this is a great write up and I love nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq235tem4hfn34edqh8hxfja9amty73998f0eagnuu4zm423s9e8ks3f750r

I would love your take on mobile privacy from the actual network provider. from what I understand, there are two major attack surfaces here.

1: your IP address and all your traffic metadata, which can be 'easily' solved by running a good VPN.

2: your SIM is constantly pinging cell phone towers and building a constant historical record of your whereabouts with quite good accuracy that your SIM provider has. this is tied to the SIM card phone number (or other SIM related identifiers).

while one can purchase a SIM non-kyc, linking a phone number to a person is usually trivial to a large actor given most people's contacts upload your phone number and name into various databases (either apps like whatsapp or into contact backup/sync solutions)

Fighting number 2 is what I'm most concerned about and it seems to be harder to do on graphene than on iOS. Largely because a high quality, cost effective, reliable VoIP app (which solves problem number 2) is hard to get to work on graphene.

Do you have any thoughts or solutions about this concern? Perhaps the concern itself is just overblown and I shouldn't worry about that?

nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqwq8aszhx3cqfa5af0j2z6fnwxhu2fg3xcuy6m3ph4ut2hrg957fszth9ey nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq8dlusgmprudw46nracaldxe9hz4pdmrws8g6lsusy6qglcv5x48sn7xyzx You can buy a non-KYC eSIM from several companies to avoid it being inherently tied to your identity.

There are data-only eSIMs rather than using calls/texts at all and we also plan to provide support for disabling calls/texts for attack surface reduction.

Most VoIP apps work fine on GrapheneOS and there's an open source app/service you can use for it.

Reply to this note

Please Login to reply.

Discussion

I agree with your other responses on wifi + VOIP. But I am not a fan of the non-kyc SIMS and never recommend them.

They are too easily compromised and linked by the users behaviors.

Tower triangulation is permanent history. It’s logged, stored, and retroactively searchable. Even non-KYC SIMs don’t help if your social graph doxes you passively.

They are a illusion of safety for people who don't really need that level of threat protection and too big a risk for those who do need it.

Compartmentalization is the easier and safer route.

Which would be the VOIP options?

I agree, the social graph is the easiest dox that happens. That is why something like a mysudo seems like an easy way to compartmentalize (using up to 9 identities)

Do you compartmentalize using voip or some other way?

Yeah, I use a non-KYC SIM. However, I have not found a good VoIP app that is high quality, affordable and reliable behind a VPN to use on nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpq235tem4hfn34edqh8hxfja9amty73998f0eagnuu4zm423s9e8ks3f750r .

As an example, I can pay roughly $100/year to mysudo on iOS and it works almost flawlessly and provides me with 9 phone numbers with unlimited calling and texting. I never have to use my physical SIM card's number with this setup for a reasonable cost.

On Graphene, I would need to have a second stock device as mysudo won't let me pay them on graphene. Then I need to install google play services on my graphene phone if I want my phone to ring when someone calls/sms me. Even once jumping through these hoops, I find that behind a mullvad VPN, I don't get all incoming calls, so it simply isn't reliable enough to use a phone replacement.

I have heard some people have good luck with jmp.chat instead on Graphene. I wish my legacy call needs were very limited so that could be affordable. Unfortunately, with the amount of calls I have to make, that would end up costing me over $50 USD/month to jmp + the associated data cost to someone like silent.link. And I still end up with only 1 phone number, instead of the 9 I'm getting on iOS to compartmentalize various parts of life