<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Mobile networks on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/mobile-networks/</link>
    <description>Recent content in Mobile networks on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 08 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/mobile-networks/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SMS 2FA no longer protects anything: what to use instead</title>
      <link>https://arpokrat.com/blog/2fa-sms-vs-yubikey-hardware-keys/</link>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/2fa-sms-vs-yubikey-hardware-keys/</guid>
      <description>&lt;p&gt;On 9 January 2024, the official X account of the Securities and Exchange Commission, the US financial markets regulator, announced the approval of Bitcoin ETFs, a decision the market had been waiting on for months. Within minutes, Bitcoin gained more than 1,000 dollars per coin. Then the SEC denied it: the account had been hacked. The price fell back by more than 2,000 dollars.&lt;/p&gt;
&lt;p&gt;What makes the case instructive is not the size of the market move, it is how ordinary the method was. According to the &lt;a href=&#34;https://www.justice.gov/opa/pr/alabama-man-sentenced-14-months-connection-securities-and-exchange-commission-x-hack-spiked&#34;&gt;US Department of Justice press release&lt;/a&gt;, Eric Council Jr., 26, printed a fake ID with a portable card printer, walked into an AT&amp;amp;T store, and convinced an employee to transfer the phone number tied to the account onto a SIM card he controlled. He received the password reset codes by SMS and passed them to his co-conspirators. He was sentenced on 16 May 2025 to 14 months in prison.&lt;/p&gt;
&lt;p&gt;One clarification is needed, and it changes how the case reads without weakening its lesson. According to the &lt;a href=&#34;https://www.sec.gov/secgov-x-account&#34;&gt;SEC&amp;rsquo;s official statement&lt;/a&gt;, multi-factor authentication had been disabled on that account in July 2023, at staff request. SMS was therefore not the second factor at the time, it was the recovery channel. And that is precisely what makes the example useful: second factor or back door, the phone number remains the point where the chain gives way.&lt;/p&gt;
&lt;h2 id=&#34;what-a-second-factor-is-supposed-to-guarantee&#34;&gt;What a second factor is supposed to guarantee&lt;/h2&gt;
&lt;p&gt;The principle fits in one sentence. A password alone is &lt;strong&gt;something you know&lt;/strong&gt;; to it you add &lt;strong&gt;something you have&lt;/strong&gt; (a phone, a physical key) or &lt;strong&gt;something you are&lt;/strong&gt; (a fingerprint). An attacker who steals your password from a breach does not thereby hold your physical object.&lt;/p&gt;
&lt;p&gt;The reasoning rests on an assumption that is rarely spelled out: that the second factor is genuinely tied to an object in your possession, and that presenting it proves something about where you are logging in. SMS fails on both counts.&lt;/p&gt;
&lt;h2 id=&#34;sms-is-not-a-possession-factor&#34;&gt;SMS is not a possession factor&lt;/h2&gt;
&lt;p&gt;Receiving a code by SMS does not prove you hold a device. It proves that a phone number, assigned by a carrier and changeable by that carrier, points to a handset. These are not the same thing. Three vectors exploit that gap, and they are not fixed the same way.&lt;/p&gt;
&lt;h3 id=&#34;sim-swapping&#34;&gt;SIM swapping&lt;/h3&gt;
&lt;p&gt;This is the attack used in the SEC case, and it relies on no technical flaw. The attacker gathers personal details about the target, often already available in public breaches, then contacts the carrier posing as them: phone lost, please move the number to a new SIM. If they are convincing, or if an employee is complicit, the number switches over and every SMS lands with them. The &lt;a href=&#34;https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf&#34;&gt;FBI&amp;rsquo;s 2024 IC3 annual report&lt;/a&gt; records 982 SIM swap complaints for that year alone and close to 26 million dollars in reported losses, counting only victims who filed a complaint. No software update fixes this vector: it does not target software, it targets a human business process.&lt;/p&gt;
&lt;h3 id=&#34;ss7-interception&#34;&gt;SS7 interception&lt;/h3&gt;
&lt;p&gt;Signaling System 7 is the protocol that lets telephone networks worldwide talk to each other: routing a call, handling roaming, delivering an SMS from one carrier to another. It was designed in 1975, when the club of operators was closed, small, and each treated the others as trustworthy by construction. It therefore carries no native authentication between networks: a request that looks legitimate is treated as legitimate.&lt;/p&gt;
&lt;p&gt;This is not a theoretical weakness. In December 2014, German researchers Tobias Engel and Karsten Nohl demonstrated it publicly at the Chaos Communication Congress: locating a subscriber and intercepting their SMS from the phone number alone. In 2017, real-world exploitation was confirmed: German carrier O2-Telefónica acknowledged that customers had had their bank accounts emptied, the attackers having obtained access to a foreign operator&amp;rsquo;s network and then set up SMS forwarding to capture banking confirmation codes.&lt;/p&gt;
&lt;h3 id=&#34;real-time-phishing&#34;&gt;Real-time phishing&lt;/h3&gt;
&lt;p&gt;The third vector matters most, because it depends on no telecom flaw and survives anything you might fix in the other two.&lt;/p&gt;
&lt;p&gt;A fake site mirrors a service&amp;rsquo;s login page perfectly. You enter your username and password, which the fake site immediately relays to the real one, which then sends an SMS to your phone. The SMS does reach you, and it is genuine. You type the code into the fake site, which relays it in turn within seconds. The session opens, and the attacker is the one holding it.&lt;/p&gt;
&lt;p&gt;This is called an &lt;strong&gt;adversary-in-the-middle&lt;/strong&gt; attack. It is industrialised: tools such as Evilginx, a reverse proxy that appeared in 2017, or kits sold on monthly subscription, put it within reach of anyone. What is stolen is not just the code either, it is the &lt;strong&gt;session cookie&lt;/strong&gt; that then allows the attacker to stay logged in without going through any authentication again.&lt;/p&gt;
&lt;p&gt;The point is architectural. The code sent by SMS carries no information about the site that requested it. It therefore cannot tell the real from the fake: it is valid wherever it is typed.&lt;/p&gt;
&lt;h2 id=&#34;this-is-no-longer-an-opinion-it-is-an-official-position&#34;&gt;This is no longer an opinion, it is an official position&lt;/h2&gt;
&lt;p&gt;The strongest argument against SMS does not come from vendors, it comes from the institutions that write the standards.&lt;/p&gt;
&lt;p&gt;In July 2025, the US NIST published the final version of &lt;a href=&#34;https://csrc.nist.gov/pubs/sp/800/63/b/4/final&#34;&gt;SP 800-63B-4, &lt;em&gt;Digital Identity Guidelines: Authentication and Authenticator Management&lt;/em&gt;&lt;/a&gt;. The text creates an explicit category of &lt;strong&gt;restricted&lt;/strong&gt; authenticators, reserved for mechanisms whose ability to resist attack has degraded as threats evolved. Section 3.1.3.3 places use of the public switched telephone network there, meaning codes sent by SMS or voice call: &amp;ldquo;Use of the PSTN for out-of-band verification is &lt;em&gt;restricted&lt;/em&gt; as described in this section and &lt;strong&gt;SHALL&lt;/strong&gt; satisfy the requirements of Sec. 3.2.9.&amp;rdquo; In practice, a service still relying on it must offer an unrestricted alternative, inform its users of the risk, and hold a migration plan.&lt;/p&gt;
&lt;p&gt;In December 2024, CISA, the US cybersecurity agency, had published its &lt;a href=&#34;https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance&#34;&gt;&lt;em&gt;Mobile Communications Best Practice Guidance&lt;/em&gt;&lt;/a&gt;, following the Salt Typhoon espionage campaign in which actors affiliated with the Chinese state penetrated several US telecom carriers. The wording leaves no room for interpretation: &amp;ldquo;Do not use SMS as a second factor for authentication. SMS messages are not encrypted&amp;rdquo;, and further on, bluntly: &amp;ldquo;Only FIDO authentication is phishing-resistant.&amp;rdquo; The document explicitly recommends hardware FIDO keys, naming Yubico and Google Titan, and specifies that once FIDO is enabled, SMS must be disabled, failing which it remains as an exploitable fallback.&lt;/p&gt;
&lt;h2 id=&#34;authenticator-apps-real-progress-a-partial-solution&#34;&gt;Authenticator apps: real progress, a partial solution&lt;/h2&gt;
&lt;p&gt;TOTP apps, for &lt;em&gt;Time-based One-Time Password&lt;/em&gt;, generate a six-digit code that changes every thirty seconds, computed locally from a secret shared at setup and the current time. Nothing travels over the phone network.&lt;/p&gt;
&lt;p&gt;The gain is immediate: SIM swapping becomes irrelevant since the number is no longer involved, and so does SS7 interception since no message is carried. Migrating to an authenticator app is worth doing on every account that cannot go further.&lt;/p&gt;
&lt;p&gt;But the third vector remains intact. A TOTP code typed into a fake site is relayed to the real site exactly like an SMS code. The app has no idea where you are logging in: it displays a number, and that number is valid for whoever presents it inside its thirty-second window. CISA says as much in the same terms, authenticator codes are better than SMS but remain vulnerable to phishing.&lt;/p&gt;
&lt;p&gt;TOTP is an honest intermediate step, not a destination.&lt;/p&gt;
&lt;h2 id=&#34;why-a-fido2-key-changes-the-nature-of-the-problem&#34;&gt;Why a FIDO2 key changes the nature of the problem&lt;/h2&gt;
&lt;p&gt;A FIDO2/WebAuthn hardware key does not merely make the attack harder, it removes its mechanical possibility.&lt;/p&gt;
&lt;p&gt;When you register it with a service, the key generates a cryptographic key pair dedicated to that service. The public half goes to the service, the private half never leaves the chip and is neither exportable nor readable. No shared secret that could be copied, no six-digit code to intercept.&lt;/p&gt;
&lt;p&gt;Then comes the decisive mechanism, &lt;strong&gt;origin binding&lt;/strong&gt;. At login, the browser passes the key the real domain name of the page on screen. That information is included in the signed data, and the browser enforces it: the page&amp;rsquo;s JavaScript can neither alter nor forge it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A FIDO2 key does not make phishing harder to pull off. It makes the result of phishing unusable.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Take the adversary-in-the-middle attack again, this time with a key. The fake site is perfect, the victim notices nothing and touches the key. The browser passes the real domain of the page, the fraudulent one. The key finds that no pair exists for that domain, or signs for it, producing a signature the real service will reject. Either way, the attacker gets nothing usable.&lt;/p&gt;
&lt;p&gt;That is where the difference in kind lies. With SMS or TOTP, security ultimately rests on the user&amp;rsquo;s vigilance, on their ability to spot a spoofed domain in an address bar at a moment when they are rushed and the page looks normal. With FIDO2, that check is performed by a machine, every time, without depending on anyone&amp;rsquo;s attention. It is that transfer of responsibility that counts, more than the cryptographic strength.&lt;/p&gt;
&lt;p&gt;The effect is measurable. Google made keys mandatory for its employees in early 2017 and &lt;a href=&#34;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&#34;&gt;reported in 2018 that it had recorded no account compromise&lt;/a&gt; across more than 85,000 people.&lt;/p&gt;
&lt;h2 id=&#34;the-real-limits-of-hardware-keys&#34;&gt;The real limits of hardware keys&lt;/h2&gt;
&lt;p&gt;Presenting them as perfect would be dishonest, and useless for preparing the decisions that matter.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The cost is real.&lt;/strong&gt; Expect 25 to 60 euros depending on the model, more for biometric versions, and to double that.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Losing a key is the real risk.&lt;/strong&gt; A single key on a critical account is a design error. You need two registered on every important account, one of them kept elsewhere, with a relative or in a safe. The second is not a convenience, it is what makes the first usable without fear.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Coverage is incomplete.&lt;/strong&gt; Many services, banks in Europe in particular, do not yet support FIDO2, hence the prioritisation that follows.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A key can be stolen.&lt;/strong&gt; Hence the need to set a PIN on the key, or to choose a fingerprint model: without that, the object alone is enough for whoever picks it up.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The fallback remains the weak link.&lt;/strong&gt; Enabling FIDO2 without disabling SMS protects nothing: an attacker simply takes the route left open. Migration is only finished once the old mechanism is removed from the account, recovery options included.&lt;/p&gt;
&lt;p&gt;On hardware, the YubiKey range covers the widest span of protocols, Google Titan keys are cheaper and limited to FIDO, Nitrokey and SoloKeys offer alternatives with open, auditable firmware, and Token2 makes models with a built-in keypad where the PIN is entered on the key rather than on a keyboard. There is no bad choice among FIDO2-certified keys, the protocol is the same and only the side uses differ.&lt;/p&gt;
&lt;h2 id=&#34;where-to-start-when-you-cannot-change-everything&#34;&gt;Where to start when you cannot change everything&lt;/h2&gt;
&lt;p&gt;The order of migration is not a matter of preference, it follows from the dependencies between your accounts.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Your main mailbox first.&lt;/strong&gt; It receives the reset links for almost everything else. An attacker who controls it takes the other accounts one by one, without attacking any of them directly. Nothing deserves to be secured before it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The password manager.&lt;/strong&gt; It concentrates the first factor for all your access, so its protection must match that of the best-protected account it holds. This is the moment to check the quality of the master password, a subject covered in detail in our article on &lt;a href=&#34;https://arpokrat.com/blog/password-entropy-shannon-security/&#34;&gt;entropy and the science behind your security&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Financial accounts and crypto platforms.&lt;/strong&gt; Targets of immediate value, where a compromise becomes an irreversible loss within minutes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Social accounts with an audience.&lt;/strong&gt; The SEC case shows what the word of a followed account is worth, and the damage is not always to its owner.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The rest can wait&lt;/strong&gt;, with a TOTP app replacing SMS. A forum or a streaming service does not justify the same effort.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;For accounts that do not yet support FIDO2: move to TOTP wherever possible, and ask your carrier to lock number portability, a free option with most of them.&lt;/p&gt;
&lt;h2 id=&#34;what-this-says-about-arpokrats-approach&#34;&gt;What this says about Arpokrat&amp;rsquo;s approach&lt;/h2&gt;
&lt;p&gt;This piece describes a problem that exists only because an identifier was placed at the centre of the system. The phone number was never designed as proof of identity: it became the backbone of online authentication out of habit, and all three attacks described above exploit that repurposing.&lt;/p&gt;
&lt;p&gt;That is the reasoning behind the design of the &lt;a href=&#34;https://arpokrat.com/protocol/&#34;&gt;Arpokrat Messenger protocol&lt;/a&gt;: no phone number, no email address, no account. The user exists as a set of cryptographic keys held on their own device, and connections are made through single-use invitation links. The logic is FIDO2&amp;rsquo;s, one level up: what a third party does not hold cannot be extracted from them, whether by social engineering against a carrier or by legal compulsion. This consistency with Zero-Knowledge architecture is developed in our article on &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;harvest now, decrypt later&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A hardware key that signs without ever exposing its secret is, incidentally, also how an offline crypto wallet works, as detailed in our &lt;a href=&#34;https://arpokrat.com/blog/how-to-build-a-cold-wallet/&#34;&gt;complete cold wallet guide&lt;/a&gt;: keep the secret part in a dedicated object, and let nothing out but a signature.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;SMS 2FA was not badly designed. When it became widespread, in the early 2010s, it was a considerable step up from the password alone, and it had going for it the one quality that counts at scale: everyone already owned a phone.&lt;/p&gt;
&lt;p&gt;The problem is not its invention, it is its survival. The SS7 demonstrations date from 2014, the real banking exploitation from 2017, the industrialisation of real-time phishing from the end of that decade. CISA wrote that it should no longer be used in 2024, NIST formalised the restriction in 2025. Roughly a decade separates the moment the flaws became exploitable at scale from the moment institutions put it in writing. And SMS remains the default second factor for most consumer services.&lt;/p&gt;
&lt;p&gt;That gap is the real information in this piece. Security mechanisms do not disappear when they stop working, but when something equally simple comes along to replace them, and that takes far longer. The question is therefore not whether you should abandon SMS, which has been settled for years. It is which other protections you take for granted are already, without anyone having written it down yet, in the same situation.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;US Department of Justice, &lt;a href=&#34;https://www.justice.gov/opa/pr/alabama-man-sentenced-14-months-connection-securities-and-exchange-commission-x-hack-spiked&#34;&gt;Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices&lt;/a&gt;, 16 May 2025&lt;/li&gt;
&lt;li&gt;Securities and Exchange Commission, &lt;a href=&#34;https://www.sec.gov/secgov-x-account&#34;&gt;SECGov X Account&lt;/a&gt;, official statement of 22 January 2024&lt;/li&gt;
&lt;li&gt;NIST, &lt;a href=&#34;https://csrc.nist.gov/pubs/sp/800/63/b/4/final&#34;&gt;SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management&lt;/a&gt;, final version, July 2025&lt;/li&gt;
&lt;li&gt;CISA, &lt;a href=&#34;https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance&#34;&gt;Mobile Communications Best Practice Guidance&lt;/a&gt;, 18 December 2024&lt;/li&gt;
&lt;li&gt;FBI Internet Crime Complaint Center, &lt;a href=&#34;https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf&#34;&gt;2024 Internet Crime Report&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Threatpost, &lt;a href=&#34;https://threatpost.com/cellular-privacy-ss7-security-shattered-at-31c3/110135/&#34;&gt;Cellular Privacy, SS7 Security Shattered at 31C3&lt;/a&gt;, demonstration by Tobias Engel and Karsten Nohl, December 2014&lt;/li&gt;
&lt;li&gt;Help Net Security, &lt;a href=&#34;https://www.helpnetsecurity.com/2017/05/04/ss7-vulnerabilities-exploited/&#34;&gt;Attackers exploited SS7 flaws to empty Germans&amp;rsquo; bank accounts&lt;/a&gt;, May 2017&lt;/li&gt;
&lt;li&gt;Krebs on Security, &lt;a href=&#34;https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/&#34;&gt;Google: Security Keys Neutralized Employee Phishing&lt;/a&gt;, July 2018&lt;/li&gt;
&lt;li&gt;W3C, &lt;a href=&#34;https://www.w3.org/TR/webauthn-2/&#34;&gt;Web Authentication: An API for accessing Public Key Credentials&lt;/a&gt;, WebAuthn specification&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>5G, Location Data and the Law&#39;s Targeting Error</title>
      <link>https://arpokrat.com/blog/5g-location-data-privacy-law/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/5g-location-data-privacy-law/</guid>
      <description>&lt;p&gt;In 2011, Detroit police asked a mobile operator for the cell site records of Timothy Carpenter&amp;rsquo;s phone. They obtained 12,898 location points spread over 127 days, around a hundred a day. Seven years later, the Supreme Court of the United States held that the request amounted to a search and required a warrant.&lt;/p&gt;
&lt;p&gt;Those 12,898 points came from fourth-generation towers, each covering a radius of several kilometres. The same request, addressed today to an urban 5G network, would not return a hundred points a day accurate to a few kilometres. It would return a far larger volume, accurate to a few dozen metres.&lt;/p&gt;
&lt;p&gt;The technology has changed scale. The legal reasoning has stayed at the same point in the chain.&lt;/p&gt;
&lt;h2 id=&#34;a-legal-interest-that-judges-recognise-on-both-sides-of-the-atlantic&#34;&gt;A legal interest that judges recognise on both sides of the Atlantic&lt;/h2&gt;
&lt;p&gt;There is an interest almost everyone accepts and almost no legal text protects effectively: the right to be somewhere without that fact being recorded.&lt;/p&gt;
&lt;p&gt;European case law established it unambiguously. In &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt; (joined cases C-293/12 and C-594/12, 8 April 2014), and then in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt; (joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016), the Court of Justice of the European Union held that such data, taken as a whole, allow very precise conclusions to be drawn concerning people&amp;rsquo;s private lives: daily habits, places of residence, movements, activities carried out and social relationships.&lt;/p&gt;
&lt;p&gt;The Supreme Court of the United States reached a comparable conclusion in &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296 (2018). It stressed a point American scholarship has commented on at length: the &lt;strong&gt;inescapable and automatic&lt;/strong&gt; nature of that collection. Nobody consents to being attached to a cell tower; you are attached because you own a phone that is switched on.&lt;/p&gt;
&lt;p&gt;The legal interest therefore exists, and it is recognised by the two courts that matter in this field. The problem lies elsewhere.&lt;/p&gt;
&lt;h2 id=&#34;what-5g-actually-changed&#34;&gt;What 5G actually changed&lt;/h2&gt;
&lt;p&gt;A common confusion treats location as data the phone transmits, in the same way as a message or a photograph. It is not. Location is a &lt;strong&gt;physical consequence of how the network works&lt;/strong&gt;. The operator knows which tower the device is attached to because it has to know in order to route a call. There is no key with which to encrypt that information, because it is not content but a property of the connection itself.&lt;/p&gt;
&lt;p&gt;That is precisely what makes 5G significant in legal terms rather than technical ones.&lt;/p&gt;
&lt;p&gt;Earlier architectures relied on wide cells. A 4G tower commonly serves a radius of several kilometres, and the position inferred from attachment alone was measured in hundreds of metres in cities, sometimes in tens of kilometres in rural areas. 5G rests on massive densification: urban cells typically cover a few hundred metres, and the engineering literature works with densities on the order of forty to fifty base stations per square kilometre, against four or five in the 3G era.&lt;/p&gt;
&lt;p&gt;The consequence is mechanical. According to &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;Ericsson&amp;rsquo;s white paper on 5G positioning&lt;/a&gt;, infrastructure deployed for connectivity alone reaches an accuracy of twenty to fifty metres outdoors and one to three metres indoors, dropping below a metre in favourable urban conditions. This is not a location feature switched on somewhere, but what the network knows by construction, with no application installed and no permission granted. We set out all of these mechanisms, along with the countermeasures that actually work, in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The intrusion has therefore grown by several orders of magnitude. The applicable legal framework remains the one designed for 2G and 3G. No normative adjustment has accompanied that change of scale.&lt;/p&gt;
&lt;h2 id=&#34;the-law-protects-access-not-generation&#34;&gt;The law protects access, not generation&lt;/h2&gt;
&lt;p&gt;European law carefully regulates who may access location data, on what conditions and under what supervision. Directive 2002/58/EC lays down the principle of confidentiality of communications, and the Court of Justice held, in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net&lt;/a&gt; (joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020), that Article 15(1) of that directive, read in the light of Articles 7, 8, 11 and 52(1) of the Charter, precludes the &lt;strong&gt;general and indiscriminate retention&lt;/strong&gt; of traffic and location data on a preventive basis. The Court nonetheless allowed framed derogations where a Member State faces a serious threat to national security that is genuine and present or foreseeable, subject to effective review.&lt;/p&gt;
&lt;p&gt;These are real protections, and it would be absurd to play them down. But they all come into play after the fact. They presuppose that the data exists and is retained, and then organise the conditions of its use.&lt;/p&gt;
&lt;p&gt;Yet if location is an unavoidable by-product of how the network operates, the relevant point of intervention is not confidentiality. It is &lt;strong&gt;persistence&lt;/strong&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An instantaneous position, needed to route a communication and erased immediately afterwards, is not an instrument of surveillance. A history of positions kept for months is one, whatever access safeguards surround it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The difference between the two is not legal, it is architectural. And the European timetable makes the question urgent rather than theoretical. The Commission &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;withdrew the proposed ePrivacy Regulation&lt;/a&gt; in 2025, for lack of agreement between the co-legislators. It has since been working on a separate instrument on data retention for criminal purposes, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;announced for 2026&lt;/a&gt; and intended to harmonise national regimes that have grown disparate since the 2006 directive was annulled. In other words, the text that will set the regime for location metadata for a decade is being written right now, on the basis of reasoning conceived in the era of kilometre-wide cells.&lt;/p&gt;
&lt;h2 id=&#34;the-precedent-5g-created-for-itself&#34;&gt;The precedent 5G created for itself&lt;/h2&gt;
&lt;p&gt;The most interesting aspect of the file is that the right answer is already in the technical standard, but applied to a different object.&lt;/p&gt;
&lt;p&gt;Up to 4G, the subscriber&amp;rsquo;s permanent identifier, the &lt;strong&gt;IMSI&lt;/strong&gt;, travelled in the clear over the radio interface during attachment. That is what made &lt;strong&gt;IMSI catchers&lt;/strong&gt; possible, those fake base stations which, according to the &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Electronic Frontier Foundation&amp;rsquo;s reference description&lt;/a&gt;, transmit more strongly than legitimate towers in order to attract handsets and capture their identifier.&lt;/p&gt;
&lt;p&gt;Since Release 15 of the 3GPP specifications, published in 2019, 5G has offered an elegant answer. The permanent identifier, now called the &lt;strong&gt;SUPI&lt;/strong&gt;, can be replaced on the radio interface by the &lt;strong&gt;SUCI&lt;/strong&gt;, a concealed identifier obtained by encrypting the subscriber-specific part using elliptic curve cryptography, with the home operator&amp;rsquo;s public key. Only the home network, which holds the corresponding private key, can decrypt it. The result is unique on each computation, which prevents correlation from one session to the next.&lt;/p&gt;
&lt;p&gt;The logic adopted deserves to be underlined, because it is exactly the logic that should guide lawmakers: you do not encrypt the position, which would be technically impossible, you encrypt the identity. A position with no attachable identity has very limited value for individualised surveillance.&lt;/p&gt;
&lt;h3 id=&#34;the-flaw-an-optional-protection&#34;&gt;The flaw: an optional protection&lt;/h3&gt;
&lt;p&gt;There is, however, a considerable caveat, and in our view it is the most concrete point of intervention in the whole file.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;NIST CSWP 36A white paper&lt;/a&gt;, published in March 2026 by the National Institute of Standards and Technology, states it bluntly. Handsets and network functions compliant with Release 15 or later are required to &lt;strong&gt;support&lt;/strong&gt; the SUCI, but enabling it remains &lt;strong&gt;optional for the operator&lt;/strong&gt;. Three conditions must be met: the equipment vendor must support it, the operator must enable it on its network, and the SIM card must carry the elements needed for the computation.&lt;/p&gt;
&lt;p&gt;A configuration trap comes on top of that. The standard provides for a &lt;strong&gt;null protection scheme&lt;/strong&gt;, in which the SUCI format is formally used but without effective encryption, so that the identifier travels in the clear. NIST writes that operators need to configure their networks with a non-null protection scheme, and recalls that a report by CSRIC, the advisory body of the Federal Communications Commission, recommended as early as 2021 that the null scheme be reserved for emergency calls placed by a handset unknown to the network.&lt;/p&gt;
&lt;p&gt;The formulation is worth stating plainly. The best available protection against mobile device tracking has existed in the technical standard since 2019. It rests on a configuration choice left to the operator&amp;rsquo;s discretion. An American federal agency finds it useful to publish a document in 2026 to remind everyone that it ought to be switched on. And no European legal instrument requires it.&lt;/p&gt;
&lt;p&gt;It should be added that the SUCI does not close the subject. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkability attacks that allow sessions to be recorrelated despite the encryption, and the protection falls entirely if the attacker forces the handset to downgrade to an earlier generation. A legal obligation would therefore not settle everything. It would nonetheless remove a gap with no defensible justification: the one between what the standard allows and what commercial networks do.&lt;/p&gt;
&lt;h2 id=&#34;three-coherent-interventions&#34;&gt;Three coherent interventions&lt;/h2&gt;
&lt;p&gt;If we take seriously the idea that location should be minimised by design rather than protected after the fact, three measures follow logically.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Make effective concealment of the identifier mandatory.&lt;/strong&gt; Require the SUCI to be enabled and prohibit null protection schemes on commercial networks, apart from the residual case of emergency calls. This is not about prescribing a new technology, or funding a rollout, but about requiring the activation of a function standardised seven years ago and already present in the equipment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Treat retention as the exception, not the default.&lt;/strong&gt; The position needed to route a communication should be erased as soon as that function is fulfilled. Building a history should call for specific justification. That is the difference between a network that knows where you are and a network that remembers where you have been.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Make custody of the key the relevant connecting factor.&lt;/strong&gt; Locating servers in the Union does not mean much if the keys that make the data intelligible are held elsewhere. The legally significant criterion should be effective control of the means of decryption, a question we examined in detail in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-follows&#34;&gt;The angle Arpokrat follows&lt;/h2&gt;
&lt;p&gt;This reasoning is not specific to telecommunications law. It is the one we apply to our own architectural choices, and it fits in a sentence: what has not been produced does not need to be protected.&lt;/p&gt;
&lt;p&gt;That is why &lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; removes GPS, Bluetooth and NFC at kernel level rather than disabling them in a menu. A switch is a policy: it can be bypassed by a privileged component, re-enabled by an update, ignored by a compromised system. Removing the code path removes the question. It is the transposition, at device scale, of the same shift we are calling for at the scale of the law: intervening on generation rather than on access.&lt;/p&gt;
&lt;p&gt;It must be said straight away what this does not do. No operating system removes a handset from the geometry of the network. As long as a SIM card is active, the operator knows the serving cell, and routing all traffic through Tor changes nothing, since it protects content and destination, not the radio layer. That is precisely why the subject is a legal one. There is a category of risks that no individual configuration reduces, and for which the only available variable is the rule applicable to the operator.&lt;/p&gt;
&lt;p&gt;The same concern governs the rest of our work. Data that does not exist cannot be requisitioned, resold, exfiltrated, or decrypted ten years from now by a machine nobody has today, a question we addressed from the angle of &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;encryption harvested now and broken later&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Public debate on mobile surveillance focuses almost exclusively on access: who can consult the data, on what basis, with what authorisation. That debate is legitimate, and the rulings handed down by the Court of Justice since 2014 have had tangible effects. But it comes too late in the chain.&lt;/p&gt;
&lt;p&gt;The prior and more decisive question is whether the history should exist at all. A database built today for a legitimate purpose remains available tomorrow for another, and the safeguards around it depend on later political decisions that nobody controls at the moment of collection. It is a bet on the stability of institutions, made for a period nobody sets.&lt;/p&gt;
&lt;p&gt;5G has multiplied the resolution of this information without any normative adjustment. It has simultaneously shown, through the SUCI mechanism, that the workable path is to dissociate position from identity rather than attempt to encrypt a physical property of the network. The technical standard supplied the answer seven years before the law asked the question.&lt;/p&gt;
&lt;p&gt;The European text on data retention is being written now. It will deal with metadata, therefore with location, therefore with what 5G now produces at a granularity its drafters never knew. Whether it will settle for organising access to a history taken for granted, or dare to question the necessity of that history, is probably the most important privacy question of the coming years in Europe. And it is a question the technical sector, for once, has already settled the right way.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt;, joined cases C-293/12 and C-594/12, 8 April 2014&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt;, joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net and Others&lt;/a&gt;, joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020&lt;/li&gt;
&lt;li&gt;Supreme Court of the United States, &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296, 2018&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology, &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI)&lt;/a&gt;, NIST CSWP 36A, March 2026&lt;/li&gt;
&lt;li&gt;Ericsson, &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;5G positioning: Locating devices anywhere&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Gotta Catch &amp;lsquo;Em All: Understanding How IMSI-Catchers Exploit Cell Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Digital Rights, &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;The ePrivacy Regulation proposal has been withdrawn, but the fight for your privacy is far from over&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;heise online, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;Data Retention: Commission to present proposal by mid-2026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Permanent geolocation: how your phone tracks you even when you think you have stopped it</title>
      <link>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</link>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</guid>
      <description>&lt;p&gt;In 2024, two researchers at the University of Maryland repeatedly queried Apple&amp;rsquo;s Wi-Fi positioning service, with no special privilege and no specialised hardware, and in a single year reconstructed the precise location of more than two billion Wi-Fi access points worldwide. Their paper, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;, shows what that map makes possible: tracking equipment moving in and out of Ukraine, observing population displacement after the Maui wildfires, following an individual through their home internet router.&lt;/p&gt;
&lt;p&gt;None of those devices had GPS switched on. The position came from somewhere else.&lt;/p&gt;
&lt;p&gt;This is the most widespread blind spot in mobile privacy: the belief that there is a location switch, and that once it is off, the phone stops knowing where it is. That belief is wrong on seven separate levels.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Location is not a feature your phone turns on. It is a property of what your phone is.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;gps-the-least-troubling-vector-of-all&#34;&gt;GPS, the least troubling vector of all&lt;/h2&gt;
&lt;p&gt;The one mechanism everybody can name is also the one that should worry you least.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GNSS&lt;/strong&gt;, the umbrella term covering American GPS, Galileo, GLONASS and BeiDou, works by listening. Satellites continuously broadcast timestamped signals, the receiver picks up several of them and computes its position from the differences in propagation time. Typical accuracy in the open: three to five metres, often several tens of metres in a city, where building façades reflect the signals.&lt;/p&gt;
&lt;p&gt;The decisive point is that this calculation is &lt;strong&gt;passive&lt;/strong&gt;. The phone transmits nothing towards the satellites, and no satellite operator knows you exist. If GNSS were the only thing in play, turning off GPS would be enough.&lt;/p&gt;
&lt;p&gt;There is a caveat, however. To speed up the first fix, phones use &lt;strong&gt;A-GPS&lt;/strong&gt;: they download satellite ephemeris data from a server, over the &lt;a href=&#34;https://en.wikipedia.org/wiki/Assisted_GNSS&#34;&gt;SUPL&lt;/a&gt; protocol. To receive the right data, the phone sends that server the identifier of the network cell it is attached to. Pure GNSS does not betray you, but the accelerator bolted onto it does.&lt;/p&gt;
&lt;h2 id=&#34;the-mobile-network-what-the-operator-knows-by-design&#34;&gt;The mobile network: what the operator knows by design&lt;/h2&gt;
&lt;p&gt;For a call to reach you, the network has to know roughly where you are. This is not an option you can enable, it is the precondition for the service existing at all. Your phone announces itself continuously to the nearest tower, and that registration leaves a record on the operator&amp;rsquo;s side. No installed app, no permission granted: an active SIM card is enough.&lt;/p&gt;
&lt;p&gt;Accuracy depends on the method:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cell ID alone&lt;/strong&gt;: from 200 metres in a dense urban area to more than 30 kilometres in the countryside, where a single tower covers a very wide radius.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Cell ID&lt;/strong&gt;, which adds the antenna sector (most sites are split into three 120-degree sectors) and signal strength: from 100 metres to a few kilometres.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Timing advance&lt;/strong&gt;, which measures the round-trip delay between phone and tower: on the order of 550 metres on GSM, around 78 metres on LTE.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multilateration&lt;/strong&gt; across three or more towers: 50 to 300 metres in urban LTE.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;5G&lt;/strong&gt; changes the scale for two cumulative reasons. Density first: 5G cells cover much shorter radii, so simple attachment is already fine-grained information. Standardisation second: since Release 16, 3GPP has built in native positioning signals. Commercial targets aim for under 3 metres indoors and under 10 metres outdoors for 80% of devices, and &lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;Release 18&lt;/a&gt; goes down to centimetre level for certain industrial use cases.&lt;/p&gt;
&lt;p&gt;The infrastructure that connects you therefore becomes a positioning system of a quality comparable to GPS, without you having enabled anything. That data is retained under national rules and made available to authorities through procedures that vary widely. It is the same underlying debate as the one covered in our piece on &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;the jurisdiction applicable to hosted data&lt;/a&gt;: technical protection and legal protection do not overlap.&lt;/p&gt;
&lt;h2 id=&#34;wi-fi-a-map-of-the-world-made-of-hardware-addresses&#34;&gt;Wi-Fi: a map of the world made of hardware addresses&lt;/h2&gt;
&lt;p&gt;Every Wi-Fi access point continuously broadcasts a unique hardware identifier, the &lt;strong&gt;BSSID&lt;/strong&gt;. These identifiers are fixed and geographically stable: a home router stays in the same place for years.&lt;/p&gt;
&lt;p&gt;Apple, Google and a handful of specialised players maintain databases mapping each BSSID to coordinates, built by their own users&amp;rsquo; phones, which report the list of visible access points together with a GNSS fix. The operation is then reversed: a phone that can see four known access points no longer needs a single satellite. In a dense urban area, accuracy routinely reaches a few tens of metres, and drops below that indoors.&lt;/p&gt;
&lt;p&gt;Two properties make this mechanism hard to neutralise. First, the phone &lt;strong&gt;scans even when Wi-Fi appears to be off&lt;/strong&gt;: since Android 4.3, the system keeps a periodic scan running to improve location accuracy, independently of the quick-settings toggle. This behaviour depends on a separate setting, buried in the location services, that almost no user has ever opened.&lt;/p&gt;
&lt;p&gt;Second, the database can be queried from outside. That is the flaw Rye and Levin exploited: the positioning interfaces return not only the requested location but also that of nearby access points, which makes it possible to harvest the map without ever going near the places involved.&lt;/p&gt;
&lt;h2 id=&#34;bluetooth-and-ble-located-by-other-peoples-phones&#34;&gt;Bluetooth and BLE: located by other people&amp;rsquo;s phones&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth Low Energy&lt;/strong&gt; adds a proximity layer, with a range of a few metres to a few tens of metres, making it far more fine-grained than the mobile network. Two uses coexist. &lt;strong&gt;Commercial beacons&lt;/strong&gt;, deployed in shops, airports and shopping centres, broadcast an identifier that apps on the phone recognise, revealing which aisle you stopped in front of and for how long. And &lt;strong&gt;crowd-sourced location networks&lt;/strong&gt;, of which Apple&amp;rsquo;s Find My is the model, since copied by Google and Samsung.&lt;/p&gt;
&lt;p&gt;This second mechanism inverts an implicit assumption. The reference analysis, &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices?&lt;/a&gt;, published in the PETS 2021 proceedings by researchers at the Technical University of Darmstadt, reverse-engineered Apple&amp;rsquo;s protocol. An offline device emits a BLE signal, any nearby Apple device picks it up, attaches its own position and sends it encrypted to Apple&amp;rsquo;s servers, without the knowledge of either its owner or the owner of the device being located.&lt;/p&gt;
&lt;p&gt;The consequence is structural: a device with no SIM card, no Wi-Fi and no network connection of any kind remains locatable, as long as a stranger walks past with a phone in their pocket. Your isolation no longer depends on your settings, but on those of passers-by.&lt;/p&gt;
&lt;h2 id=&#34;inertial-sensors-locating-you-without-location-permission&#34;&gt;Inertial sensors: locating you without location permission&lt;/h2&gt;
&lt;p&gt;A phone contains an accelerometer, a gyroscope, a magnetometer and often a barometer. These sensors fall under a permission category separate from location: an app can read them without ever having asked where you are.&lt;/p&gt;
&lt;p&gt;Researchers at Princeton demonstrated this with &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe&lt;/a&gt;. Their app starts from the IP address and time zone for a coarse position, then reads the sensors: the accelerometer gives the acceleration and braking profile, the gyroscope the sequence of turns, the magnetometer the heading, the barometer the changes in altitude. A neural network identifies the mode of transport, walking, car, train or plane, and the route is matched against public mapping, elevation and weather data. The result: a trajectory of accuracy comparable to GPS, with no location permission. The method has limits, which the authors document, since it fails in areas without roads and degrades on uniform grid layouts, where many routes produce the same signature. It remains the demonstration that a denied permission is not a closed door.&lt;/p&gt;
&lt;p&gt;The barometer additionally supplies the dimension GNSS handles poorly, the vertical one. US requirements for emergency calls mandate floor-level accuracy of plus or minus 3 metres for 80% of indoor calls. Knowing which floor someone is on is a different kind of knowledge from knowing which city block they are in.&lt;/p&gt;
&lt;h2 id=&#34;the-data-market-the-most-mundane-vector&#34;&gt;The data market: the most mundane vector&lt;/h2&gt;
&lt;p&gt;The mechanisms above describe how a position is computed. What remains is where it goes, and that is where most of the everyday risk lies.&lt;/p&gt;
&lt;p&gt;Thousands of apps integrate &lt;strong&gt;advertising SDKs&lt;/strong&gt;, third-party software components a developer adds to monetise their work or measure their audience. These components inherit the host app&amp;rsquo;s permissions: a weather app that legitimately needs your location passes it to companies whose names you have never read. To this are added &lt;strong&gt;advertising bid streams&lt;/strong&gt;, where your approximate position is broadcast to dozens of potential buyers every time a banner is displayed, including to those who buy nothing and simply listen.&lt;/p&gt;
&lt;p&gt;This raw material feeds an industry. The Electronic Frontier Foundation documented the case of &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Fog Data Science&lt;/a&gt;, which claimed billions of data points on more than 250 million devices, sold to local US police forces. Brian Krebs described &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;Locate X&lt;/a&gt;, a product that lets you draw a polygon on a map and view the history of devices that entered and left that area.&lt;/p&gt;
&lt;p&gt;This vector requires no technical feat, only that somebody is willing to pay. The price is modest.&lt;/p&gt;
&lt;h2 id=&#34;imsi-catchers-active-location&#34;&gt;IMSI catchers: active location&lt;/h2&gt;
&lt;p&gt;The mechanisms described so far exploit normal operation. There is also active location, carried out by a third party intervening on the network.&lt;/p&gt;
&lt;p&gt;An &lt;strong&gt;IMSI catcher&lt;/strong&gt;, or cell-site simulator, is a piece of equipment that impersonates a legitimate tower. Phones within range attach to it, revealing their subscriber identifier and their presence within a limited perimeter.&lt;/p&gt;
&lt;p&gt;5G was supposed to close that door by replacing the permanent cleartext identifier with an encrypted one, the SUCI. The closure is partial. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkage attacks that make it possible to re-correlate sessions despite the encryption. More importantly, the protection collapses entirely if the attacker forces the device to fall back to an earlier generation, 2G in particular, whose authentication is one-way. A 5G phone remains vulnerable to an attack designed for a 1990s network, because it still agrees to go down there.&lt;/p&gt;
&lt;h2 id=&#34;countermeasures-and-how-effective-they-really-are&#34;&gt;Countermeasures, and how effective they really are&lt;/h2&gt;
&lt;p&gt;Every measure below does something. None of them does everything, and the gap between what they do and what people credit them with is what produces bad decisions.&lt;/p&gt;
&lt;h3 id=&#34;airplane-mode&#34;&gt;Airplane mode&lt;/h3&gt;
&lt;p&gt;Airplane mode cuts transmission from the cellular modem, Wi-Fi and Bluetooth. That is real, and it is the best result available for such little effort.&lt;/p&gt;
&lt;p&gt;What it does not do: it does not stop the inertial sensors, it does not delete already cached positions, which will be sent on reconnection, and on most devices it allows Wi-Fi or Bluetooth to be switched back on separately without leaving the mode. Finally, it is a software state, not a power cut: its reliability depends on the integrity of the system enforcing it.&lt;/p&gt;
&lt;p&gt;An underrated detail: detaching from and re-attaching to the network are themselves timestamped events on the operator&amp;rsquo;s side. A phone that vanishes at 9 pm in one cell and reappears at 11 pm in another has produced information, not silence.&lt;/p&gt;
&lt;h3 id=&#34;mac-address-randomisation&#34;&gt;MAC address randomisation&lt;/h3&gt;
&lt;p&gt;Mobile systems today emit random MAC addresses when scanning, to prevent tracking from one place to another. The intent is good, the result incomplete. The reference work, including &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough&lt;/a&gt;, shows that the content of discovery frames is often enough to re-identify the device: the number of information elements, their values and their order form a fingerprint. Add to that sequence numbers, which are incremental and therefore chainable, and the timing signature specific to each model. Some studies report successfully tracking half of all devices for at least twenty minutes.&lt;/p&gt;
&lt;p&gt;Finally, a conceptual limit: randomisation only applies to the discovery phase. As soon as you connect to a network, the address used is stable for that network, by design, so that the connection works. The café you go to every morning recognises you.&lt;/p&gt;
&lt;h3 id=&#34;actually-turning-off-scanning&#34;&gt;Actually turning off scanning&lt;/h3&gt;
&lt;p&gt;This is the most cost-effective and most overlooked setting. On Android, Wi-Fi scanning and Bluetooth scanning are two separate options, located in the location services, independent of the quick-settings toggles. As long as they are active, turning Wi-Fi off from the panel is not enough: the scanning continues.&lt;/p&gt;
&lt;p&gt;Disabling them removes an entire layer of collection, at no cost other than a slightly slower first position fix. For most readers, this is the best ratio between effort spent and result obtained.&lt;/p&gt;
&lt;h3 id=&#34;app-permissions&#34;&gt;App permissions&lt;/h3&gt;
&lt;p&gt;Revoking location permission from apps that manifestly do not need it remains useful, and recent systems offer three gradations: one-off authorisation, authorisation limited to active use, and &lt;strong&gt;approximate location&lt;/strong&gt;, which only transmits an area on the order of a kilometre.&lt;/p&gt;
&lt;p&gt;This does not, however, protect against SDKs hosted inside an app that has a legitimate reason to access your location, nor against inertial sensors, nor against the network layers, which go through no permission at all.&lt;/p&gt;
&lt;h3 id=&#34;what-a-vpn-does-not-protect&#34;&gt;What a VPN does not protect&lt;/h3&gt;
&lt;p&gt;A point worth clarifying, because the opposite belief is very widespread: &lt;strong&gt;a VPN does not hide your location&lt;/strong&gt;. It hides your public IP address, so it falsifies IP-based geolocation, which is in any case the crudest mechanism on this list.&lt;/p&gt;
&lt;p&gt;A VPN touches neither the GNSS receiver, nor Wi-Fi scanning, nor Bluetooth, nor the sensors. It changes nothing about what your operator knows, since the encrypted tunnel travels through its towers and cellular attachment remains visible to it. It does not stop an app holding location permission from transmitting exact coordinates inside the tunnel. A VPN protects the content and destination of your communications on an untrusted network, and that is already a lot. Location is not within its scope.&lt;/p&gt;
&lt;h3 id=&#34;physical-limits&#34;&gt;Physical limits&lt;/h3&gt;
&lt;p&gt;A Faraday pouch works in the literal sense: it blocks transmission and reception. So does removing the battery, where that is still possible. A dedicated device, or simply leaving your phone elsewhere, remains the most robust measure.&lt;/p&gt;
&lt;p&gt;These solutions share a flaw that has to be faced head-on: they produce an anomaly. A phone that goes quiet for two hours every Tuesday evening is saying something. Against an adversary who analyses patterns rather than instantaneous positions, absence is data.&lt;/p&gt;
&lt;h3 id=&#34;three-adversaries-three-strategies&#34;&gt;Three adversaries, three strategies&lt;/h3&gt;
&lt;p&gt;This is the most important distinction in this article, and the one you read least often.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against an advertiser or a data broker&lt;/strong&gt;, the fight is winnable. Permission discipline, disabling scanning, a system without proprietary location services, resetting the advertising identifier: together these sharply reduce the volume collected. This adversary is after cheap volume, not your particular case.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against your operator&lt;/strong&gt;, no configuration is enough. Cellular location is the precondition for the service. The only real variables are legal, what the law permits to be retained and disclosed, and material: which device, which SIM card, in whose name, switched on where.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against a targeted state adversary&lt;/strong&gt;, the reasoning changes again, since it combines legal access to operator data, active location via cell-site simulator, requisitions to platforms and, where applicable, compromise of the device itself. Software countermeasures reduce the surface, but the realistic goal is not disappearance: it is knowing precisely what remains exposed.&lt;/p&gt;
&lt;h2 id=&#34;the-arpokratos-approach&#34;&gt;The ArpokratOS approach&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; answers this landscape with a choice that follows from the distinction above: what needs to be neutralised is neutralised at system level, not in a menu.&lt;/p&gt;
&lt;p&gt;On &lt;strong&gt;GNSS&lt;/strong&gt;, the hardware driver is removed. The device behaves as if the chip did not exist, both for applications and for the system itself. The difference from a settings toggle is not cosmetic. A toggle is a policy: it is enforced by a layer that can be bypassed by a sufficiently privileged component, re-enabled by an update, or ignored by a compromised system. Removing the code path removes the question, since there is no longer anything to enable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth&lt;/strong&gt; is handled at the Core level, on the same logic. Bluetooth switched off in the settings in practice leaves the software stack alive on many devices, to feed proximity services and crowd-sourced location networks. Absent at system level, it cannot talk to a shop beacon, take part in a Find My-style network, or serve as a zero-interaction attack surface.&lt;/p&gt;
&lt;p&gt;It has to be said plainly what this does not do. &lt;strong&gt;ArpokratOS does not make a phone undetectable.&lt;/strong&gt; As long as a SIM card is active, the operator knows the cell you are attached to, and no operating system changes that, not even with all traffic routed over Tor. Routing protects the content and the destination, not the radio geometry. Anyone promising invisibility is selling a story.&lt;/p&gt;
&lt;p&gt;What such an architecture provides is more modest: the removal of the application and proximity layers, through which the vast majority of real-world collection passes, and an explicit threat model for what remains. It is the same reasoning applied to choosing a desktop system, detailed in our &lt;a href=&#34;https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/&#34;&gt;operating system comparison&lt;/a&gt;: the useful question is not whether a tool protects, but what it protects against and at what price.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This article does not provide a method for disappearing. That method does not exist, and texts claiming otherwise mostly produce false confidence, which is more dangerous than no protection at all because it makes people take risks.&lt;/p&gt;
&lt;p&gt;The aim was to replace a binary question, am I locatable or not, with a useful one: by whom, with what accuracy, at what cost to them, and does it matter to me. The answer differs for a journalist protecting a source, an executive travelling in a sensitive jurisdiction, a lawyer whose appointments reveal a strategy, or a private individual annoyed that an advertiser knows their habits.&lt;/p&gt;
&lt;p&gt;What deserves attention, in fact, is not the performance of each of these mechanisms taken in isolation, but the fact that they overlap. A position accurate to fifty metres is not very interesting. A position accurate to fifty metres, every fifteen minutes, for two years, draws a home, a workplace, a religion, a health condition, an affair, a source. Location data is the metadata that makes all the others legible, and that is why it is worth so much.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Erik Rye, Dave Levin, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;, IEEE Symposium on Security and Privacy, 2024&lt;/li&gt;
&lt;li&gt;Alexander Heinrich et al., &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices? Security and Privacy of Apple&amp;rsquo;s Crowd-Sourced Bluetooth Location Tracking System&lt;/a&gt;, PoPETs, 2021&lt;/li&gt;
&lt;li&gt;Arsalan Mosenia et al., &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe: Tracking a Smartphone User around the World&lt;/a&gt;, IEEE Transactions on Multi-Scale Computing Systems&lt;/li&gt;
&lt;li&gt;Mathy Vanhoef et al., &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms&lt;/a&gt;, AsiaCCS, 2016&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;5G NR Positioning Enhancements in 3GPP Release-18&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police&lt;/a&gt;, 2022&lt;/li&gt;
&lt;li&gt;Krebs on Security, &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;The Global Surveillance Free-for-All in Mobile Ad Data&lt;/a&gt;, 2024&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://ssd.eff.org/module/mobile-phones-location-tracking&#34;&gt;Mobile Phones: Location Tracking&lt;/a&gt;, Surveillance Self-Defense&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Utiq: The new telecom &#39;Super-Cookie&#39; threatening your privacy</title>
      <link>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/utiq-supercookie-telecom-privacy/</guid>
      <description>&lt;p&gt;The scheduled end of third-party cookies on web browsers has triggered a true arms race in the targeted advertising industry. While Google is trying to impose its own standards (like the Privacy Sandbox), another unexpected player has decided to grab a piece of the pie: &lt;strong&gt;your Internet Service Provider (ISP)&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Thus was born &lt;strong&gt;Utiq&lt;/strong&gt; (formerly known as project &lt;em&gt;TrustPid&lt;/em&gt;), a joint venture founded by European telecommunications giants. Sold to the general public as a &amp;ldquo;transparent and respectful&amp;rdquo; solution, Utiq is actually what cybersecurity experts fear most: a &amp;ldquo;supercookie&amp;rdquo; operating at the network level.&lt;/p&gt;
&lt;h2 id=&#34;what-is-utiq-and-how-does-it-work&#34;&gt;What is Utiq and how does it work?&lt;/h2&gt;
&lt;p&gt;Traditionally, advertising tracking (cookies) is managed by your web browser (&lt;a href=&#34;https://www.google.com/chrome/&#34;&gt;Chrome&lt;/a&gt;, &lt;a href=&#34;https://www.mozilla.org/firefox/&#34;&gt;Firefox&lt;/a&gt;, &lt;a href=&#34;https://www.apple.com/safari/&#34;&gt;Safari&lt;/a&gt;). You could block it using extensions (like &lt;a href=&#34;https://ublockorigin.com/&#34;&gt;uBlock Origin&lt;/a&gt;) or a privacy-oriented browser (like &lt;a href=&#34;https://brave.com/&#34;&gt;Brave&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Utiq shifts the problem one step back: to the level of your network connection.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Here is how the trap springs:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Network interception:&lt;/strong&gt; When you browse the internet via your mobile connection (4G/5G) or your fiber box, Utiq uses your IP address and your telecom subscription data to identify you.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Consent (the false choice):&lt;/strong&gt; Upon arriving at a partner site, a pop-up window asks you to accept Utiq. Due to the fatigue associated with cookie banners (&lt;em&gt;Consent Fatigue&lt;/em&gt;), millions of users click &amp;ldquo;Accept&amp;rdquo; without reading.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The &amp;ldquo;Network Signal&amp;rdquo;:&lt;/strong&gt; Once consent is given, Utiq directly contacts your telecom operator. The latter generates a unique, pseudonymized identification token (the network signal) which it transmits to advertisers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;You are now trackable from site to site, not by a file stored on your computer, but by &lt;strong&gt;the very infrastructure that provides you with the internet&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&#34;why-utiq-is-a-privacy-nightmare-opsec&#34;&gt;Why Utiq is a privacy nightmare (OPSEC)&lt;/h2&gt;
&lt;p&gt;The initiative raises serious problems for digital sovereignty and the confidentiality of your data:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tracking at the source:&lt;/strong&gt; Unlike classic cookies, you cannot simply &amp;ldquo;clear your history&amp;rdquo; or &amp;ldquo;empty your cache&amp;rdquo; to get rid of Utiq. The identification token is generated by your ISP.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The centralization of profiles:&lt;/strong&gt; Telecom operators already know your name, physical address, banking details, and location in real-time. By linking your web browsing history via Utiq to this, they create behavioral profiling of daunting precision.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The flaw of pseudonymization:&lt;/strong&gt; Utiq defends itself by not sharing your name in plain text, claiming to use &amp;ldquo;encrypted&amp;rdquo; tokens. However, in the cybersecurity world, it is proven that pseudonymization is reversible. Cross-referencing these tokens with other databases allows individuals to be easily re-identified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;which-operators-use-utiq&#34;&gt;Which operators use Utiq?&lt;/h2&gt;
&lt;p&gt;Utiq was founded by an alliance of the four largest European operators. If you are a customer of one of them (or one of their low-cost subsidiaries), your connection is potentially already &amp;ldquo;compatible&amp;rdquo; with this tracking.&lt;/p&gt;
&lt;p&gt;Here are the founders and links to their respective privacy policies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.orange.fr/portail/politique-de-confidentialite&#34;&gt;Orange&lt;/a&gt;&lt;/strong&gt; (France, Spain, Poland, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.vodafone.com/privacy-center&#34;&gt;Vodafone&lt;/a&gt;&lt;/strong&gt; (Germany, Spain, UK, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telefonica.com/en/privacy-policy/&#34;&gt;Telefónica / O2 / Movistar&lt;/a&gt;&lt;/strong&gt; (Spain, Germany, etc.)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://www.telekom.com/en/company/data-privacy-and-security&#34;&gt;Deutsche Telekom&lt;/a&gt;&lt;/strong&gt; (Germany, Central Europe)&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;The OPSEC tip:&lt;/strong&gt; Although Utiq offers a centralized consent management portal (&lt;a href=&#34;https://consenthub.utiq.com/&#34;&gt;consenthub.utiq.com&lt;/a&gt;) to revoke access, the best defense remains technological.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-zero-trust-approach-to-counter-utiq&#34;&gt;The Zero-Trust approach to counter Utiq&lt;/h2&gt;
&lt;p&gt;The philosophy of digital sovereignty, driven by ecosystems like &lt;strong&gt;Arpokrat&lt;/strong&gt;, relies on a simple principle: never trust the network infrastructure.&lt;/p&gt;
&lt;p&gt;To technically neutralize systems like Utiq, the solution is to hide your traffic from your own internet service provider:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Using a sovereign VPN:&lt;/strong&gt; By encrypting your traffic as soon as it leaves your device, your ISP only sees an unreadable stream of data directed towards a VPN server. It can no longer inject or read Utiq tokens.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Tor network (&lt;a href=&#34;https://orbot.app/&#34;&gt;Orbot&lt;/a&gt;):&lt;/strong&gt; Onion routing prevents any end-to-end identification.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;DNS Encryption (DoH/DoT):&lt;/strong&gt; Prevents your operator from knowing which websites you request to visit.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In summary, Utiq is proof that internet service providers are no longer content with being mere &amp;ldquo;pipes&amp;rdquo;; they want to become data brokers. More than ever, encrypting your traffic is no longer a security option, but an absolute necessity to preserve your digital silence.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>