Can You Actually Have a Private Phone Plan? w/ Ruddy Wang - Head of Consumer at Cape
E7

Can You Actually Have a Private Phone Plan? w/ Ruddy Wang - Head of Consumer at Cape

Today, I'm sitting down with Rudy Wang,
head of consumer at Cape, a

cellular company that's been the subject

of much discussion in our spaces lately.

Cape promises to go above and beyond
the privacy and security that

other phone carriers in the US provide.

Full disclosure, I published some of
my own initial impressions of

Cape on my channel back in May, and Cape
did send me a mobile phone

afterwards that I've used to test

their service for the last month or so.

As always, we never publish interviews
at a company's request,

share our questions, or edit them
on their behalf or accept

compensation in exchange for our
content on this channel.

I wanted to sit down with them here
to get some of the technical

questions I had answered, and also to
answer some common questions

I've been seeing on our forum and in our

exclusive signal chat for
channel supporters.

If you want to see more videos like
this, remember to subscribe.

Unfortunately, my own video feed when
we recorded this had some

issues, so I apologize if that's a
bit distracting, but my audio

should be fine and all of his stuff

should be fine, so hopefully
it's not too bad.

Anyways, here's the interview.

Rudy, thank you for joining me here.

Why don't we start out by you just giving
people who listen to this

overview of Cape for people who

haven't heard of it and
what you do there.

Yeah.

Cape is a privacy-first mobile carrier.

By mobile carrier, I think AT&T
Verizon is mobile,

except that we're an MVNO.

We don't own our own towers, but we
own the entire mobile core.

That's all the

telecom infrastructure minus the towers.

You would sign up for us like a

regular cell phone plan subscription.

Except it's more private and secure.

That means we practice minimal
data collection

and then we also have a bunch
of features that

improves your privacy and just

makes it harder to track you over time.

Very cool.

Yeah, I want to get into some of

that mobile core stuff in a minute.

But first, who would you say
Cape is actually for?

What kind of customers do
you sell for and

what's the threat model that
it's designed around?

Yeah, so Cape was started and
designed for everyone.

It's designed so that

I think the basic philosophy is using
your cell phone shouldn't

involve a compromise in your
privacy and security.

Right now, if you use any existing

option, that is what you're doing.

I think we all benefit from the convenience
of having a smartphone

in a pocket all the time that we
can do amazing things with.

But as a sort of underlying trade-off
for being able to have that

connectivity, we are basically carrying
a tracking beacon around

with us all the time and entrusting
an industry that has a pretty

poor cybersecurity record for
protecting that data.

That's kind of the overall
vision for Cape.

In the

present day, today, and now, the folks
who are interested in Cape

and who we're speaking most to are

people who are already privacy aware
and already using, for

example, things like encrypted chat apps

and other types of solutions
that allow you

to opt out of the overall surveillance
economy.

And so that's definitely the folks

that we're speaking to right now.

But the overall vision is this is

just how cell phone service should work.

It shouldn't work as a way to

essentially

leak data about yourself 24-7.

Yeah, absolutely.

So you mentioned your current

audience is more privacy-focused people.

I know you've recently announced some
pricing changes and I feel

like I've seen a lot more talk about
Cape since that happened.

Do you think that that's expanding your

audience a bit more or how's that going?

Yeah, definitely.

I think the pricing change.

So the context here is that we have
one standard $99 plan.

Recently, we announced that if you

sign up this year or earlier, you get

all of our features for $70 forever.

So that means your price is
never going to change.

And that definitely makes Cape
available to more people.

And that's part of the overall goal
for us is to make privacy

shouldn't be purely a premium product

that only people who can
pay for it get it.

And so I think that does expand
the audience.

Part of the reason why we did it this way

right now is because we don't
have multiple plans.

A typical cell phone carrier has,
if you go to the website,

immediately you'll see lots and
lots of different plans.

And actually, on the back end of all
that, they have hundreds and

hundreds of plans because they're using
data about you to try to

predict, OK, what's Jonah's marginal
willingness to pay?

And this is the plan based off all
the data I've collected about

him and I'm collecting about
him in real time.

This is when he's most likely to churn.

So I'm going to give him this exact
offer so I can price Jonah's

plan at exactly as marginal willingness

to pay and extract maximum
value from that.

So we don't have any of that because
we're building the entire

software stack of telco from scratch.

We actually don't have multiple plans.

Our focus this year is

adding value through privacy
and security features.

And eventually we want to be able
to support multiple plans.

Those multiple plans might include things

like lower gigabytes and
things like that.

But that just hasn't been
a focus right now.

And so this ends up being a good
compromise in that if you join

this year, you get that lower price.

And we get to continue to
focus on building

privacy and security features
in the future.

Hopefully, we'll not hopefully not too
far in the future, we'll be

able to roll out multiple tier plans just

to make that available for
more more folks.

But it is for us a heavy research
and development type work.

And so

that's why the price point that we're at.

Very cool.

I assume when you do have multiple
plans, you're going to avoid

those privacy problems that you

mentioned with the other
telecom carriers.

Yeah, totally.

So just by nature, we collect less
information about our customers.

Obviously, we minimize the amount
of information that

we collect.

We're not buying it from other kind of

data brokers and trying to combine that.

And so it's just going to be a very
simple, straightforward plan.

The other thing you'll notice
about our plan is that,

formerly $99, now $70, all taxes
and fees are included.

So here's one fact, like I forget which

carrier it was, but I think it was AT&T.

They hired a whole team and a

specialist that at the store
explains your

first bill to you when you sign up
because the first bill always

looks different from other bills because
you have activation fee.

They add on insurance package
that you can

only call in later to remove
and things like that.

And so as part of that commitment to

transparency, we just keep it at $99,

or now $70 all the doesn't matter
where you live.

We will

take the taxes

off on our part and all the fees
and things like that.

And so it's predictable and it's the

same all the time and there's
no bill shock.

So that includes global roaming.

And again, you're not going
to end up like

suddenly with this huge
like roaming bill.

And so that's the idea just to keep
it simple and transparent.

Before we continue, I want to remind
you that Privacy Guides is a

nonprofit project that's focused on
privacy advocacy and delivering

the best consumer technology rights
advice on the internet.

Please consider supporting our mission
at privacyguides.org donate

and getting subscribed to the channel.

That is very cool because I know some
carriers used to do taxes and

fees included like T-Mobile and I

don't think any of them do anymore.

But it seems like taxes and fees are
a way for other carriers to

kind of increase the prices over time.

I don't know where some of
those fees come from.

But speaking of your $70 plan currently,
you also have this set up

with referral programs where if you use
a referral code to sign up,

you would get another $20 off,
which brings it to $50.

And as far as my understanding is both
of those promotions, the

referral code thing and the $70
thing are for life.

But I think a concern that I see

people have is with sustainability.

I'm wondering because it seems like
you're giving out a lot of

fairly cheap plans or even free plans
in some cases because you

only need, I believe, three referrals
right now if you were

referred yourself to get a
completely free plan.

So what is your what is your
math look like on that?

Because I don't know.

Some people think, yeah, that's
not sustainable.

Yeah.

So just to be just to be
specific on that,

you get a referral, brings you down to

50, and then you refer three
other people.

Right.

And so each of each one of
those knocks off $20.

But for the asterisk on the forever
part, if one of those three

people leaves Cape, that
discount goes away.

So so, you know, I think
that's one thing.

If you if you

imagine a model whereby
100 percent of all

Cape subscribers are maxing
out their referrals.

So essentially, when you add an additional
Cape subscriber, you're

you're basically you're basically
taking off $40.

Right.

So if every every single Cape subscriber
was on a referral,

basically that would converge to

that would converge to $30 eventually.

Like, you know, if you had an infinite
number of Cape subscribers,

that is not sustainable
for the long term.

And that's why the early adopter

promotion is going to be is
going to be temporary.

We will keep the we will keep
the referral plan

forever.

It works a lot like, you know, when
we first started, a lot of

people asked us about family plans.

So something like 70 to 80 percent of
postpaid mobile subscribers

in the U.S. are on some sort
of family plan.

So that's a very common ask.

And our idea was we're going
to do something

a little bit more simple than
the family plan,

but that you can kind of
like post anywhere.

You can post it on social media or and

like get Reddit strangers to sign up.

And that ends up basically being a group,
not necessarily of your

family that's associated with each

other, but like a random
group of strangers.

And I think that's also a little bit

more private than traditional
family plans.

So the $70 plan currently is going to

be going away at the end of the year.

You say referral plans are
sticking around.

Are you planning to keep it at the same

like discount as it is now in same terms?

Because I believe I don't know when you
change this exactly, but it

used to be ten dollars a month
off for each referral.

And then you change it to this.

Do you think the 20 is something
you can stick with or?

Yeah, I think that's totally sustainable.

If you think about at the $99 price
point, if every Cape user was

using it, it would converge to $60 and

not everyone is going to use it.

And so 60 would be the absolute floor
in terms of in terms of like

if every single user was using it.

So it is it's sustainable.

Cool.

Well, I think that sounds
that sounds good.

I think people will be happy
to hear that.

Let's get into some of the more
technical questions.

I think one of the things you were
telling me about and you kind of

make a big deal about this on your
site is that Cape is a heavy

MVNO that runs its own mobile core as

opposed to a light MVNO like
most other ones.

Can you explain what the difference or
distinction is between those

and why that matters for
people's privacy?

Yeah, so a light MVNO.

So

first, the distinction between M&O and
MVNO in the U.S., basically,

there's three basic three basic
M&O's team over rising.

AT&T, they own all the towers.

And MVNO is somebody who uses their

towers but can still sell
cell phone service.

So think of your like mobile, Boost

Mobile, Consumer Cellular, all those guys

are going to be relying on the

infrastructure of somebody of
one of the main M&O's.

And in fact, it's become so easy
to spin up new MVNO's that

like I think Mr.

Beast has an MVNO coming out.

There's one of my favorites
is Meow Mobile.

So it's a mobile carrier for cat owners.

I think Progers, the grocery store,
has a mobile carrier.

It's very easy to spin up an MVNO because
basically you're using

all the same core infrastructure, but
you're putting a marketing

spin over and some like billing and
customer support over it.

What we have is the mobile core.

And so the mobile core is basically like,
I don't know how to, it's

maybe like the brain or the the brain or

the central nervous system of a telecom.

And it's what decides what calls
get routed where.

It determines user authentication.

So basically, are you allowed to
use this network right now?

If you're allowed to use it, how much
data are you allowed to use?

And

it generates, for example, call logs.

And so it allows us a lot more control
over a bunch of privacy and

security aspects of the experience than
just having a light MVNO.

And so that is a pretty significant
difference.

There are very few heavy MVNO's
in the United States.

One example of another MVNO would be a

heavy MVNO would be like Boost
Mobile or DISH.

So DISH was an M&O.

So they had they had spectrum.

And so they were out there to compete
with the other ones.

And then eventually they sold off all
their spectrum holdings and

therefore kind of defaulted from
M&O into a heavy MVNO.

And so the fact that we own the

mobile core allows us to
do special things.

And so I mentioned the fact that

when you own that infrastructure,
you produce call logs.

So we can now determine how long
do we keep those call logs.

A light MVNO would just have to default
to the retention period of

the of the M&O, whereas we can define
a different period.

And so we were able to define 24 hours
for that instead of years.

There's other things like so I mentioned
that the mobile core is

what decides where calls are routed.

So think in your mind of

of like those old style telephone
switchboards where like there's

women switching like little gear boards

around to actually connect those calls.

So that all happens in the
mobile core today.

And one of the attacks or ways to one
of the vulnerabilities of

telecom is that you can actually
hijack that system.

So those are called SS7 or
signaling attacks.

I think you've covered them
a little bit before.

But basically that allows you to decide,
hey, instead of switching

this to the right person, switch
it to me, the attacker.

And so I can intercept calls, SMS
and metadata like location.

So we have control over that layer

so we can implement protections there.

And there's you know, there's a

whole bunch of lists of other things that

we're able to do as a heavy MVNO that
as a light MVNO, your your

options are really limited and your hands

are kind of tied behind your
back in terms of

in terms of in terms of what you can do.

Cool.

I definitely want to get into more
of the specifics about the

mobile core and some of those
attacks you mentioned.

But first, you talked about call logs.

And I think that that's something
that will maybe confuse some

people who are less familiar
with how this works.

I mean, I've looked at some
privacy focused

carriers in the past, which
can go unnamed.

But a big concern that I have with
a lot of them is that so much

data that they collect gets shared with
their underlying upstream

carrier to the extent that even some
of those carriers that I've

looked at will say in their privacy

policies that all of your
usage or all of the.

Yeah, all of the usage on their networks
is going to be subject to

their upstream carriers privacy policy
as well, which sort of, I

think, defeats the purpose of a lot
of those privacy protections.

You're handling a lot more in house,
but at the end of the day, all

of Kape subscribers are going
to be attaching to

whatever carrier partners towers
are out there.

So say I'm communicating with an AT&T
tower, for example, what is

it that AT&T is actually able to see
about me in terms of data

being shared in terms of identifiers
or metadata or anything else

that their infrastructure might
be able to access?

Yeah, so AT&T will still be able
to see quite a bit.

We'll have to share information with
AT&T just in order for

the service to be able to work.

So you would still, they would see the MZ

number, otherwise known as the
subscriber ID number.

They'd see the device ID number,
also known as the IMEI.

They'd be able to see if it's
a data session,

they'd be able to see how many
gigabytes are used.

They'd be able to see a cell ID.

Cell ID would be basically
think of that as like

an abstraction of like cell phone towers.

And those can vary in size between
like miles to, you know, if

you're in a rural area, it could
be like many, many miles.

If you're in an urban area, it
might be like a smaller

radius there.

So they'd be able to see all
of those things.

What they wouldn't be able to get is
they wouldn't be able to match

up that information with, for example,
subscriber information since

we don't collect name, address,
things like that.

We do things that add noise to the
ability to track things.

So we do that by rotating the IMZ number,
the subscriber ID number.

Typically, that number will be static
for as long as you have the

same SIM.

So basically, as long as you're a
subscriber of a particular

mobile carrier, but we will
rotate that daily.

We're able to do that again, not only
because we have our mobile

core, but we also produce our own SIM.

So that's another thing.

Like, MVNOs don't produce their own SIMs.

A SIM is basically

think of that as like an operating
environment

that the telecom has access to
on your phone itself.

So because we have our own SIMs, we
can basically change the IMZ

number that is shared to the
telecom network.

Other things that they'll be able to

see

is the phone number that you're
using as well.

If you use a secondary phone number
of CAPEs, so if you're a CAPE

subscriber, you get one primary
phone number

and you also get two secondary
phone numbers.

If you're using a secondary phone
number to, let's say, like

communicate with a bank or something
to that effect,

the AT&T, you know, if it was on an
AT&T tower, AT&T still would

not be able to see the secondary
phone number.

They would only be able to see the
primary phone number, even if

you're communicating with the secondary.

I don't know if that makes sense.

But basically,

we make it a lot harder to breadcrumb
together all the different

bits of information, since we're feeding

in a lot more noise and a
lot more friction.

And the overall thought is that

when these carriers have an abundance
of clean data, that's the

data that they're going to prioritize
in terms of monetizing.

If there's a whole bunch of data that

has sand in it, it becomes a lot harder.

The last thing I'll mention is that
we do have more than one

carrier partner, so we're able to switch
traffic between the two.

Right now, in practice, you'll mostly
default to one of our carrier

partners, but before the end of the year,

we'll be rolling out something where
you'll have a little bit more

control in terms of being able to swap

traffic between more than one network.

Very cool.

That preemptively answers the question

that I had about your new
carrier partnership.

So that's exciting.

What is that going to look like?

Do you have any set plans?

I was wondering if that'll be tied to
any of the MZ rotation stuff

that you do or if it'll just be like
a switch in the app or...

Yeah, I mean, it'd be really cool if
basically your MZ rotates and

your network rotates at the same time.

That won't be a V0 for us
in the beginning.

Essentially, you'll just be able to

opt between the two different networks.

You'll default to one of the
networks, but then

you'll be able to switch to
the other network.

And that would be completely unique.

It'd be completely unique like
any other carrier.

If they have a deal with more
than one of the

MNOs, the only way to switch would
be to get a new SIM.

That takes a couple of minutes
and it's not

particularly reversible and
things like that.

This will just happen in

real time.

We've had

my employees, including myself,
testing it already.

And basically, when the network switches,
I don't even notice.

I don't have any drop calls
or anything like that.

It just happens in the background,

which is going to be pretty unique.

In 2024,

when I think CAPE was just beginning
to be public, you shared a

device with 404 Media that would rotate
more than the MZ number.

It would rotate the IMEI and stuff.

And I understand that that device is

not being sold to the public anymore.

A lot of people

are hoping to see those identifiers
rotated too.

And I guess thinking about what the
carrier themselves can see is

the IMEI number something that AT&T,
for example, could see when

I'm connecting with their towers.

Or is that something that's
encrypted between

the device and the mobile
core or something?

Yeah, the AT&T can see the IMEI number.

And so who would not be able to see
the IMEI number at first would

be, for example, like a Stingray.

A Stingray that gets the IMEI, they can

only get that after mutual
authentication.

And a Stingray is, by definition,
a fake base station.

And therefore, it shouldn't be able
to authenticate with the user.

And so in general, Stingrays don't get
the IMEI or if they can get

it, they can only get it after
getting the IMZ.

Whereas, you know, like a domestic
growing partner, if it was like

AT&T Verizon, etc., they would
be able to see the IMEI.

And, you know, we have had

customers express interest
in this product.

The reason we haven't rolled it out is
because it's very expensive.

And so we do make it available for

essentially our enterprise customers.

And it's $500 per month.

And at that price point,

the

consumer market for that is pretty small.

And we'd have to do a whole
bunch of work to

be able to support billing
and things like that,

billing, onboarding and all those things.

And so we do want to make it

available and we want to bring
the price down.

But that's going to be a future thing.

That's

not going to be a this year thing

that we're going to make that available.

Yeah.

Is the main challenge

with that finding like a hardware partner
that can support that or

like what makes that so expensive
on your end?

Yeah, it's it's expensive in that

you do need a hardware partnership.

And so you have to actually work with
the manufacturer for that.

There's a whole bunch of IP rights
involved in that.

And then IMEI themselves are also are
also not are also limited.

They're they're actually
a scarce resource.

So differently from from MZ numbers,

there's actually like a limited
number of them.

And all of that basically costs
a lot more money.

Got it.

Going back to what you said about
owning your own SIM cards.

There are some I mean, some cards are
an interesting thing because

I think a lot of people don't think
about them as like their own

computers or like operating
system in your phone.

I remember in 2019,

an exploit and SIM cards called
SIPJACKER was discovered.

I think it was only applicable
to carriers

in a handful of countries,
not everywhere.

But I think it demonstrates that sort
of innocuous things that you

don't think about like your SIM card
can be exploited by attackers.

Does owning your own SIM card allow
you to harden against these

type of exploits like a theoretical one
in the future or reduce the

attack surface of your SIM
card in any way

compared to what other carriers
might be using?

Yeah, yeah, absolutely.

The SIMJACKER report, I think
that was put out by

by a telecom security outfit named INIA.

And so, yeah, we've we've
talked with them

multiple times about how to
harden SIM security.

And in general, and it's not
just SIM cards, right?

It's like everything about telecom has

really low standards for
for cybersecurity.

So there's a huge there's
a huge amount of

area in which we can make
things more secure.

And that's what makes our that's what

makes CAPE as a telecom really
different from

from any other company.

So if you look at a regular
telecom operator,

their R&D budget is only three percent
of their entire budget,

which is incredibly, incredibly low.

So like a regular software company, that

number will be more like 16, 17 percent.

And the reason for that is that what
a telecom operator is doing,

what their whole business model is, is I

have this sort of I have
this sort of like

monopoly control over a bunch of

spectrum that I've bid on and bought.

And now I'm going to outsource
all the actual

R&D to all these other vendors
to do for me.

And so I'm going to have
my SIM vendor here.

I'm going to have like some mobile
core vendors here.

I'm going to have like other vendors

doing other key parts of infrastructure
here.

And if you look at the org chart as
an actual telecom operator,

even if they have the like the title
of engineer or architect,

there's very few people who are

actually hands on keyboard writing code.

It's very, very different for us.

So we've internalized a lot
of these functions.

So in bringing in bringing the SIM in
house and things like that,

we have a lot more control over it.

And, you know, it just fits our it fits
our business model better

and it allows us to innovate
better like that.

And so for us, we are our company
is mostly engineers who are

actually hands on keyboard writing

code for for our actual telecom network.

Can you share like how much of your
budget is R&D percentage?

It's the majority.

It's majority.

I mean, you can you could probably

back into it just from our LinkedIn.

Yeah, you probably just check
our check our LinkedIn.

We have over over 100 employees
right now.

And I think the majority are technical
in some fashion.

So either an engineer,

you know, a wireless solutions architect,
some sort of solutions

architect or product person, like

definitely over 50 percent is that.

And that's our that's our
biggest expense.

It's funny.

I think I made this video about
Cape on my channel.

And I feel like I heard from a lot
of different people at Cape.

It seems like you do have
a lot of employees.

And I just mentioned Cape to a friend
who said that they had a

friend who was also applying at Cape.

So is this something that
are you expanding

pretty quickly or what's what's
that looking like?

Yeah, we're definitely expanding
pretty quickly.

So we are we are venture backed.

We've raised over one hundred
ninety million dollars.

And the reason and the reason that we
need to be venture backed is

because it's a huge amount of
fixed investment to be

really like full stack software
telecom operator.

So it's it's just it's just
a big R&D heavy

kind of kind of venture.

But I think the good thing about that
for us is that once we once

we make this investment, it'll become

easier to scale to more and
more customers.

And so we do see like there's
just I think

you've probably seen from
your own viewers.

I think there's a huge growth
and interest

in this kind of in this kind
of technology.

And if you look even beyond

if you look even beyond,

you know, cell phone carriers, there's
interest overall in.

A

privacy related technology or basically
ways to participate in the

modern Internet without also like giving
up all your privacy and

giving over all of all of your data.

And so I think we've seen that
with with the rise

of AI, a lot more people are
concerned about that.

I think like Dr.

Go, for example, had a huge surge in

in interest as soon as Google

changed its search

privacy policy and in terms
of prioritizing AI.

And I think even prior to that, like
signal, one of their biggest

boosts was when WhatsApp changed
their privacy policy.

So I think there's I think
a general trend in

terms of there's more interest
in the space.

And so it's a huge, huge and
growing area that

we want to place ourselves as central
in being able to serve.

Are there any specific moments in the
past where you've seen like a

boost in your subscribers because
of some event?

Yeah, it's it's interesting.

It's interesting in that

maybe like in a specific area.

So for so, for example, we
partner with the

Electric Electronic Frontier
Foundation in terms of

giving free service to free Cape

Service to journalists, for example.

The reason that we require
a partner is that

we want someone who's like independently
from us able to determine,

OK, you know, who qualifies for
this and who doesn't.

We come back to our for free for your
discounted Cape Service

during one of the so our highest day
ever of inquiries for that was

in the week leading up to the
last No Kings protests.

So that's one example of probably

probably just events that
are happening in

in our in our like current

socio political environment where

there's where there's a lot more people
that value some sort of

privacy for for their activities.

Going back to

being venture backed for a second,
that's a concern that I see

people have as well, especially
because it

seems like we've seen a lot
of venture backed

companies in the privacy space in the

past kind of get acquired or go bust.

It seems like making back that investment
has to be a top priority

for investors, obviously, and they'll do

that through whatever means possible is

because I've also seen I don't remember
if it was from you, but I

believe I've read something from somebody
at Cape that the consumer

side of things is losing money, which
probably makes sense because

it's so new and it requires such
an upfront investment.

But is any of that concerning or should
people be concerned about

the long term future or why shouldn't
they, I guess?

Yeah, I think so.

If the consumer side is, yeah, the
consumer side is losing money

because of fixed cost investment.

Right.

But but in terms of terms of the

business model, it's absolutely
sustainable.

We're seeing really fast
growth and really

good uptake in terms of in terms
of the business.

We also have a significant

enterprise business that's
doing really well.

And even beyond that, we did

you know, early on when we first started
the company, we put in the

privacy policy if Cape were ever to

be required, that the choir needs to

respect the same privacy, the same
privacy policy and the same

privacy promises given to
consumers there.

At this point, I think we are we are
growing at such a rate that

we're growing at such a rate that

acquisition is probably not a
likely outcome for us.

But we are essentially

we are essentially the only player in
this space that is set up to

be a privacy and security first telecom.

And if you think across the different
sectors, not just consumer,

consumer being one sector, but if you
think across all the all the

different other sectors, if you

think about enterprise and the amount of

the amount of potential that's available
there, we are the only

ones well placed to to satisfy
that demand.

The last thing I'll say is that
the mobile market is huge.

Every single person, every single adult
in the United States has

like one or two cell phone plans.

I think it's I think it's almost like
it's getting close to two

lines for every American right now.

If you took a small sliver of that

as being

privacy conscious and privacy aware,

that is actually a massive,
massive market.

Let's get back to some of the
more technical stuff.

I understand that the way you've set
up that mobile core you were

talking about is pretty unconventional
because you are running

everything in Amazon Web Services when
traditional carriers, to my

understanding, everything in like a
proprietary hardware stack.

A big part of that, I assume, would
be for legacy reasons.

But also partly I would imagine that
gives them some sort of

network isolation or maybe air
gapping protections.

In your case, what's the actual security

model that you're relying on
with your mobile car?

Yeah, so we really want to treat
telecom like software.

So that's that's the basic idea.

If you look at modern software,

a lot of is cloud based

that reduces our overall surface
area for for attack.

We don't have a whole bunch of legacy
hardware and protocols.

If you look at modern telecoms, they
may actually use AWS or other

cloud services, but they have to

integrate that with a lot of
legacy technology.

So a lot of a lot of legacy
on-prem stuff.

Any of the major carriers you look
at today are the results of

decades and decades of mergers
and acquisitions.

So they have they have acquired all
these different companies,

maybe regional carriers, different
technologies.

It's all this stuff that's gathered
up over decades and decades.

They've got to stitch all that together
and make it all work.

And they can't deprecate or retire any

of that technology because there's some

there's some segment of their

population that is still relying on that.

It could be like less than 1 percent,
but they're not going to

retire that technology until
that 1 percent is gone.

You can see that, for example, with with

things like 3G and 4G, it took
forever to retire 3G.

And there's still tons of

mainstream networks that
will still use 3G.

And so it's just a very hard
thing to get rid

of that to get rid of that
legacy technology.

But the result of having all that legacy
technology stitch together

with like duct tape and and string
is that there's all these

different attack surfaces for attackers
to attackers to make it in.

And you can see that from the record

of telecom breaches over the years.

So all the major telecoms get
breached all the time.

And so the fact that we
don't have to have

all that baggage with us
is really positive.

So, for example, our network doesn't
support 2G and 3G period.

You'll never notice the difference

because most of the United
States now has 4G

coverage.

And and so but it means that we can
eliminate SS7 attacks, for

example, from the things that
we need to worry

about because SS7 relies on
2G, 3G technology.

And so that's a huge attack surface
that you've just lopped off.

The other thing about being cloud
first is that we're able to

any sort of security updates, we get
that right away and supplied

uniformly across our entire stack.

We get to iterate really quickly and
we don't have to worry about,

you know, plugging holes and all this
other legacy technology.

And so for that reason, we're
one of the few

in terms of like just treating telecom
like modern software.

We have gotten SOC 2 Type
2 certification for

for Cape for the Cape consumer business.

If you look at legacy telecoms, they'll
get the SOC 2 Type 2

certification, which is a which is like
very like normal run of the

way run the mill certification if you're

buying any sort of enterprise software.

Right.

So that's quite normal.

But if you look at any of the main
telecom operators, they will

normally have that certification only

for their business to business platform.

But we're just like, again, treating

consumer like regular commercial
software.

And so there's a whole bunch of
other things that we do.

For example, we

use our user authentication model
uses PKI technology.

So private public keys.

That's fairly common in modern software.

If you use a crypto wallet or
anything like that,

that's that's common, but totally unique

when you bring it over to
the telecom space.

Most telecoms, they will keep all of your

payment information, all your
credit card information.

They will store it themselves, even
though today we have all these

payment gateways that can expose payment
by APIs and therefore.

So we'll we use Stripe as
a payment gateway.

Stripe Stripe keeps the full payment

data and we only get the payment token.

And so in that way, we're
able to separate

payment information from subscriber
information.

And all those things are, I think,

pretty run of the mill for
regular software.

But when you bring a sort of software
model of security and

innovation over to telecom, it
becomes quite novel.

I guess I've used the Stripe
dashboard before.

I feel like Stripe does give you insight
into your customers.

How is that data decoupled
from what you have?

Yeah, so I think for the so for the
default Stripe dashboard,

you're not getting the full
credit card number.

And there is also options to not collect

to not collect address,

the full street address.

We have to collect the zip code for
tax reporting purposes.

And then but beyond that,
we can choose to

not collect the rest of that information.

And so that essentially allows
us to separate that data.

And we're hoping in the future to

add additional payment methods as well.

And so right now you could go into a
store, buy prepaid card, use

that prepaid card, you know, pay cash
for the prepaid card and use

that prepaid card to sign up
for your subscription.

You kind of touched on this earlier
when we talked about the

referral programs, but I saw a few people
in some groups that have

been still kind of confused about this.

I believe your referral program
is handled by

like coupons or something
similar in Stripe.

And what what insight does that

give you into like who's using these

coupon codes or like how like

accounts might be interconnected
basically?

Yeah, so we'd be able to see if those
accounts are interconnected.

But then and so that's part of why we
have framed it as a general

referral program that you can share

with anybody, including strangers.

And therefore they're interconnected,
but those connections are

less meaningful than if they're just
traditional family plans where

you're meant to share them where you
like log into an admin portal

and you share it, you know, you share

them specifically with people
that you know.

And so, you know, the referral program
is made a lot easier in

that, you know, you get there's a code,
there's a link, you can

give that link to pretty much anyone.

You don't have to attach your name to it.

They don't have to be tied to
your billing account.

So on the back end, those
those relationships

are maintained, but they're
less meaningful.

Really quick.

You also mentioned carriers
still using 3G.

Is that the case in the US?

Because I thought they were phased out.

Yeah, so 3G is not completely
deprecated in the US.

That's why SS7 tax are are still a
thing and and still possible.

So the latest Citizen Lab report
is called Bad Connections.

So Citizen Lab is like kind
of called like

the counterintelligence of civil society.

So they're based in I think it's

Toronto and they have a whole bunch of

kind of top level researchers that help

journalists and, you know, other
civil society actors.

Who are under threat of surveillance

combat that.

And so one of their recent reports that
came out just a month ago

talked about signaling attacks and talks
about the fact that cross

protocol tax are still often used.

So basically one way that attackers
will try to get past firewalls

for this is they'll use SS7 attack,
which is based off 2G, 3G, and

then they'll mix that up with the
diameter attack, which is the

signaling language that is
used for 4G and 5G.

So signaling protocol is just considered
that as like a machine to

machine language for machines, for
telecom operators to talk to

each other on whether this call should
be connected, whether it's

allowed, you know, things like that.

So it's definitely still in use.

And it's this kind of thing where

there's very practical, very

little practical use to keeping it live.

But it's very hard to retire
legacy technology.

Probably there's like some pocket,
there's probably some, you know,

pockets that's rural pockets that's only

still covered by 3G or 2G even that makes

operators not want to completely
retire it.

Yeah, I guess you kind of touched
on this a bit.

I know a big selling point
for CAPE is the

protections against these network
signaling attacks.

I think a lot of people heard about
that SS7 attack from the

Veritasium video that came out, I think

like two years ago or something
like that.

What kind of protections do
you have against that?

And also, in addition to SS7, you
mentioned diameter, which I

believe is for 4G networks,
is that correct?

And

does that have similar attacks that
can be done against it?

Or does that offer additional protection?

Yeah, it has the same attacks.

In theory, it's supposed to
be a lot more secure.

But in practice, all the same
attacks are available.

There was a public dissent opinion

by an employee of CISA, the kind
of US cybersecurity agency.

And he published this opinion,
I think, in 2024.

And he basically said,

this is still a problem, right?

Like, since SS7 and like

a lot of, you know, everybody moving

over mostly to 4G, 5G, it's
still a problem.

And you can see it in the Citizen Lab
report as well, that a lot of

the attacks are actually, you know,
the Citizen Lab report

mentions both SS7 and diameter attacks.

So diameter attacks, they're
still happening.

It's the same kind of attack.

So telecoms have put in place firewalls.

And the basic way in which
telecoms defend

against this is what's called
a velocity check.

Velocity check is basically, you know,
I'm here, let's say, in

Virginia right now, and I fly over to,

you know, or I'm here in Virginia, and a

telecom operator in, let's
say, Indonesia says,

you know, I'm actually over there.

But my last attached data from two
hours ago is in Virginia.

The velocity check basically says,
well, there's no way that I

could have flown from here to
Indonesia in two hours.

And so that's the velocity check.

The problem is that in our own CAPE
research, and there's published

research on this on our website, is
that a huge number of networks

can be included within a standard
velocity check.

So a lot of times, the last attached
information or the last

network information can be as
old as four hours old.

If you are with four hours, there's

a huge amount of countries in which,

you know, if you spoofed from
that country's network,

you know, that would actually work.

And I think the Citizen Lab
report showed that

there's probably like 150 different
countries that,

you know, if you're in Europe somewhere,
there's like 150 different

countries in which you could
potentially be

a potential, like, legit operator

and still pass that velocity check.

And so what we do is we will check

against your actual real location.

And so,

you know, taking the case,
like, let's say,

Bahamas, Bahamas is much closer
to here, Virginia.

Let's say there's an attacker.

They've compromised the network
in Bahamas.

They've released the Bahamas,

route me all his SMS and call data.

What we will send to the phone,

to the phone of the CAPE subscriber
is, okay, there's a network in

Bahamas requesting your information
and location data.

Are you actually in the Bahamas?

And then it does an on-the-device check
and sends back a yes or no.

And if it's no, Rudy's not
in the Bahamas.

So we never actually have to know

that Rudy's in Virginia right now.

We just have to know that
Rudy's not in the

Bahamas and then we can decline
that attach.

And if you look at the citizen lab report

shows that cross-country tax
is a common vector.

And so there's like all these countries
from like Mozambique to

Lichtenstein and stuff like that, where

like basically they try one
attack from here.

That gets blocked by a low
velocity check.

They're going to try another attack from

here and eventually one of
them makes it in.

It's funny because as you're saying
that I just realized, like I

think a lot of people who are maybe
more, we'll say dedicated to

privacy will use like Faraday Vakes

or they'll turn off their phones often.

But I guess that would make you
more susceptible to

this sort of thing if your phone is
off for a long period of time

because the velocity checks
if you're not on CAPE.

Ironically, yeah, because your last
attached data is actually going

to be like, you know, if it's like
12 hours old, that could be

like, you know, you could be
like halfway across it.

So I was looking at your network roadmap
and it said that you

implemented something called a GTP proxy
in October of last year.

I was trying to look into your documentation
and I didn't see a lot

of that, but I understand that GTP
see attacks are another

documented form of threats that are kind

of separate from the S07 diameter thing.

Can

you explain like what this GTP proxy
feature is and does it provide

any sort of protections against
this thing?

So the GTP proxy wasn't designed to

specifically address these
kind of protections.

It basically allows us

to do many other things.

So we have a number of different proxies.

So, for example, are the velocity, the
location check firewall that

I just mentioned that's, for example,
operated by a proxy.

We can also, we're also working on
standing up, for example, an MZ

rotation proxy that makes that
MZ rotations smoother.

So it's not geared towards that
specific attack, but

the GTP proxy attack.

But it allows us to essentially to
put in place the instruments

that we can address those attacks and to

further scriber off the station
in the future.

Well, that's good news.

I hope.

Are there any other like big like

security focused plans that
are on your roadmap?

And is your roadmap on your site

currently up to date or what
does that look like?

I've heard conflicting things.

Yeah, we need to update it.

It's always constantly

going to be iterative as
we just progress in

terms of our roadmap and get
more feedback as well.

I think spam filtering is on there.

And so we will be launching our own

spam filtering solution later this year.

We've gotten a lot of feedback
in terms of

secondary numbers in that people
want to be able to

port in their existing number as, for
example, a secondary number.

They want to be able to, we have a lot
of folks that started off by

signing up with Cape with a new

number and they kept their old number.

And now they want to switch everything
over to Cape.

So we've gotten requests for it.

Can I keep my account?

Rather than having to cancel my account,
port in my number and just

like swap out my existing primary number.

So that'll be another thing.

So all these things in terms of like
more dynamic management of

primary versus secondary numbers and

being able to swap them in and out.

That's something that we've gotten
a lot more signal on.

And so it's probably something that
we'll try to include in the

roadmap that isn't currently published
on the website right now.

The

being able to switch between the network.

So the domestic roaming partner, I
think is something that's not

currently published on the roadmap,

but we are definitely going to do that.

I'm trying to think what else

is potentially out of date.

But we're

updating that roadmap every month.

And so you should see the
new things on there.

Cool.

I think when it comes to the roadmap
and your features, I've seen a

lot of people either surprised or kind
of disappointed about the

not so great support for RCS with
Cape at the moment.

I believe it only works with iOS if
you disable IMSI rotation and

it doesn't work at all with Android

unless you're using GrapheneOS
to my knowledge.

Is that true?

Yeah, so basically

we wanted to get RCS working much
earlier, but we realized that

when you mix RCS with certain

things like IMSI rotation, it breaks it.

And so every time your IMSI rotates,
it turns RCS off.

And so we've been working through
each of those.

The issue is that we need to work with

essentially each OEM or handset
manufacturer.

So whether it be like Google or Apple
or any of these guys to be

able to get our settings as a carrier
recognized by them.

And so this requires them to prioritize
us in some sort of way, fit

us into their development cycle, which
is often planned a year in

advance and to then ingest
those settings.

The reason it works faster with

GrapheneOS is, you know, GrapheneOS is

we had already been talking to, they're
kind of more nimble and so

they're able to just like take
our settings in faster.

And that's why RCS with GrapheneOS
works faster.

For all the others, we are,

we do have all that scheduled
to be fixed this year.

It's just, you know, we got
to fall in line

with their roadmaps to get those
changes accepted.

And the fact that we have these
additional features like IMSI

rotation, it adds another layer of

complexity of where things can break.

And so that's why it's taking longer.

Yeah, I think some people find it

unfortunate because you also just
deprecated Last Mile SMS

encryption, I believe, which wasn't
like a perfect security

feature, but might have provided some
protection, I'd imagine,

until like RCS with end-to-end encryption
is more widely available.

Yeah.

What was that?

To be clear, yeah, to be clear,
we'll bring it back.

The Last Mile encryption is

available for all of your
secondary numbers.

It just won't be available for your
primary number anymore.

And it was previously like an

experimental feature that
only worked for iOS.

And

so the reason for taking away right
now is whenever we do one of

these things, it basically
breaks more things.

And so we're just trying to decrease the

complexity while we, for example,
get RCS working again.

We roll out all these different ability
to manage numbers and

swapping numbers between like, you
know, port-in to primary,

primary to secondary, things like that.

And once we've sorted out a lot of
those things and we have our

carrier settings recognized by the major
manufacturers, that's when

it makes sense to look again at Last

Mile encryption for primary number.

So that's why it's just basically to
simplify things so that we can

make the core product features
more robust.

But again,

for Last Mile encryption, you still do

have it for both of the
secondary numbers.

Can you explain, I was reading about
your disappearing Colog's

product feature, and you mentioned this
earlier, how you only keep

some of those for like 24 hours or

a matter of days or months or so.

I would imagine that all of the all of
that data has to be used for

like billing purposes, like your upstream
carriers would have to

bill you for usage and stuff like that.

How is how is all of that data collected?

And does any of that, any of those

disappearing logs features
interfere with that?

Or do you have to do some
additional logging

separately in order to get that
data from your carrier?

How does all of that work?

Yeah, so the whole billing reconciliation
process is basically

about like both sides comparing receipts.

And so, for example, if we have if we
have a roaming partner, the

roaming partner says like, you know,
your subscribers used 100

gigabytes, 100 gigabytes
of data in France.

We'll want to look on our side and be
like, okay, I also have 100

gigabytes of data used in France.

It matches.

We don't have any dispute.

Or if there's, you know, some big

discrepancy,

then then I want to be able to peel down.

Okay, like what what went wrong?

Why is that?

Why has what has gone wrong there?

And so

that's why, like, some monthly
data is useful.

So I think you can see in our blog

posts, internal CRs are kept for 30 days.

And then what we can glean
from individual CDR.

So individual CDRs will have a huge
amount of data, right?

So we'll have the cell ID that
gives the subscriber,

subscriber location,

you know, all the identifiers, like the

phone number, the device ID,
the MZ and all that.

So what we'll do is we'll strip all that
data from individual CDRs.

And we'll get an aggregate level of data.

So by aggregate, how much did how much

data was used over the course
of the month?

And that way we can compare that
monthly aggregate data with

whatever our roaming partner
is reporting to

us and thereby resolve any
billing dispute.

So it's basically a receipts
comparison thing.

In essence, we strip all identifying
information and aggregate.

And that's how we can

do the, do the

billing reconciliation.

One last thing that I saw people,
at least a couple of people

asking about on our Privacy
Guides form is

about Apple's limit precise
location feature.

Have you looked into that at all?

Or is that something that Cape
is even able to support?

Or does that need like hardware support?

Or?

Yeah, what's going on?

Yeah, yeah, it's a very, it's a very
cool feature basically uses a

concept like of timing advance and
introduces randomness into that

timing advance so that you can't so
basically that the carrier

cannot infer precise location anymore.

On our side, the the only location
data that we have is cell ID.

So cell ID is already in precise data.

Right now, Apple is only supporting
this for boost mobile.

And, you know, we'd love we'd
love to be the second.

We'd love to be the second carrier
that they support this with.

If you look at it, I think they support
only a few countries and

only one carrier for each of those

countries.

So, you know, tell, tell Apple to,
to put us put us in next.

So that's something on that's something
on Apple side of things.

Yeah, we would need.

Yeah, we would need to be able to
work with them to enable it.

Interesting.

Well, yeah, like I said, I won't I

won't take up too much more your time.

I think that kind of wraps it up.

Is there anything that you wanted to

talk about that we didn't discuss here?

I think in general, there's a what's
important for people to

remember is there's no perfect solution

in in the cellular network
area right now.

So if you're used to things
like encrypted

apps like like signal that can
do into encryption,

the the cell phone networks were

designed for interoperability, right?

It's designed so that you know, it works
with your bank, you know,

you can call your grandma on it and
all those things that makes it

wonderful in that it's the most interoperable,
most universally

useful thing that you could
use to connect.

I can connect from somebody
here all the way.

Across the world.

But that's also its source of weakness.

And we're going piece by piece.

Making things better.

Incrementally to plug up those holes.

And so a lot of so a lot of those
things that we're doing

is not even really sexy.

I think that the things that a lot of

customers focus on is like ems rotation.

You know, the secondary numbers, the

network lock, all the fancy
things that we do.

Probably the most important
thing that we do is

that we just take cybersecurity
more seriously.

It's central to our business model.

And it's central to our whole
security model.

If you go to our trust center, we
are way more transparent

about our security posture than anybody
else that that that I know

of any other carrier that I know of.

That's why we got the SOC 2 Type
2 compliance certification.

And that's also why, you know, we are

building our own mobile core and

making it making sure it's cloud first.

All these like basic

software principles that are familiar
to cybersecurity

professionals, like bringing
that over to telecom.

That's going to be what kind of makes
the biggest difference in

your average, everyday phone user.

Because if you think about it,

what is most likely going
to happen to you?

Your cell phone carrier is going
to sell your location data.

Because they've done it in the past.

They've been fined $200 million
for doing so.

Or they're going to lose their they're
going to lose that data.

So I think there's an AT&T hack of
their snowflake instance.

And it was basically because they
weren't using multi factor

authentication at that point,
which is super unsexy.

Right?

Like just making sure you have that

basic cybersecurity cybersecurity
hygiene.

But that's actually a major that's
going to be one of the major

benefits of of having this different kind

of like security focused telecom carrier.

Very cool.

Yeah, I mean, that cybersecurity
focus is just so important.

Yeah, I think that's kind of it.

For now, I think we covered most of the
things that I've seen a lot

of people talk about or ask me since

we've been talking about cave recently.

So I'm excited to share this with people.

And hopefully,

it answers questions or prompts
more questions.

Maybe I'll have to come back to you.

Yeah, yeah.

Yeah,

totally.

I'm up.

I'm up for I'm up for answering
more, more questions.

I think that'll happen.

I'll be following privacy guides closely

and see if I can see if I
can jump in there.

But if but if I can't just hit me up and

be be glad to talk again.

If you have any more questions, be sure
to leave a comment or come

join the discussion on our community

forum at discuss privacy guides.net.

I'd like to again thank
Rudy from Cape for

answering my questions about the service.

And I hope it's answered some of

the questions you might have had to

Episode Video

Creators and Guests

Jonah Aragon
Host
Jonah Aragon
Program Director at Privacy Guides
Ruddy Wang
Guest
Ruddy Wang
Head of Consumer at Cape