11 ms·
Cell Service for the Fairly Paranoid
- jerlam 8mo agoSecondary numbers sounds neat: https://www.cape.co/blog/product-feature-secondary-numbers https://www.cape.co/blog/product-feature-secondary-numbers I've been using my Google Voice number for something similar. But Cape doesn't specify if/when these numbers are rotated in any way - you have three numbers to track now, and you can't retain these numbers if you switch services.
- alek-cape 8mo agoIt's probably worth calling out that this is an experimental feature, and we are happy to get any and all feedback on things we can build out around them. They are real numbers, not VOIP. That can matter depending on what they are used for and if the entity you are expecting a message from blocks sending to VOIP numbers. The numbers don't rotate like our identifier rotation. They are yours. You can choose to delete a secondary number in the app, and if you have less than two, create a new one after 30 days.
- treetalker 8mo agoIf anyone uses this and could tell us about your experience, please do!
- mingus88 8mo agoI’m a skeptic. It’s only been a handful of years since Anom was backdoored by the Feds. The surveillance data provided by cell phones is simply too good to let someone work around it https://www.vice.com/en/article/anom-backdoor-fbi-years-of-arrests/ https://www.vice.com/en/article/anom-backdoor-fbi-years-of-a...
- cucumber3732842 8mo agoIf you're not doing "fed" level shit and just don't wanna make your petty shit trivial for the locals to dredge up that's probably fine. Like they're not gonna burn that kind of capability over tax evasion, state civil law violations, etc.
- johndoylecape 8mo agoThis Anom comp comes up a lot. It's super hard to prove a negative, so no matter many how times I say "Cape is not a honeypot," the critics will just respond "that is exactly what a honeypot would say." We're working on some ideas to address this with audits etc, but it will always be tough. However, if you like the idea, and like the features, then maybe it is worth your time to do the work and get comfortable with the company. Because we're the only ones providing some of these features, and we have a lot more in the hopper still to come. I hope we can win your trust at some point.
- jrexilius 8mo agoGood luck! It's a tough sell and some people won't accept that there are people from the defense sector that really care about the Constitution. Transparency is proly your best friend. But once you sign a Qualcom or carrier NDA, you are pretty tied-up as far as open-sourcing things or transparency, I'd imagine. Still, keep up the good fight!
- johndoylecape 8mo agoAlso, the reporter who broke the Anom story has written about Cape a couple of times: https://www.404media.co/i-dont-own-a-cellphone-can-this-privacy-focused-network-change-that/ https://www.404media.co/i-dont-own-a-cellphone-can-this-priv... https://www.404media.co/privacy-telecom-cape-introduces-disappearing-call-logs-that-delete-every-24-hours/ https://www.404media.co/privacy-telecom-cape-introduces-disa...
- fc417fc802 8mo agoI have no particular reason to trust that you aren't a honeypot but I'd like to point out that I also have no particular reason to trust that any other cell service provider isn't. In fact given the recent e911 location data sale scandal I generally assume that all of them are. Even if it turned out that you were in fact a honeypot, protection against SIM swapping and encrypted voicemail presumably both provide security benefits regardless. It's similar to the situation with VPN providers. The provider could literally be the NSA themselves and I'd _still_ most likely see security benefits from using it (unless the NSA happens to be my adversary of course).
- dguido 8mo agoI use Cape every day on my iPhone. The service is excellent, and the security features haven't ever interfered with my use of the phone. They have a convenient mobile app for setting up extra features like the IMSI rotation and getting support. As a tech savvy user, it matches what I want. I'm a target for a variety of things, and knowing that no one can SIM swap me is worth the subscription alone. The SS7 protections, encrypted voicemail, secondary numbers, IMSI rotation, etc are all a bonus.
- rsync 8mo agoYou would be better off hosting your “phone number “at Twilio and then forwarding that number to a throwaway SIM card that nobody knows the number to. Your “phone number “that people interact with cannot be hijacked with SS7 because it’s not a real number… you’re immune to sim swaps … And you can Jettison your physical phone and SIM card at any time with no penalty. As a bonus, because your actual phone number is now programmable you can do interesting things like set up a SMS firewall. You can, for instance, collapse all incoming text messages to ascii-256. Or truncate their overall length. Or CC your incoming SMS to a dedicated mailbox. I have operated like this since 2016. I have no idea what my physical SIM phone number is and neither does anybody else.
- dlenski 8mo agoFrom their "Features" drop-down: > Minimal Data Collection > Identifier Rotation > Secondary Numbers > Disappearing Call Logs > SIM Swap Protection > Network Lock > Encrypted Voicemail > Private Payment > Last-Mile Encrypted Texting > Secure Global Roaming "Identifier (IMSI) Rotation", "Secure Global Roaming" and "Network Lock" do look interesting *IF* they can actually address some of the baseband vulnerabilities that plague all modern devices. That's a Big If. SIM Swap Protection you already get by using a VoIP number rather than a cell number. And the other features are irrelevant if you're using over-the-top end-to-end encrypted messaging, like Signal, rather than Plain Old Telephone Service and SMS.
- 0xWTF 8mo agoThey built their own mobile core, does that help with resolving your "Big If"? I'm not a cellular guy, I don't know which pieces of the stack cover which attack vectors: I'm genuinely asking. Also, the 50 foreign countries seems interesting.
- dlenski 8mo ago> They built their own mobile core, does that help with resolving your "Big If"? Not really, but I too am uncertain about how to think about it. Here's my long-winded but still limited understanding of the main vulnerabilities that are unique : NETWORKS: If I build a network, and I build it out of switched Ethernet, and I control the premises completely, then I can generally trust that the data flowing through it isn't being secretly logged or tampered with. Moving away from this simplicity, my distrust of the network increases rapidly. A cellular network is pretty much the opposite of this simple one-man, one-room, wired network, so I distrust it completely. There is only one credible solution here: all traffic over the network must be end-to-end encrypted and authenticated. That means TLS/DTLS/QUIC/ESP/Wireguard with key-pinning and/or correctly implemented and maintained PKI. Assume that any and all traffic that is not E2E-encrypted and authenticated is subject to some combination of mass surveillance and/or individually-targeted attacks. CELLULAR DEVICE HARDWARE: For historical reasons, modern smartphones contain [at least] two CPUs: 1. The main "application" processor, an ARM64 SoC running an OS and applications made by Google or Apple. They've put substantial efforts into hardening these OSes and applications against remote attacks. Whether they're doing "enough" is another question; whether you should trust them is another question. But they're at least trying pretty hard to prevent rando malware-for-hire attackers from pwning your device via over-the-air vulnerabilities. 2. The "baseband" processor, a ghastly fossilized thing that runs a stack of overly-complex firmware dating back to 2G days, and controls access to the cellular network. It is probably developed by Qualcomm, which along with Samsung has a near-monopoly on baseband processors for modern devices sold outside of China. Qualcomm in particular is litigious and complacent about security issues (https://news.ycombinator.com/item?id=38620067 https://news.ycombinator.com/item?id=38620067), and almost everything about the processors and their firmware are closed-source and non-public. The baseband processor is insecure both due to inattention, as well as treachery. The end user of the device does NOT control it in the way that the end user controls the main processor. Some nebulous combination of the baseband vendor, the carrier, and the government controls it (e.g. https://news.ycombinator.com/item?id=46848303 https://news.ycombinator.com/item?id=46848303). So the baseband processor is an untrustworthy thing that should be walled off from the rest of the system, and only allowed to communicate with the rest of it via narrow and well-defined interfaces. However, this was not the case for many years: the baseband processor has had way too much access to the system. In recent years, this situation has improved somewhat: recent Pixel devices with Google Tensor SoCs (and maybe others) have the baseband isolated via an IOMMU. https://grapheneos.org/faq#baseband-isolation https://grapheneos.org/faq#baseband-isolation --- Okay, so can "Cape" do anything to assuage my concerns about _any_ of the above issues? Honestly, not very much. ¯\_(ツ)_/¯ Cape can't increase my trust in the cellular network. Cape can't increase my trust in the baseband processor on my device. Cape can only do a couple things to make the baseband and the network Slightly Less Evil: shuffle IMSI frequently to prevent IMSI-based tracking, and don't let random scammers call up and SIM-swap me.
- buttocks 8mo agoWill not pass muster with FCC. Know Your Customer regulations require the company to … know the customer. They will not last.
- gruez 8mo ago>Know Your Customer regulations require the company to … know the customer Which KYC regulations exist for carriers? AFAIK you can walk into any store and get a SIM card. The most they ask for is maybe E911 which they don't check.
- whiterock 8mo agonot in Europe no more for a few years now.
- gruez 8mo ago"Europe" isn't a monolith, and there are quite a few countries that don't require any KYC, UK and NL to name two.
- jrexilius 8mo agoYou don't need an ID to buy a SIM in UK? I remember not needing one a long time ago but in recent years was asked for one.. maybe not a law? irregularly applied?
- psim1 8mo agoCarriers both land/VoIP and wireless must attest to having fraud mitigation measures; this is the "Robocall Mitigation Database" and in Cape's record they exempt themselves from STIR/SHAKEN attestation but state they have measures to prevent fraudulent calling. (which is required for them to be permitted to operate) What kind of measures are possible to prevent fraudulent calls when the caller is your anonymous customer? The answer is obviously "none," unless you respond to every complaint by terminating service of the offending customer and hoping they don't come back.
- throwaway57572 8mo agoYou might check out who the CEO is here and how he runs the company and then consider whether you'd trust them. And look at the infra providers they use. Not what I would call the most upstanding bunch.
- helterskelter 8mo ago...care to elaborate?
- theearling 8mo agoPalentier and A16Z connections...
- Ms-J 8mo ago"but... but... trust me!" By the way, if you look at this thread you can see Cape has deployed narrative control.
- nxobject 8mo agoThis probably doesn't cover what OP said, but after reading the CEO's intro post, I left a little more depressed. Make money off surveillance, and then make money off selling a privacy product. > At Palantir, where I started in technical roles more than 10 years ago, I learned about a wide array of vulnerabilities in the cellular network that present a threat not only to mission-focused organizations in government, but also to everyday people. I came to see mobile phones — and the networks that power them — as perhaps the largest risks to our privacy and security. > If you told Americans twenty years ago that corporations and governments would conspire to attach powerful tracking devices to nearly every adult worldwide, it would’ve sounded like science fiction. And yet, that’s not far from where we are today. https://www.cape.co/blog/building-the-future-of-mobile-privacy?g=int https://www.cape.co/blog/building-the-future-of-mobile-priva...
- johndoylecape 8mo agoI hear what you're saying, though another framing would be "learn about serious problem, build company to fix serious problem."
- monster_truck 8mo agoDo not fall for a word of this. If you've spent any time dealing with actual SIP providers (ie not the shit you'd hook an app up to, the ones debt collectors use), you'll know exactly how much you can trust them. Same difference
- dguido 8mo agoI have a conflict of interest here (I am an advisor to Cape, also a security expert, and my company has done security audits for Cape), you should absolutely look more deeply into what Cape has created. Their service is fundamentally different than other "security-focused cell providers" (mostly snake oil IMHO) because Cape wrote their own mobile core, nearly from scratch. They control the whole software stack and have done really innovative things with it. Here are a few things you might want to look at more closely: Encrypted voicemail uses public key crypto: https://www.cape.co/blog/product-feature-encrypted-voicemail https://www.cape.co/blog/product-feature-encrypted-voicemail How they use full control of the mobile core to detect SS7 signaling attacks https://www.cape.co/blog/product-feature-network-lock https://www.cape.co/blog/product-feature-network-lock Swapping SIMs is done via digital signatures, not customer support https://www.cape.co/blog/cape-product-feature-secure-authentication https://www.cape.co/blog/cape-product-feature-secure-authent... They're the only provider that can rotate your IMSI, and do it continuously for you https://www.cape.co/blog/product-feature-identifier-rotation https://www.cape.co/blog/product-feature-identifier-rotation They're also one of very few organizations doing original research on cell network security: Collaborating with the EFF to release software for detecting cell site simulators (e.g, imsi catchers et al) https://www.cape.co/blog/how-eff-and-cape-collaborated-to-improve-detection https://www.cape.co/blog/how-eff-and-cape-collaborated-to-im... Identifying novel weaknesses for physically tracking people on cell networks https://dl.acm.org/doi/pdf/10.1145/3636534.3690709 https://dl.acm.org/doi/pdf/10.1145/3636534.3690709
- anonymous541908 8mo agoIs it free and open source software?
- roughly 8mo ago
- helterskelter 8mo agoHow does this compare to Phreeli [1]? Has anyone here used either of the services? 1: https://www.phreeli.com https://www.phreeli.com
- Noaidi 8mo agoPeel really only protect your privacy at the level of purchase. Not associating your name address or any other data with your phone number. Cape seems to be doing something far more technical so that no one can locate you by your phone number using ordinary triangulation.
- konaraddi 8mo agoI hope this succeeds and isn’t backdoored
- wao0uuno 8mo agoIt's a pretty obvious honeypot. They're promising privacy even though they can't realistically provide it. The whole thing has ties with American surveillance companies. It's Operation Trojan Shield all over again.
- LorenDB 8mo ago> Enjoy unlimited high-speed data; after 50GB, speeds may slow to 256 kbps. Last I checked 256 Kbps is not high speed. You can advertise this as unlimited data, or you can advertise it as 50 GB of high-speed data, but you can't call it unlimited high-speed data.
- johndoylecape 8mo agoThat's a fair point, we should change that verbiage.
- quietsegfault 8mo agoWhy can’t it throttle to something slightly higher? Even 100-200 KBps? Is that a requirement from the “upstream” network provider?
- johndoylecape 8mo agoIt's not. We chose this baseline sort of by default based on the practices of some other major carriers. Your question is a good one, and we'll take it as feedback.
- altairprime 8mo agoI would be a lot less worried about signing up for that plan if I could soft-cap myself at 10GB until I login to the app and push a button that says "yeah for real I'm going to use another 10GB of mobile data", so that if iOS goes bonkers and tries to download my entire 90GB iTunes library over cellular, it doesn't fuck me over for a month. I haven't exceeded 7GB/mo intentionally for years, but it's happened twice so far against my express wishes, and carriers are uniformly awful at that.
- bsstoner 8mo agoThis is good feedback. We don’t want caps and throttling to be a blocker for signing up and using us. Since we’re at a premium price point we should economically be able to be a lot more generous than existing carriers.
- gruez 8mo ago>Identifier Rotation >Protect yourself from persistent tracking by rotating your IMSI every 24 hours, so you appear as a new subscriber each day. But nothing for IMEI, which is fixed for a given device. Unless you got a new phone to use with this service, it can instantly be linked back to whatever previous service you're using. If we assume that whatever carrier they partner with keeps both IMEI and IMSI logs (why wouldn't they?) it basically makes any privacy benefits from this questionable. It's like clearing your cookies but not changing your IP (assuming no CGNAT). The other benefits also seem questionable. "Disappearing Call Logs" don't really help when the person you're calling has a carrier that keeps logs, and if both of you care about privacy, why not just use signal? They're asking $99/month for this, which is a bit steep. If you only care about the rotating IMSI, don't care about PSTN access (ie. no calls/texting), you can replicate it with some sort of data esim for much cheaper. The various e-shops that sell esims don't do KYC either.
- bsstoner 8mo agoHi -- Head of Product at Cape. This is a good question. I will say up front there is no silver bullet for privacy on cellular networks given the way they were designed to interoperate. Our strategy is to offer many different protections that collectively make it harder for your activity to be tracked. The details of what our carrier partners can see is in the table at the bottom of our privacy summary: https://www.cape.co/privacy-summary https://www.cape.co/privacy-summary. We add noise to their data by doing things like rotating your IMSI daily and spreading traffic among multiple carrier partners. If the data is messy enough and not associated with your personal information, there should be less monetary incentive for the carrier to try to piece it together when they have an abundance of clean data with stable identifiers and verified personal information. Additionally, with disappearing call logs, it's about reducing surface area. Fewer logs in less places.
- montyanne 8mo ago> We add noise to their data It’s interesting that Apple is going down a similar path with hardware filtering location retrieval commands and neighborhood-level blurring on their C1 modems. Really awesome work from that team by making sure they’ve considered privacy as a first party feature for that chip. How do you guys view the relative value of privacy/security at the network provider layer of the cell stack for the average user/citzen? Even if Cape doesn’t retain metadata yourselves (eg LTE positioning info), is that data not still retained and repackaged by the tower owners themselves? Eg babel street, venntel, etc. A rotating IMEI every 24 hours might make it marginally more difficult for logical tracking, but there’s still only physically one location the phone can be in without fuzzing at the hardware level. I should also say - I’ve been following y’all’s work for a while (and considered some of those early forward deployed engineer positions), but I’m struggling to see how this all works as a consumer product. Would be awesome to see an eventual partnership with Apple/Qualcomm to bring this to the hardware level since privacy is a tough nut to crack even at full MVNO.
- iamnothere 8mo agoUnfortunate that it doesn’t seem to support Linux phones. Phreely or Purism’s AweSIM would be a better fit for anyone running a non-Android/non-iOS setup. Hopefully they add this in the future.
- efficax 8mo agoNo way this isn't funded by the CIA
- burnt-resistor 8mo agoIn-Q-Tel probably.
- Bender 8mo agoFrom Gemini: based in Arlington, VA, is primarily funded by high-profile venture capital firms, including Andreessen Horowitz (a16z), which led their Series B, A Capital, Costanoa Ventures, ex/ante, Point72 Ventures, and XYZ Ventures.* Arlington, VA ... is an interesting location that aligns with your guess. A similar situation happened some time ago with a drug cartel that thought they built their own private phones and phone network. I am not saying it's related, just feels similar.
- mzmzmzm 8mo agoSo it's an MVNO mostly on the AT&T network with extra privacy features? I think it still all then comes down to how you use your phone and how much you can trust the whole pipeline. I use Credo Mobile which doesn't seem totally different. https://www.credomobile.com/our-story https://www.credomobile.com/our-story
- drnick1 8mo agoWhat about crypto payments? How does this compare to silent.link?
- Ms-J 8mo agoI've looked into this company before and when I saw who was behind it and on the team it was an immediate red flag to never use or trust this company. Look at who Doyle has worked for previously and what connections he has. Palantir and the military, to start.
- johndoylecape 8mo agoDoyle here :) I'm very proud of my military service! Prior to Cape, I led the national security business at Palantir. That experience was actually the catalyst for Cape. It’s where I first learned about the massive array of vulnerabilities that exist in our current cellular networks. I saw how those gaps impacted not just government organizations, but everyday people, and I realized that the mobile phones we carry every day are perhaps the single largest risk to our privacy. I needed that experience to understand the depth of the problem, but once I left to start Cape, that connection ended. Cape has no ties to Palantir. We aren't a subsidiary, we aren't a "front," and we don't share data with them. The only thing we took from Palantir was the desire to fix a broken system. If you want to see me and some of the rest of our founding team talk more about this topic, you can watch this video on our Instagram page here. Another related theory I’ve seen online is that Cape is a honeypot for law enforcement. Cape is not a honeypot. It’s so hard to prove a negative, but at least I can say it clearly and out loud: Cape is not a honeypot. We are a group of individuals who deeply value privacy. That mission carries across everything we do, from our work with the US government and allies, to everyday people, and everything in between. We are incredibly proud to work with people who protect our country by ensuring they have secure, trusted communications wherever they are. https://www.bloomberg.com/news/articles/2024-04-18/us-navy-trying-experimental-tech-to-protect-guam-from-hacks https://www.bloomberg.com/news/articles/2024-04-18/us-navy-t... We also work with the EFF to provide investigative journalists and activists with free Cape service so they can do their work safely. https://www.cape.co/journalists-and-activists https://www.cape.co/journalists-and-activists We partner with non-profits to support victims of domestic abuse who are facing cyber-stalking and digital harassment. https://www.cape.co/break-free https://www.cape.co/break-free We are a young company growing exponentially, and we don't plan on slowing down. We know we have to earn your trust every day. The truth is, no one else is building a high-quality, first-class solution to these specific cellular problems. We are committed to being the ones who do it right.
- floam 8mo agoThere’s a chance this catches on with some folks with blacklisted IMEI’s due to a quirk on AT&T MVNOs where service works for a few days before getting halted per IMSI.
- maybsum1else 8mo agoi think this thread is a honeypot
- johndoylecape 8mo agoYou just made the list.
- loteck 8mo agoHi Cape team, I'd like a service like yours that allows private signups and that works continuously to prove ongoing private operations. I don't need huge data plans, I'm fine with WiFi mostly. It needs to cost way less per month than your current pricing. It would be cool if you could find a way to serve people like me.
- bsstoner 8mo agoAppreciate the feedback, we’ll likely experiment with different plans down the road, but for now we’re focused on rolling out as much additional privacy/security value as we can to justify the premium price point.
- mr_machine 8mo agoI on the other hand am fine with the premium price... but it looks like I'd need to install a proprietary app to use the service. That's a 'hell naw' from me.
- rsync 8mo agoIt would be more useful and beneficial to have a privacy oriented twilio than a privacy oriented carrier. If we treat the carrier as adversarial, dumb pipes we can move the security and all of the capabilities into the cloud platform. A personal comms stack like this should be carrier-agnostic, phone-agnostic, sim-agnostic. See my other post in this HN topic - I have done this since 2016 ...
- Doohickey-d 8mo agoAnother option for anonymous mobile service: https://silent.link/ https://silent.link/ eSIM, global, variable pricing per country with per-GB billing, anonymous crypto payments and no KYC. Although it seems to not have some of the additional security features of the OP.
- anon5739483 8mo agoMaybe have an onion web service and add direct Monero payment support. This will help privacy LARP'ers get into the mood. Truth be told, if you're paranoid by any measure and use a cell phone -> YNGMI. It's not cheap enough for average person to care and not private enough for ulta-paranoid to pay and use. The whole mobile infrastructure is utterly broken in terms of security and privacy so it's still refreshing to see any kind of attempt being made in this area.
- bartvk 8mo agoFYI, I had to walk through the first dozen or so steps of the signup form to figure out that it's available in the US only. I suspected as much, but I figured I'd post it here, since it's not in their FAQ.
- chasil 8mo agoThis is also $99/month, and likely rides on another major network as an MVNO.
- jp0001 8mo agoHold on. Cell towers still know where the device is. If a group of people in an area have stable ismi’s and one person’s ismi is rotating daily, it doesn’t take a genius to figure out who’s now using cape. Using it for travel makes sense, but again being a device that doesn’t a have an owner is, as the kids say, sus.
- inigyou 8mo ago[dead]
- bsstoner 8mo agoIt depends what your threat model is. Most telco data collection and resale is based on IMSI’s attached to KYC’d customers. If they can’t get personal information and the IMSI looks like it’s a day old, that data is inherently less valuable to data brokers. The large telcos have plenty of clean data with stable IMSI’s tied to KYC’d customers that is worth more.
- voidUpdate 8mo agoDoes cape use its own cell towers, or do they rely on third parties to provide the actual infrastructure? And if they do use third parties, are they sure that they aren't also storing data about the connected devices etc?
- bsstoner 8mo agoWe don’t operate our own towers and as you point out we can’t control what someone there does. Our privacy and security model is to treat the towers as untrustworthy. This is why we do things like rotate your IMSI daily or split your traffic across multiple underlying network partners. We want to make any data that is collected noisy and less valuable to data brokers.
- deleted 8mo ago[deleted]
- pona-a 8mo agoI have some questions about the "Last-Mile encryption" and "Encrypted Voicemail". Does Cape receive cleartext and resend it encrypted? What does this achieve? Integrity? Does the service drop unencrypted messages?
- bsstoner 8mo agoWe receive in cleartext and encrypt with a key controlled by the customer. Most carriers store voicemail and SMS in cleartext on their servers. The goal is reduce exposure while preserving interoperability. This post on encrypted voicemail gets into more technical details about how it works: https://www.cape.co/blog/product-feature-encrypted-voicemail?slug=blog https://www.cape.co/blog/product-feature-encrypted-voicemail...
- AdamN 8mo agoI know it'a a bit of a pivot but the following would make me move: 1/ eSIM activation outside the US 2/ The family plan is weird. My wife and I don't want to manage two separate bills. 3/ multiple eSIMs and numbers in different countries all within the one account (Germany in particular)
- Aromatic_War 8mo agoIt’s rare to see an MVNO thread get into the weeds of the mobile core, but as a Full MVNO, Cape is essentially running its own sovereign telco infrastructure. From an outside perspective, they are definitely among the few who are treating the signaling plane with the proper level of scrutiny (they built their own signalling firewall) But even with a proprietary core and a signaling firewall, Cape is still an island in a sea of legacy protocols and peer MNOs with different intentions... I'd be interested to see how they are hardening the IMS (IP Multimedia Subsystem) and VoLTE/VoWifi stack. SIP signaling and RTP streams for voice are often unencrypted internally. If Cape is applying their 'Network Lock' logic to the IMS layer, they could potentially mitigate SIP-level spoofing and voice interception that occurs at the interconnect. Their 'Encrypted Voicemail' (using asymmetric keys on the device) is a strong signal that they understand the 'Last Mile' problem. Also even if SEPPs are not really a thing, i'd be curious to know if they've started looking at this. In the small world of telco security (disclaimer i work for P1Security), they are definitely working in the right direction. Any international ambition, particularly in EU, will be a tough sell though....
- simfree 8mo agoMitigating SIP and TDM spoofing requires broad cooperation among every other Telecom provider. That doesn't exist today, you can't prevent people from spoofing your number.
- dakolli 8mo agoPartnered with EFF, might as well say this is a US government honey trap.
- varispeed 8mo agoWhy this gives honeypot vibes?
- ddtaylor 8mo agoI guess making honeypot phones and calling them secure fell out of fashion, so now we backdoor at the carrier level?
- horoscope_slump 8mo agoFirst, I think we can learn some stuff from looking at how the US government actually operated its known honeypots to evaluate the likelihood of Cape being a honeypot. First, when it ran Anom, it went out of its way not to collect data on persons inside the United States. U.S. Anom users never had any of their data captured by the FBI because it raised profound 4th Amendment concerns. Cape is operating in the U.S. and is seeking U.S. users. Typical U.S. honeypots are generally targeted abroad. Second, the U.S. government has historically not used former military officers with ties to defense contractors as the people that built and operated the honeypots. With Anom, they co-opted trusted members of the secure phone community. The very fact that the company is very open about its founders is a pretty good sign that they are probably not a honeypot because they would not make a very good honeypot for the truly criminal element. Third, Cape is incorporated in the United States and seeking U.S. users. In the process, it's making some fairly aggressive claims in its privacy policy and terms of service about its products that would subject them to breach of contract and fraud claims if in fact they were secretly not doing those things. Fourth, the legacy telecoms have a long history of selling your data, secretly cooperating in national security programs of questionable legality, etc. It seems like Cape can't possible a worse option than the status quo.
- hrimfaxi 8mo ago1. Citation needed. People in the US were arrested under this operation though they were foreign nationals. 2. History matters until it doesn't. There was a time when the US did not perform science experiments on unsuspecting populations, too. The government does not get the benefit of the doubt when it comes to "past performance is not indicative of future performance". 3. We have seen sitting presidents pardon people for crimes they have yet to commit. 4. "Not worse" is not a selling point.
- 8mo ago
- driverdan 8mo agoWhy is this so much more expensive than other MVNOs? Mint Mobile, for example, is $30/m for unlimited. Most MVNOs can be funded anonymously, through in store purchases.
- 306bobby 8mo agoI believe for reasons Aromatic_War stated in a top comment above: they're actually doing novel stuff with their control planes, not just using what's already there like most MVNOs
- johndoylecape 8mo agoThis is right. Deploying our own packet core and IMS core, building our own BSS from scratch. All of this stuff is expensive (and hard). We're hoping to be able to bring the price down over time.
- dmarks100 8mo agois RCS support planned in the future?
- fortranfiend 8mo agoGuess I'm more paranoid than fairly. Id class this in a wait and see category maybe try it out on a secondary device for a trial run. You'd have to have the need to their services to justify the cost or just not care about cost.
- mrbluecoat 8mo agoPair it with your Dark Wire phone for perfect anonymity! /s https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/ https://www.hachettebookgroup.com/titles/joseph-cox/dark-wir...
- ranger_danger 8mo agohttps://piefed.social/c/privacy/p/1813919/privacy-cell-service-provider-cape-was-created-by-former-palantir-employee-funded-by-an https://piefed.social/c/privacy/p/1813919/privacy-cell-servi...
- ThePowerOfFuet 8mo agoCan't even roam in the EU with it? Useless for an awful lot of HN.
- vivzkestrel 8mo ago- this is my biggest gripe with any of these privacy products - how do I know you are actually implementing what you claim on your webpage?
- fnikacevic 8mo agoAnd how do we know it's not another FBI/CIA honeypot?
- OhMeadhbh 8mo agoIf only they supported physical SIMs, I could use it on my punkt phone.
- 4d4m 8mo agoAny plans on how to secure the hardware layer, where phone modems and infra equipment are insecure/rooted by design?
- pibaker 8mo agoThe problem with every service targeting "safety conscious" people is that by virtue of using that service you mark yourself as someone with something to hide and draws attention. The lack of signal is a signal in itself. It's like walking into a bank wearing a ski mask. Yeah we don't know who is under the mask but we know there is probably something fishy going on. Your best bet at staying safe is always to not raise any attention at all, and that usually means doing what the average citizen with 2.4 kids does.
- floam 8mo agoPlease add an arbitration opt out option or better yet ditch requiring people who care about their rights waive their right to a trial and jury.
- ownash 8mo agoI used cape for a while - they had a promo where the service was cheaper. I'll be honest, the service itself - the signal I got on the device - was just not worth the full price of $99. It could just be my area. I also had to constantly turn voicemail on and off or else I wouldn't get voicemails. The customer support team was great to work with and actually extended the trial price for me. But ultimately, the service just does not seem competitive on a usability level with major carriers and this was an issue for me. It very much could have been my local area but Verizon and T-Mobile are far, far more reliabl and comparable in price.
- bsstoner 8mo agoThanks for trying us out and for the feedback. We are have had some bugs with voicemail that we should have resolved now. And improving the network is our #1 priority this year. Hopefully you'll give us another shot down the road!
- snapplebobapple 7mo agoYou guys coming to canada any time soon? I would switch on a heartbeat