Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

There is no privacy concern, really, as this is unique to the device, not subscriber, and only shared with the network operator, who obviously already "tracks" the subscriber through the SIM , which contains the subscriber identifier (IMSI).

On the other hand, the IMEI in principle makes tracking and disabling of stolen devices easy.

By the way, in the UK it is actually an offence to change the IMEI [1]

[1] https://www.legislation.gov.uk/ukpga/2002/31/section/1



The IMEI also allows a network operator to track a device across multiple sims. And I think it's also shared with roaming operators if roaming happens.


IIRC when you put a SIM into a new device for the first time, part of the tower auth includes the IMEI of the previous device you used it with also.


This is 100% a privacy concern if you're dealing with state level actors.


They can track you with or without the IMEI. Next identifier is the IMSI read from your SIM card and I guess you're not replacing it every day...


Disclaimer: used to work in SIGINT, so please treat anything I say about this with appropriate skepticism.

There are people that for various reasons do cycle out their SIM card frequently as a means to avoid tracking. This is ineffective. Changing the IMEI/discarding devices entirely is more effective.


But if you change IMEI and use the same SIM card, you're still trackable as if nothing changed, right? The IMSI would be the same. I guess you need to change both at the same time...


Dudes have been driving around with fake base stations, rare, but has happened. Only sent spam sms messages with links but could be expanded with buying data from data brokers. A really serious crime though


I would think state level actors have enough tools to deal with this issue. If nothing else they could go the old fashioned way and just, you know, follow you.


It isn't usually the goal of SIGINT to only collect data about a target's location nor are targets always that easy to follow.


"There is no privacy concern, really..." Except for the network operator, who needs to track a SIM card not a phone, but who can track you across networks and SIM cards if he has the IMEI. There is no reason the IMEI needs to be stable.

The network operator does NOT need to know who you are, even if you live in a repressive country that mandates tying ID to mobile phone lines. Get a SIM card in person and top up in cash, or use a virtual credit card, or pay in cryptocurrency for an eSIM, or get a subscription in a less oppressive country and roam.

Invisv is a great suggestion.


Any immutable id is inherently a privacy concern. Network operators are ISP's, and ISP's have been known to do things like hijack unresolvable DNS entries to a search page with ads. The network operator knows who you are and what imei was associated with your account.

I wouldn't be surprised if there were some 'ghost'/virtual profiles associated to an imei similar to how Facebook would do with the like button


Well, there's your phone number. Networks and law enforcement only need that.

Existing privacy level is adequate for members of the public. Anyone who actually, really requires more either has state agencies resources available or is being wanted by state agencies...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: