Cape Mobile - A Private Cellular Provider?

A whileago I wrote an artical about a service called [PGPP][5]. It was possitioned as a privacy respecting cellular carrier. I was all over it and used it till it ended up shutting down back in June of 2024. Since then I have gone between using a Cellular provider and just using WiFi.
While I did manage with using just WiFi, I have found it some what restrictive and has landed me in a few sticky situations.
Soon after the shutdown of PGPP, Cape Mobile came onto the scene. This company was offering a similur service with some interesting features but at the time they were missing some things that were quite important to me. The main one being IMSI (Internatinal Mobile Subscriber Identity) rotation. Since I lasted used the service, about a year ago, this has since been added. So I decided to take another look at this service.
A little disclamer about me#
I currently work at Proton. There is an existing relationship between Cape Mobile and Proton. I am writing this as an indvidule interested in the world of cellular and this has not been checked over or approved my either Proton or Cape Mobile. Proton isn’t aware I am writing this and Cape Mobile is only aware as I have reached out to them to clarify some information. When asking for comment, I did say that I worked at Proton but made it clear that I am reaching out as an indevidual and wasn’t trying to pull any strings.
I first heard and tried Cape Mobile before I worked at Proton.
Another thing I have to mention is that I worked at Palantir as well. The founder of Cape Mobile and, as far as I am aware, other employee’s also worked at Palantir. When working there, I didn’t know any one that went on to work at Cape Mobile and I don’t have any personal contacts to people at Cape Mobile.
Aren’t they just another MVNO, using Big telco’s network?#
Yes but no, they do lease the cell towers from a 3rd party company that dosn’t have a good track record on privacy. While this might start the alarm bells ringing for you, it isn’t as big of a problem as you might first think.
There are lots of MVNOs on the market, think MintMobile, GiffGaff, Trump Mobile and a bunch of others. These other services are likely going to be a Thin or Light MVNO. These stlyes of MVNO are basicly all marketing comapnies re-selling what the big providers are already selling. They spice it up with a bit of celebritry branding here and some diffrent pricing structure there but at the end of the day all they controll is marketing and Billing. They don’t have any control over what is called the “Core Network”.
The Core network is whole other ball game. If you consider cellular towers as “Dumb” devices, the Core network dose all the functions a telco company would need. This includes, verifying subscribers have access, routing calles, routing texts and data. Having control over this allows you to do some interesting things around privacy, which we will get into.
Breaking down how each feature benifits privacy#
Minimal Data Collection & Disappearing Call Logs#
Firstly, this is one of the only services that offer minimal data collection and disappearing call logs. On that note, they are one of the few telco companies that spell out in simple terms what they do collect. That isn’t a small thing, telco companies are often very cadgy about what they do say they collect. Cape Mobile’s openess about what they do and do not collect is very refreshing.
Their data retention policy is comparible to “no log VPNs”. We can’t truily know that they don’t keep this data and they haven’t had a independint review into this as far as I could tell.
That being said, on sign up, they don’t collect huge amounts of data. It is just a state and area code. They do also take payment details but they use process called “Tokenization” [SOURCE][1]. This is affectively a inhouse “crypto currancy”. Now don’t panic, this isn’t some bs Web 3.0 crap. Their payment system is seperate from their account system. They need to be able to still track billing, so they use this system that allows they to say “This account has paid” with out saying “This account paid, here is the payment refrence”. The payment referance would be enough to figure out who owns the cellular plan. This was first seen in a service by Invisv’s PGPP cellular service. This same method is also apparently going to appear in Phreeli’s cellular service [SOURCE][1].
I will also talk a little about Phreeli’s competing service later. Spolier, it isn’t doing nearly as much to protect their users.
Secondary Numbers#
For me this isn’t a big feature in lots of ways but I do think it is cool. You can get another number to use at the same time. This isn’t any dual sim setup, this is on the same phone. That being said, it is used within the app. So it dosn’t intergrate nearly as well into your device. That being said, for things like bank codes over SMS, this could be really useful. You have your normal number that you can hand out to people but then keep some of these more sensative messages seperate.
While there are other services like MySudo and Google Voice, this would already be included. Now Cape’s service is way more limited as you can only use it on one device but this might be enough for you. This is also a feature you can safely ignore.
Identifier Rotation (IMSI Rotation)#
Now, this is one of the feature I am very excited about. When I first tried this service, this was missing and honestly was one of the reasons I decided to move away from the service. It isn’t a silver bullet for privacy but it goes a long way to helping your privacy!
Lets step back for a second. What is a IMSI and why is it important? In simple terms, a IMSI is a unique identifier given to you by the cellular company saying which subscriber you are. It allows you to authenticate to their network. In most (if not all) this data is not rotated and non-changable unless you get a new SIM.
The IMSI isn’t always being broadcast. Cellular carriers also use something called TMSI. When you connect to the network, you will provide your IMSI to the network and then they will return a TMSI to you. This works in the same way as your IMSI but is intended to be used for a short time.
In practice, there are numarace carriers that don’t rotate these and the issue arrises.
Encrypted Voicemail#
Now this is a weird one. It is common knloage that voicemail, along with most data sent over cellular, isn’t encrypted. So whats the deal? Well, this isn’t E2E (End to End) encryption, this is encryption at rest.
This means if some one intercepts this data before it reaches Cape Mobile, well its not evry priavte at all but if the goverment or some attacker tries to get their hands on it after the fact, they really won’t get anything other than garbled encrypted data.
Is this useful for your threat moddle? I can’t awnser that but I can say, this is one less pice of data that can’t as easily be bulk collected.
SIM Swap Protection#
Now, this one is a big one for some, esspesially people who are in the public eye. One problem we have seen for well over a dacade now is the profiles of public figures getting hijacked because someone Sim jacked them and then used SMS to reset the credentials.
Obviously, one of the best protections against this is to not have this as a recovery method but that isn’t always possible. Some banks mandate it and some social media accounts.
Their protection works by removing the human for account recovery. Now if you have ever played with crypto you are going to recognise this. Instead of a email and password to access your account, instead you have a seed that you use to validate your account. You save it somewhere where it won’t get lost, like writing it in a physical password book or in a password manager. You use this seed to ensure you don’t get locked out but as you only know it, it means attackers can’t trick some low paied employee to get into your account. For me this isn’t a huge threat but I can really see how useful this is.
Network Lock#
Now, Network Lock attempts to fix one problem that plaiged cellular infrastructure, SS7 attacks.
A little history, the infrastructure we still rely on to this day was designed decades ago. While it has had some updates over that time, the archtecture still is based on trust. When there were only a few cellular companies, mainly in western countries, this didn’t matter as much. Now this network has grown far larger, incresing the amount of companies have to be trusted to keep their security under control. In practice, this isn’t possible. These days you can pay a relatively small amount of money, we are talking a few thousand dollars, to get access.
This access can then be used to trick other companies that the device is in another location, unlocking the ability to get upto a whole bunch of nafarious things.
So, how dose Cape address this? In their application, when you turn this feature on, it will request location access. You then send your general location over to them on a regular basis, when you connect to a new cellular tower, it will ensure the locations match. When they don’t, they block the request otherwise it continues as expected. This simple and elequant solution fixes a major problem that has been exploited for years. If you want to know more information on how this works, I reccoment a video by Veritasium caled [Exposing The Flaw In Our Phone System][2]. It goes into wonderful detaul on how this all works with a real demonstration of the attack.
One other note, it isn’t your phone number that is used in this process, it is acturly you IMSI number. Someone will capture it and then that data can be used to target you in this attack. This means the IMSI rotation I talked about earlier also helps hugly on addressing this issue, as by the time they have captured the IMSI you will be close to roatating the identifier.
Secure Global Roaming#
As far as I can tell, this isn’t exactly one feature that protects you but it seems to be a bunch of security policies some of which have already been spoken too.
Firstly, when they detect you they rotate your IMSI. This is a good idea and something I would manually do when using PGPP but this isn’t really a seperate feature. Symantics though and it dose happen by default rather than the opt-in nature of Identity Rotation.
The main thing I can see is they seem to use their own core network, even when you were abroad. It is quite common for a network operator to use the foreign network. This is called “local breakout”. According to Cape, they say this can be used to monitor your activity using their local infrastructure. This honestly makes a lot of sence to do and will likely help with your security when traveling.
How much of PGPP is in this service (This might be crap)#
I remeber reading someware that they licenced technoligy from Invisv (PGPP) but I can’t find this referance any where, so I am assuming I miss-remebered. That being said when looking at an artical Joseph Cox, from 404 Media, the screen shots appear to be very similure to how the PGPP application looked. I can’t help but think there is some cross over. That being said, that isn’t a bad thing. The whitepaper released by Invisv was very interesting and addressed some serious problems with how that infrastructure worked.
The Experiance I have using it#
The sign up was a breeze, it is very similure to creating a crypto account. You get a seed of words and save them someware safe (make sure you do as you won’t get your number back without it). Then you add the payment method and all is good. It adds a eSIM to your phone and you can start going about your buisness.
The app is supper simple (in a good way) and I’ve had no issues with using it, not that I need to interact with it much.
One of the main features I wanted to use has had a few problems. IMSI Rotation has worked most of the time but there have been a two occasions where I have had to reboot my phone for it to work. To note, I am running GraphineOS which could also be part of the problem. I think if you enable this feature you should be prepaired for it to brake time to time but I wouldn’t say it is a huge problem.
That being said, apart from those two times, it has worked without issue. Your Data will drop for a few mins (at most) but you don’t really notice.
In terms of cell service, I’ve had no issue at all using it. It is about as fast as any other provider I have used.
Some of the Things I would love to see Cape Mobile implement#
Before Cape there was PGPP, they had a feature called “TAL randomization” [SOURCE][3] . I won’t go into the gritty details but it further reduced the carriers ability to track your location by randomizing a list of cell towers your device would move through without re-authenticating. This is a gross simplification.
I am using Cape in the UK, I get a US number which obviously isn’t that useful. I can sign up to things online with it but that is about all. Now that isn’t a problem, it is a US service. One thing that would be good to have is a “Data Only” plan. I don’t need (nor want) the calling SMS etc and it would reduce the attack surface.
Also, on a similure note, it would be awsome to see Cape Mobile expand into diffrent reagons. I would love to move my family over to this plan as the privacy is un-matched.
What about Phreeli?#
I should start this with the fact that I haven’t used Phreeli.
While the ideals behind the service are great, what they offer is very limited. There “main feature” of “tokenizing” isn’t even implemented. Yes, they don’t collect a bunch of data on sign up, they don’t protect you in the ways that count.
If you are chosing between the two services, I would strongly recomend Cape Mobile over Phreeli.
If you are planning to use this service, please consider using my code: S0F381SM#
Sources: [0]: https://www.cape.co/blog/tokenization-for-payment [1]: https://www.phreeli.com/files/PhreeliDoubleBlindArmadilloWhitePaper.pdf [2]: https://www.youtube.com/watch?v=wVyu7NB7W6Y [3]: https://www.usenix.org/conference/usenixsecurity21/presentation/schmitt [4]: https://www.404media.co/i-dont-own-a-cellphone-can-this-privacy-focused-network-change-that/ [5]: https://godfrey.online/posts/pgpp-hacking-a-broken-network/
- https://www.youtube.com/watch?v=K1C-bR728ro They oonly use Diamiter - 36:42
Comments
You can respond to this post on Mastodon: 🔗 or click to copy the URL to your clipboard so you can paste it into your client.