Hacker News new | ask | show | jobs
by reizorc 568 days ago
Does this mean they can track the location of specific IMEIs from orbit?
2 comments

HawkEye 360 has been doing this for a few years.
This is really interesting. Based on their wikipedia I can see they collect a lot of RF traffic - are IMEIs identifiable with the raw data captured that way? I'm surprised they are not encrypted. I say this as someone who knows nothing about the space.
In 2G/3G networks, IMSI is unencrypted in the initial handshake process while the handset gets a TMSI, so it can very trivially be passively observed, but only at specific points in time.

In 5G this is somewhat fixed - the handset uses its Home Network Public Key to encrypt the device-specific IMSI (producing a SUCI) which only the Home Network can decrypt. The MCC and MNC (carrier information) are still sent in the clear to allow the encrypted SUCI to route to the correct Home Network for decryption.

Which means military has been doing this for decades
They always have been...
It’s interesting as Apple randomizes the MAC address but not imei number.
IMEI randomisation would actually make them unusable in Turkey.
spacex? No, the direct to cell sats require much larger antenna to pick up cell signals. The regular Starlink sats aren’t capable of that.