell towers know. This is all very hypothetical,

548
00:40:14,550 --> 00:40:19,440
but I'm assuming it's more of this like inferring from data points rather than it being just like

549
00:40:19,450 --> 00:40:25,320
a broadcast directly to a cell carrier. Is that correct? Yeah. And to draw a distinction too,

550
00:40:25,500 --> 00:40:29,720
like a lot of these things are exchanged after you've authenticated to the network. So like people

551
00:40:29,900 --> 00:40:34,660
aren't like, you know, sitting there pulling this information, but the network operator who kind of

552
00:40:34,680 --> 00:40:40,560
owns your authentication and owns your connection process can see this type of information as it kind

553
00:40:40,600 --> 00:40:45,180
of leaks through inside channels and through normal functionality. And, you know, sometimes,

554
00:40:45,830 --> 00:40:50,320
and I don't know if many operators do this, I think back to the times where people use user

555
00:40:50,640 --> 00:40:55,560
agents and web browsers to optimize, you know, for, you know, Internet Explorer versus, you know,

556
00:40:55,730 --> 00:41:00,800
Chrome versus something else. And so there may be good ways to, you know, use this information.

557
00:41:01,320 --> 00:41:05,700
I don't know if anyone is, but a lot of this is information that's passed, you know, to your

558
00:41:05,900 --> 00:41:09,620
operator. A lot of times you've ordered, you may have ordered your device from them, or hopefully

559
00:41:09,650 --> 00:41:14,600
you got it from, you know, external. So they may have some insight into this already, but a lot of

560
00:41:14,680 --> 00:41:19,120
it is, you know, not any person can walk off the street and, you know, set up a radio next to you

561
00:41:19,160 --> 00:41:23,940
and get all that information, but they can get the little snippets and then the network operator

562
00:41:24,120 --> 00:41:29,480
themselves can get, you know, a lot more because they have the same keys that are distributed on

563
00:41:29,500 --> 00:41:34,380
your SIM and therefore like you're more freely sending them that information. And, you know,

564
00:41:34,580 --> 00:41:41,620
also note that not only does your operator see this, when you go through a roaming infrastructure,

565
00:41:41,900 --> 00:41:48,480
in many cases, they can also see this type of traffic. And so if, you know, if I'm a U.S.

566
00:41:49,240 --> 00:41:55,900
citizen with a U.S. carrier and I go on a lovely family vacation to France, the French operator

567
00:41:56,340 --> 00:42:00,080
can see a lot of this information before it gets back to the U.S. carrier.

568
00:42:00,680 --> 00:42:06,160
And so as you kind of travel, you're proliferating this information to other networks as well,

569
00:42:06,940 --> 00:42:09,700
depending on what protocol and what features that you're using.

570
00:42:11,340 --> 00:42:11,600
Got it.

571
00:42:11,660 --> 00:42:15,300
And now before I dive into a bit more about your guys' service here,

572
00:42:15,800 --> 00:42:20,860
can you maybe cover how well and also not well and what issues are addressed and aren't addressed

573
00:42:21,000 --> 00:42:24,540
by maybe a pretty common workflow that our audience might have,

574
00:42:24,820 --> 00:42:27,620
which is maybe they have a phone, they're using the latest version.

575
00:42:28,160 --> 00:42:30,440
Maybe some of them already use even lockdown mode

576
00:42:30,620 --> 00:42:34,100
or they have things like disabling 2G and maybe even 3G.

577
00:42:34,110 --> 00:42:35,700
They might use a more modern cell carrier.

578
00:42:36,120 --> 00:42:37,780
They might have a system-wide VPN enabled

579
00:42:38,010 --> 00:42:41,560
and maybe they use exclusively Signal and maybe a few other VOIP services.

580
00:42:43,240 --> 00:42:45,440
I would probably say that's a lot of our audience.

581
00:42:45,830 --> 00:42:48,400
So what are they protected against in that workflow

582
00:42:48,450 --> 00:42:50,760
and what is still kind of up in the air?

583
00:42:51,420 --> 00:42:51,660
Yeah.

584
00:42:52,220 --> 00:42:55,480
And so everything is like, you know, death by a thousand cuts.

585
00:42:55,800 --> 00:42:57,260
There's lots of little things to do.

586
00:42:57,500 --> 00:43:03,240
And there's not necessarily ever a like, there's the one thing you could do that solves everything.

587
00:43:03,720 --> 00:43:06,860
You know, everyone focuses on kind of individual components.

588
00:43:07,340 --> 00:43:12,320
Like a VPN can like, you know, hide from your ISP, certain information to provide guarantees.

589
00:43:12,880 --> 00:43:16,420
And, you know, when used in conjunction, they can be, you know, a very powerful thing.

590
00:43:16,520 --> 00:43:18,800
So we'll start with like, you know, a VPN.

591
00:43:19,440 --> 00:43:25,460
You know, VPN, you know, as a cellular provider, your cellular providers also like your internet service provider, they're your ISP.

592
00:43:26,080 --> 00:43:30,880
And so on the normal circumstances, they can see every IP address you're sending information to.

593
00:43:31,640 --> 00:43:33,120
They can see unencrypted traffic.

594
00:43:33,310 --> 00:43:35,420
A lot of times they can see DNS if left unencrypted.

595
00:43:36,560 --> 00:43:38,720
You know, all of those are covered by something like VPN.

596
00:43:39,320 --> 00:43:40,760
You know, your voice and data records.

597
00:43:41,740 --> 00:43:44,760
Those can be, like you said, covered by like an over-the-top app like Signal.

598
00:43:45,080 --> 00:43:53,580
You can turn off 2G and 3G, and that can prevent what we end up calling close technical surveillance or in-person, close-to-you types of attacks.

599
00:43:54,200 --> 00:43:59,000
It can help with certain downgrade attacks to pull information off your device in 2G and 3G.

600
00:43:59,240 --> 00:44:07,420
But what really, even with lockdown mode, even with a VPN, you've protected the data that's available at the application layer.

601
00:44:07,780 --> 00:44:11,000
The whole cellular side is still left wide open.

602
00:44:11,660 --> 00:44:23,680
And so, you know, you even with lockdown mode, you're in 4G in a particular area, someone can still grab your IMSI, you know, pretty easily, especially if they're, you know, an advanced adversary.

603
00:44:24,840 --> 00:44:28,040
They could see you were in spot A and they can see you're at spot B.

604
00:44:28,620 --> 00:44:36,860
Or if they have access to the network, they could see, you know, maybe where your home is and where the protest was, you know, correlating different, you know, different components that you didn't want.

605
00:44:36,920 --> 00:44:39,220
even if you're in lockdown mode the whole time.

606
00:44:39,450 --> 00:44:40,740
They can still see, you know,

607
00:44:40,900 --> 00:44:43,060
if you own the actual radio towers,

608
00:44:43,520 --> 00:44:45,480
again, we talked about the triangulation

609
00:44:45,700 --> 00:44:47,260
and those types of things that data exists

610
00:44:47,290 --> 00:44:48,040
and can be there.

611
00:44:49,340 --> 00:44:51,800
If you think about like your phone will do,

612
00:44:52,140 --> 00:44:54,100
even if you're only using Signal, for example,

613
00:44:54,460 --> 00:44:57,620
most phones are what are called voice-centric devices,

614
00:44:58,460 --> 00:44:59,880
which means that if they're voice capable,

615
00:45:00,440 --> 00:45:03,160
they will always attempt to have a voice connection,

616
00:45:03,840 --> 00:45:05,480
even if it's not actually used.

617
00:45:06,120 --> 00:45:10,520
And so like you'll actually connect to your voice channel and you'll send a registration message.

618
00:45:10,940 --> 00:45:20,140
Even though you're not using it, you're not making a phone call, that information still flows with might have like identifier information like your IMSI, like your user agent and things like that.

619
00:45:20,380 --> 00:45:24,620
Even though you're not making a phone call, that still is there because you're registering.

620
00:45:25,360 --> 00:45:41,000
And so those pieces hide behind like what the phone was sort of designed to do and less so the all the things that use the data channels and the peripheral pieces that exist sort of within the phone like Bluetooth and Wi-Fi, which are kind of a lot more understood.

621
00:45:41,590 --> 00:45:53,420
And a lot of the cellular pieces are sort of still deferred to other people to attempt to sort or to, in most parts, leave alone because global standards are difficult and move slow.

622
00:45:54,300 --> 00:46:00,480
And, you know, in the end, people want a device that works and don't want to trade off functionality in many cases.

623
00:46:01,300 --> 00:46:03,340
Got it. I feel like you did a really good summary there.

624
00:46:03,580 --> 00:46:08,000
So in that exact summary you just gave, you guys are trying to do something a bit different here.

625
00:46:08,260 --> 00:46:16,080
So in the past and to this day, actually, like kind of our formal recommendations are like, hey, this is what you have control over on your phones, which is the things we just talked about.

626
00:46:16,280 --> 00:46:19,720
Like you can use Signal, you can use a VPN, you can enable lockdown mode, etc.

627
00:46:20,020 --> 00:46:22,860
These are all the things you have control over, but ultimately you can't do anything

628
00:46:23,040 --> 00:46:23,680
about your cell carrier.

629
00:46:23,720 --> 00:46:27,500
If you want cell connectivity, you kind of just have to deal with these problems.

630
00:46:27,900 --> 00:46:31,780
And the best maybe that you can do, which is what I've been doing, is I just use an MVNO,

631
00:46:32,180 --> 00:46:35,380
which allows me to register under whatever information.

632
00:46:35,580 --> 00:46:36,960
It doesn't need a social security number.

633
00:46:38,040 --> 00:46:39,320
I can even use it with a different name.

634
00:46:39,400 --> 00:46:40,780
I get it shipped to a private mailbox.

635
00:46:41,220 --> 00:46:43,960
I do all the basic stuff there, and that's kind of what we've been recommending.

636
00:46:44,440 --> 00:46:46,140
But it's not dealing with any of those root issues.

637
00:46:46,900 --> 00:46:54,140
And so I was quite fascinated with you guys saying that you have your own kind of ways of doing things and your own infrastructure to get around these problems.

638
00:46:54,410 --> 00:46:58,560
And so I'll kind of leave it open to you to kind of start that thread, I suppose.

639
00:46:59,119 --> 00:47:02,180
Yeah. And let me talk more generically.

640
00:47:02,330 --> 00:47:03,740
Like, what was our approach as a company?

641
00:47:04,500 --> 00:47:12,320
Our approach to the company was like, I guess I sum it up like positive control is sort of like the word, the phrase I end up using,

642
00:47:12,500 --> 00:47:19,080
which is how do we like try to get involved in as many of the places as possible?

643
00:47:19,170 --> 00:47:26,920
And, you know, many, many MVNOs are light MVNOs or what they are, are they're like effectively a sales,

644
00:47:27,340 --> 00:47:29,780
a sales platform on top of another carrier.

645
00:47:30,270 --> 00:47:35,700
And so they mostly facilitate connecting you, a paying customer with cellular service on another person's network.

646
00:47:36,420 --> 00:47:40,200
And in many of those cases, you use their SIMs, you use their voice servers,

647
00:47:40,520 --> 00:47:43,480
you use their data nodes, all of that.

648
00:47:44,030 --> 00:47:45,960
And I think, you know, for Cape,

649
00:47:46,080 --> 00:47:47,500
what we ended up trying to do is like,

650
00:47:47,620 --> 00:47:50,580
how can we own more of that process

651
00:47:51,760 --> 00:47:54,380
and those components so that we can change them

652
00:47:54,780 --> 00:47:56,780
based off of what we think is important

653
00:47:57,400 --> 00:48:00,000
and ideally what we hope is important to,

654
00:48:00,210 --> 00:48:02,020
you know, privacy and security conscious users,

655
00:48:02,450 --> 00:48:04,120
you know, around the country and the world.

656
00:48:04,960 --> 00:48:06,760
And, you know, without that degree,

657
00:48:07,430 --> 00:48:08,760
again, it's still just like, you know,

658
00:48:08,800 --> 00:48:16,760
if I only have one internet service provider and they're the only ones and I, you know, slap a new sticker on it and say it's something different, it's really the same underlying thing.

659
00:48:17,180 --> 00:48:22,420
You know, maybe you get to do, you know, I can, you know, use a fake identity or false identity or, you know, use a fake name.

660
00:48:23,180 --> 00:48:29,400
But in the end, all those components, it's all still the same underlying like software and hardware that's at play.

661
00:48:30,080 --> 00:48:35,460
And so we think we thought, OK, let's how do we change this so that it's our software at play?

662
00:48:36,040 --> 00:48:41,180
you know, as an MVNO, focusing mostly on software, like, how can we make sure that,

663
00:48:41,360 --> 00:48:46,920
you know, the traffic is running through us rather than through something we know has these

664
00:48:47,160 --> 00:48:53,860
vulnerabilities. And therefore, we can now inject a different threat model, we can inject different

665
00:48:54,360 --> 00:48:57,580
technology, different thoughts, different processes to how we want to handle this.

666
00:48:57,940 --> 00:49:01,960
So the first step was like, you know, I call it choosing hard mode, which is like, you know,

667
00:49:02,180 --> 00:49:05,359
building, you know, building the network out from underneath it. And that gives you options of what

668
00:49:05,380 --> 00:49:10,000
to do. And so, you know, one option, you know, to all MVNOs is how you want to do billing. And so

669
00:49:10,120 --> 00:49:13,980
that's, you know, that's an easy one to like kind of cross off. Another thing we talked about with

670
00:49:14,000 --> 00:49:19,000
the CDRs, which is, you know, even if you're, you know, on another MVNO and you're still connecting

671
00:49:19,380 --> 00:49:23,860
to like the underlying carrier, they're the one generating the CDRs. They still see your IMSI,

672
00:49:24,300 --> 00:49:28,060
which is static. They can still see your IMEI because you're connected to the network. They

673
00:49:28,060 --> 00:49:32,680
can still see the phone number you're calling from. They can, and they'll store it for however

674
00:49:32,700 --> 00:49:37,640
long the underlying carrier wants, probably years. You don't get to control that if you don't own the

675
00:49:37,820 --> 00:49:42,660
underlying like network components. And so, you know, like for us, what do we, you know, what does

676
00:49:42,660 --> 00:49:48,940
Cape get to do? We get to decide what's the retention period on CDRs. And our retention period

677
00:49:49,200 --> 00:49:55,760
is as short as we can possibly make it and still be able to like be a legally complying business

678
00:49:55,980 --> 00:50:00,619
that won't get driven out of business in a day. And so, you know, we try to delete like as quickly

679
00:50:00,640 --> 00:50:04,860
as possible, always trying to figure out how do we shrink the time? Is there ways we can take the

680
00:50:05,040 --> 00:50:10,600
information when it's produced, anonymize it, and throw out the old copies? But we can choose to make,

681
00:50:10,760 --> 00:50:16,840
you know, active decisions in what data is produced and take things that even the content

682
00:50:17,000 --> 00:50:23,780
of the CDRs. Like we actively try to remove identifiers that are unnecessary to even do

683
00:50:23,900 --> 00:50:29,220
billing remediation from what we're doing. And so like, I don't want to know the information.

684
00:50:29,840 --> 00:50:31,660
I hope our users don't want to know that information.

685
00:50:32,370 --> 00:50:35,420
And so minimizing it as absolutely as possible

686
00:50:35,980 --> 00:50:37,640
and then destroying it as soon as we can,

687
00:50:38,020 --> 00:50:40,180
it becomes something we can do by owning it,

688
00:50:40,560 --> 00:50:41,540
by owning the whole network.

689
00:50:41,890 --> 00:50:47,040
And then moving towards pieces like your IMSI, for example,

690
00:50:47,920 --> 00:50:49,380
something that's typically static.

691
00:50:49,550 --> 00:50:52,420
You go and sign up for a normal MVNO.

692
00:50:52,670 --> 00:50:54,620
They give you your SIM card or your eSIM.

693
00:50:55,320 --> 00:50:56,480
Your IMSI is not changing.

694
00:50:57,540 --> 00:51:03,880
It's static unless you ask for a new SIM card or download a new eSIM or you change carriers.

695
00:51:04,380 --> 00:51:08,040
But it is something that can be controlled if coordinated properly.

696
00:51:08,550 --> 00:51:14,080
And by owning our core and by owning the core network behind it, we can facilitate a user

697
00:51:14,400 --> 00:51:18,680
changing their identity over time without needing them to do much.

698
00:51:18,930 --> 00:51:21,000
An IMSI in the end is just a number.

699
00:51:21,220 --> 00:51:24,080
It's a 15-digit number that exists on your SIM card that identifies you.

700
00:51:24,800 --> 00:51:32,720
And as long as we know what IMSIs can connect to the network and the key material behind them, we can set it to be whatever we want.

701
00:51:32,770 --> 00:51:46,600
And so someone with an IMSI grabber can sit there and collect your IMSI, but we can change it at any time we want and actively want to do that type of activity because it's an important part of our threat model for addressing a 4G deficit.

702
00:51:46,780 --> 00:51:52,020
it. And it can be complicated and it can, you know, maybe, you know, interfere a little bit

703
00:51:52,040 --> 00:51:55,880
with a user. If, you know, if they want to rotate their IMSI, you have to, you know, disconnect and

704
00:51:55,980 --> 00:52:01,840
reconnect. But having users who are bought into the value that's gained by it allows us to then

705
00:52:02,000 --> 00:52:06,520
implement that feature in our core network such that they can change what's typically a static

706
00:52:06,780 --> 00:52:11,480
identifier. Now there's, you know, other parts of our network that kind of sit behind the scenes,

707
00:52:11,620 --> 00:52:15,380
you know, and you mentioned like, you know, SS7 before, you know, there's, you know, a whole

708
00:52:15,400 --> 00:52:20,560
control signaling plane that exists in the global network. You know, in 4G, it's under a protocol

709
00:52:20,710 --> 00:52:25,280
called diameter. But it's all kind of comes down to like, you know, signaling traffic, which is,

710
00:52:25,400 --> 00:52:29,000
you know, how do I tell the network where I am? How do I tell them the feature set? How do I

711
00:52:29,240 --> 00:52:32,800
distribute the data? How do I do authentication? All of this happens on that plane. And we can

712
00:52:32,990 --> 00:52:39,020
actively develop signaling protection or rules or above and beyond like industry standard to prevent

713
00:52:39,580 --> 00:52:43,820
someone from saying that you're actually in another country when you're in the United States.

714
00:52:44,660 --> 00:52:51,600
and what we actively want to do is have our users participate in their own sort of defense,

715
00:52:52,520 --> 00:52:56,200
which are let them set thresholds for what they're willing to tolerate or not tolerate.

716
00:52:56,360 --> 00:53:00,560
Just a lockdown mode is an opt-in type feature that, you know, even when you turn it on,

717
00:53:00,600 --> 00:53:02,420
it says like, hey, this is really not for most people.

718
00:53:03,600 --> 00:53:06,960
You know, have people have a say in the type of protection that they want

719
00:53:07,020 --> 00:53:11,160
and make some of those trade-offs for, you know, maybe, you know,

720
00:53:11,320 --> 00:53:16,740
ease of use versus security versus, you know, something else. Like if I want to say, you know,

721
00:53:16,880 --> 00:53:23,160
hey, I want to block, you know, all incoming, like roaming requests from, you know, X number

722
00:53:23,170 --> 00:53:27,820
of countries or any country that's not like the country that I'm currently living in. That's

723
00:53:27,880 --> 00:53:33,340
something that we can do because we own the signaling plane, we own our network, and we own

724
00:53:33,460 --> 00:53:39,040
the features and functionality that we can then provide to our users to do. And so, you know,

725
00:53:39,100 --> 00:53:45,280
that type of control is what becomes really like a key part in how we can implement protection

726
00:53:45,620 --> 00:53:51,880
at the cellular layer, ranging from just doing table stakes things well, along with an audience

727
00:53:52,140 --> 00:53:56,200
that understands, because you, you know, you take a really big carrier, and they're going to be

728
00:53:56,440 --> 00:54:01,840
geared a lot more towards a common user, someone who needs connectivity, who wants a low price,

729
00:54:01,900 --> 00:54:06,440
who wants, you know, all these different things, as opposed to someone who wants to actively

730
00:54:06,460 --> 00:54:12,340
participate in choosing private and secure things, using features that maybe are a little

731
00:54:12,420 --> 00:54:13,220
bit more complicated.

732
00:54:13,880 --> 00:54:15,040
You know, it all kind of depends.

733
00:54:15,300 --> 00:54:19,380
And with, you know, sort of a bought in audience on that feature of people who actively want

734
00:54:19,520 --> 00:54:23,940
to be able to set these things and control them, it gives us a lot more ground to roll

735
00:54:24,140 --> 00:54:28,920
out those types of features that can like address these things at a root level with the

736
00:54:29,070 --> 00:54:30,980
user kind of involved in that process.

737
00:54:31,380 --> 00:54:34,580
It's kind of like a high level how I end up thinking about how we provide protection,

738
00:54:35,220 --> 00:54:40,460
sort of above and beyond normal over the top to address that cellular layer, which is

739
00:54:41,290 --> 00:54:48,800
pretty difficult to get to without really getting down into the weeds and putting a lot of investment

740
00:54:49,080 --> 00:54:53,720
into standing up a network and interconnecting it with the rest of the global telco network.

741
00:54:55,040 --> 00:55:02,740
Yeah. And that's kind of, I guess, maybe what's a bit misunderstood in general is like the mobile

742
00:55:02,740 --> 00:55:06,320
core aspect of things, because I think people are quite used to the MVNO and how they work.

743
00:55:06,920 --> 00:55:11,040
How and why? I mean, I know why, actually, because you guys wanted more control. But

744
00:55:11,440 --> 00:55:15,100
I think, you know, way back in the day, I just for fun kind of looked into like what it looks

745
00:55:15,200 --> 00:55:21,380
like to start an ISP or cell company. And it's overall seen as largely impossible to start like

746
00:55:21,420 --> 00:55:27,940
your own nowadays. So why would you or how did you opt for this mobile core? Because it sounds like

747
00:55:27,940 --> 00:55:31,700
you actually have to own a lot more infrastructure than a typical company. And how are you still able

748
00:55:31,700 --> 00:55:36,300
to compete? Or do you not compete as well against maybe something like Verizon in some ways here?

749
00:55:37,140 --> 00:55:41,980
Yeah, you know, why we chose to do this? Well, you know, I said, like, you know, positive control,

750
00:55:42,150 --> 00:55:48,640
but also like, it's hard to build towards requirements if you can't do anything about it.

751
00:55:48,780 --> 00:55:54,380
And how do you challenge like, how do you challenge the status quo? And it's harder.

752
00:55:55,560 --> 00:56:00,040
It's harder to make agreements with, because again, you know, even as an MVNO, we have to

753
00:56:00,060 --> 00:56:04,680
make agreements with other carriers because we don't have a radio network. We don't have

754
00:56:05,200 --> 00:56:09,720
tens of thousands of towers across large countries, and we don't have infrastructure

755
00:56:10,540 --> 00:56:16,220
around the world to support all of it. But what we do have are passionate people who want to

756
00:56:16,570 --> 00:56:22,260
dig through these annoying problems, ranging from you talk about setting up an ISP, even going and

757
00:56:22,340 --> 00:56:28,080
registering, getting our own ASNs, getting your own IP address space, cleaning the IP address space

758
00:56:28,100 --> 00:56:29,640
because you can get IPs,

759
00:56:29,650 --> 00:56:31,700
but if you want people to be able to access websites,

760
00:56:32,400 --> 00:56:34,120
a lot of people block based on source IP.

761
00:56:34,430 --> 00:56:38,540
And so going after each one of these pieces

762
00:56:39,080 --> 00:56:39,800
presents an opportunity.

763
00:56:40,460 --> 00:56:43,320
And yeah, it makes it difficult to compete

764
00:56:43,430 --> 00:56:46,260
on the early stages because in order to be

765
00:56:47,050 --> 00:56:48,760
a cellular service that you can sell,

766
00:56:49,380 --> 00:56:50,380
just kind of an expectation

767
00:56:50,800 --> 00:56:52,860
that you provide a bare-bones set of features.

768
00:56:53,700 --> 00:56:55,600
And it can take a while to get to that

769
00:56:56,070 --> 00:56:57,120
bare-bones set of features.

770
00:56:57,540 --> 00:57:02,480
But it also, you know, having a community built in of people who care about these problems

771
00:57:03,280 --> 00:57:07,600
also kind of creates a bit more tolerance around, you know, explaining and providing

772
00:57:07,800 --> 00:57:12,360
transparency around the process, why it takes time to build it, because you have to make

773
00:57:12,880 --> 00:57:14,640
good decisions each step of the way.

774
00:57:15,380 --> 00:57:19,800
Knowing that like, you know, phone companies have had like decades of head start, you know,

775
00:57:19,960 --> 00:57:21,020
on us is tough.

776
00:57:21,300 --> 00:57:26,140
But our goal is to be a comparable choice on like, you know, the bare bones functionality.

777
00:57:26,820 --> 00:57:34,480
You can get all your data services, voice messaging, just like you would any other operator, but have significantly more play in your privacy and security.

778
00:57:34,640 --> 00:57:45,840
And so, you know, it can be it can be hard because, again, you know, we're also sometimes at the whim of, you know, of Verizon, Timo and AT&T because they own all the cellular infrastructure and radio towers in the country.

779
00:57:46,320 --> 00:57:48,720
You know, and a lot of that has been built out over many years.

780
00:57:49,180 --> 00:57:56,560
But going down this path, especially with a more niche community, is kind of an area that I don't say they're not necessarily interested in.

781
00:57:56,620 --> 00:58:03,600
it's harder for them to capture that we can invest in doing those types of things and get,

782
00:58:03,680 --> 00:58:07,220
you know, very passionate response back from the community about things we should or shouldn't do

783
00:58:07,260 --> 00:58:12,440
or build, which is what, you know, I guess the fun part of it, but also the challenging part.

784
00:58:12,460 --> 00:58:19,700
Because again, there's no like one, you know, problem, but a space of problems. And thinking

785
00:58:19,980 --> 00:58:24,080
forward to the future, you know, I would hate to ever be known as like a one problem company.

786
00:58:24,780 --> 00:58:27,260
You know, maybe you can high level put it that way.

787
00:58:27,480 --> 00:58:33,560
But I want to be thought of as someone who can be, who can provide solutions to the space as it changes.

788
00:58:34,060 --> 00:58:41,640
And I think that's the other important part, too, is as we go to 5G to 6G, forever, like always having this specific lens on the problem.

789
00:58:42,060 --> 00:58:44,760
You know, it kind of flows into, you know, we're choosing to have a core.

790
00:58:45,140 --> 00:58:47,080
We're choosing to build, we're choosing to build components.

791
00:58:48,020 --> 00:58:56,980
And so we can, yes, maybe we have some catching up to do, but we can then play in the game going forward as the space changes as well.

792
00:58:58,540 --> 00:59:02,320
Yeah. And I mean, it's a totally different approach, like a typical cellular provider.

793
00:59:02,570 --> 00:59:06,900
I think it's maximum data collection versus you guys are minimum.

794
00:59:07,030 --> 00:59:08,260
So it's quite a different approach.

795
00:59:08,420 --> 00:59:17,780
So because of this infrastructure that you guys control, you're able to pretty much modify a lot of these different things that otherwise really can't be modified if anyone's using a cell carrier.

796
00:59:18,320 --> 00:59:22,700
So I think I read, is it 24-hour for CDR deletion?

797
00:59:23,280 --> 00:59:23,460
Yes.

798
00:59:23,920 --> 00:59:28,620
And then is that configurable by the user or is that just a staple that you set for all users?

799
00:59:29,780 --> 00:59:31,760
Right now it's just a staple we set for everyone.

800
00:59:32,030 --> 00:59:34,220
You know, all records get purged.

801
00:59:35,180 --> 00:59:35,260
Cool.

802
00:59:35,320 --> 00:59:45,160
You know, sometimes there's some downsides, like maybe we need to do if there's any processing and stuff we need to do, like if we miss our window, then we're out of luck.

803
00:59:45,440 --> 00:59:47,240
And, you know, that's something that we have to absorb.

804
00:59:47,720 --> 00:59:51,500
And that was a conscious choice, which is like we can absorb business, business things.

805
00:59:52,100 --> 00:59:54,420
It's hard to absorb like breaking privacy concerns.

806
00:59:54,560 --> 00:59:59,000
And so always moving towards the like, this is what we need to delete.

807
00:59:59,400 --> 01:00:05,080
And this is what wins when there's like a tie or race, you know, to it is the decision we've made.

808
01:00:05,920 --> 01:00:14,780
And then what about like IMSI rotation? Because you mentioned you guys will automatically rotate that. Is that on a set frequency or is that like a user on demand thing?

809
01:00:15,540 --> 01:00:30,280
Right now, it's both. And so by default, it's once every 24 hours. But there's also an on-demand feature as well. So we know that people can't coordinate their schedules with what EMSI rotation time they set.

810
01:00:30,820 --> 01:00:46,560
And so knowing like, hey, if someone goes to a protest and wants to change their empty afterward, we need to be flexible to be able to accommodate them when they're in the event, before the event, after the event, and not limit them to like, I can only participate in events right as I'm at a border of an empty change or something like that.

811
01:00:47,120 --> 01:00:48,200
And so it's both.

812
01:00:49,700 --> 01:00:49,940
Got it.

813
01:00:49,960 --> 01:00:55,640
And then when it comes to other user configurable things, is all of this mostly automatic?

814
01:00:55,940 --> 01:00:58,860
What's configurable for me as a customer in there?

815
01:00:58,940 --> 01:00:59,060
Yeah.

816
01:00:59,700 --> 01:01:06,040
So, and I think the, you know, the options you have are different based on, you know, the different types of offerings we have.

817
01:01:06,100 --> 01:01:08,680
We have, you know, a normal consumer service.

818
01:01:08,960 --> 01:01:19,960
And we also have, you know, service, a service called Obscura, which also has a device side component to it that is a bit more of the advanced, like very targeted mode kind of piece.

819
01:01:20,420 --> 01:01:23,160
But, you know, kind of, you know, standard out of the box.

820
01:01:23,680 --> 01:01:26,500
There are, you know, the normal cellular service that you get.

821
01:01:27,060 --> 01:01:29,560
We provide our kind of standard signaling protection.

822
01:01:29,650 --> 01:01:35,940
So that's something that everyone gets ranging from, again, there are lots of industry standard type protections you get.

823
01:01:36,600 --> 01:01:46,840
Plus, you can kind of opt into sort of the advanced protection or being in the loop of like being notified when certain events happen, staying in the loop.

824
01:01:47,580 --> 01:01:50,740
MZ rotation is a big one that we launched not too long ago.

825
01:01:51,360 --> 01:01:53,380
So being able to like, you know, easily toggle that on,

826
01:01:54,480 --> 01:01:56,840
you get, you know, change your MZ once every 24 hours

827
01:01:57,940 --> 01:02:01,440
or on demand as needed in the button with a button on there,

828
01:02:01,780 --> 01:02:05,300
along with, you know, lots of kind of default implicit choices

829
01:02:05,840 --> 01:02:07,500
that we kind of have that run on the background,

830
01:02:07,720 --> 01:02:10,000
a lot of which are network and device side coordination,

831
01:02:10,600 --> 01:02:12,840
things that are called like carrier bundles,

832
01:02:13,520 --> 01:02:15,820
which are kind of device configuration provided by your network.

833
01:02:16,260 --> 01:02:21,460
So kind of the implicit like good choices along with the different features that we have set.

834
01:02:22,030 --> 01:02:26,740
We recently also added in, I think we're calling it like last mile encryption,

835
01:02:27,640 --> 01:02:30,060
which takes certain SMS and sends it.

836
01:02:30,510 --> 01:02:33,240
Instead of sending it over the telephony channel once it hits us,

837
01:02:33,460 --> 01:02:37,380
we send it via encrypted comms to your device instead.

838
01:02:37,710 --> 01:02:41,440
So just eliminating like another leg of potential compromise that happens.

839
01:02:41,610 --> 01:02:45,360
And so that can be potentially useful, especially if you're sitting

840
01:02:45,360 --> 01:02:47,360
in a roaming type scenario.

841
01:02:48,030 --> 01:02:49,100
Instead of distributing your traffic

842
01:02:49,190 --> 01:02:50,400
through someone else's infrastructure,

843
01:02:50,450 --> 01:02:51,880
we can deliver it directly to you.

844
01:02:52,300 --> 01:02:53,900
Because again, a lot of these SMS come over,

845
01:02:54,440 --> 01:02:56,520
these insecure channels that can happen.

846
01:02:56,700 --> 01:02:59,020
And depending on the countries and the laws,

847
01:02:59,140 --> 01:03:01,620
certain things are forced to be unencrypted

848
01:03:01,980 --> 01:03:03,160
for lawful intercept purposes

849
01:03:03,580 --> 01:03:05,100
and compliance with regulatory.

850
01:03:05,520 --> 01:03:07,300
So I think those are a lot of the things

851
01:03:07,440 --> 01:03:09,620
that come kind of standard now in the app.

852
01:03:09,800 --> 01:03:13,900
And I think we're working on more features to roll out,

853
01:03:14,100 --> 01:03:18,300
one, provide transparency around, you know, situations that you're in. So you can, you know,

854
01:03:18,420 --> 01:03:23,320
make a good decision about like, Hey, am I more or less secure than it was before, along with more,

855
01:03:23,620 --> 01:03:27,320
you know, more features on the signaling side. I guess I also didn't mention the multi-number

856
01:03:27,900 --> 01:03:32,220
multi-number features. If you want to receive messaging on, you know, having kind of secondary

857
01:03:32,520 --> 01:03:37,100
and tertiary numbers as well to sign up for other, you know, other features and functions and other

858
01:03:37,300 --> 01:03:41,520
services as well. So there's a lot of, a lot of things you can, you can choose from there.

859
01:03:42,080 --> 01:03:43,800
I don't dislike it. It does the job.

860
01:03:44,170 --> 01:03:47,540
But I can't say I love my VOIP app that I use for like my second and third number.

861
01:03:48,340 --> 01:03:54,020
And I assume those would show up as like if you're trying to register for an Amazon or Google account,

862
01:03:54,170 --> 01:03:57,080
I bet they would still register as like an actual real phone number.

863
01:03:57,380 --> 01:03:58,680
You guys don't use VOIP for that?

864
01:03:58,860 --> 01:04:03,240
Those all come from our main, the same numbering pool that we have.

865
01:04:03,360 --> 01:04:03,780
That's pretty cool.

866
01:04:03,880 --> 01:04:05,440
And so, yeah, it's a big thing.

867
01:04:05,680 --> 01:04:09,560
And, you know, I also mentioned like, you know, I mentioned IP address reputation.

868
01:04:09,940 --> 01:04:15,460
phone number reputation is like a huge uphill battle. I said we chose hard mode, you know,

869
01:04:15,580 --> 01:04:20,940
being a network operator and being like independent comes with a lot of challenges. And like,

870
01:04:21,400 --> 01:04:25,700
how do you prove to people you're not malicious? How do you prove to people, you know, these aren't

871
01:04:25,820 --> 01:04:30,840
spam numbers. And, you know, a lot of times like the regulatory landscape of the country is a bit

872
01:04:30,980 --> 01:04:34,400
out of date, you know, in order to get, you know, phone numbers that belong to you, you need to own

873
01:04:34,580 --> 01:04:38,720
spectrum. That's kind of a, it's kind of a crazy thing to think about is you have to go and buy

874
01:04:38,740 --> 01:04:44,440
spectrum in different locations to get access to phone numbers from those locations. And,

875
01:04:44,920 --> 01:04:48,580
and then you have to worry about like, hey, if, if meta doesn't like my phone numbers,

876
01:04:48,800 --> 01:04:52,120
they're going to block me from WhatsApp. And, you know, everyone in the world uses WhatsApp,

877
01:04:53,040 --> 01:04:57,360
you know, outside of the US and, you know, people want to be able to, you know, communicate or

878
01:04:57,860 --> 01:05:02,940
again, things being flagged as VoIP numbers, even though they're not. And so it's this constant

879
01:05:02,960 --> 01:05:09,920
uphill battle of proving your reputation, fighting for your reputation, and then providing features

880
01:05:10,280 --> 01:05:15,640
that get to take advantage of the reputation that you have. It's tedious. It's the battle we chose.

881
01:05:15,960 --> 01:05:21,400
It's the battle I fight every day. And I love it. Like, you know, it's, it could be demoralizing

882
01:05:21,720 --> 01:05:26,840
sometimes, but you know, you get these breakthroughs that are just great. A little side note. It's

883
01:05:27,870 --> 01:05:32,160
always fun. I bet. And it's a universal problem with all privacy tools. You know, SimpleLogin,

884
01:05:32,180 --> 01:05:35,760
And when I first used it, we put out an interview when they just started.

885
01:05:36,080 --> 01:05:37,680
No one really knew who they were yet.

886
01:05:38,260 --> 01:05:44,180
And it blew my mind because there was really no such thing as an email aliasing service at that point in time, as far as I was concerned.

887
01:05:44,340 --> 01:05:45,460
Like something that just forwarded.

888
01:05:45,540 --> 01:05:47,960
You can just generate emails and they all forward to one email inbox.

889
01:05:48,740 --> 01:05:56,480
And I was able to create a Facebook account just to test with a simple login email, an Amazon account, I think even a Google account.

890
01:05:56,880 --> 01:06:01,220
And nowadays that sounds mind-blowing because there is no way in hell you can create.

891
01:06:02,040 --> 01:06:03,340
an account with those services.

892
01:06:03,500 --> 01:06:05,060
But that's kind of the same problem.

893
01:06:05,340 --> 01:06:07,620
These privacy tools do have an overall reputation.

894
01:06:08,640 --> 01:06:10,320
It's why VPNs get blocked

895
01:06:10,380 --> 01:06:12,000
when you try to log into your bank.

896
01:06:12,180 --> 01:06:13,380
It's why Tor Browser gets blocked

897
01:06:13,420 --> 01:06:14,060
on different websites.

898
01:06:14,300 --> 01:06:15,220
And it's quite frustrating

899
01:06:15,300 --> 01:06:16,320
and it's an ongoing issue.

900
01:06:16,480 --> 01:06:17,700
So I'm not surprised that you guys

901
01:06:17,780 --> 01:06:18,700
have to deal with that too.

902
01:06:19,620 --> 01:06:21,440
Yeah, there's no regulation around it.

903
01:06:21,760 --> 01:06:24,140
Like people, services do whatever they want.

904
01:06:24,220 --> 01:06:26,660
And so they can say,

905
01:06:26,840 --> 01:06:28,060
hey, we don't think this is worth it.

906
01:06:28,200 --> 01:06:29,580
There's no one authority to go to.

907
01:06:29,980 --> 01:06:31,220
I mean, there's an authority that says

908
01:06:31,240 --> 01:06:36,400
phone numbers are real, but that's really only one data source that people are using to determine

909
01:06:36,500 --> 01:06:40,780
in their services. But yes, this is a legal thing. Here's the paperwork for it. They're like, well,

910
01:06:41,120 --> 01:06:47,600
I'm still going to block it anyway. I saw spam from there. Sorry. Or you have to work your way

911
01:06:47,780 --> 01:06:53,600
through a mega corporations like hierarchy from like the support email address all the way to the

912
01:06:53,740 --> 01:06:58,180
top to see if you can figure out what happens. And it's frustrating for users who want to do the

913
01:06:58,200 --> 01:07:03,100
right thing and use the right services and then get basically punished for trying to do that.

914
01:07:03,260 --> 01:07:08,720
And so it's an uphill battle, but it's crazy how much I've learned going through all those.

915
01:07:09,020 --> 01:07:10,400
It's how arbitrary some of them are.

916
01:07:11,340 --> 01:07:15,860
Yeah, it's frustrating. And I think, you know, in my view, we don't really have any protections

917
01:07:16,480 --> 01:07:20,380
as end users in the US when it comes from a data perspective. But if there was something

918
01:07:20,960 --> 01:07:26,500
like a GDPR that was federal in the US, I think something that would be very modernized that even

919
01:07:26,520 --> 01:07:33,520
the GDPR didn't really encompass, as far as I'm aware, is like the right to register or access

920
01:07:33,860 --> 01:07:39,980
services without needing to use the mainstream thing, right? Because right now, if you have a

921
01:07:40,100 --> 01:07:43,700
Gmail account, you can register for anything in the world, for the most part. Like Gmail's never

922
01:07:43,880 --> 01:07:47,520
blocked, but sometimes using Proton gets blocked, and Proton is a legitimate service. Sometimes

923
01:07:48,060 --> 01:07:52,380
using SimpleLogin should be acceptable. And so I think it would be nice to have more protections

924
01:07:52,380 --> 01:07:56,900
for end users where you as a user can pick any service you want.

925
01:07:56,960 --> 01:08:00,020
And as long as that service is legally compliant, that should be okay.

926
01:08:00,460 --> 01:08:03,280
And I feel like, I don't know, there should be some kind of something there.

927
01:08:03,300 --> 01:08:06,360
And I'm sure you have better language around this than I do since you deal with it so often.

928
01:08:07,200 --> 01:08:11,240
Yeah, I wish there was some authority I could go to to just say like,

929
01:08:12,120 --> 01:08:17,420
hey, like we're real, like please make like X, Y, and Z play along with us.

930
01:08:18,319 --> 01:08:18,920
It would be great.

931
01:08:19,640 --> 01:08:19,779
Yeah.

932
01:08:20,319 --> 01:08:22,200
Okay, now I do have just quick hit questions.

933
01:08:22,319 --> 01:08:27,680
here. You mentioned Obscura. Not to be confused, I assume, with Obscura VPN, which is a totally

934
01:08:27,799 --> 01:08:35,380
different service. I interviewed them separately. Can you just briefly explain what it looks like

935
01:08:35,380 --> 01:08:38,799
if someone goes for Obscura and how that differs from your typical offering?

936
01:08:39,920 --> 01:08:48,520
Yeah. So Obscura is a much more, I'll call it the lockdown mode equivalent. It's significantly more

937
01:08:48,560 --> 01:08:54,060
you know, advanced and tailors to a more advanced adversarial model. And it puts a lot more in

938
01:08:54,299 --> 01:08:59,560
control, you know, of, you know, for the user. It's like, how do I craft my persona? You know,

939
01:08:59,630 --> 01:09:03,920
how do I change certain different identifiers? And the user's more involved in setting those

940
01:09:04,060 --> 01:09:09,359
configurations. You know, there's a significantly more device side component. So it's not a BYOD.

941
01:09:10,220 --> 01:09:14,980
It's a like, here's a device. And again, it's, it's, it's something that's tailored more towards

942
01:09:15,000 --> 01:09:20,620
like highly targeted people, you know, it's a is an advanced mode. You know, probably most people,

943
01:09:21,160 --> 01:09:25,200
most people don't necessarily need it. And, you know, for some, for some who do get it, you know,

944
01:09:25,259 --> 01:09:28,680
it can be probably overkill for what they need, but provides, you know, a sense of personal

945
01:09:28,940 --> 01:09:33,080
security around it, which again, is, is hard to quantify, but very important for people who are

946
01:09:33,089 --> 01:09:38,299
in stressful situations. So, you know, but also from the technology side, it's just, it's a lot more

947
01:09:39,880 --> 01:09:43,839
control over those types of settings that you would have, like, you know, something like MZ

948
01:09:43,859 --> 01:09:47,880
rotation, you know, having more access to those types of things, which again, someone doesn't

949
01:09:47,960 --> 01:09:53,560
need to be tweaking it at a particular, you know, super, super high frequency given a normal threat

950
01:09:53,819 --> 01:09:58,700
model. But, you know, to some others, it might be more tractable for them to have this advanced

951
01:09:58,920 --> 01:10:05,660
solution. But it's sort of a more encompassing device plus network combined solution rather than,

952
01:10:06,320 --> 01:10:10,420
you know, device light, because, you know, it's hard to, you know, write solutions that are

953
01:10:10,760 --> 01:10:16,360
prolific to all device types so they can vary greatly and the network bundle. So kind of like

954
01:10:17,020 --> 01:10:23,780
just a more advanced mode. And then what device do you ship for that? These are on the nothing phone.

955
01:10:24,560 --> 01:10:30,700
Oh, cool. Is there a reason? Is it because they're like affordable or? I mean, we work with them.

956
01:10:30,810 --> 01:10:36,000
I don't remember all the exact initial reasons, but yeah, they've been, they're a good device to

957
01:10:36,000 --> 01:10:37,840
work with. And does it just run like the stock

958
01:10:38,200 --> 01:10:39,940
ROM? Or do you guys customize it

959
01:10:39,940 --> 01:10:41,900
out of the box a little bit? There's more device

960
01:10:42,100 --> 01:10:44,040
side customization on

961
01:10:44,140 --> 01:10:45,340
it that we've worked through.

962
01:10:45,940 --> 01:10:47,460
So it's a bit more tailored.

963
01:10:48,260 --> 01:10:49,800
Got it. So registration,

964
01:10:50,220 --> 01:10:52,000
I believe you guys just generate a QR code, kind

965
01:10:52,040 --> 01:10:54,020
of like creating a Bitcoin wallet type of deal.

966
01:10:54,280 --> 01:10:55,960
Is that the whole account? Yep. And so

967
01:10:56,620 --> 01:10:57,300
each of the different offerings,

968
01:10:58,200 --> 01:10:59,700
the web checkout to

969
01:11:00,260 --> 01:11:01,860
there. So yeah, that basically is just

970
01:11:02,080 --> 01:11:04,020
facilitating setup of your

971
01:11:04,040 --> 01:11:06,080
on-device information.

972
01:11:06,470 --> 01:11:10,400
And so we use recovery phrase,

973
01:11:11,170 --> 01:11:12,260
very a la crypto wallet,

974
01:11:13,260 --> 01:11:15,040
very hard to compromise and needed,

975
01:11:15,470 --> 01:11:18,280
just like you'd have your big security reset phrase

976
01:11:18,330 --> 01:11:19,740
for your password manager or whatever.

977
01:11:20,320 --> 01:11:24,600
Having this phrase that's both memorable and capturable

978
01:11:25,020 --> 01:11:27,520
that I think people in the community can hopefully understand

979
01:11:27,840 --> 01:11:29,380
is a big aspect to it.

980
01:11:29,480 --> 01:11:32,460
And that gates a lot of things like recovery

981
01:11:32,460 --> 01:11:37,040
or changing sims, you know, hence a lot of the sim swap attack is like, it's not a person who

982
01:11:37,160 --> 01:11:41,640
goes in and does it. You have to provide a complicated thing, you know, based in cryptography

983
01:11:41,900 --> 01:11:48,860
to kind of allow you to change certain aspects of your account. Got it. And then did you guys

984
01:11:49,100 --> 01:11:53,500
opt for this from a privacy perspective? Because I assume that way doesn't require any emails,

985
01:11:53,800 --> 01:11:57,760
any names, et cetera. Or is this also like a sim swap protection kind of thing or both?

986
01:11:59,080 --> 01:12:03,840
Yeah, it's a bit of both. You know, we always, you know, have to walk the line of like,

987
01:12:04,260 --> 01:12:08,160
we don't want to collect any information, but we also like sometimes need to, you know,

988
01:12:08,420 --> 01:12:11,640
to get in contact with folks. We always have this debate back and forth. Like,

989
01:12:12,100 --> 01:12:16,580
do we collect email? Do we not collect email? Like, ideally, we don't collect it, but we might

990
01:12:16,660 --> 01:12:21,100
need to like, send something to someone or facilitate. And so, you know, part of this was

991
01:12:21,260 --> 01:12:27,180
like, how do we not have to do that? So like, you know, if you're a recovery phrase, we don't need

992
01:12:27,200 --> 01:12:29,160
to like send you an email reset link or anything.

993
01:12:29,190 --> 01:12:31,320
You just go in and you can enter your phrase

994
01:12:31,560 --> 01:12:32,520
and recover that way.

995
01:12:32,860 --> 01:12:34,720
You know, part of like the web checkout is,

996
01:12:34,730 --> 01:12:35,840
you know, how do we like,

997
01:12:36,580 --> 01:12:38,100
can we walk the line of collecting

998
01:12:38,390 --> 01:12:39,600
less information as possible?

999
01:12:40,540 --> 01:12:42,740
It's getting your QR code and go from there.

1000
01:12:43,740 --> 01:12:45,080
So it's a little bit of both.

1001
01:12:45,900 --> 01:12:47,700
Can you pay with non-fiat?

1002
01:12:48,020 --> 01:12:49,180
Like what options do you guys have?

1003
01:12:49,540 --> 01:12:51,900
I mean, right now it's all just credit card

1004
01:12:52,350 --> 01:12:52,880
for right now.

1005
01:12:53,290 --> 01:12:55,740
I think we hope to be able to accept

1006
01:12:55,740 --> 01:12:57,580
other currencies and stuff.

1007
01:12:57,840 --> 01:12:59,120
It's something that constantly comes up,

1008
01:12:59,380 --> 01:13:00,620
but not something we have right now.

1009
01:13:01,000 --> 01:13:03,120
Okay. And then just a broad question.

1010
01:13:03,240 --> 01:13:04,240
Someone might be hearing this,

1011
01:13:04,440 --> 01:13:07,100
but if you give someone something

1012
01:13:07,260 --> 01:13:08,180
that they install on their device,

1013
01:13:08,280 --> 01:13:09,480
like a VPN or Signal,

1014
01:13:09,920 --> 01:13:11,540
it's more tangible that it's actually doing

1015
01:13:11,740 --> 01:13:12,720
what it's promising to do.

1016
01:13:13,060 --> 01:13:14,820
But this is a lot more behind the scenes.

1017
01:13:15,520 --> 01:13:17,180
So theoretically, someone could just say,

1018
01:13:17,200 --> 01:13:18,040
we're doing all these things,

1019
01:13:18,100 --> 01:13:19,840
and there's no way for me as a user to verify that.

1020
01:13:20,100 --> 01:13:21,860
So how can we even trust you guys

1021
01:13:22,500 --> 01:13:24,600
that you're doing what you're saying you're doing?

1022
01:13:24,800 --> 01:13:28,240
Like, how do we know that you're deleting the call logs after 24 hours?

1023
01:13:28,580 --> 01:13:30,300
Is there any kind of transparency there?

1024
01:13:30,430 --> 01:13:32,240
Or is it still a trust me system,

1025
01:13:32,470 --> 01:13:35,640
which isn't any different than what you get from another cell carrier, I suppose?

1026
01:13:36,800 --> 01:13:36,920
Yeah.

1027
01:13:37,350 --> 01:13:39,680
And when it comes down to, you know, different components,

1028
01:13:40,120 --> 01:13:41,280
there's kind of different answers.

1029
01:13:41,620 --> 01:13:43,800
So, you know, for example, you know, we have an app

1030
01:13:44,200 --> 01:13:45,560
and the app can facilitate, like,

1031
01:13:45,740 --> 01:13:47,420
how do I prove that the second number is working?

1032
01:13:47,560 --> 01:13:49,420
It's like, well, you're receiving information on the second number.

1033
01:13:50,220 --> 01:13:51,140
It's a great way to do it.

1034
01:13:51,500 --> 01:13:53,220
Same thing for some of our signaling protection,

1035
01:13:53,540 --> 01:13:57,520
like basically providing information of like, yep, this is where we see a network attached coming in,

1036
01:13:58,020 --> 01:14:01,320
giving you that information. You'd be like, yep, that's me. Like, I know I just connected to the

1037
01:14:01,420 --> 01:14:06,920
network. So there are things that are like very easily we're able to like kind of share via our

1038
01:14:07,100 --> 01:14:12,020
app of what's happening. And then there are like things like CDRs are, you know, it's a bit harder.

1039
01:14:12,200 --> 01:14:15,540
How do I prove that we're not, you know, we're not collecting, you know, that information.

1040
01:14:16,100 --> 01:14:20,400
Parts of that are like, you know, we can share out our, you know, share out our policies,

1041
01:14:20,700 --> 01:14:22,600
share out a copy of like, what does a CDR look like?

1042
01:14:22,700 --> 01:14:23,700
What are we collecting? What are we not?

1043
01:14:24,220 --> 01:14:27,360
In the end, there's a bit of trust that has to happen there.

1044
01:14:27,650 --> 01:14:31,120
I would say ideally, like someone can like prove that that doesn't happen.

1045
01:14:31,190 --> 01:14:33,220
And we have to figure if there's a great way to figure it out.

1046
01:14:33,300 --> 01:14:35,900
We're always trying to figure out how do we prove to our people what we're doing?

1047
01:14:36,260 --> 01:14:39,880
You know, the hope would be that one day is sort of the blessing and the curse.

1048
01:14:40,140 --> 01:14:42,720
If like, you know, we're compromised, you know, maybe all companies are

1049
01:14:43,440 --> 01:14:44,760
that there's nothing that comes of it.

1050
01:14:44,880 --> 01:14:46,500
Like people don't have this information stolen.

1051
01:14:46,800 --> 01:14:50,100
Like that's case in point is like, you know, in a zero trust model,

1052
01:14:50,180 --> 01:14:54,040
like you get compromised and like they can't do anything with it. We say, hey, we were compromised,

1053
01:14:54,520 --> 01:14:57,900
but like no one sees anything. Blessing and a curse because you have to be compromised for that

1054
01:14:57,900 --> 01:15:02,540
to happen. And then try to do things like, you know, publish blog posts, publish pieces about

1055
01:15:02,600 --> 01:15:07,680
the technology that we're doing. Try to like, you know, let people see the methodology by which we're,

1056
01:15:07,840 --> 01:15:11,860
you know, by which we're doing things and provide them with a, hey, look, we've thought about this

1057
01:15:11,960 --> 01:15:16,700
type of problem, these types of solutions. This is how we came up with it. Like you can try to be a

1058
01:15:16,720 --> 01:15:21,780
little bit more assured that, you know, we're surrounding the problem in the right way and make

1059
01:15:21,780 --> 01:15:26,220
a more informed decision about it. But we're also always on the lookout of, you know, how do we prove

1060
01:15:26,340 --> 01:15:32,660
to people what they're interested in? And is there things that we can provide that make that happen

1061
01:15:33,020 --> 01:15:39,120
is kind of an area we're always looking to expand in. Got it. And then what's your compatibility

1062
01:15:39,690 --> 01:15:46,080
between devices? So, I mean, right now, you know, we support both Android and iOS. There's some

1063
01:15:46,100 --> 01:15:51,200
caveats to them just because of how difficult the OEM ecosystem is. And we're a small company,

1064
01:15:51,200 --> 01:15:58,200
so we haven't tested on everything. And there's a lot of things from OEMs that are very locked down

1065
01:15:58,440 --> 01:16:04,400
to people who don't have large scale agreements with that we're working on whittling those away.

1066
01:16:04,540 --> 01:16:10,600
But for the most part, normal services works on iOS and most mainstream Android devices. We try to

1067
01:16:10,620 --> 01:16:14,980
work with, you know, with graphene to make sure graphene works. We know, you know, a large

1068
01:16:15,390 --> 01:16:19,580
percentage of the community likes graphene is participating in that community. And so we want

1069
01:16:19,580 --> 01:16:23,880
to be part of that as well. So we try to, you know, make sure graphene support, you know,

1070
01:16:24,120 --> 01:16:29,420
works and is functional. And as we uncover things that are different between stock, stock roms,

1071
01:16:29,610 --> 01:16:34,080
you know, we work to address those as well. And then, you know, we have other, some, some other

1072
01:16:34,180 --> 01:16:40,580
limitations, like we made a decision to support, you know, provide eSIMs. So like if you're in

1073
01:16:40,600 --> 01:16:46,500
non-eSIM capable device, which again, I think most newer devices in the last probably good

1074
01:16:46,640 --> 01:16:52,200
number of years support eSIM. And so there's certain device type restrictions based on

1075
01:16:52,440 --> 01:16:57,520
technology like that. And like I said, working through some of the kinks with the different

1076
01:16:57,740 --> 01:17:01,680
ROMs that are published by different OEMs and the different features and how they interact with our

1077
01:17:01,800 --> 01:17:06,760
network. It's a very tailored process, even in Android and in iOS and how you push configuration

1078
01:17:06,760 --> 01:17:08,880
out to them that control the telephony side.

1079
01:17:09,080 --> 01:17:10,720
It's actually also super fascinating.

1080
01:17:10,760 --> 01:17:13,820
I didn't know any of this existed before I dug in at Cape.

1081
01:17:13,980 --> 01:17:17,460
You know, a good amount of that is actually in the Android source code, if you ever want

1082
01:17:17,500 --> 01:17:20,260
to poke around these different carrier configuration settings.

1083
01:17:21,020 --> 01:17:25,800
And there's some folks who published the carrier bundles pulled things via iTunes at one point

1084
01:17:26,000 --> 01:17:28,000
on iOS, somewhere on GitHub as well.

1085
01:17:28,480 --> 01:17:31,700
If you ever want to look what different carriers are setting behind the scenes.

1086
01:17:33,480 --> 01:17:33,880
Fascinating.

1087
01:17:34,120 --> 01:17:37,400
And are you guys U.S. only or are you international as well?

1088
01:17:38,140 --> 01:17:40,680
Right now, I think we're U.S. only.

1089
01:17:41,120 --> 01:17:44,540
That doesn't mean we don't support international roaming,

1090
01:17:45,160 --> 01:17:48,600
but our network is geared towards U.S. regulatory perspectives

1091
01:17:48,700 --> 01:17:50,180
and something towards U.S. customers,

1092
01:17:50,540 --> 01:17:53,180
but the hope that we can expand that to be global.

1093
01:17:54,400 --> 01:17:57,920
And if someone roams, like if I'm a U.S. customer, I use Cape,

1094
01:17:58,140 --> 01:18:00,740
and then I go visit Germany for a conference,

1095
01:18:01,620 --> 01:18:03,960
will I still get the Cape protections even though I'm in Germany?

1096
01:18:04,140 --> 01:18:06,040
or is it just kind of going to fall back

1097
01:18:06,200 --> 01:18:07,600
to a regular cell carrier at that point?

1098
01:18:07,980 --> 01:18:10,220
Yeah, you'll get some of CAPE's protections

1099
01:18:10,620 --> 01:18:11,600
depending on, you know,

1100
01:18:11,980 --> 01:18:13,860
where you are and the infrastructure you're in.

1101
01:18:14,000 --> 01:18:16,240
So things like IMSI rotation will still function.

1102
01:18:17,420 --> 01:18:19,180
You know, there's a slightly different threat model

1103
01:18:19,380 --> 01:18:21,180
as in like now instead of your data flowing,

1104
01:18:21,480 --> 01:18:22,940
you know, more directly through us,

1105
01:18:23,120 --> 01:18:25,260
it's flowing through these international roaming channels.

1106
01:18:25,440 --> 01:18:27,100
So there's, you know, maybe some different purview,

1107
01:18:27,540 --> 01:18:28,460
but a lot of the main features

1108
01:18:28,660 --> 01:18:29,720
will still continue to function.

1109
01:18:29,940 --> 01:18:31,640
It all uses, it all comes back home,

1110
01:18:31,980 --> 01:18:33,980
eventually touches our network in some capacity.

1111
01:18:35,440 --> 01:18:38,720
Got it. And then how do you guys handle law enforcement requests if those come up?

1112
01:18:38,940 --> 01:18:45,580
We have to follow all of the regulatory compliance of any U.S. operator. That means we participate in

1113
01:18:45,740 --> 01:18:56,480
CLIA and legal wiretaps if given to us. So we have to comply by those. Based on how people send

1114
01:18:56,580 --> 01:19:03,240
our requests, we have not had problems, at least on the lawyer side, of making sure when things

1115
01:19:03,280 --> 01:19:08,000
like IMSI rotation, like if we're given requests against IMSIs, there's only so much we can

1116
01:19:08,200 --> 01:19:13,560
guarantee by definition. Things that we can't encrypt, we don't have to try to decrypt,

1117
01:19:13,750 --> 01:19:17,400
which means like, hey, you know, if signal data traffic comes through our network, like

1118
01:19:17,580 --> 01:19:22,480
we're under no obligation to decrypt it. I think the law is, and lawyers can check me

1119
01:19:22,490 --> 01:19:26,820
if I'm right, is like, you can't be compelled if you don't own any of the keys. So, you

1120
01:19:26,840 --> 01:19:33,220
know, again, we'll have to comply for lawfully provided warrants. And then I think there's

1121
01:19:33,240 --> 01:19:37,400
you know, other parts where we'll, we'll do what we can to, you know, inform people.

1122
01:19:38,210 --> 01:19:42,800
If there's no gag orders on those types of enforcements, like those are things that we

1123
01:19:42,800 --> 01:19:47,240
can attempt to do is like, let people know if there are wiretaps, if we're legally allowed to

1124
01:19:47,290 --> 01:19:51,400
do so. So we try to do the best within the legal system while still being compliant.

1125
01:19:52,500 --> 01:19:54,500
Yeah, I mean, you guys are still a company. I think it's one of the most

1126
01:19:55,440 --> 01:19:59,781
misunderstood things is like, you can just be a company and take money from people and then just

1127
01:19:59,800 --> 01:20:05,040
ignore all the laws and somehow still exist. Exactly. You know, we don't want to encourage

1128
01:20:05,520 --> 01:20:09,780
criminal activity or anything like that. But, you know, privacy and security is always a double-edged

1129
01:20:09,920 --> 01:20:16,240
sword. And so we have to walk that line carefully and again, follow all the legal requirements that

1130
01:20:16,240 --> 01:20:20,460
we need to. Yeah. And I feel like, I don't know how true this is. I don't know if you guys have

1131
01:20:20,590 --> 01:20:25,040
insight into this, but what you're describing, I mean, based on what I see, it seems like

1132
01:20:25,220 --> 01:20:31,260
law enforcement and typical cell carriers, it's a very loosey-goosey relationship. And it seems

1133
01:20:31,380 --> 01:20:35,040
like it's quite easy for that to happen, where even what I'm hearing from you sounds like if

1134
01:20:35,280 --> 01:20:40,560
cell carriers even did a little bit more of that pushback, that would still be a big win for maybe

1135
01:20:40,700 --> 01:20:44,880
some overall rights for individuals. Because I don't know if they always get a warrant when they

1136
01:20:45,040 --> 01:20:48,920
tap on these cell carriers. Because I've seen lots of stories where they didn't get a warrant. So I

1137
01:20:49,000 --> 01:20:52,740
have to assume there is some way that they can get that. Yeah. I don't have a lot of experience,

1138
01:20:53,040 --> 01:20:58,300
But if it's anything like the TV shows, it seems like they manipulate their way in.

1139
01:20:58,520 --> 01:21:05,480
But I think our goal is to always challenge everything, make sure everything is in order,

1140
01:21:06,240 --> 01:21:09,120
and then comply to those that are following the law.

1141
01:21:10,660 --> 01:21:15,380
Yeah, and then something I'm sure you guys have seen, and I think it definitely made my ears perk up as well.

1142
01:21:15,540 --> 01:21:19,680
I don't know the exact relationship, but I think some of you guys used to work at Palantir.

1143
01:21:19,960 --> 01:21:22,040
And I know that's a very controversial company.

1144
01:21:22,080 --> 01:21:24,300
And so I don't know if you want to say something about that.

1145
01:21:25,160 --> 01:21:25,280
Yeah.

1146
01:21:25,400 --> 01:21:27,460
And I'm one of those people.

1147
01:21:27,920 --> 01:21:35,400
I worked at Palantir for eight and a half years in the government space and as a software

1148
01:21:35,620 --> 01:21:35,720
engineer.

1149
01:21:36,620 --> 01:21:41,640
And like many of us, we came acutely aware of these types of problems while working there.

1150
01:21:42,480 --> 01:21:46,480
And we had access to different challenging data problems.

1151
01:21:47,060 --> 01:21:53,440
And it really kind of like an eye-opening experience to what was happening in the world and the types of problems that exist.

1152
01:21:53,570 --> 01:22:01,080
And so, you know, if there's any if there's any takeaway, you know, I think everyone's going to have their own sort of personal feelings about companies in general.

1153
01:22:01,480 --> 01:22:06,900
But I think my biggest takeaway from Palantir was curiosity and like commitment.

1154
01:22:07,900 --> 01:22:19,180
And that like I'm, you know, like for me and like for many of us, it's like understanding a problem that exists, understanding the scope can be large and understanding there's lots of ways to approach the problem.

1155
01:22:19,660 --> 01:22:22,860
Sometimes those are short term, sometimes they're medium term, sometimes they're long term.

1156
01:22:23,680 --> 01:22:30,540
And really like, I don't know, choosing that hard mode type, you know, type problem that is worth it and not letting that, you know, shy away.

1157
01:22:30,900 --> 01:22:35,120
And so at the very least, you know, letting people know that, you know, despite what they

1158
01:22:35,300 --> 01:22:39,500
may think about, you know, different companies, like those are sort of the philosophies that

1159
01:22:40,060 --> 01:22:45,000
us of us that came from those types of companies have brought, you know, forward to Kate.

1160
01:22:46,500 --> 01:22:49,620
Yeah, I think it's, there's the two ways of looking at it, because there are other privacy

1161
01:22:49,800 --> 01:22:52,880
projects in this space that were started from people who almost worked for the opposite.

1162
01:22:53,600 --> 01:22:55,240
Like the thing they're trying to protect against now.

1163
01:22:55,670 --> 01:22:59,500
So the two ways of looking at it is like, oh, they can't be trustworthy whatsoever.

1164
01:22:59,900 --> 01:23:04,580
Or the other perspective is like, oh, they saw how how the food is made.

1165
01:23:05,040 --> 01:23:07,840
And they're like, oh, I don't want to keep I don't want to do that anymore.

1166
01:23:08,220 --> 01:23:10,480
So I suppose it's everyone's feelings towards that.

1167
01:23:10,700 --> 01:23:11,940
For me, it kind of depends on the company.

1168
01:23:12,220 --> 01:23:13,980
Like when I actually get to meet the people behind it.

1169
01:23:14,600 --> 01:23:17,620
Like I feel like it for me, it's a little bit more telling as to like maybe the intentions

1170
01:23:17,880 --> 01:23:18,240
behind it.

1171
01:23:18,640 --> 01:23:20,580
I'm down to the last few questions, I promise here.

1172
01:23:20,920 --> 01:23:21,900
They have to be right here for them.

1173
01:23:22,740 --> 01:23:27,180
If you guys can hear the air blurs, you guys partnered with Proton.

1174
01:23:27,900 --> 01:23:28,860
What is what does that look like?

1175
01:23:28,900 --> 01:23:30,360
what does the partnership with Proton look like?

1176
01:23:30,380 --> 01:23:32,100
And why did that, or how did that come about?

1177
01:23:33,240 --> 01:23:36,700
Yeah, and so I think it's always sort of our philosophy

1178
01:23:37,100 --> 01:23:39,160
that there are many different pieces of the puzzle

1179
01:23:39,380 --> 01:23:40,300
that have to come together

1180
01:23:41,000 --> 01:23:43,220
to actually form a privacy picture

1181
01:23:43,420 --> 01:23:45,340
or a security picture, whatever you want to say.

1182
01:23:46,020 --> 01:23:47,500
And I think there's an acknowledgement,

1183
01:23:48,100 --> 01:23:48,960
at least on our part,

1184
01:23:49,200 --> 01:23:51,860
that not everyone has to do every single thing.

1185
01:23:52,100 --> 01:23:53,520
We can provide some insight

1186
01:23:53,620 --> 01:23:54,840
into what the cellular side's doing.

1187
01:23:54,980 --> 01:23:56,440
We can provide protections that are in there.

1188
01:23:57,000 --> 01:23:58,760
But still there's an untapped part,

1189
01:23:58,800 --> 01:24:02,880
like these tools aren't mutually exclusive. In fact, they're designed to be used together.

1190
01:24:03,600 --> 01:24:08,080
And I think a big part of what the partnership means to me is the acknowledgement of that fact,

1191
01:24:08,500 --> 01:24:12,960
the acknowledgement of, you know, one, it's, you know, it's kind of hard to say, like,

1192
01:24:13,160 --> 01:24:16,480
I'm going to put all my eggs in one basket. And it's like, I think part of it saying, hey,

1193
01:24:16,940 --> 01:24:20,780
you can spread your eggs out in multiple baskets. That's okay. People are doing different things.

1194
01:24:20,940 --> 01:24:25,060
They're going to specialize in different pieces. And I think, you know, a great way to do that is

1195
01:24:25,080 --> 01:24:28,140
showing up, you know, a partnership with Proton who provides, you know, a complimentary service,

1196
01:24:28,840 --> 01:24:33,120
you know, to what we're doing, to a community of people who are going to, I think, understand

1197
01:24:33,590 --> 01:24:38,780
the value of both of them. So is the partnership more of just like a publicity, like you guys are

1198
01:24:38,900 --> 01:24:43,920
partners? Or is there some, like, do you get like a Proton discount if you join Cape? Does it come

1199
01:24:44,060 --> 01:24:49,340
with a subscription, vice versa? Yeah, I don't know if the promotion is still running. But,

1200
01:24:49,570 --> 01:24:53,060
you know, it was when you signed up for, you know, for Cape, you'd get, you know,

1201
01:24:53,380 --> 01:24:55,740
And months of pro time for free.

1202
01:24:56,260 --> 01:24:58,440
Trying to like, you know, again, get into the community,

1203
01:24:59,120 --> 01:25:02,100
help people build, you know, a good set of tools at their disposal.

1204
01:25:02,800 --> 01:25:05,000
And, you know, select products that are complimentary.

1205
01:25:05,380 --> 01:25:07,960
Got it. And then who would you just overall say Cape is for?

1206
01:25:08,240 --> 01:25:09,940
You know, you brought up a lot of concerns today.

1207
01:25:10,540 --> 01:25:12,480
And we talked a lot about the technical side of things.

1208
01:25:13,360 --> 01:25:15,920
And I think it's natural for our audience to say,

1209
01:25:16,320 --> 01:25:18,260
okay, like, I get it. I get who it's for.

1210
01:25:19,740 --> 01:25:22,540
But if someone's just using Verizon, they don't think about this stuff.

1211
01:25:22,740 --> 01:25:24,020
Like, why should they even care about this?

1212
01:25:24,020 --> 01:25:25,600
And is Cape even for that person?

1213
01:25:25,870 --> 01:25:28,180
Or would you still argue there's a place for it there?

1214
01:25:28,940 --> 01:25:29,200
Yeah.

1215
01:25:30,700 --> 01:25:32,360
In my dream, Cape's for everyone.

1216
01:25:33,500 --> 01:25:39,180
And I think my goal has always been to sort of try to meet people where they're at.

1217
01:25:39,840 --> 01:25:42,760
And, you know, different people are going to have different, you know, insights into

1218
01:25:43,280 --> 01:25:46,320
different systems and features and functions and have different value systems.

1219
01:25:47,120 --> 01:25:52,041
And when it comes to privacy and security, I've always wanted to, you know, and this is

1220
01:25:52,060 --> 01:25:58,780
my kind of my dream going into CAPE is help raise the bar for everyone, but also give people the

1221
01:25:59,080 --> 01:26:04,540
opportunity to like lift it themselves in addition to that. And so my hope is that CAPE is for

1222
01:26:04,740 --> 01:26:09,300
everyone. And I want it to be approachable for everyone. It doesn't mean everyone will select it

1223
01:26:09,300 --> 01:26:15,540
and they have their other criteria, but I don't want it to be something that people are afraid to

1224
01:26:15,720 --> 01:26:21,141
choose because it's so complicated. But I want people who really understand, you know, the space

1225
01:26:21,140 --> 01:26:23,280
to really be able to get a lot of value out of it.

1226
01:26:23,320 --> 01:26:26,480
And so a lot of it's meeting people where they are,

1227
01:26:26,740 --> 01:26:27,580
understanding their use cases,

1228
01:26:28,100 --> 01:26:30,440
automating or doing things in an automated fashion

1229
01:26:30,640 --> 01:26:31,860
for people who don't understand it,

1230
01:26:31,960 --> 01:26:33,580
but know they have concerns about it,

1231
01:26:33,920 --> 01:26:38,480
but also letting those folks who want to get in hard mode,

1232
01:26:39,080 --> 01:26:42,020
enabling them to kind of control their own fate there as well.

1233
01:26:42,420 --> 01:26:42,760
Got it.

1234
01:26:42,860 --> 01:26:44,500
And then the last question I have for you is just,

1235
01:26:44,680 --> 01:26:48,080
what's the most shocking thing that you've seen anywhere

1236
01:26:48,380 --> 01:26:50,520
that you think would maybe blow someone's mind?

1237
01:26:50,780 --> 01:26:54,440
Yeah, I think people hear about these things like cell tower translation, even old forensic

1238
01:26:54,660 --> 01:26:56,740
files would introduce the concept.

1239
01:26:56,830 --> 01:27:00,160
But what's something that's just so crazy that if you told most people, they might not

1240
01:27:00,210 --> 01:27:00,940
even believe you?

1241
01:27:01,520 --> 01:27:04,400
I mean, there's definitely a few things.

1242
01:27:05,120 --> 01:27:11,080
I think the thing I didn't realize, you know, so like so much, I mean, basically the telecom

1243
01:27:11,160 --> 01:27:12,240
is like a whole private internet.

1244
01:27:12,860 --> 01:27:17,280
I think people like may kind of figure that out, but may not realize it.

1245
01:27:17,460 --> 01:27:23,460
And that like these networks all interconnect through all these private exchanges and do all these different types of things.

1246
01:27:23,600 --> 01:27:33,000
And not always encryption is necessary or encouraged, but all these things kind of happen in a way that's not necessarily accessible to most folks.

1247
01:27:34,160 --> 01:27:36,540
The data travels through all kinds of interesting paths.

1248
01:27:37,580 --> 01:27:40,000
And it's way more sort of complicated behind the scenes.

1249
01:27:40,180 --> 01:27:43,960
It's not just carrier A sending traffic over the Internet to carrier B.

1250
01:27:44,300 --> 01:27:52,000
They have these private fiber connections that does X, Y, and Z, and they go into this hub, which connects to these 100 other carriers that do all these things.

1251
01:27:52,440 --> 01:27:57,140
There are all these companies and stuff that sit in the middle that facilitate it.

1252
01:27:58,020 --> 01:28:04,120
It's way more, I mean, I guess the internet is complicated, but it's like a whole do-over of that.

1253
01:28:04,210 --> 01:28:05,380
That I kind of found baffling.

1254
01:28:05,380 --> 01:28:08,220
I think in my heart of hearts, I always knew that.

1255
01:28:08,620 --> 01:28:15,400
But how you like untangle that to connect to other people and how these intercarrier, these carriers work.

1256
01:28:15,540 --> 01:28:21,000
And then knowing that kind of how well the world of cellular works is sort of baffling.

1257
01:28:21,200 --> 01:28:26,940
You're like, maybe you open every every system and you're like, oh, it's all duct tape and bubble gum.

1258
01:28:27,300 --> 01:28:30,000
And you open it up, you're like, hey, this is kind of duct tape and bubble gum.

1259
01:28:30,260 --> 01:28:33,220
But it kind of works is like amazing that it happens.

1260
01:28:33,860 --> 01:28:35,960
That to me was the most surprising thing is like.

1261
01:28:37,580 --> 01:28:39,160
I don't know how else to put it.

1262
01:28:39,340 --> 01:28:43,060
It's hard to put into words, but you peek underneath.

1263
01:28:43,720 --> 01:28:45,720
Yeah, you peek underneath and you're like,

1264
01:28:45,860 --> 01:28:47,280
I cannot believe this thing functions.

1265
01:28:48,580 --> 01:28:51,340
And then you close it and maybe it looks like a well-oiled machine,

1266
01:28:51,560 --> 01:28:55,260
but it's all kind of crazy behind the scenes,

1267
01:28:55,520 --> 01:28:59,540
which is kind of ripe for injecting ourselves

1268
01:28:59,920 --> 01:29:01,240
and solving some tough problems.

1269
01:29:02,500 --> 01:29:04,480
Nice. Well, thank you so much, David, for your time.

1270
01:29:04,700 --> 01:29:07,540
I know this is a super vague industry.

1271
01:29:07,980 --> 01:29:10,460
It's been really hard for me to do coverage for this behind the scenes.

1272
01:29:10,520 --> 01:29:13,740
Like the research on it is quite limited, especially from a privacy perspective.

1273
01:29:14,240 --> 01:29:18,400
And so I do feel like it's a pretty limited expertise that you guys probably have right now.

1274
01:29:18,600 --> 01:29:25,660
And so having you on this interview and being able to ask these direct questions is very helpful for not just me, because I learned a lot from this, but also our audience, I'm sure.

1275
01:29:26,620 --> 01:29:27,780
So just thank you for your time.

1276
01:29:27,800 --> 01:29:29,660
I know I kept you much longer than we anticipated.

1277
01:29:30,900 --> 01:29:31,440
Yeah, no problems.

1278
01:29:31,660 --> 01:29:32,740
I'm glad I can provide this.

1279
01:29:32,900 --> 01:29:37,180
I think if there's one thing I've learned, you know, one, like I had to acquire all this

1280
01:29:37,360 --> 01:29:37,560
information.

1281
01:29:37,630 --> 01:29:42,380
I didn't come from a traditional telco background and it was hard to get this information and

1282
01:29:43,000 --> 01:29:48,600
sort of the transparency around it is, is one of the things like I'm very passionate

1283
01:29:48,840 --> 01:29:48,960
about.

1284
01:29:49,590 --> 01:29:53,880
And so, you know, letting people peek behind the curtain, you know, every now and then

1285
01:29:54,040 --> 01:29:54,800
is a, is a treat.

1286
01:29:56,020 --> 01:29:56,160
Awesome.

1287
01:29:56,360 --> 01:29:56,820
Well, thank you, David.

1288
01:29:57,770 --> 01:29:58,320
Thank you so much.

1289
01:29:59,280 --> 01:30:00,400
And there we have it.

1290
01:30:00,440 --> 01:30:03,680
I really hope that you all learned as much from this as I did.

1291
01:30:03,840 --> 01:30:11,800
There were a lot of new things that I hadn't heard before, a lot of nuance that I just feel like needed to be discussed when it came to cellular based privacy.

1292
01:30:12,120 --> 01:30:14,020
It's a very, very tricky thing.

1293
01:30:14,100 --> 01:30:18,340
And it's been hard to offer that many pieces of advice because it feels like there's not that much control.

1294
01:30:18,800 --> 01:30:23,040
So I'm really happy that there are teams like Cape that are coming forward and trying to do something about it.

1295
01:30:23,120 --> 01:30:27,260
And we are starting to see other services step up and try to offer more privacy on the cellular level.

1296
01:30:27,500 --> 01:30:30,880
So I really hope that this is a trend that we begin to see move in the right

1297
01:30:31,140 --> 01:30:33,760
direction because up until now, it's been pretty horrific.

1298
01:30:33,920 --> 01:30:36,500
I really want to thank Cape for their service and also taking the time to

1299
01:30:36,740 --> 01:30:38,520
explain all of these concepts in an interview.

1300
01:30:39,000 --> 01:30:42,520
And we will have an upcoming video soon that is also partnered with Cape where

1301
01:30:42,660 --> 01:30:46,160
we actually pretty much take all of this and make it a very consolidated,

1302
01:30:46,860 --> 01:30:48,580
typical guide that you would find on Techlore.

1303
01:30:48,640 --> 01:30:51,080
So it's very actionable advice for all of you out there.

1304
01:30:51,620 --> 01:30:52,740
So we'll see you in that video.

1305
01:30:53,040 --> 01:31:24,440
And thank you for watching this Techlore Talks interview.