Sunday, February 17, 2019

I followed Michael Bazzell's advice and now have a semi-anonymous* cell phone

Podcast in question: https://soundcloud.com/user-98066669/111-back-to-basics-phones-mysudo

  1. I opened a PO Box that can receive mail in my real name and an alias name (they asked if that was a family member--yes--and were they over 18--also yes)

  2. My Protonmail/VPN account was coming up for expiration, so instead of continuing it, I opened a new account under an alias, using a SecureCore VPN (they ask for an email to prevent spamming, and I gave them an old junk email--they say they only store the hash of that email to monitor how many people are making accounts), and purchased some Monero, then paid for a Protonmail/VPN Visionary account using Monero-xmr.to-Bitcoin. So now I have a 99% anonymous Proton Visionary account

  3. I installed a Protectli box between my ISP wifi router and my new wifi router (see next). This Protectli box is running pfSense and has an always on ProtonVPN

  4. I installed a Ubiquiti Pro Wireless Access Point, disabled as much telemetry/analytics as possible, and everything that leaves this wifi router goes to the Protectli box, and anything leaving that goes through ProtonVPN

  5. I ordered a prepaid Mint Sim card from their website. They have a promo right now of 3 months service for $20 total, 8 GB of data per month at LTE speed. This was paid for using a Mastercard gift card, purchased with cash, and delivered to my alias name at my PO Box

  6. I purchased a new iPhone from the apple store in cash. This was surprisingly much easier than I expected. I told them I travel internationally, and as such needed the unlocked version, and I would activate it at home. They did ask for my name for a waiting list, and I gave them a made up name.

  7. At home, on your web browser, through your protected VPN network, go to icloud.com and create a new icloud account in your browser (this will be used for your phone). I used an alias name, with a first name that could be male or female, found a condo in a large city and used that address (just don't put an apartment number) and found the local phone number for their front desk and listed that as my phone.

  8. Boot up the phone, connect to the VPN protected wifi, and set it up with no icloud account. You want the phone to boot up with as little set up as possible. Once you get to the home screen, then go to Settings and log in with your iCloud account. This may take some time. Once that's done, go to all the other settings and disable as much as possible (i.e. Siri is disabled, no iCloud backup, custom alpha-numeric password following this guide, etc...)

  9. Purchase a few gift cards or iTunes gift cards with cash. Keep the amounts low ($50-100) otherwise the store will get suspicious. Load these into your iCloud account/iTunes balance. If you have an iTunes gift card, it will auto load the full amount. If you have a regular gift card, then you have to specify how much, and it will consider that card as your primary card and will withdraw when necessary.

  10. Download miniKeePass (or whatever your password manager is) from the store (and your other apps as necessary, particularly a VPN app--obviously it is Proton for me)

  11. Using a junk email, mail yourself (on your laptop) your password database. Log in to this email in Safari on iOS, download the attachment, and open it in miniKeePass (or whatever you have). Now you have all your passwords on your phone, and can log in to whatever your apps are (for me, things like Protonmail, ProtonVPN, Privacy.com, Firefox Focus)

  12. Download MySudo from the App Store. Open the app, buy whichever plan you want. I got the 9 number plan, I think it's like $15/month. Now you have 9 VOIP numbers. I picked the number's area code based on what makes sense--i.e. my utility number is where my house is, my personal number is from an area code in a different state, my work phone number is from where my work is)

  13. Bonus: download Signal and use that for all commications when able.

  14. Delete as many Apps as necessary that you don't use, and put the MySudo app where the Phone app usually goes, and same thing with Signal for Messages.

  15. Boom. A semi-anonymous cell phone, for a hundred dollars less a month than a regular plan, AND you get 9 numbers too.

Ninja-Edit: 17. When you're not at home, and connected to the cell data network, always turn your VPN app on. This way Mint Sim/T-Blowbile can't see what you're accessing, and more importantly it's much harder to trace back to you.

Shaolin-Monk-Edit: 18. What to do with your old phone number? Port it to Google Voice, and set it up to forward all texts, calls, and voicemails to your Gmail inbox. Now set Gmail up so that it auto-forwards-and-deletes all emails to a separate Protonmail email address that is only used for this purpose. Now, if anyone calls or texts my old number, I get an email in my Proton inbox and I can either call/text them back using the appropriate new number in MySudo, or just ignore them.

  • It's semi-anonymous because 100% anonymity is impossible in the digital world
  • When the mint sim runs out in 3 months, I'm just going to order a new sim card with a new number that I won't use for anything, so it's transparent to me, but will save me a ton of money

Any thoughts on ways I can improve my strategy? My threat model is a little unique, and an iPhone is completely acceptable for my needs



No comments:

Post a Comment