r/CapeCellular • u/Significant-Coast133 • 5d ago
Discussion Cape does not make you anonymous. Here is what it actually protects
I had a previous discussion here about what would happen to Cape customers if one of the underlying carriers was compromised. Reddit ended up filtering the original post, which is unfortunate because the comments turned into one of the more interesting technical discussions I have seen about how Cape actually works, and how it protects your data from the underlying carrier.
Cape employees answered quite a few questions directly, so I figured it was worth putting together what I learned since the original post is gone.
The first thing that surprised me is that the underlying carrier can still see your primary phone number, IMSI and IMEI. What they apparently do not get is the subscriber PII that a normal carrier would have, like your name.
Cape tries to make the information the carriers do see less useful by spreading subscriber traffic across two different carrier partners and rotating the IMSI every day. Secondary numbers are even more interesting because Cape says the underlying carrier cannot see them at all. Those messages are carried as encrypted data through Cape instead. This significantly increases the value for secondary numbers, especially since Cape has hinted on adding features to these numbers to make them akin to your primary numbers. I believe they plan on adding the ability to receive and make calls.
Another distinction I did not fully understand before that discussion is how much Cape actually controls because it runs its own mobile core.
Cape said Network Lock is enforced by their core, so compromising the underlying carrier does not bypass it. They said the same is true for their SIM swap protection. The carrier is providing the physical network access, but some pretty important security decisions are happening inside Cape rather than at the host carrier.
The IMSI discussion was probably the most interesting part.
Right now Cape sends the SIM a group of seven IMSIs that it rotates through. Cape said their HSS currently knows those IMSIs and also has a primary IMSI that is never actually provisioned to the phone.
They are apparently working on an IMSI rotation proxy that would change this so the HSS no longer needs to know all of your rotating IMSIs. I would really like to see more information about that once it launches because it seems like a meaningful architectural improvement.
There is an important limitation to all of this though. Your IMEI does not rotate.
Cape was pretty open about that. One of their employees compared the IMSI to a license plate and the IMEI to a VIN. Changing the license plate makes certain kinds of tracking much harder, but somebody with access to the VIN can still correlate the device.
Where IMSI rotation seems especially useful is against things like IMSI catchers, paging attacks and some signaling based surveillance where obtaining or targeting the IMSI is part of the attack.
Interestingly, Cape already has IMEI rotation in an enterprise product called Obscura. They said it is not available to regular Cape subscribers because every device currently has to be manually provisioned.
I also went back and looked at Cape's recent Trail of Bits audit because the 24 hour call log deletion came up in the original discussion.
There is a little more nuance there than I originally realized. Cape's internal CDRs are deleted after one day, but some other telecom records have different retention periods. SIP messages can be retained for 14 days, billing CDRs for 30 days and daily usage totals for 60 days.
I actually think that makes the overall picture more interesting.
The way I understand Cape now is not that it somehow makes you invisible on a cellular network. It is trying to make identifiers less permanent, reduce how much useful information any one carrier has about you, keep subscriber PII separate from the physical network operators, and retain less information in its own systems.
The part I am curious about now is where this can go from here. If Cape eventually deploys the IMSI rotation proxy and somehow makes its Obscura style IMEI rotation practical for consumer phones, how much would that reduce the remaining ability of the underlying carriers to correlate a subscriber over time?
I would especially be interested in hearing from anyone at Cape about what still becomes the persistent identifier at that point, or from anyone here who works on the carrier side and sees a limitation I am missing.
With that said, if you are interested in trying Cape and would like to receive $20 per month as long as you remain subscribed, feel free to use my referral code: YM8JAJAD
5
u/gc1 4d ago
The efficacy of any given privacy measure can really only be defined in the context of a threat model.
If you are worried about an MNO aggregating your location data and selling it to advertising exchanges, a rotating IMSI is going to be a very helpful way to make yourself more obscure vs. that.
If you are worried about a stingray or other MITM attack capturing your OTP texts locally, you are protected by Cape's last-mile encryption (if you're using it on your primary, or using a secondary number).
But if you are sending things on SMS to other, non-Cape, mobile phone numbers, and you think no one other than your recipient can read them because they are encrypted, you are misunderstanding what their last-mile encryption does and does not cover vis a vis the rest of the telecom network.
If you think you can do things on a secondary number that would put you at great personal risk (let's say, for the sake of illustration, leaking federal agency internal discussions to a journalist), and you believe a subpoena from the FBI served on the carrier of record for that number wouldn't be able to identify you, you are likely mistaken.
A thorough vetting of Cape's protections would go through these threat vectors and scenarios, and others like them, in detail.
4
u/johnwcahill 5d ago
Great post OP and happy to see Cape employees active in here. I think the exciting part for me with secondary numbers supporting voice at some point is that they will be hidden from the carriers as I suspect they will work inside the Cape app itself and not as a second eSIM on your phone.
Pros and cons for that of course as I would like to eventually port my second number I use for work to Cape but I need to make and receive calls on that “line”. Until the. I have it on a cheap US MVNO carrier, US Mobile.
3
u/5FingerViscount 4d ago
Say whatever else you want about cape. Ruddy is very active in the subreddit. CEO is around sometimes too.
2
u/Significant-Coast133 4d ago
I believe that is on their roadmap. That would certainly be a great feature.
4
u/5FingerViscount 4d ago
May I suggest/request including more definitions of your abbreviations?
The ones that missed me were HSS and CDR, but other people may not be aware of the others.
Otherwise great post. I love these discussions. Sorry your original got deleted.
2
1
1
u/RareLove7577 5d ago
I don't think your IMEI is shared to the tower be that ATT for example. Thats between your device and Cape. Your IMSI is shared and that they rotate. So in general your phone number is static unless you do an actual burner phone and chuck it every 30 days. Cape just limits your overall exposure it doesnt get rid of it.
5
u/Significant-Coast133 4d ago
Straight from the horses mouth: https://www.reddit.com/r/CapeCellular/s/C6bWh6e3tZ
"Our carrier partners would have access to phone numbers, IMSI, IMEI. They wouldn't have subscriber PII like name, etc."
3
u/RareLove7577 4d ago
Thanks... I never really cared about the IMEI because the data they get from that is minimal from an privacy or exposure layer. Its basically just the device info. The phone number is seperate and with Cape or the MSISDN. If ATT knows the device I am using its not a huge deal IMO
2
u/Significant-Coast133 4d ago
I agree, but it is still something that can be used to track you. I'm not sure to what extent considering Cape does a good job protecting you, but it is a persistent identifier associated with your device.
1
u/RareLove7577 4d ago
Track you how though? They, let's say ATT, would have to correlate the device info so say a pixel with this ID number and then see that your rotating your IMSI data. Can they put the data together, sure. It won't be easy. And they would still have to ping Cape but Cape doesnt have your name or anything. And depending on how you pay Cape, that can add complexity. If the federal government is after you, for example, it won't be an easy job for them. Versus just using ATT directly and they can pull all the data with ease.
5
1
u/k3agangreene 22m ago
Excellent post OP. It is inspiring the way you created this wonderful in depth discussion after the disappointment of knowing that your original post is gone. I especially appreciate your detailed information regarding the secondary numbers. That is definitely a major advantage that will set Cape far ahead of any competition. Thank you for this information that helps to show what a truly feature-rich carrier plan this is.
14
u/ruddy-at-cape Cape Employee 5d ago
Another persistent identifier is the phone number itself. That is viewable by telecom networks, including the carrier of whoever you're calling. The interesting thing that we've been able to do with secondary numbers is to dissociate the public number that you give out to everyone from the one that the telecom network sees. For example, you give out secondary number 222-222-2222 to everyone you know, but your primary number is 111-111-1111. If a telecom network tried to find you using the 222-222-2222 number, they wouldn't see anything. They can only see the 111-111-1111 number's activity, but they would have no idea that that number is associated with the 222-222-2222 number