[00:00.540 --> 00:07.680] So, thanks for pulling up to the trials and tribulations of making your own phone. [00:09.580 --> 00:11.420] So, I'll give you the TLDR up front. [00:11.760 --> 00:15.280] This is my journey of trying to make a mobile phone in 2025. [00:16.020 --> 00:27.200] So, you can notice the talk is called Trials and Tribulations, not How To, because this is a super incomplete project that still has quite a few hurdles ahead of it. [00:27.200 --> 00:31.220] And while there's been lots overcame, there's still quite a ways to go. [00:32.140 --> 00:35.060] But I'll be highlighting the software and hardware that has been built. [00:35.920 --> 00:43.100] And the interesting privacy implications that a lot of this has, along with colored construction paper, is really fun. [00:43.360 --> 00:48.640] So, all my slide decks were made with a scanner and lots of construction paper. [00:51.040 --> 00:52.100] So, who am I? [00:52.380 --> 00:53.420] I'm Wes Appler. [00:53.640 --> 00:57.180] I'm a professional software engineer at the Open Technology Center. [00:57.200 --> 01:03.320] And, of course, views and opinions presented are all mine and do not reflect that of my employer. [01:04.280 --> 01:07.120] But I'm also an amateur and self-taught hardware engineer. [01:08.120 --> 01:10.880] So, I'm a FOSS advocate and contributor. [01:11.420 --> 01:18.580] And depending on the day, I'm an artist, ham operator, runner, photographer, and as of late, a Brooklyn resident. [01:19.260 --> 01:24.560] So, actively accepting any restaurant recs and happy hour invites. [01:26.920 --> 01:30.980] So, when you tell people you're building a phone, obviously, the first question you're going to get is, why? [01:31.420 --> 01:34.940] The smartphone is so tried and true and ultra convenient. [01:34.960 --> 01:36.640] So, why would you reinvent the wheel? [01:39.550 --> 01:43.490] So, for me, there's been a couple of miscellaneous interests that kind of drove this. [01:44.450 --> 01:46.170] One was just learning in general. [01:47.710 --> 01:54.670] Rust has always been like that acquaintance that seems pretty chill, you've wanted to hang out with, but never got the opportunity. [01:55.210 --> 01:57.950] This project was like my first, second, and third hang. [01:58.110 --> 01:59.390] So, we're kind of besties now. [02:00.450 --> 02:06.390] I also was curious about mobile networks and the protocols, the infrastructure, and vulnerabilities that came with them. [02:07.050 --> 02:11.870] Along with just designing RF hardware and better printed circuit boards in general. [02:13.270 --> 02:15.390] So, I also wanted to disconnect more. [02:15.910 --> 02:21.670] This project originally rose in the pandemic when I felt way too connected to my smartphone. [02:21.670 --> 02:24.730] All information coming at my fingertips was bad. [02:25.450 --> 02:28.350] And I just needed like a barrier of separation. [02:29.010 --> 02:33.310] But the real primary motivator behind this, though, is privacy. [02:34.550 --> 02:36.890] So, cell networks are inherently insecure. [02:37.810 --> 02:42.370] Signaling system number seven, or SS7, is very actively leaking your data. [02:42.870 --> 02:46.670] Your location, calls, and SMSs can be exposed. [02:47.070 --> 02:50.230] And 404 Media has done some really interesting coverage of this. [02:50.430 --> 02:58.570] I didn't realize until 10 minutes before that I had two articles by Joseph Cox linked here, but he's also done fantastic work covering it. [02:59.810 --> 03:08.290] But, like you can see the Department of Homeland Security said that China, Russia, Iran, Israel, are all spying on U.S. citizens just using SS7. [03:08.870 --> 03:11.030] And the barrier to entry is super low. [03:12.290 --> 03:16.030] But the next privacy point is government surveillance. [03:16.790 --> 03:23.630] So, IMSI catchers and stingrays pull unique identifiers to your device, which can correlate you to specific locations. [03:23.630 --> 03:30.850] And depending on the attacks being had, even decrypt some messages or metadata of who you're messaging and contacting. [03:31.950 --> 03:34.490] And cops buy data from data brokers. [03:34.730 --> 03:39.830] There's been a ton of interesting talks so far on this here, so I'll spare you the details. [03:40.190 --> 03:45.950] But, you know, things like abortion clinics, visiting places of worship. [03:46.830 --> 03:48.990] All this are kind of leading to profiling. [03:49.930 --> 03:52.070] And general big tech data extraction. [03:52.070 --> 04:03.830] So, things like assisted GPS, something that helps your phone correlate to GPS satellites a lot easier, sends Google your unique device identifier and your location, obviously. [04:04.470 --> 04:06.130] And then also real-time bidding. [04:06.130 --> 04:14.810] So, when you're being sold ads, sensitive information like what websites you're visiting and location data, once again, are being exposed. [04:17.920 --> 04:21.400] So, now that I've decided I wanted to build a phone, where do you even start? [04:21.720 --> 04:23.900] Obviously, a phone is such a complex mechanism. [04:24.220 --> 04:25.900] There's so many different aspects to it. [04:26.020 --> 04:27.140] Hardware and software. [04:27.900 --> 04:29.680] So many different threads to untangle. [04:30.540 --> 04:32.920] And analysis paralysis was so real. [04:33.560 --> 04:41.360] So, I decided to start what seemed the most logical, where the phone would be connecting to the cell provider. [04:42.620 --> 04:45.540] So, that would be the hardware and the modem. [04:46.780 --> 04:50.740] So, finding and understanding modems proved to be a pretty difficult task. [04:50.980 --> 04:54.180] I started my journey and datasheet paywall help. [04:55.420 --> 05:11.500] Every manufacturer wanted you to provide some information on yourself, like, you know, email, corporation name, phone number, bunch of other ridiculous information that was all coming from a website that looked like it was built in 1998. [05:11.500 --> 05:13.620] So, I was, like, a little hesitant. [05:14.400 --> 05:15.740] Burners are definitely recommended. [05:17.620 --> 05:25.560] But, in this research and kind of looking around at what already existed, it seemed a modem called the SIM 7600 would fit my needs pretty well. [05:26.340 --> 05:33.580] So, for some people that have done IoT projects so far, WaveShare did a pretty interesting Raspberry Pi hat. [05:33.580 --> 05:37.280] And that's kind of what inspired me to start looking at the SIM 7600. [05:39.120 --> 05:43.560] So, once I decided I want to kind of roll with that direction, I started reaching out to some sales representatives. [05:44.600 --> 05:53.920] When you tell a sales representative that you're a hobbyist hacker, and you wanted to build your own phone, it leads to quite a few dry email inboxes. [05:54.100 --> 05:56.000] Nobody wants to reply, nobody wants to interact. [05:56.780 --> 05:58.000] Which, yeah, rightfully so. [05:58.000 --> 06:01.860] So, when all else fails, fake an IoT startup. [06:03.940 --> 06:10.100] Previously, I had done some IT consulting and had a few spare email domains laying around that seemed plausible enough. [06:10.360 --> 06:19.220] So, after a couple emails saying, you know, we have a client that needs an initial prototype, but this could lead to a couple hundred orders. [06:19.240 --> 06:20.860] You know, you start getting some calls. [06:21.060 --> 06:22.040] You start getting some calls. [06:22.040 --> 06:28.080] So, I had a couple sales reps lined up and got some really useful information. [06:29.480 --> 06:31.680] Some not useful information as well. [06:33.020 --> 06:39.220] One sales rep told me that I needed carrier certification for any modem that was going on any major network. [06:39.880 --> 06:51.820] Because these carriers were very specific about what devices could join their network, and they didn't want anything weird or sloppy when it came to, you know, their protocols and connections. [06:52.420 --> 06:56.240] So, somebody pointed me in the direction of a modem called the Dragonfly Nano. [06:57.320 --> 07:05.200] So, as opposed to the SIM 7600, this was a system on a chip, a system on a circuit board. [07:05.940 --> 07:08.520] So, it required, like, an actual... [07:08.940 --> 07:16.380] There was a connector on there, and it would need to be situated into another PCB, rather than the SIM 7600 being able to be directly soldered. [07:17.300 --> 07:24.500] And the Dragonfly Nano also had a couple limitations that were less than ideal that we'll revisit a little later. [07:25.740 --> 07:31.320] But as it turns out, no carrier certification was ever needed, and I'm still convinced it's just a money grab. [07:32.300 --> 07:34.940] But we will also revisit that. [07:35.700 --> 07:45.980] So, due to cost-effectiveness and the SIM 7600 fitting better within the constraints of the project, as I learned more, I realized that I could still roll with that, and it seemed to work pretty well. [07:47.820 --> 07:52.300] So, the next step in my hardware journey was to build a development board. [07:53.220 --> 07:59.660] So, this is pretty intimidating, as I had never designed a PCB that had any form of RF hardware before. [08:02.160 --> 08:08.300] So, I started to expose the features of the SIM 7600 and just kind of do a general breakout. [08:09.940 --> 08:28.420] And Michael Osmond actually has a really great talk about how designing RF hardware really isn't that hard, because a lot of the manufacturers of specific components will offer you very beautiful and wonderful diagrams on, you know, what specific inductors you need, [08:28.540 --> 08:31.520] what resistors, and, like, everything that you need, basically. [08:31.520 --> 08:36.280] So, if you can just copy and paste that, for the most part, you'll be pretty okay. [08:37.420 --> 08:45.500] But, the first version of my development board had antennas broken out to external receptacles, so you can connect bigger external antennas. [08:45.740 --> 08:59.680] It had a USB-C receptacle for interfacing, nano-SIM card slot, a headphone jack and onboard mic for being able to take calls, and URI2C and SPI voltage shifters. [09:00.000 --> 09:10.860] So, it could bring the 1.8 volts of the SIM 7600 up to, like, more traditional 3.3 and 5 volts for URI and stuff. [09:11.340 --> 09:16.200] It also had labeled pins compatible with most breadboards and indicator LEDs. [09:17.720 --> 09:19.440] So, this is what it looked like. [09:19.600 --> 09:28.240] This is the result of hours of 0201 component soldering, which, for those who don't know, it's, like, the thickness of, like, eight human hairs. [09:28.520 --> 09:31.100] You're, like, I was, like, hand soldering this with a soldering iron. [09:32.320 --> 09:33.280] It's masochism. [09:33.280 --> 09:34.120] It really is. [09:35.240 --> 09:38.640] But, yeah, once it was done, I felt gratified. [09:38.640 --> 09:41.100] I was like, wow, I have such a beautiful PCB. [09:41.100 --> 09:43.200] I was so excited to plug it in. [09:43.900 --> 09:46.900] I popped my SIM in so excitedly. [09:47.560 --> 09:50.880] And reader, it didn't even turn on. [09:51.080 --> 09:52.500] It didn't even turn on. [09:54.060 --> 09:57.280] So, you know, back to sea trials and tribulations. [09:58.200 --> 10:05.740] I was actually at a specific point within my move where I was dismantling my electronics workbench at the time. [10:05.960 --> 10:12.240] So, I didn't have much time to, like, go back and actually troubleshoot, figure out what went wrong. [10:12.240 --> 10:22.040] So, for the sake of time, I just used that previously mentioned WaveShare Raspberry Pi hat until I could go back and actually troubleshoot. [10:22.480 --> 10:29.680] But from there, I decided to make a pivot to software, once again, because I didn't have my electronics workbench. [10:31.360 --> 10:33.340] So, getting started with the software. [10:34.120 --> 10:39.500] So, the communication with the modem happens via serial over UART. [10:40.220 --> 10:42.760] And it uses the Haze command set. [10:43.460 --> 10:49.900] So, I'm not going to go too in the weeds with, like, what the Haze command set is, but it's a pretty old protocol. [10:50.460 --> 10:55.220] It was developed in the 80s to interface with modems and it's still used by lots of modems today. [10:56.300 --> 11:03.740] It appears to be pretty synchronous until you get a phone call or a text message and then you get some weird result codes. [11:04.700 --> 11:12.340] So, it's kind of, like, troublesome to develop for, but I still made an attempt. [11:12.640 --> 11:15.080] So, I needed an abstraction layer. [11:15.080 --> 11:24.840] If I was going to build anything that was, you know, relatively complex and, you know, involved. [11:25.240 --> 11:28.480] So, I started making a modem handler service in Rust. [11:29.120 --> 11:40.640] And the initial features included APIs for sending and receiving SMSs, which included emoji encodings, call handling, answering, ending, and dialing calls. [11:43.480 --> 11:45.760] And IMEI is getting in setting. [11:45.820 --> 11:48.440] So, we'll also revisit this a little later. [11:49.680 --> 11:56.100] But you can get signal quality of, like, how good your connection was to the base station. [11:57.140 --> 11:59.800] And it would handle the modem-provided errors. [12:00.540 --> 12:05.960] So, it would use a Rust package called Tokyo to handle things asynchronously as well. [12:05.960 --> 12:10.000] So, like, you know, when in unsolicited, previously mentioned unsolicited result code. [12:10.180 --> 12:13.860] So, that would be, like, getting a new text, getting an incoming call would come up. [12:13.980 --> 12:14.920] They'd be able to handle that. [12:16.360 --> 12:29.360] And I had plans to expose the API system-wide via Dbuzz, which would just make it more accessible to any other service that was running, you know, sending messages, making these calls, et cetera. [12:32.280 --> 12:35.340] And, yeah, this is what it looks like when you're talking to yourself. [12:37.460 --> 12:39.520] But, so, yeah. [12:39.760 --> 12:43.040] So, I was also pretty optimistic about this. [12:43.180 --> 12:45.320] Felt pretty good about the software that had been written. [12:45.980 --> 12:46.760] Still do. [12:46.980 --> 12:57.240] But then, as I was ready to make that Dbust implementation, I thought back to a previous project where I was interfacing with a CARS diagnostic computer. [12:58.460 --> 13:09.260] And whenever I would connect to this diagnostic computer on my Linux Ubuntu machine, I would have an issue with a service that was running on my Ubuntu machine. [13:09.260 --> 13:12.020] And it would always tie up that serial connection. [13:12.520 --> 13:15.260] And that service was called Modem Manager. [13:15.840 --> 13:19.040] And I don't remember what jogged my memory. [13:19.040 --> 13:22.100] I think I was trying to find a sexier name than Modem Handler. [13:22.100 --> 13:24.560] And I was like, oh, Modem Manager, Modem Handler. [13:26.140 --> 13:29.380] But I was like, what is this Modem Manager? [13:31.020 --> 13:38.060] And Modem Manager is a Dbust activated daemon, which controls mobile broadband devices and connections. [13:38.780 --> 13:53.080] Whether built-in devices, USB dongles, Bluetooth-paired telephones, or professional RS-232 USB devices with external power supplies, Modem Manager is able to prepare and configure the modems and setup connections with them. [13:53.560 --> 14:01.220] So the software I had just developed was already developed and had been tried and tested since 2008, which is great. [14:01.240 --> 14:02.040] It's part of the process. [14:02.040 --> 14:05.820] I'm glad that I had done what I do now. [14:06.060 --> 14:07.660] I'm glad I have the knowledge that I do now. [14:09.620 --> 14:19.140] So moving forward, I'm really looking forward to exploring Modem Manager more and having that layer of compatibility and ensuring that that is the right move for this project. [14:20.280 --> 14:23.180] But yeah, this discovery was made like two weeks before this talk. [14:23.340 --> 14:24.200] And I was like, damn. [14:27.420 --> 14:28.540] Thanks, thanks. [14:31.620 --> 14:33.280] But yeah, so the next steps. [14:35.800 --> 14:38.060] Obviously, I want this to be a standalone device. [14:38.320 --> 14:42.540] So there's basically two types of support that I want. [14:42.740 --> 14:49.040] I would like a price-effective standalone device with an embedded Linux processor and the modem to be on board. [14:49.040 --> 14:52.260] So everything in one neat package, a nice user interface. [14:52.260 --> 14:54.720] I was thinking something along the lines of BP. [14:55.020 --> 14:57.880] Like I would really love to have a physical tactile keyboard on there. [14:59.160 --> 15:02.000] But and then I'd also like support for custom builds. [15:02.180 --> 15:16.940] So like to continue on with this Raspberry Pi and maybe like a nice little hat and making it just kind of like extendable and be able to be built on top of for like a wide use case, IoT, whatever. [15:16.940 --> 15:21.480] And to wrap all software services into an easily deployed package. [15:24.100 --> 15:26.180] And encryption moving forward. [15:26.960 --> 15:30.420] I would... there's this really interesting project. [15:30.820 --> 15:32.680] And it's called Presage. [15:32.820 --> 15:33.640] It's by Whisperfish. [15:34.380 --> 15:42.400] So Whisperfish made an unofficial signal client, which is very well supported by Whisperfish. [15:42.400 --> 15:45.520] And they've done like a lot of really, really cool development on it. [15:46.200 --> 15:50.140] But Signal hasn't always been fond of third-party clients and unofficial clients. [15:50.360 --> 15:52.900] So obviously like support for that could end at any time. [15:53.820 --> 15:55.760] And things could get kind of weird. [15:56.460 --> 15:59.580] But ideally, this would be the phone's default for communications. [16:01.580 --> 16:04.960] But there's also this issue of encrypting SMS in transit. [16:06.120 --> 16:09.080] So SMS is stored plain text for the most part. [16:09.360 --> 16:11.160] And carriers all have access to it. [16:11.800 --> 16:13.300] It's been a problem in the past. [16:14.500 --> 16:18.580] So I think there's projects around that do encrypt SMS. [16:18.920 --> 16:22.740] But encrypting the content of the messages being sent would be huge if possible. [16:23.320 --> 16:30.900] And it could only be obviously be received by other of this type of phone or clients that would be developed to decrypt. [16:31.800 --> 16:34.180] But things like the metadata would still be exposed. [16:34.380 --> 16:39.960] Obviously, your carrier would know who you're messaging, what times you're messaging, all that other fun stuff. [16:40.660 --> 16:44.000] And of course, encrypting data at REST by default. [16:44.800 --> 16:48.160] So your call history, SMSs, et cetera. [16:50.340 --> 16:52.940] Now, this is one of the most interesting pieces to me. [16:53.120 --> 16:56.280] One of the things that I was like the most excited about for this project. [16:56.280 --> 16:59.940] And this is why I didn't roll with that Dragonfly Nano. [17:00.260 --> 17:04.740] Because these carrier-certified modems cannot switch up their IMEI. [17:06.160 --> 17:10.600] So an IMEI is an International Mobile Equipment Identity. [17:11.420 --> 17:17.540] It's a 15-digit identifier that is intended to be unique for each specific piece of hardware. [17:19.040 --> 17:21.480] So it carries a device's make and model. [17:21.700 --> 17:26.640] So each one of your phones should have an IMEI that identifies the make and the model. [17:26.840 --> 17:29.720] So, you know, like a Google Pixel would have a very specific IMEI. [17:31.200 --> 17:33.860] And it's how a carrier determines device compatibility. [17:34.080 --> 17:39.820] If you've ever brought your phone to a specific carrier and they've said, Oh, sorry, like your device is not compatible. [17:40.860 --> 17:42.280] It's probably compatible. [17:42.580 --> 17:47.260] They just have a specific deal with a specific make of a phone. [17:48.720 --> 17:52.280] That, you know, they say, Oh, you got to buy ours instead. [17:53.760 --> 18:04.200] So this identifier is also carrier agnostic and used by cops and other creepy agencies to track a device's activity. [18:05.640 --> 18:07.380] But most importantly, it's spoofable. [18:10.850 --> 18:16.450] So some eSIM chips allow for seven plus operator, different operator profiles. [18:16.750 --> 18:22.030] So you can think of this as like you're carrying seven different SIM cards in your pocket that you can all pop in. [18:23.450 --> 18:28.470] And modems like the SIM 7600 allow for setting and changing of the IMEI. [18:28.950 --> 18:33.150] You'll get one from the manufacturer, but, you know, it doesn't need to stay that way. [18:34.810 --> 18:42.570] So changing the IMEI based on the operator profile makes a phone harder to surveil from a carrier's perspective. [18:42.930 --> 18:56.210] So if, you know, a great example of this would be if you're at a protest, you had seven different operator profiles, seven different SIM active SIMs that you can hop from, and each one had a different IMEI associated with it. [18:56.210 --> 19:13.170] But you could have, you know, we'll say like this, a Raspberry Pi with this Waveshare hat look like iPhone 11, Google Pixel 7a, and some kind of Samsung flip all, you know, just by swapping these IMEIs to the carrier, at least. [19:14.450 --> 19:16.430] And it allows for more network compatibility. [19:16.870 --> 19:21.310] So when I first got the Waveshare hat, it did not... [19:21.310 --> 19:28.790] I think the carrier that I went with was some... it was like either straight talk or whatever was like cheapest at Walmart for 30 bucks for two months. [19:29.810 --> 19:33.570] And it did not allow the Waveshare hat to connect to the network. [19:33.950 --> 19:46.450] So really quick, doing like a quick Google search on what the Google Pixel 7's IMEI was, I was able to appear to the carrier as a Google Pixel 7a and connect like without issue. [19:46.830 --> 19:47.150] So... [19:48.170 --> 19:50.070] So more network compatibility. [19:53.160 --> 19:55.080] And there's more than just GSM. [19:55.080 --> 20:01.900] So in a device like this, some decentralized comms could also be included, which would be pretty cool. [20:03.060 --> 20:06.560] Just like spitballing would be some mesh networking. [20:07.560 --> 20:14.460] Like Qual is like a really cool decentralized messenger that can work over Bluetooth, Wi-Fi and just the general Internet. [20:15.040 --> 20:16.840] So something like that would be sweet. [20:17.040 --> 20:23.060] Mesh-tastic and a couple other LoRa add-ons to be able to make the hardware swappable would be pretty sick. [20:23.700 --> 20:29.200] And some offline data sharing like the old pirate boxes used to do and stuff. [20:29.800 --> 20:30.360] So... [20:30.360 --> 20:34.480] And yeah, I would love any further suggestions on that. [20:36.540 --> 20:37.660] But the... [20:37.660 --> 20:42.220] One of the last features moving forward that I think would be pretty cool would be stingray spotting. [20:42.220 --> 20:47.920] So to be able to detect stingrays and things like IMSI catchers, obviously like the... [20:47.920 --> 20:50.440] You wouldn't be able to catch a passive IMSI catcher, but... [20:51.500 --> 20:54.940] To be able to analyze traffic from the modem and the base station. [20:55.680 --> 21:06.880] And when something weird is happening, like a 2G downgrade request, it would notify the user and maybe say like something strange could be going on very similarly to how the ray hunter does. [21:08.640 --> 21:14.720] So yeah, this could be custom built or ideally made compatible with EFF's Rayhunter platform. [21:14.720 --> 21:19.520] It also uses Rust and I think that there's some compatibility with like the Pine phone and stuff. [21:19.660 --> 21:23.600] So I don't know how much of a stretch that implementation would actually be. [21:25.120 --> 21:25.620] But... [21:26.440 --> 21:26.940] Yeah. [21:27.560 --> 21:28.240] So this... [21:28.240 --> 21:29.800] I mean, we kept it pretty short actually. [21:30.060 --> 21:35.860] But if you want to get involved, there's no formal channels yet as this project is still super in its infancy. [21:37.080 --> 21:38.520] But feel free to email me. [21:39.520 --> 21:42.540] Wes at lamemakes.com or my website. [21:42.660 --> 21:49.220] If you're cool, you can subscribe to the RSS at lamemakes.com and I'll be posting like all my updates there. [21:51.080 --> 21:54.060] But yeah, I'll take any questions if anybody's got them. [21:54.200 --> 21:55.780] But that's about it for me. [21:57.020 --> 21:57.460] So... [21:57.460 --> 21:58.040] Thanks, y'all. [22:03.000 --> 22:04.000] Yeah, we'll start here. [22:04.240 --> 22:07.500] So you mentioned the Pine phone a minute ago. [22:07.720 --> 22:09.260] And I just wanted to... [22:09.260 --> 22:10.080] I was just serious. [22:10.280 --> 22:12.320] Have you considered the... [22:14.660 --> 22:16.080] No, which one is that? [22:16.080 --> 22:16.480] Sure. [22:16.480 --> 22:18.300] That's the module that's in the Pine phone. [22:18.540 --> 22:18.900] And it's... [22:18.900 --> 22:19.960] And one of the updates... [22:19.960 --> 22:20.820] It's also 4G. [22:21.040 --> 22:21.900] It has... [22:21.900 --> 22:23.080] ...thing which is available to it. [22:23.260 --> 22:25.340] Like it's got 150 makedowns that's like makedown. [22:25.640 --> 22:25.780] Sure. [22:25.880 --> 22:28.540] But it also has an open-source firmware for it. [22:28.880 --> 22:28.900] Okay. [22:29.000 --> 22:31.240] Because Pine phone books have been making... [22:31.240 --> 22:32.820] You know, I've been working on this for a while. [22:32.980 --> 22:34.340] It's got an open data sheet and whatnot. [22:34.580 --> 22:34.760] Sure. [22:35.820 --> 22:36.240] So... [22:36.240 --> 22:37.920] And it's compatible with them. [22:38.220 --> 22:38.440] Mm-hmm. [22:38.920 --> 22:39.320] So... [22:39.320 --> 22:40.460] It might work out... [22:40.460 --> 22:43.780] That might be another alternative notion for this project. [22:44.020 --> 22:44.340] Just... [22:44.340 --> 22:45.500] Just so that... [22:45.500 --> 22:47.560] If you wanted to have more data... [22:47.560 --> 22:49.640] You know, more cellular data for whatever reason... [22:49.640 --> 22:49.960] Mm-hmm. [22:50.100 --> 22:52.060] Use that instead of the... [22:52.060 --> 22:56.360] And have a little bit more of a wider... [22:57.040 --> 22:57.440] Well... [22:57.440 --> 22:57.900] Yeah, yeah. [22:58.040 --> 22:58.920] No, that would be fantastic. [22:59.540 --> 23:04.380] Especially because I think the SIM 7600, at least like the cheapest model, definitely has a throttle... [23:04.380 --> 23:06.660] A bottleneck in terms of like the data that you can use. [23:06.660 --> 23:08.520] I think it's only like 10 mag. [23:08.980 --> 23:09.280] But... [23:10.220 --> 23:10.820] Yeah, no. [23:10.940 --> 23:11.400] I'll have to... [23:11.400 --> 23:12.940] I'll definitely have to connect with you after that. [23:13.060 --> 23:13.320] And... [23:13.320 --> 23:13.860] Because I want to hear more. [23:13.980 --> 23:15.880] Especially like an open-source mode, it would be sweet. [23:16.500 --> 23:16.900] But... [23:16.900 --> 23:17.540] So... [23:17.540 --> 23:17.900] Yeah. [23:18.200 --> 23:18.400] Go ahead. [23:18.860 --> 23:19.120] Okay. [23:19.180 --> 23:19.660] That's a question. [23:19.880 --> 23:20.020] Yeah. [23:20.240 --> 23:24.140] First of all, you mentioned all the slides by the GSM webinar. [23:24.420 --> 23:24.520] Yeah. [23:24.940 --> 23:27.660] If I'm not mistaken, GSM being a 3G technology... [23:28.220 --> 23:28.360] Mm-hmm. [23:28.360 --> 23:29.860] I believe there aren't any... [23:31.960 --> 23:32.360] Right. [23:32.360 --> 23:32.780] That's correct. [23:33.000 --> 23:35.260] I've used GSM here more as a blanket term. [23:35.520 --> 23:35.740] Yeah. [23:35.740 --> 23:37.720] But like, yeah, no, you're totally right. [23:37.860 --> 23:46.660] And that was like, in terms of my disconnection journey, like that was a huge thing that I couldn't just go get like a flip phone from like 2007 and pop a SIM card in it. [23:46.780 --> 23:49.180] Because there's no 3G support anymore, which really sucked. [23:51.640 --> 23:53.000] Yeah, no, no. [23:53.200 --> 23:53.640] I wish. [23:53.900 --> 23:54.260] I wish. [23:54.640 --> 23:55.080] I wish. [23:58.340 --> 23:59.340] Yeah, yeah. [24:00.160 --> 24:00.320] Okay. [24:00.360 --> 24:02.580] My second question has to do with SS7. [24:02.840 --> 24:05.380] You know, there's sort of three levels of attacks here on phones. [24:05.380 --> 24:08.540] One is like spyware, like take a system on the phone. [24:08.660 --> 24:11.640] Second is like busy capture CSS, like man in the middle. [24:12.080 --> 24:13.500] The third is SS7 on the note. [24:13.620 --> 24:13.940] Mm-hmm. [24:13.940 --> 24:14.420] Actually that. [24:15.060 --> 24:16.480] Is SS7... [24:16.480 --> 24:21.980] So what I'm curious as to like what your mitigations would be for those SS7 attacks. [24:22.160 --> 24:27.600] Is it just taking things out of, like out of van, out of the network and doing things like that signal calling and so on? [24:27.740 --> 24:27.800] Mm-hmm. [24:27.800 --> 24:32.840] Or do you have any ideas on how to mitigate the SS7 vulnerabilities right now? [24:33.120 --> 24:33.420] Yeah. [24:33.680 --> 24:33.900] Yeah, yeah. [24:33.960 --> 24:35.920] And just for the live stream, I'll repeat the question there. [24:36.020 --> 24:44.160] That was just like, what's the strategy to mitigate and like get away from SS7 attacks and kind of like fill in the holes that those vulnerabilities have? [24:44.940 --> 24:45.380] Yeah. [24:45.500 --> 24:57.560] So very similar to what you said basically, to get out of van more and to resort more to signal as the default and potentially encrypting SMS where possible. [24:58.040 --> 25:03.720] Like, I mean, like I said, there's still going to be a ton of leaks that happen there in terms of metadata and who you're contacting and when you're contacting them. [25:04.620 --> 25:12.740] But to give the user more granular control too of when understanding when your modem's connecting to the network, what information specifically is being shared over there. [25:14.360 --> 25:22.960] And yeah, just being like making sure there's a bunch of red warnings if they're sending plaintext SMS or like calls over the network and stuff like that. [25:23.240 --> 25:25.180] So yeah. [25:26.480 --> 25:26.880] Yeah. [25:28.020 --> 25:39.040] I know that you said you stepped away from hardware a little bit, but I'm curious like what form factor you're like trying to go for with a phone or if you are kind of like switching all the time as you think of things. [25:39.460 --> 25:40.200] Yeah, yeah. [25:40.300 --> 25:45.440] So the question was like, what kind of form factor in terms of hardware is the phone going to kind of aim for? [25:45.440 --> 25:45.560] Sure. [25:46.920 --> 25:48.020] It's really interesting. [25:48.220 --> 25:51.980] I've kind of like experimented with a bunch of different kind of form factors. [25:52.920 --> 26:03.520] Like I mentioned, I was kind of in love with like the beepy situation that like very much like a Blackberry kind of look, tactile keyboard and like can still fit comfortably in your pocket. [26:03.520 --> 26:10.020] Ideally, we'll see how that actually plays out, you know, in terms of practicality and stuff. [26:10.240 --> 26:19.060] But yeah, like a standalone device that was just super slim and within means and still price effective probably is around there. [26:19.260 --> 26:20.260] But yeah, yeah. [26:21.080 --> 26:24.020] So anybody else? [26:24.020 --> 26:24.100] Yes. [26:25.400 --> 26:25.760] Yeah. [26:26.840 --> 26:29.220] Can you detect silent SMS? [26:32.000 --> 26:33.020] Silent SMS. [26:33.260 --> 26:34.880] I don't know if I'm familiar with silent SMS. [26:35.020 --> 26:36.200] Silent SMS as well. [26:36.460 --> 26:39.640] SMS, which told, is there not shown to the user? [26:40.340 --> 26:41.580] Delivers of the network. [26:41.800 --> 26:44.560] The point being, of course, this is a data point. [26:44.700 --> 26:45.180] Sure. [26:45.500 --> 26:51.380] Which means your phone acknowledges the SMS, which means they can now track you. [26:51.380 --> 26:54.180] And this is information that is then legally available. [26:54.560 --> 27:02.520] So this is how police will track you or they'll generate data that they can legally acquire a result. [27:02.740 --> 27:03.600] How is all the virus? [27:05.240 --> 27:06.100] Sure, sure. [27:06.260 --> 27:06.780] No, absolutely. [27:07.060 --> 27:11.180] So the question was like, can, would this platform be able to detect silent SMS? [27:11.560 --> 27:18.700] Silent SMS being a almost invisible SMS packet that gets sent and your phone acknowledges that it was received. [27:19.140 --> 27:19.560] Yeah. [27:19.720 --> 27:20.500] And it totally could. [27:20.680 --> 27:22.760] With the granular control you have over the modem. [27:23.260 --> 27:34.360] And obviously these, these URCs, these unsolicited result codes that come from the modem and are being handled, it could totally, again, in the same way that it would notify the user that there's an IMSI catcher or something weird happening. [27:34.360 --> 27:37.100] It could say, you received an empty SMS. [27:37.180 --> 27:38.240] What's the deal with that? [27:38.500 --> 27:40.180] So, yeah, absolutely. [27:40.300 --> 27:40.920] That's a great question. [27:41.940 --> 27:42.360] Yeah. [27:43.800 --> 27:44.220] Yeah. [27:44.420 --> 27:46.380] We were talking about mentioning three different types. [27:46.780 --> 27:48.580] I mean, my two, three different types of attacks. [27:48.840 --> 27:54.920] Was it the spyware, like, you know, Pegasus, and then, you know, SELSAT simulators, and then FESA 7. [27:55.040 --> 28:04.360] I think the spyware uses silent SMS typically as a way, as an entry point, as a foothold on a lot of devices. [28:04.360 --> 28:04.900] Okay. [28:05.100 --> 28:07.440] Because the user doesn't have to click on a link and so on. [28:07.620 --> 28:12.980] So it's that those vulnerabilities leverage silent SMS as the initial flow. [28:13.280 --> 28:13.660] Sure. [28:14.020 --> 28:14.140] Okay. [28:14.340 --> 28:14.580] Okay. [28:14.700 --> 28:15.240] Now that makes sense. [28:15.380 --> 28:15.960] That's super interesting. [28:16.140 --> 28:17.640] I've never heard of this silent SMS before. [28:17.820 --> 28:19.040] So I'll definitely have to do a deep dive. [28:19.280 --> 28:20.300] But yeah, go ahead. [28:20.500 --> 28:27.680] So recognizing that it's not a complete project yet, but is there plans to open-source the hardware design on GitHub and put all the code out there? [28:27.900 --> 28:28.140] Yeah. [28:28.140 --> 28:38.160] Because you've mentioned Rayhunter, and I feel like it would be a great opportunity to have open-source hardware that can run without open-source Rayhunter, even for growing the rest of the cell phone. [28:39.100 --> 28:40.000] Yeah, absolutely. [28:40.220 --> 28:42.220] So every step of this, every ounce of it would be open-source. [28:42.800 --> 28:44.840] There's, like, no profit motive. [28:45.000 --> 28:47.760] This is really more just, like, for fun to hang out. [28:47.900 --> 28:48.680] So, like, absolutely. [28:48.720 --> 28:56.200] If I could build any form of, like, open-source hardware platform that especially would cooperate with Rayhunter, like, that would be really sick. [28:56.200 --> 28:56.840] So... [29:00.480 --> 29:01.080] Right now? [29:01.240 --> 29:01.580] No. [29:02.040 --> 29:03.340] Yeah, right. [29:04.680 --> 29:05.560] Right, right. [29:06.340 --> 29:08.260] No, just kind of gradually chipping away. [29:09.000 --> 29:09.820] Deadlines are great. [29:10.040 --> 29:14.260] So maybe when I have to give my next talk, we can, you know, aim for some form of innovation. [29:15.600 --> 29:16.760] Yeah, yeah, yeah, yeah. [29:16.860 --> 29:18.160] I'm sure it'll be a great year. [29:19.560 --> 29:19.920] But... [29:22.300 --> 29:22.660] Yeah, yeah, yeah. [29:22.660 --> 29:23.760] But, yeah, yeah, yeah. [29:23.940 --> 29:27.340] And again, anybody that wants to come contribute, like, I so welcome it. [29:27.700 --> 29:28.240] But, yeah. [29:29.620 --> 29:35.700] One of the things that always seems to be, like, the utilities still have a lot of horrible devices is the battery wipe. [29:36.160 --> 29:36.220] Mm-hmm. [29:36.220 --> 29:37.840] How are you planning? [29:38.260 --> 29:40.860] What's your strategy for approaching that? [29:42.420 --> 29:44.500] I haven't even gotten there yet, to be honest. [29:44.700 --> 29:47.700] Like, I haven't even gotten it to turn on a lab bench power supply. [29:48.640 --> 29:49.120] So... [29:49.600 --> 29:52.800] But, like, yeah, battery life would be really great. [29:53.700 --> 29:54.140] Um... [29:54.680 --> 29:55.120] Yeah. [29:55.500 --> 29:55.680] Yeah. [29:55.920 --> 29:56.140] Yeah. [29:58.960 --> 29:59.820] Would be cool. [30:00.860 --> 30:01.300] Um... [30:01.300 --> 30:06.420] But, yeah, I mean, that would definitely be a consideration once, once, um, I got there to, uh, to a working prototype. [30:06.640 --> 30:06.720] Yeah. [30:07.920 --> 30:09.300] But, also, also good question. [30:09.440 --> 30:09.500] Yeah. [30:09.580 --> 30:10.040] Thank you for that. [30:10.780 --> 30:11.220] So... [30:11.220 --> 30:11.580] Yep. [30:12.200 --> 30:16.320] My talent is I can spot typos with my eyes shut, but I'm dancing. [30:17.100 --> 30:17.980] Oh, no! [30:18.580 --> 30:18.880] No! [30:19.400 --> 30:19.460] No! [30:19.920 --> 30:20.320] Okay. [30:20.320 --> 30:29.160] So, my confession is that I made this in a, um, completely legitimate, uh, version of Photoshop that totally didn't have spell-checking. [30:29.360 --> 30:33.060] So, there's probably, it's probably riddled with typos, but I appreciate you guys tolerating it. [30:33.340 --> 30:33.780] So... [30:36.680 --> 30:37.820] So, awesome. [30:38.340 --> 30:38.720] Yeah? [30:39.000 --> 30:41.340] Have you thought about turning off some of the sensors and hardware? [30:42.000 --> 30:44.640] And, like, you know, the headphone jazz, so that really... [30:47.540 --> 30:48.520] Yeah, yeah, yeah. [30:48.640 --> 30:48.920] Absolutely. [30:48.920 --> 30:57.420] So, I mean, the, one of the, the prime motivations for this is just that, like, um, you would get that granular control over all the sensors on the device. [30:58.160 --> 31:05.420] You would be able to say when the modem is connecting to a base station, um, and, you know, when your microphone is on. [31:05.580 --> 31:09.400] Ideally, you'd get, like, some kind of formal visual indicator of that. [31:09.400 --> 31:17.760] Um, and, you know, maybe, like, in the UI or something, they would be, like, okay, like, disable my mic until I say, specifically, I want it on or off. [31:18.180 --> 31:21.240] Um, but, yeah, that would, that would be a huge aspect of this function. [31:27.440 --> 31:35.280] I was actually planning on having, um, if, you know, again, it comes back to form factor, but, and the standalone device, a series of DIP switches. [31:35.920 --> 31:49.140] Um, so, DIP switches being, like, really, you know, like, this little small panel of switches that, like, you would find on, like, the back of your garage door opener or something that could control a bunch of the actual components, specifically, your modem, [31:49.480 --> 31:53.160] um, and, you know, things like the microphone and stuff. [31:54.900 --> 31:56.240] Yeah, yeah, yeah, yeah, yeah. [31:56.300 --> 32:08.440] And especially, like, you know, if, if the modem is closed source, to be able to physically kill the power on that so you know exactly what's happening and when it's communicating, you know, so, um, so, yeah, physical switches are ideal, I think. [32:08.720 --> 32:09.680] But, uh, yeah. [32:11.560 --> 32:24.530] Um, so, in the interim, um, I have, uh, Graphene Pixel 7, um, or Pixel 6a, actually. [32:25.130 --> 32:26.890] And, um, and it's taken care of me. [32:26.950 --> 32:40.810] Uh, it pisses my friends and family off that, like, I have to go on the Uber website to call the, you know, call an Uber or, um, you know, like, I have to sandbox, like, any apps I want to use Google Play services, but, um, but it is sort of just, I'm living, [32:40.930 --> 32:41.510] I'm living happy. [32:41.510 --> 32:47.730] So, uh, and so that's, that's the meantime, but, uh, I still feel a little too connected to it at times. [32:47.970 --> 32:53.220] So, but yeah, absolutely. [32:53.440 --> 32:53.680] Absolutely. [32:53.940 --> 33:02.200] Like if I, you know, I'm, I am unfortunately still on Instagram phone or use Instagram, I gotta go to the website, you know, so having that and I have, um, like Firefox focus. [33:02.200 --> 33:07.640] So every time I want to log in, I gotta retype my password, um, do all that, you know? [33:07.780 --> 33:12.660] So there's definitely like this extra aspect of, do I really want to do this right now, you know? [33:12.960 --> 33:15.620] So, um, but yeah, yeah, so that's a, that's a great question. [33:15.660 --> 33:18.720] And if anybody has any, uh, I'd love to hear your privacy alternatives too. [33:18.940 --> 33:20.040] So come find me. [33:20.160 --> 33:20.300] Yeah. [33:20.460 --> 33:21.480] Can you leave that slide up? [33:21.580 --> 33:23.140] Cause I can't see it and I want to take a picture. [33:23.140 --> 33:23.500] Yeah. [33:23.740 --> 33:24.320] Yeah, absolutely. [33:24.680 --> 33:25.160] Absolutely. [33:25.700 --> 33:27.960] Um, and slide deck will be on my website later too. [33:28.300 --> 33:30.100] Um, I didn't make the post yet, but I will. [33:30.420 --> 33:30.500] So. [33:31.820 --> 33:32.300] Yeah. [33:32.580 --> 33:37.350] Do you have any resources you can suggest to that? [33:37.750 --> 33:38.230] Yeah. [33:38.510 --> 33:52.230] So specifically that Michael Osmond talk that I mentioned, um, that I can find the name of, it was a Hackaday Supercon talk and I meant to toss the QR code in the PowerPoint. [33:52.910 --> 33:57.830] But Michael Osmond in general is just a fantastic resource and like seemingly such a cool guy. [33:58.090 --> 33:58.750] I've never met him. [33:58.870 --> 33:59.850] I hope to one day. [34:00.270 --> 34:04.230] Um, uh, I can probably find the name of the talk quick. [34:04.730 --> 34:09.450] Um, but basically, yeah, just saying that like, it's not as hard as you think it is. [34:09.690 --> 34:11.510] Uh, lots of the math is already done for you. [34:11.690 --> 34:13.570] Lots of the circuit design is already done for you. [34:13.750 --> 34:21.430] If you just follow these manufacturers guidelines and like check the docs, um, it's, it's a lot easier. [34:21.430 --> 34:28.270] I mean, this is coming from somebody again whose prototype didn't turn on, but, um, but yeah. [34:28.990 --> 34:29.570] Yeah. [34:29.730 --> 34:29.750] Yeah. [34:30.050 --> 34:33.510] Um, uh, it's Michael Osmond, simple RF circuit design. [34:33.750 --> 34:36.630] It was a Hackaday Supercon talk. [34:36.630 --> 34:41.790] And I think he's going over the Ubertooth one and like how he designed it. [34:41.910 --> 34:46.830] But also from the perspective, I think of a software engineer, cybersecurity expert, I think he was. [34:47.090 --> 34:47.970] But yeah, go ahead. [34:48.430 --> 34:50.930] What GCDs design software to use? [34:50.990 --> 34:53.850] And then what, uh, aggregation services? [34:54.950 --> 34:57.530] So I used, I'm loving the, all these questions, by the way. [34:57.630 --> 34:58.310] I think this is fantastic. [34:58.310 --> 34:58.770] It's cool. [34:58.910 --> 34:59.710] I have this much time too. [35:00.250 --> 35:08.330] Um, so I used, uh, KiCad for all my PCB designs and for PCB fabrication. [35:08.330 --> 35:13.530] I actually had the privilege of being sponsored by PCBWay for this project. [35:13.830 --> 35:25.750] Um, and I like, I'm not sponsored to say this or advocate for them, but like I, I was pretty impressed in terms of like what the price versus quality like turned out to be. [35:25.750 --> 35:32.190] Uh, and the turnaround time, like for it being a fab in China, like the turnaround is like super fast. [35:32.570 --> 35:37.250] Um, I was expecting four weeks and I think I got it in like probably like four or five days. [35:37.470 --> 35:39.450] So it was, yeah, it was crazy. [35:39.610 --> 35:40.810] It was, it was really sweet though. [35:41.370 --> 35:46.110] Um, I've used it a couple of times and really enjoyed it, but also I've never been disappointed by Osh Park. [35:46.350 --> 35:49.650] Like you get what you pay for in terms of like the, that super high quality. [35:49.930 --> 35:54.790] Um, but yeah, but the purple is great. [35:54.790 --> 35:57.170] The purple is great, but sometimes I like fun colors too. [35:57.470 --> 36:01.250] So, you know, if I wanted a little more obnoxious, I'll go with PCBWay. [36:01.670 --> 36:02.410] But yeah. [36:03.510 --> 36:03.710] Yeah. [36:04.430 --> 36:08.450] Um, have you considered running your own cell phone service provider with this phone? [36:08.670 --> 36:09.630] That would be pretty sick. [36:09.890 --> 36:10.630] That would be pretty cool. [36:12.170 --> 36:12.610] Yeah. [36:13.010 --> 36:13.390] Yeah. [36:13.630 --> 36:13.950] Really. [36:14.290 --> 36:14.470] Really. [36:14.930 --> 36:18.430] Start answering calls from three letter agencies and you know. [36:20.670 --> 36:21.110] Yeah. [36:21.410 --> 36:21.530] Yeah. [36:21.770 --> 36:21.810] Yeah. [36:21.870 --> 36:23.110] I heard the retirement's really good. [36:23.110 --> 36:28.130] Um, so, yeah, yeah, yeah, yeah. [36:28.450 --> 36:32.370] Um, so no, I think I'll sit that one out for the time being, but, um, but yeah. [36:32.830 --> 36:32.930] Yeah. [36:33.310 --> 36:33.490] So. [36:34.970 --> 36:35.250] Awesome. [36:35.850 --> 36:37.450] Last call for questions. [36:39.350 --> 36:39.730] Sweet. [36:40.090 --> 36:45.730] Well, um, definitely come say hi, you know, come, come talk to me, even if it's just about what you're planning to have for lunch. [36:45.910 --> 36:48.050] Um, and, uh, yeah, it's a pleasure. [36:48.190 --> 36:48.590] It's a pleasure. [36:48.810 --> 36:48.950] Thanks. [36:48.990 --> 36:49.110] Thanks, y'all. [36:49.910 --> 36:50.050] Bye.