25 ms·
Cophone – Mobile work phones running in the cloud
- t1tech 3y agoHi HN, My name is Tudor and I am the maker of cophone. With cophone you can have your private virtual smartphone running in the cloud, complete with a phone number so you can use it just as you use your physical smartphone. And it works from your browser! Although cophone mainly targets companies, private individuals are welcome! At the moment only US phone numbers (+1...) are available, but more country codes are coming soon. Also having multiple numbers is in the pipeline! Signal app works - just choose "Call" instead of "Text" when verifying your number. You CAN receive text messages, but some apps that require you to receive one in order to register might still NOT work (i.e. Whatsapp). That's because they might not recognize cophone numbers as mobile numbers so you'll never receive the challenge message. Main desktop browsers are supported. Chrome on Android also works but on IPhone there're still some issues, esp on older iOS versions. I'm working on it! Cophone is marked as beta because I haven't tested it at scale and there are still some rough edges. I am exploring having a freeware version with a common, shared phone number and an extension for each user. So you'd dial +123456789 followed by #098765 to get connected via PSTN with a cophone user - let me know what you think of this. I'd love to get your feedback! Don't hold back if you have a feature request or something doesn't work as expected for you! If you'd like a deluxe tour please reach out (tudor at cophone dot io) and I'll be happy to show you around!
- A4ET8a8uTh0 3y agoI want to offer some words of encouragement since I did not have a chance to play with it ( mildly busy Friday ). Still, I think it is a genuinely interesting project and I can see myself using it. I will check it out after the day is done. GL. I really think you got something here.
- Obscurity4340 3y agoHow does it compare to something like MySudo or SilentPhone?
- t1tech 3y agoCophone is a complete smartphone - but virtual. You can install any app in the App Store as well as place and receive calls and text messages, just like you are today with your physical smartphone. MySudo and SilentPhone offer a limited set of their own apps that you can use. Cophone does not have this limitation, you can install and use whatever app is available in the store.
- throwawayadvsec 3y agoYou do realize that a lot of apps are blocked on emulators? Do you manage to bypass those limitations?
- t1tech 3y agoYes, this is an issue that I can only partially bypass at the moment.
- mgkimsal 3y agoIs it something I can use for 2fa? I jump between a lot of VPNs and systems, and having to use my personal phone device for 2fa is annoying at best, and something I'd like to avoid in future. I don't understand quite what "App Store" means in this context. I can download and install stuff from apple's App Store? Or something else? Thanks.
- numpad0 3y agoOnly if you and your IT dept could be comfortable with trusting this guy's code, choice of tech stack, honesty, and opsec. Not that suspicions are warranted or that phone 2FA is much better, but still.
- t1tech 3y agoYes, you can use it for 2fa. AppStore in this context is the e /OS/ App Lounge: https://doc.e.foundation/app-lounge#where-do-the-applications-in-the-app-lounge-come-from https://doc.e.foundation/app-lounge#where-do-the-application... From the link: "Where do the applications in the App Lounge come from? App Lounge can be used to install Native as well as Progressive Web Apps (PWAs) from a single interface. Apps are managed differently depending on their source. Applications from the Google Play Store are fetched using the Google Play API. Progressive Web Apps (PWAs) and Open Source Apps from F-Droid are fetched using the CleanAPK API (more info on the CleanAPK is covered below). App lounge allows you to filter apps by Open Source, PWAs, or just show all apps."
- JimDabell 3y ago> Yes, you can use it for 2fa. You say elsewhere you provide virtual phone numbers. If this is the case, you cannot use it for SMS-based 2FA reliably. Sometimes you will receive codes, but most of them won’t be delivered.
- t1tech 3y agoThis is, unfortunately, true. Some codes will NOT be delivered to your cophone.
- ec109685 3y agoDoesn’t seem like running Signal on a phone hosted in someone else’s data center is the smartest thing to do.
- deleted 3y ago[deleted]
- alienthrowaway 3y agoIt's pretty smart if you're a spammer / phisher. Legitimate use-cases for this setup seem to be few and far between. I wonder how it handles (or skirts) the STIR/SHAKEN requirements in the US.
- wkat4242 3y agoHow does it work with notifications? Is it possible to get a notification on the user's phone when one of the apps in the virtual phone pushes a notification?
- t1tech 3y agoNot yet! For that you would need to install an app that would basically relay the notifications from the virtual smartphone to your smartphone.
- JediPig 3y agosome of us are trying to get rid of the smart phone ;). I want a flip phone but 2FA is a problem with flip phones. I recently started to use 1password paid just 2FA. on a serious note, this is unfortunately what scammers like to use, it would be prudent to lock it down before scammers put you in the middle of a legal cases. I have a long story, I tell people about scammmers, but in the case, please be careful. Grandma is getting conned by these telephone virtual numbers.
- CryptoBanker 3y agoAgreed. This type of service is ripe for committing fraud. I'd be very very careful about the customers you serve
- stikit 3y agoHow are you planning on dealing with licensing for the iOS version you are working on?
- amelius 3y agoAnd can it be used to run iOS apps inside a browser inside an Android phone?
- t1tech 3y agoCophones are running an Android version from e/OS/ You can access the virtual smartphone from a browser running in a physical smartphone. Unfortunately not all smartphones/browsers support it.
- DANmode 3y agoAny comments on why e/OS for your image and not GrapheneOS, given superior patch interval and other benefits that your users may want/need?
- ThePowerOfFuet 3y agoBecause no secure element, which is a hard requirement for GrapheneOS (hence Pixel-only).
- t1tech 3y agoSorry for the misunderstanding. Cophones run e/OS/, which is an Android based OS.
- politelemon 3y agoVery interesting concept. I'm not a decision maker at my workplace but it's something I'd definitely mention in conversations. I really like the idea of not having to carry a work phone.
- yoshamano 3y agoSo it's an Android VM that can be accessed from a browser for $15/month. For an extra $10/month you can attach a phone number to it that has free incoming calls and SMS along with pay-per minute outgoing calls and pay-per message SMS. I see App Lounge in the screenshot so I assume the VM's are running /e/. Have you tried installing any of the MDM's out there like AirWatch or InTune? As a thought exercise, how about some light abuse. What would happen if I rammed a couple TB of BitTorrent data through that VM. Maybe used it as seedbox. Or maybe a proxy so I can access a streaming service. It feels like you're really trying to sell the phone part, and that the Android VM is a means to an end. However, this is just a random phone number that I suspect isn't portable. So if I stop using your service I can't take the number with me. So why wouldn't I get a Skype number for $6.50/month, Skype to Phone for $3.50/month, and then use the web.skype.com page to make all the phone calls I want. Or you can do what I do and use jmp.chat for phone calls and SMS and have it all routed to the XMPP client of your choice (as long as that client supports all the needed features).
- t1tech 3y agoThe VM without a phone number was a way to offer free trials without having a phone number. Will see if it takes the test of time. > I assume the VM's are running /e/. Yes. > Have you tried installing any of the MDM's out there like AirWatch or InTune? No, I haven't tried. Cophone is very new and because of this lacks some functionality or app support. > What would happen if I rammed a couple TB of BitTorrent data through that VM. Maybe used it as seedbox. Or maybe a proxy so I can access a streaming service. Any tool can be abused. I have some bandwidth checks in place and some monitoring. More sophisticated abuse prevention is under development. > why wouldn't I get a Skype number... It's not just about the number, it's the whole package. Think BYOD but without the hassle of mixing work and private data. These devices could be supplied by your employer, with all the apps and number(s) that you need from day 1.
- janfromdaito 3y agoAny plans to offer other country codes than +1 ?
- t1tech 3y agoYes, this is (also) on high priority. But it depends alot on the country, some have very strict regulations around this. Which countries are you mostly interested in?
- _rdvw 3y agoKindly, how can you seriously be calling this secure? By your pictures this is /e/OS, a system which hasn't had the browser/WebView updated in 7+ months, is consistently 2 months behind the ASB, is 1 year behind the PSB, and has a PDF viewer with an engine from January 2016. That is 196 known security issues in the browser, hundreds in the OS, and another 60 in the PDF viewer. I document these issues and many more here: https://divestos.org/misc/e.txt https://divestos.org/misc/e.txt If this really is /e/, you seriously need to address this. Go rebase on an actual production OS like GrapheneOS, my DivestOS, or CalyxOS.
- t1tech 3y agoThank you for your feedback! I will have a look at the alternatives you proposed.
- warcloud 3y agoHey Tudor, I really like the concept and I think it could be the future of corporate access in a way, but I'm trying to look at this through a security lens. I think my main concern with this would be around potential unauthorized access and the impact that might have on an organization. If my target market for this is enterprise clients, I would go to great lengths to ensure that the only person who could access this virtual phone, is the user that's intended to access it. I'll try to keep this short, but here are some ideas I think would really boost adoption and practicality: 1. IP Whitelisting In the portal, users should be able to add a VPN gateway IP or users home IP to an allowlist at the very least. 2. Zero Trust integration The goal here is to be able to enforce device/user identity restrictions in a way that only certain devices/users have access to their virtual smartphone. 3. Management Plane With the above in mind, it might make sense to have IT/Management configure the whitelisting/user certificates for ZTNA in a management portal, so there is separation of duties here. With the above feature requests in place, I would then add a 3rd line item on the pricing page for "Enterprise Pricing" with a "Contact us for a quote" option. For my use case, and I think others may have a similar use case, I would like to use this for my MFA applications and various other internal applications, but if there's no way to restrict access to an individual user, this is essentially a huge security risk from a business standpoint. Hope you find this useful!
- ec109685 3y agoAren’t you missing the huge whole that Tudor and anyone who works for them can read all your data?
- ec109685 3y ago*hole.
- t1tech 3y agoThank you, this is useful! Indeed risk mitigation is crucial for companies. Your points are really good, I think they struck a good balance between functionality and security. One other thing that I am considering, since it is a popular request, is to provide an app that can be installed on a physical device. The device would basically act as a proxy for the cophone's notifications but in addition would also notify the user about potential unauthorized accesses. > 3rd line item ... Totally! Thanks! > use this for my MFA applications and various other internal applications This!
- oaththrowaway 3y agoThis is something I could have used a few times over the last few years. Looks very cool, unfortunately I don't have a need for it at the moment!
- barbazoo 3y agoI get the appeal of a virtual SIM but I don't get the smartphone part. I'm curious, when would I need a service like that?
- t1tech 3y agoSome enterprises provide their employees with a physical smartphone. So they end up carrying 2 devices with them (1 personal, 1 business). Cophone is a complete replacement for the second one.
- ec109685 3y agoWhat corporation is going to be okay with having their private data stored in someone else’s cloud outside of their control?
- toyg 3y agoAll the ones using AWS.
- ec109685 3y agoAWS if you are doing it right, makes it quite for any individual at AWS to hack into your data. All bets off with Cophone.
- toyg 3y agoI might be jaded but I assume the percentage of people "doing it right", among AWS customers, is in the single digit. Most companies don't care about anything but price. The rest is largely theatre, particularly outside the tightly-regulated sectors like healthcare and banking.
- count 3y agoLol, almost all of them. Email, DNS, file shares. Nearly every company today is using the cloud for some component of that... Even the US DOD is using the cloud for email storage.
- fcoury 3y agoI subscribed but when I try to login I am getting this error: > Something went wrong. If you forgot your password, you can reset it. When I try to reset it I get a link and the link leads to an empty page. Any idea what can be the issue?
- t1tech 3y agoSorry for that, I'm checking it.
- fcoury 3y agoThe password reset page has some JS errors: 2.0b62168b.chunk.js:1 Uncaught SyntaxError: Unexpected token '<' main.b556c503.chunk.js:1 Uncaught SyntaxError: Unexpected token '<' manifest.json:1 Manifest: Line: 1, column: 1, Syntax error. Thank you!
- phh 3y agoYet another innovation thing that Web Environment Integrity (and SafetyNet) (will) hinder.
- toyg 3y agoTo be honest I only really need the virtual number, to redirect to arbitrary phones. The stuff Google never bothered to export to these godforsaken European colonies.
- gumballindie 3y agoAre you telling me there is a concept out there for “virtual phone numbers”? I feel like i’ve been living under a rock. I’d find such a service particularly useful. I’d use a phone number for each type of activity. I get so many spam calls it’s crazy.
- noman-land 3y agoI've been doing this with Twilio for years. It's great.
- gumballindie 3y agoI dont understand how i missed this. I own three phones, one real dumb, just to workaround the issue.
- DANmode 3y agoHow many HN threads do you read a week? =] Up until the latest AI wave, Twilio was almost in every thread about a new service!
- lopkeny12ko 3y agoIs there an open source server you use to proxy SMS/calls to your real phone?
- gregsadetsky 3y agoYou can have calls redirected on Twilio to another number easily by using a "Twimlet" which is a pre-built "TwiML" (Twilio's XML markup) generator. https://www.twilio.com/labs/twimlets https://www.twilio.com/labs/twimlets I use the "Forward" one for calls. For SMS, it used to be not too complicated - I would host a file directly on Twilio (using a Twilio bin) to forward the SMS to another number. Recently, sending out SMS's has become a lot more complicated due to compliance (Twilio wants to make sure you don't spam people - but the burden on small developers was just too much for me, after ~2-3 months of back and forth emailing with them to get approved) I've switched my SMS forwarding to use https://pushover.net/ https://pushover.net/ . I use Twilio's hosted nodejs platform to get the incoming SMS message, and use Pushover's API. It's potentially brittle-ish overall (lots of pieces) but it's also been working for years. A native mobile app that would let me just get calls and sms for my hosted Twilio phone numbers is really what I'm asking for... :-)
- PaulKeeble 3y agoIts not very price competive with a mobile phone contract or pay as you go.
- lopkeny12ko 3y agoI don't understand? If you need a computer and browser to access your "virtual smartphone," what's the point? This looks like a classic solution in search of a problem.
- RyanShook 3y agoMain question I have is who is the target audience? If you're making this for work teams then it seems an app would be necessary. If you're making this as a burner line it seems there are cheaper options.
- t1tech 3y agoI am exploring having an app, I think that makes more sense for everybody.
- nikau 3y agoSeems like its an android emulator attached to a real phone number. One use could be to run something like whatsapp to have a virtual US presence if in another country, or maybe have a business number separate from your personal number and use whatsapp web interface to read/send messages.
- t1tech 3y agoThink BYOD, but without mixing personal and business data. So you can just open a browser on your personal mobile phone and access your work phone. Then, when you're in front of your (work) laptop, you just open a browser tab to access the same cophone instance.
- cj 3y ago(iPhone user here) isn’t there the concept of a “work profile” on Android phones to help segment work vs. personal?
- SkyPuncher 3y agoI would absolutely use this. I have a work and personal phone. For many reasons, it's very difficult to merge everything onto a single device. Further, I really don't need to do much "phone" stuff with my work phone. It's mostly a glorified pager, 2FA, and occasional Slack/Email. Anything serious gets a sit-down on my computer. This would effectively let me carry a full-isolated, properly segmented work phone without having to carry two devices.
- deleted 3y ago[deleted]
- danpalmer 3y agoAt my previous company we regularly had need for shared numbers that callers would not know were shared[^1]. We tried using Twilio/etc for this, and it sometimes worked, but we ran into issues in some cases where the systems we were using the phones with banned the use of virtual numbers. I don't know how these systems determine that numbers are virtual, but doing so appears trivial and mostly correct with US/UK numbers. So, question for Cophone, do these phones have a "real" number, or a virtual number? And, perhaps a follow-up, are these VMs with a virtual network stack, or are they physical devices with a real physical SIM/eSIM/modem with screen sharing? [^1]: This sounds nefarious, but we essentially partnered with a lot of retailers, and needed to interact with their customer service and operations departments who were a long way organisationally from those who signed the partnership contracts, and with little scope for deeper integrations. The lowest friction option was to pretend to be a completely normal customer rather than explain our special case setup every time. Fun fact, this is why we used a gender-neutral name on the postal address, so that anyone from our company could call up and claim to be the recipient.
- t1tech 3y agoCophone has virtual phone numbers. This is - one of - the reasons why some services like WhatsApp won't even sent you a text message, although it is possible to receive SMSes. Cophones are VMs with virtual stacks.
- danpalmer 3y agoThanks for the clarification, this makes complete sense for what you're trying to do. It's a little sad that there isn't a good solution for this yet though.
- rsync 3y agoHere's the solution: https://kozubik.com/items/2famule/ https://kozubik.com/items/2famule/ (sorry about the bad SSL cert - I stopped caring after acme.sh blew up)
- dmarinus 3y agomobile phone ui often use touch gestures, is this properly handled through the browser?
- t1tech 3y agoYes, from what I've tested. You obviously need a device with a touch screen though (a physical mobile phone, tablet or laptop with a touchscreen)
- rhasenack 3y agoI've worked in a small consultancy where we'd use our personal phones to talk to clients - mainly using Whatsapp. It was hell, since there was no way I could get away from personal messages during work time and vice versa. This would've been something nice to have at that time - I would be able to, without having two phones, have personal and work related Whatsapp numbers on seperate places (but still accessible when needed).
- t1tech 3y agoThis is exactly one of the use cases of cophone.
- sitzkrieg 3y agoif you're getting a lot of "i dont get the point" comments on HN from a very technical crowd, you're probably onto a new market need or WAY off depending :)
- t1tech 3y agoHaha, only time will tell. But there are already some patterns that can guide me further, so I appreciate all the feedback and try to learn from it.
- hugs 3y agoSoftware/app testing (manual or automated) is always a killer app for stuff like this. And my anecdotal observation of HN over the years is that most of HN doesn't get the point when it comes to anything that could be a killer testing tool. Running browsers on desktop OSes in the cloud? I don't get it! (My first startup) Robots to automate tapping on phones? I don't get it! (My second startup) I'm not surprised people don't understand the value of something like Cophone. It doesn't mean the value isn't there. It just means they probably don't spend enough time dealing with software testing issues to see the potential.
- jollyllama 3y agoThis is pretty cool. I could just carry a laptop around and pull up my "phone app" when I need to, and forego the need to carry around a phone.
- t1tech 3y agoYou can use your personal phone to access it, BYOD style but completely separated from your personal data.
- SkyPuncher 3y agoThis is an amazing concept! Right now, I carry around two cell phones - work and personal. My use case for my work device is surprisingly limited. I basically need it for notifications and 2FA. For anything serious, I switch to my laptop. However, I _really_ need that work phone. BYOD/Shared devices is a thing at many companies, but that comes with it's own host of issues. Most notably, I don't want a corporate MDM on my personal phone. I also want to be able to let my family use my personal phone without worrying about breaking. This virtual device, effectively lets me carry a single device while having nice, clear boundaries. As long as notifications come through well, this could effectively replace my need to carry a work phone.
- t1tech 3y agoThank you for the feedback! Indeed, this is something that I have learned from the comments here: that cophone needs to forward the notifications from the virtual smartphone to the physical one(s). Will put it on high priority!
- rsync 3y agoLeave the work phone plugged in at office and forward messages to an email inbox (or personal phone SMS) using the SMSForwarder app.
- SkyPuncher 3y agoCan't do that. Breaks privacy barriers.
- jarebear6expepj 3y agoI have encountered a lot of problems trying to rely on virtual numbers from various VOIP providers. Very curious how that plays in to your stack. I know for instance a lot of Twilio is default blacklisted, but larger ORGS/ISP's who run essentially the same virtual VOIP (such as Comcast) but at different scale have no problems. Why is there a difference? Who is determining bad VOIP from good VOIP? Are there steps you can, or are, taking to work on having your numbers legitimized? Where are you sourcing your numbers? I'll take my questions off the air :). Thanks!
- t1tech 3y ago> Why is there a difference? Who is determining bad VOIP from good VOIP? I don't know :( > Are there steps you can, or are, taking to work on having your numbers legitimized? Sourcing the phone numbers from a company with a reputation to defend - Twilio - is the main method. > Where are you sourcing your numbers? Twilio
- rsync 3y agoI don’t think it is correct to say that twilio numbers are blacklisted - rather, they simply test/lookup as not true mobile numbers. Which they aren’t. Your bank then decides not to send codes to non mobile numbers but it’s not because it is a twilio number per se…
- ajot 3y agoVery nice, I like it. As a total ignorant on this space: a) how is this different from Canonical's Anbox in the cloud offering? b) could I use this to run banking apps that won't run in my phone (mainly due to the unlocked bootloader)?
- t1tech 3y agoa) AFAIK Canonical's Anbox does NOT give you a phone number. Also afaik, they don't provide a recent Android version, so you're stuck with a really old version. b) This is a really good point! I don't know atm, I'll have to look into it.
- ajot 3y agoThank you for your answers! I'll keep your company in mind, hope everything goes great!
- xnx 3y agoI love this as a way to circumvent per-device two-factor authentication that is increasingly being required to prevent login sharing.
- batch12 3y agoIs this a problem a lot of people are having?
- xnx 3y agoProbably not. I personally hate when services dictate the authentication method that must be used instead of leaving that up to the user (with sensible defaults, and the option of 2FA). I like that this service could give back some of that control.
- deleted 3y ago[deleted]
- paxys 3y agoLooks neat, but I'm curious what the actual use case of something like this is. What can you do on a phone emulator running on some server and accessed from your browser that you can't just...do directly on the browser?
- contingencies 3y agoNice project. Commercially, I would suggest that you white label this at a heavily discounted wholesale rate to VOIP providers. They have existing channels and user base that should allow you to scale without huge marketing investment, and once one or two of them bring your service onboard the rest should buy in. Alternatively, just sell it out to a larger player and move on.
- t1tech 3y agoThank you! That's great input! This is all very fresh so I'm still building connections. I have to admit Voip providers were not on my list but it totally makes sense.
- contingencies 3y agoMore broadly you could look at global serviced office providers, people like https://www.servcorp.com/en/about-us/ https://www.servcorp.com/en/about-us/ or even https://www.wework.com/ https://www.wework.com/
- tjoff 3y agoThis seems great, and I've always wanted something like this (though for me, the cloud is a dealbreaker). A bit too expensive for my uses, I think the corporate use-case makes much more sense so good for targeting that! I'd prefer to have a virtual machine on the phone where I could isolate apps etc. Would be nice with a second phone number tied to that virtual machine, maybe a sip one could work. But since that doesn't seem to materialize I'm playing with the idea to have an old phone at home and remote into it using VPN+VNC or something from my real phone. Would work in theory but last I experimented with it the experience was pretty bad.
- nikolay 3y agoI paid and now keep getting "Your phone is starting" and it's spinning forever and never finishes.
- deleted 3y ago[deleted]
- t1tech 3y agoSorry again for that, we had some issues scaling up. Your cophone is up and running!
- ggm 3y agoCan you talk a little about the legalisms -Here's a few: How did you get an Indial group, what T&C did you sign up to? Does host know you terminate and originate phone from this service? Do you have to make a statutory declaration about EMS geolocation? What's your STIR/SHAKEN/SPAMACT requirements? Do you have KYC and AML licencing? Are you actually a registered telco, and have common carrier licencing? Do you have a warrant canary? I'm not trying to white-ant you. If you go into widespread use, I'm sure these will be asked. Different economies have different regulators and rules.
- smartbit 3y agoRidiculous pricing. Acrobit Groundwire mobile SIP client [0] costs $10 once and is EU based therefore GDPR compliant. Add a prepaid SIP provider, mine charges less than $10/year for the number plus calling costs that are so low I don’t notice then. Once in a while I add $100 credit to my SIP provider, good for several years with 3 numbers. For incoming calls Groundwire send a notification that pops up the app and shows the UI. Works flawlessly, many options for deniing calls, forwarding etc, etc. Some numbers are shared with others, just disable it on my phone and the other person enables it to start receiving incoming calls. I really don’t see the business case for paying $10/$15 per month. [0] https://en.wikipedia.org/wiki/Acrobits https://en.wikipedia.org/wiki/Acrobits
- oriettaxx 3y agocan you disclose your SIP provider? or suggests any?
- _8j50 3y agoI like the idea but from a security perspective this has even more issues. Mobile devices get ratted all the time, even cheap and modest RATs just screenshot the whole screen frequently, how can the site enforce screenshot prevention? Assuming the malware doesn't have a bypass for that of course or simple things like malicious keyboard apps and browsers (defeating the best 2fa)? Practically, it is best to have a work phone with a removable battery you take out when nott working and use for no other purpose. Ideally, smartphones are not fit for any purpose that involves sensitive and highly impactful (you get fired, jailed, divorced,etc...) purposes. But for me, I could actually use this if I am ever forced to use a mobile phone. Even for personal use, i am struggling painfully with android x86 in a vm! I like the product.