Phone Privacy is Even More Important Than You Think

Ruddy Wang talks about phone privacy and why the system right now doesn't exactly work.

You probably know at this point that your phone knows a lot about you. But if you’re concerned about privacy, bad news: Your phone (and your carrier) know a lot more about your daily life than you probably realize. And the way the global phone systems are built means that criminals can intercept your communication without you even realizing. If you want to shore up your phone privacy, learn what your phone knows about you and what you can do to make it more private and secure.


See Hidden Phone Tracking with Ruddy Wang for a complete transcript of the Easy Prey podcast episode.

Ruddy Wang started his career as a U.S. diplomat working in embassies all over the world. Even back then, embassies knew that phones gave away a lot of information and didn’t let them inside. Eventually, he moved from diplomacy to technology and ended up joining Facebook. It gave him his first insight into how companies collect people’s data, and also some of the ways it can be used against them. After nearly two decades launching and scaling businesses around the world, he became the Head of Consumer Growth at Cape, a privacy-first mobile carrier that collects as little data about consumers as possible. The company excited him both because he could see the use cases of a private and secure mobile carrier, but also because he’s a cell phone user like everybody else and likes that it gives people the ability to opt out of the surveillance economy.

What Our Phones Give Away

Phones give away a lot of data by default. To provide service, phones have to be constantly looking for the closest cell tower. That gives away your location, which is obviously sensitive data. It reveals where you live, where you work, where you worship, medical appointments you go to, and all of the patterns of your life.

Any phone, by nature of just providing you with cell phone service, has to be looking for the closest cell phone tower … as a part of that, it gives away a bunch of metadata.

Ruddy Wang

Your phone also gives away information about your contacts and how you’re contacting them. It can reveal who you’re calling or texting, when you’re doing it, how often, and where you’re doing it from. Phones are constantly broadcasting that data. And carriers store it, often for years.

Carriers store a lot of data about you. Some is necessary to operate. They do need to know where you are to provide service and know if roaming charges apply. But in many cases, there’s no technical reason to keep the data as long as they do. They’re keeping it to sell.

There is no technical reason for collecting as much data as the main [cell] carriers collect, unless there’s some other purpose. And that other purpose is … you can use that data to monetize it, you can sell it.

Ruddy Wang

The way the global telephony system works also exposes your information. It’s interoperable, so it doesn’t matter where you are or what carrier you have, it will work. But that’s because there are interchanges and handoffs between your carrier and the other person’s, and all of those parties can see at least some of your info. It works, but it’s detrimental to phone privacy.

Mobile Phone Identifiers

The two most common identifiers that identify specific devices or users are the IMSI and IMEI. The IMSI is the International Mobile Subscriber ID. Ruddy compares it to a car’s license plate because it’s the most visible and most common. If surveillance is trying to target you specifically, they’re going to look for your IMSI first, and it’s what telecom networks look at. The IMEI is a device ID number, which is more like your car’s VIN. It’s less used, less visible, and harder to get.

These numbers don’t tend to change. But just like you can often put the same license plate on a different car but each car has a unique VIN, the IMEI is associated with your particular phone while the IMSI is associated with you as a mobile customer. When you get a new phone, the IMEI will change. But if you’ve been a Verizon customer for the past ten years, you’ve had the same IMSI number the whole time. This is especially true now with the increase in eSIMs. Your IMSI number is tied to your SIM card, and changing physical SIM cards could sometimes change that number. But with eSIM cards it’s going to stay the same.

Because that number doesn’t change, though, it can also be a phone privacy risk. Bad guys can harvest that number through a variety of methods. And once they have it, they can do all sorts of nefarious things. That includes intercepting your communications, tracking you over time, finding out where you are right now, and more.

The System Allows Attacks on Phone Privacy

Signaling attacks are a type of attack that leverages your IMSI number and access to a mobile network. And access to a mobile network isn’t as hard to get as you might think. If Ruddy’s mobile provider is Verizon, Verizon knows where he is and where he’s been within their network. But someone wouldn’t necessarily have to access Verizon to attack him. They might, for example, have access to Singtel, a mobile provider in Singapore. They could even have that access not through Singtel itself, but through a third party vendor Singtel uses.

Once they have your IMSI number and access to any mobile network, there’s a lot they can do. They could ping Ruddy’s phone and find out exactly where he is right now. Or they could spoof his phone, tricking Verizon into believing Ruddy is actually in Singapore right now and his calls and texts should get rerouted to the attacker instead. Obviously that’s a huge breach of phone privacy – and carries a lot of risk.

This all starts with your IMSI. Because the number doesn’t usually change, criminals often harvest it years before the actual attack. It doesn’t matter how good Verizon’s security is if attackers don’t have to breach Verizon to do this. It works because this is the way the global telecommunication systems are set up by design. This system is why international roaming works. But it also makes these attacks hard to prevent.

If you are a Verizon customer, I don’t have to have compromised Verizon in order to be able to location track you and intercept some of your communications. 

Ruddy Wang

Why Signaling Attacks Happen

One common phone-based attack is SIM swapping. Criminals port your number to an entirely different phone in order to get your two-factor authentication (2FA) codes and get into your account. Signaling attacks are similar and done with similar goals. The criminals who do it want to get the 2FA codes that get texted to you so they can get into your accounts. But with a signaling attack, they can do it without going through the effort of porting your number.

SIM swapping is a scarier and much more powerful attack. They’re not just redirecting some of your communications, they’re taking ownership of your phone number. But you’ll notice a SIM swap happened because your phone will lose service. With a signaling attack, there is no sign on your phone because it’s leveraging the way global phone systems work. It’s an invisible attack.

The way the global phone system works is a risk to phone privacy.

There have been some noteworthy times it’s been used, too. A few years ago, a story came out of Germany where someone was opportunistically using signaling attacks to get one-time passwords for people’s bank accounts. A US senator not long ago demonstrated how a signaling attack could let someone listen in on a phone call. And it’s the same kind of attack that Iran uses to find US troops during conflicts. So there are a lot of dangers, not just to phone privacy but also physical safety, in these attacks.

It’s Hard to Stop Signaling Attacks

There’s not much that can be done about signaling attacks. It’s not a bug you can patch – it’s the way the system is designed. The system is set up to be interoperable, trust each other, and communicate with each other. That’s why it works. If you stop allowing that, the whole global telecommunication system breaks.

The problem with some of these types of attacks is that there’s really nothing you can do because it’s the way the system is designed to work.

Ruddy Wang

On an individual level, there are some things you can do. On Apple, you can put your phone into lockdown mode. This limits your device to using newer protocols. It’s not perfect protection, but it reduces your attack surface. On Android devices, you can use GrapheneOS, which is a more private and secure operating system. Graphene has the option to restrict calls to 4G/5G only, which also reduces your attack surface.

As a phone privacy-focused mobile provider, Cape also takes some extra steps to protect customers from these attacks. One is that they change your IMSI number every day. Since there’s often a huge gap between getting the IMSI number and making the attack, having it change daily makes it almost impossible for these attacks to work. They also have a feature called Network Lock, which is basically enhanced signaling protection. That means if Cape gets a notification from Singtel saying Ruddy is in Singapore right now, they’re going to send a question to his phone asking if Ruddy is really in Singapore. Because Cape also has an app on customers’ phones, it’s a double verification. If the phone says Ruddy isn’t in Singapore, Cape will deny the request to forward his communications.

Phone Privacy, Security, and MNVOs

There are two categories of mobile service providers – MNOs and MVNOs. MNO stands for Mobile Network Operator, and that’s any telecom company that owns network towers. In the US, there’s only three: AT&T, Verizon, and T-Mobile. MNVO stands for Mobile Virtual Network Operator, and that’s companies like Mint Mobile, Consumer Cellular, and everybody who isn’t one of the MNOs. MVNOs provide service by leasing tower space from the MNOs that own them.

In the US, most MVNOs are “light MVNOs,” which means they still use the infrastructure of the MNOs. Cape is the only MVNO in the country that has its own mobile core and its own SIMs. A mobile core is the software brain of the system. Mobile cores make the ultimate decision about whether a signaling attack works or not. The SIM is a tiny operating system that lives in your phone, and that affects how the phone appears to the network tower. Cape has their own mobile core and SIMs because it allows them to better protect phone privacy. Having their own SIMs is what lets them change your IMSI number every day.

Unfortunately, there are some things Cape can’t do for privacy. Because they don’t own the towers, they can’t do anything if your coverage is bad. And though call priority is part of the negotiations when they rent space on an MNO’s towers, ultimately it’s up to the company that owns the towers who gets priority, and they’re going to choose their own customers over an MNVO. Another is encryption – because everything has to be interoperable in order to work, they can’t end-to-end encrypt everything. Instead, they do “last-mile” encryption, where everything from the Cape mobile core to your device is encrypted, to make it harder on hackers.

Protecting Against SIM Swaps

Cape’s commitment to phone privacy also helps protect against SIM swaps. A lot of carriers just use a PIN code. But social engineering, stealing the real phone owner’s identity, and data breaches can get around that. A very common method is either social engineering or even bribing a mobile carrier employee. One study revealed customer support employees at T-Mobile getting $300 per SIM swap. All of these are based on the fact that ultimately, the carrier is the one making the decision about moving phone numbers from one SIM card to another.

Cape takes the completely opposite approach that only the customer should be allowed to make that decision. So every customer gets a recovery phrase, which is a 24-word passphrase. If you’ve ever used a crypto wallet, it’s the same concept. This phrase is nowhere in Cape’s systems. It’s generated on the device and no one at Cape knows it. To port a number to a different device, you have to have that phrase.

That means there’s no way to social engineer or bribe a Cape employee into doing a SIM swap for you. Even if a legitimate customer called in saying they lost their recovery phrase and wanted to port their number, there would be no way for the customer service representative to help them. You’ve probably heard about the millions in cryptocurrency locked in wallets because people forgot their passphrases, and this is the same thing. Because there’s nothing Cape can do without the recovery phrase, the customer would essentially lose their phone number. That is the downside. But unfortunately, better phone privacy and security does sometimes come with downsides.

Everyone Can Benefit from Better Phone Privacy

Ultimately, Ruddy thinks Cape’s target audience is everyone. Everyone deserves better phone privacy, and Ruddy believes this is how phone service should work by default. It’s an essential utility at this point, and mobile providers shouldn’t be collecting as much information as possible and selling it to others. He hopes this attitude will eventually drive changes through the whole industry.

This is the way cell phone service should work. It should just by default not collect as much information about you as possible and should by default not be selling your information to third parties.

Ruddy Wang

In the beginning, Cape’s earliest adopters were people with obvious use cases: Activists who are public figures in controversial areas, journalists who have sources to protect, and domestic violence survivors who want to minimize ways their abusers can track them. One early adopter said that they had to make their contact information public to do their job, but that also turned them into a target, so they appreciated Cape’s commitment to privacy.

These days, though, these use cases are only a small percentage of Cape’s customers. Most people are regular people who just want better phone privacy and are tired of regular mobile carriers tracking them, collecting their data, and selling it to others. They know it’s always getting easier for others to exploit their data, and they just want to opt out of the whole surveillance economy.

Collecting Minimal Data

There’s a common misperception that you have to give your phone provider your ID and address in order to get cell service. That’s actually not required by law. But people assume it is required because it’s basically a universal practice. Sometimes there’s more legitimate reasons. If your plan gives you a free phone, for example, they’re going to want to do a credit check.

But the primary reason is that the more data they get, the easier it is to track you over time, upsell you, and sell your information to third parties. All three of the major MNOs in the past years have either acquired an ad network or have partial ownership in an ad network. That’s because they’re all in the data monetization business just as much – if not more – than the mobile service provider business. It’s often more profitable to collect and sell your data than provide the actual service.

If you look at the major mobile carriers … all of them have in the past years either acquired an ad network or has partial ownership in an ad network. They’re all in the data monetization business.

Ruddy Wang

One of the ways Cape maximizes phone privacy is by requiring as little information as possible and keeping it for as short a time as possible. They don’t require ID documents, a name, or an address, though they do require a zip code because it’s needed for tax purposes. And they never sell your data – it’s not part of their business model. Their privacy policy also lays out exactly how long they keep all of your data for. For some things, like location data collected as part of call logs, that amount of time is just one day.

Phone Privacy and Security, Now and In the Future

Ruddy doesn’t see a lot of other MVNOs doing what Cape is doing any time soon. It’s a huge amount of infrastructure investment. Very few MVNOs employ more than minimal engineers, and the MNOs spend very little on research and development. He hopes that in the future, there will be more competition. More companies will start to care about phone privacy, and the MNOs will start offering more privacy-focused features. But he is concerned that for the MNOs, it will be at a premium price tag.

If you want better phone privacy now but aren’t ready to make the jump to using Cape, there are things you can do to improve your privacy now. Go through your apps and manage the data sharing on them. Most apps don’t need nearly as much information as they ask for. And most people don’t realize that they have by default opted in to let their mobile carrier share their data and they can opt out. It’s a pain, but it can be done. Cape has a guide to opting out with your mobile carrier.

Finally, both signaling attacks and SIM swapping are much less useful if your 2FA codes don’t come through text message. Using a passkey, a hardware key, or an authentication app requires a little extra effort. But it will go a long way towards making you more secure.

Learn more about Cape at cape.co or find them on all of the social media channels.