Can You Actually Have a Private Phone Plan? w/ Ruddy Wang - Head of Consumer at Cape
E7

Can You Actually Have a Private Phone Plan? w/ Ruddy Wang - Head of Consumer at Cape

Editor's note: This transcript was AI generated and may contain inaccuracies, it is provided on a best-effort basis for your convenience.

JONAH: Today, I'm sitting down with Ruddy Wang, head of consumer at Cape, a cellular company that's been the subject of much discussion in our spaces lately. Cape promises to go above and beyond the privacy and security that other phone carriers in the US provide. Full disclosure, I published some of my own initial impressions of Cape on my channel back in May, and Cape did send me a mobile phone afterwards that I've used to test their service for the last month or so. As always, we never publish interviews at a company's request, share our questions, or edit them on their behalf or accept compensation in exchange for our content on this channel. I wanted to sit down with them here to get some of the technical questions I had answered, and also to answer some common questions I've been seeing on our forum and in our exclusive signal chat for channel supporters.

If you want to see more videos like this, remember to subscribe. Unfortunately, my own video feed when we recorded this had some issues, so I apologize if that's a bit distracting, but my audio should be fine and all of his stuff should be fine, so hopefully it's not too bad. Anyways, here's the interview. Ruddy, thank you for joining me here. Why don't we start out by you just giving people who listen to this overview of Cape for people who haven't heard of it and what you do there.

RUDDY WANG: Yeah. Cape is a privacy-first mobile carrier. By mobile carrier, think AT&T, Verizon, or T-Mobile, except that we're an MVNO. We don't own our own towers, but we own the entire mobile core. That's all the telecom infrastructure minus the towers. You would sign up for us like a regular cell phone plan subscription. Except it's more private and secure. That means we practice minimal data collection and then we also have a bunch of features that improves your privacy and just makes it harder to track you over time.

JONAH: Very cool. Yeah, I want to get into some of that mobile core stuff in a minute. But first, who would you say Cape is actually for? What kind of customers do you sell for and what's the threat model that it's designed around?

RUDDY WANG: Yeah, so Cape was started and designed for everyone. It's designed so that I think the basic philosophy is using your cell phone shouldn't involve a compromise in your privacy and security. Right now, if you use any existing option, that is what you're doing. I think we all benefit from the convenience of having a smartphone in a pocket all the time that we can do amazing things with. But as a sort of underlying trade-off for being able to have that connectivity, we are basically carrying a tracking beacon around with us all the time and entrusting an industry that has a pretty poor cybersecurity record for protecting that data. That's kind of the overall vision for Cape. In the present day, today, and now, the folks who are interested in Cape and who we're speaking most to are people who are already privacy aware and already using, for example, things like encrypted chat apps and other types of solutions that allow you to opt out of the overall surveillance economy.

And so that's definitely the folks that we're speaking to right now. But the overall vision is this is just how cell phone service should work. It shouldn't work as a way to essentially leak data about yourself 24-7.

JONAH: Yeah, absolutely. So you mentioned your current audience is more privacy-focused people. I know you've recently announced some pricing changes and I feel like I've seen a lot more talk about Cape since that happened. Do you think that's expanding your audience a bit more or how's that going?

RUDDY WANG: Yeah, definitely. I think the pricing change. So the context here is that we have one standard $99 plan. Recently, we announced that if you sign up this year or earlier, you get all of our features for $70 forever. So that means your price is never going to change. And that definitely makes Cape available to more people. And that's part of the overall goal for us is to make privacy shouldn't be purely a premium product that only people who can pay for it get it. And so I think that does expand the audience. Part of the reason why we did it this way right now is because we don't have multiple plans. A typical cell phone carrier has, if you go to the website, immediately you'll see lots and lots of different plans. And actually, on the back end of all that, they have hundreds and hundreds of plans because they're using data about you to try to predict, OK, what's Jonah's marginal willingness to pay?

And this is the plan based off all the data I've collected about him and I'm collecting about him in real time. This is when he's most likely to churn. So I'm going to give him this exact offer so I can price Jonah's plan at exactly as marginal willingness to pay and extract maximum value from that. So we don't have any of that because we're building the entire software stack of telco from scratch. We actually don't have multiple plans. Our focus this year is adding value through privacy and security features. And eventually we want to be able to support multiple plans. Those multiple plans might include things like lower gigabytes and things like that. But that just hasn't been a focus right now. And so this ends up being a good compromise in that if you join this year, you get that lower price.

And we get to continue to focus on building privacy and security features in the future. Hopefully, we'll not hopefully not too far in the future, we'll be able to roll out multiple tier plans just to make that available for more folks. But it is for us a heavy research and development type work. And so that's why the price point that we're at.

JONAH: Very cool. I assume when you do have multiple plans, you're going to avoid those privacy problems that you mentioned with the other telecom carriers.

RUDDY WANG: Yeah, totally. So just by nature, we collect less information about our customers. Obviously, we minimize the amount of information that we collect. We're not buying it from other kind of data brokers and trying to combine that. And so it's just going to be a very simple, straightforward plan. The other thing you'll notice about our plan is that, formerly $99, now $70, all taxes and fees are included. So here's one fact, like I forget which carrier it was, but I think it was AT&T. They hired a whole team and a specialist that at the store explains your first bill to you when you sign up because the first bill always looks different from other bills because you have activation fee. They add on insurance package that you can only call in later to remove and things like that. And so as part of that commitment to transparency, we just keep it at $99, or now $70 all-in; it doesn't matter where you live.

We will take the taxes off on our part and all the fees and things like that. And so it's predictable and it's the same all the time and there's no bill shock. So that includes global roaming. And again, you're not going to end up like suddenly with this huge like roaming bill. And so that's the idea just to keep it simple and transparent.

JONAH: Before we continue, I want to remind you that Privacy Guides is a nonprofit project that's focused on privacy advocacy and delivering the best consumer technology rights advice on the internet. Please consider supporting our mission at privacyguides.org/donate and getting subscribed to the channel. That is very cool because I know some carriers used to do taxes and fees included like T-Mobile and I don't think any of them do anymore. But it seems like taxes and fees are a way for other carriers to kind of increase the prices over time. I don't know where some of those fees come from. But speaking of your $70 plan currently, you also have this set up with referral programs where if you use a referral code to sign up, you would get another $20 off, which brings it to $50. And as far as my understanding is both of those promotions, the referral code thing and the $70 thing are for life.

But I think a concern that I see people have is with sustainability. I'm wondering because it seems like you're giving out a lot of fairly cheap plans or even free plans in some cases because you only need, I believe, three referrals right now if you were referred yourself to get a completely free plan. So what does your math look like on that? Because I don't know. Some people think, yeah, that's not sustainable.

RUDDY WANG: Yeah. So just to be specific on that, you get a referral, brings you down to 50, and then you refer three other people.

JONAH: Right.

RUDDY WANG: And so each one of those knocks off $20. But for the asterisk on the forever part, if one of those three people leaves Cape, that discount goes away. So, you know, I think that's one thing. If you imagine a model whereby 100 percent of all Cape subscribers are maxing out their referrals. So essentially, when you add an additional Cape subscriber, you're basically taking off $40. Right. So if every single Cape subscriber was on a referral, basically that would converge to $30 eventually. Like, you know, if you had an infinite number of Cape subscribers, that is not sustainable for the long term. And that's why the early adopter promotion is going to be temporary. We will keep the referral plan forever. It works a lot like, you know, when we first started, a lot of people asked us about family plans.

So something like 70 to 80 percent of postpaid mobile subscribers in the U.S. are on some sort of family plan. So that's a very common ask. And our idea was we're going to do something a little bit more simple than the family plan, but that you can kind of like post anywhere. You can post it on social media or and like get Reddit strangers to sign up. And that ends up basically being a group, not necessarily of your family that's associated with each other, but like a random group of strangers. And I think that's also a little bit more private than traditional family plans.

JONAH: So the $70 plan currently is going to be going away at the end of the year. You say referral plans are sticking around. Are you planning to keep it at the same like discount as it is now in same terms? Because I believe I don't know when you change this exactly, but it used to be ten dollars a month off for each referral. And then you change it to this. Do you think the 20 is something you can stick with or?

RUDDY WANG: Yeah, I think that's totally sustainable. If you think about at the $99 price point, if every Cape user was using it, it would converge to $60 and not everyone is going to use it. And so 60 would be the absolute floor in terms of like if every single user was using it. So it's sustainable.

JONAH: Cool. Well, I think that sounds good. I think people will be happy to hear that. Let's get into some of the more technical questions. I think one of the things you were telling me about and you kind of make a big deal about this on your site is that Cape is a heavy MVNO that runs its own mobile core as opposed to a light MVNO like most other ones. Can you explain what the difference or distinction is between those and why that matters for people's privacy?

RUDDY WANG: Yeah, so a light MVNO. So first, the distinction between MNO and MVNO in the U.S., basically, there are three basic MNOs: T-Mobile, Verizon, and AT&T. They own all the towers. And MVNO is somebody who uses their towers but can still sell cell phone service. So think of US Mobile, Boost Mobile, Consumer Cellular, all those guys are going to be relying on the infrastructure of somebody of one of the main MNOs. And in fact, it's become so easy to spin up new MVNOs that like I think Mr. Beast has an MVNO coming out. There's one of my favorites is Meow Mobile. So it's a mobile carrier for cat owners. I think Kroger, the grocery store, has a mobile carrier. It's very easy to spin up an MVNO because basically you're using all the same core infrastructure, but you're putting a marketing spin over and some like billing and customer support over it.

What we have is the mobile core. And so the mobile core is basically like, I don't know how to, it's maybe like the brain or central nervous system of a telecom. And it's what decides what calls get routed where. It determines user authentication. So basically, are you allowed to use this network right now? If you're allowed to use it, how much data are you allowed to use? And it generates, for example, call logs. And so it allows us a lot more control over a bunch of privacy and security aspects of the experience than just having a light MVNO. And so that is a pretty significant difference. There are very few heavy MVNOs in the United States. One example of another MVNO would be a heavy MVNO would be like Boost Mobile or DISH. So DISH was an MNO. So they had spectrum.

And so they were out there to compete with the other ones. And then eventually they sold off all their spectrum holdings and therefore kind of defaulted from MNO into a heavy MVNO. And so the fact that we own the mobile core allows us to do special things. And so I mentioned the fact that when you own that infrastructure, you produce call logs. So we can now determine how long do we keep those call logs. A light MVNO would just have to default to the retention period of the MNO, whereas we can define a different period. And so we were able to define 24 hours for that instead of years. There's other things like so I mentioned that the mobile core is what decides where calls are routed. So think in your mind of like those old style telephone switchboards where like there's women switching like little gear boards around to actually connect those calls.

So that all happens in the mobile core today. And one of the attacks or ways to one of the vulnerabilities of telecom is that you can actually hijack that system. So those are called SS7 or signaling attacks. I think you've covered them a little bit before. But basically that allows you to decide, hey, instead of switching this to the right person, switch it to me, the attacker. And so I can intercept calls, SMS and metadata like location. So we have control over that layer so we can implement protections there. And there's you know, there's a whole bunch of lists of other things that we're able to do as a heavy MVNO that as a light MVNO, your options are really limited and your hands are kind of tied behind your back in terms of what you can do.

JONAH: Cool. I definitely want to get into more of the specifics about the mobile core and some of those attacks you mentioned. But first, you talked about call logs. And I think that's something that will maybe confuse some people who are less familiar with how this works. I mean, I've looked at some privacy focused carriers in the past, which can go unnamed. But a big concern that I have with a lot of them is that so much data that they collect gets shared with their underlying upstream carrier to the extent that even some of those carriers that I've looked at will say in their privacy policies that all of your usage or all of the. Yeah, all of the usage on their networks is going to be subject to their upstream carriers privacy policy as well, which sort of, I think, defeats the purpose of a lot of those privacy protections.

You're handling a lot more in house, but at the end of the day, all of Cape subscribers are going to be attaching to whatever carrier partners towers are out there. So say I'm communicating with an AT&T tower, for example, what is it that AT&T is actually able to see about me in terms of data being shared in terms of identifiers or metadata or anything else that their infrastructure might be able to access?

RUDDY WANG: Yeah, so AT&T will still be able to see quite a bit. We'll have to share information with AT&T just in order for the service to be able to work. So you would still, they would see the IMSI number, otherwise known as the subscriber ID number. They'd see the device ID number, also known as the IMEI. They'd be able to see if it's a data session, they'd be able to see how many gigabytes are used. They'd be able to see a cell ID. Cell ID would be basically think of that as like an abstraction of like cell phone towers. And those can vary in size between like miles to, you know, if you're in a rural area, it could be like many miles. If you're in an urban area, it might be like a smaller radius there. So they'd be able to see all of those things.

What they wouldn't be able to get is they wouldn't be able to match up that information with, for example, subscriber information since we don't collect name, address, things like that. We do things that add noise to the ability to track things. So we do that by rotating the IMSI number, the subscriber ID number. Typically, that number will be static for as long as you have the same SIM. So basically, as long as you're a subscriber of a particular mobile carrier, but we will rotate that daily. We're able to do that again, not only because we have our mobile core, but we also produce our own SIM. So that's another thing. Like, MVNOs don't produce their own SIMs. A SIM is basically think of that as like an operating environment that the telecom has access to on your phone itself. So because we have our own SIMs, we can basically change the IMSI number that is shared to the telecom network.

Other things that they'll be able to see is the phone number that you're using as well. If you use a secondary phone number of Cape's, so if you're a Cape subscriber, you get one primary phone number and you also get two secondary phone numbers. If you're using a secondary phone number to, let's say, like communicate with a bank or something to that effect, the AT&T, you know, if it was on an AT&T tower, AT&T still would not be able to see the secondary phone number. They would only be able to see the primary phone number, even if you're communicating with the secondary. I don't know if that makes sense. But basically, we make it a lot harder to breadcrumb together all the different bits of information, since we're feeding in a lot more noise and a lot more friction. And the overall thought is that when these carriers have an abundance of clean data, that's the data that they're going to prioritize in terms of monetizing.

If there's a whole bunch of data that has sand in it becomes a lot harder. The last thing I'll mention is that we do have more than one carrier partner, so we're able to switch traffic between the two. Right now, in practice, you'll mostly default to one of our carrier partners, but before the end of the year, we'll be rolling out something where you'll have a little bit more control in terms of being able to swap traffic between more than one network.

JONAH: Very cool. That preemptively answers the question that I had about your new carrier partnership. So that's exciting. What is that going to look like? Do you have any set plans? I was wondering if that'll be tied to any of the IMSI rotation stuff that you do or if it'll just be like a switch in the app or...

RUDDY WANG: Yeah, I mean, it'd be really cool if basically your IMSI rotates and your network rotates at the same time. That won't be a V0 for us in the beginning. Essentially, you'll just be able to opt between the two different networks. You'll default to one of the networks, but then you'll be able to switch to the other network. And that would be completely unique. It'd be completely unique like any other carrier. If they have a deal with more than one of the MNOs, the only way to switch would be to get a new SIM. That takes a couple of minutes and it's not particularly reversible and things like that. This will just happen in real time. We've had my employees, including myself, testing it already. And basically, when the network switches, I don't even notice. I don't have any dropped calls or anything like that.

It just happens in the background, which is going to be pretty unique.

JONAH: In 2024, when I think Cape was just beginning to be public, you shared a device with 404 Media that would rotate more than the IMSI number. It would rotate the IMEI and stuff. And I understand that device is not being sold to the public anymore. A lot of people are hoping to see those identifiers rotated too. And I guess thinking about what the carrier themselves can see is the IMEI number something that AT&T, for example, could see when I'm connecting with their towers. Or is that something that's encrypted between the device and the mobile core or something?

RUDDY WANG: Yeah, AT&T can see the IMEI number. And so who would not be able to see the IMEI number at first would be, for example, like a Stingray. A Stingray that gets the IMEI, they can only get that after mutual authentication. And a Stingray is, by definition, a fake base station. And therefore, it shouldn't be able to authenticate with the user. And so in general, Stingrays don't get the IMEI or if they can get it, they can only get it after getting the IMSI. Whereas, you know, like a domestic roaming partner, if it was like AT&T Verizon, etc., they would be able to see the IMEI. And, you know, we have had customers express interest in this product. The reason we haven't rolled it out is because it's very expensive. And so we do make it available for essentially our enterprise customers.

And it's $500 per month. And at that price point, the consumer market for that is pretty small. And we'd have to do a whole bunch of work to be able to support billing and things like that, billing, onboarding and all those things. And so we do want to make it available and we want to bring the price down. But that's going to be a future thing. That's not going to be a this year thing that we're going to make that available.

JONAH: Yeah. Is the main challenge with that finding like a hardware partner that can support that or like what makes that so expensive on your end?

RUDDY WANG: Yeah, it's expensive in that you do need a hardware partnership. And so you have to actually work with the manufacturer for that. There's a whole bunch of IP rights involved in that. And then IMEIs themselves are also not are also limited. They're actually a scarce resource. So differently from IMSI numbers, there's actually like a limited number of them. And all of that basically costs a lot more money.

JONAH: Got it. Going back to what you said about owning your own SIM cards. I mean, SIM cards are an interesting thing because I think a lot of people don't think about them as like their own computers or like operating system in your phone. I remember in 2019, an exploit in SIM cards called Simjacker was discovered. I think it was only applicable to carriers in a handful of countries, not everywhere. But I think it demonstrates that sort of innocuous things that you don't think about like your SIM card can be exploited by attackers. Does owning your own SIM card allow you to harden against these type of exploits like a theoretical one in the future or reduce the attack surface of your SIM card in any way compared to what other carriers might be using?

RUDDY WANG: Yeah, absolutely. The Simjacker report, I think that was put out by a telecom security outfit named Enea. And so, yeah, we've talked with them multiple times about how to harden SIM security. And in general, and it's not just SIM cards, right? It's like everything about telecom has really low standards for cybersecurity. So there's a huge amount of area in which we can make things more secure. And that's what makes what makes Cape as a telecom really different from any other company. So if you look at a regular telecom operator, their R&D budget is only three percent of their entire budget, which is incredibly low. So like a regular software company, that number will be more like 16, 17 percent. And the reason for that is that what a telecom operator is doing, their whole business model is: I have this sort of like monopoly control over a bunch of spectrum that I've bid on and bought.

And now I'm going to outsource all the actual R&D to all these other vendors to do for me. And so I'm going to have my SIM vendor here. I'm going to have like some mobile core vendors here. I'm going to have like other vendors doing other key parts of infrastructure here. And if you look at the org chart as an actual telecom operator, even if they have the like the title of engineer or architect, there's very few people who are actually hands on keyboard writing code. It's very different for us. So we've internalized a lot of these functions. So in bringing the SIM in house and things like that, we have a lot more control over it. And, you know, it just fits our it fits our business model better and it allows us to innovate better like that. And so for us, we are our company is mostly engineers who are actually hands on keyboard writing code for our actual telecom network.

JONAH: Can you share like how much of your budget is R&D percentage?

RUDDY WANG: It's the majority. It's majority. I mean, you can you could probably back into it just from our LinkedIn. Yeah, you probably just check our LinkedIn. We have over 100 employees right now. And I think the majority are technical in some fashion. So either an engineer, you know, a wireless solutions architect, some sort of solutions architect or product person, like definitely over 50 percent is that. And that's our biggest expense.

JONAH: It's funny. I think I made this video about Cape on my channel. And I feel like I heard from a lot of different people at Cape. It seems like you do have a lot of employees. And I just mentioned Cape to a friend who said that they had a friend who was also applying at Cape. So is this something that are you expanding pretty quickly or what's that looking like?

RUDDY WANG: Yeah, we're definitely expanding pretty quickly. So we are venture backed. We've raised over one hundred ninety million dollars. And the reason that we need to be venture backed is because it's a huge amount of fixed investment to be really like full stack software telecom operator. So it's just a big R&D heavy kind of venture. But I think the good thing about that for us is that once we make this investment, it'll become easier to scale to more and more customers. And so we do see like there's just I think you've probably seen from your own viewers. I think there's a huge growth and interest in this kind of technology. And if you look even beyond, you know, cell phone carriers, there's interest overall in. A privacy related technology or basically ways to participate in the modern Internet without also like giving up all your privacy and giving over all of your data.

And so I think we've seen that with the rise of AI, a lot more people are concerned about that. I think like DuckDuckGo, for example, had a huge surge in interest as soon as Google changed its search privacy policy and in terms of prioritizing AI. And I think even prior to that, like Signal, one of their biggest boosts was when WhatsApp changed their privacy policy. So I think there's I think a general trend in terms of there's more interest in the space. And so it's a huge and growing area that we want to place ourselves as central in being able to serve.

JONAH: Are there any specific moments in the past where you've seen like a boost in your subscribers because of some event?

RUDDY WANG: Yeah, it's interesting in that maybe like in a specific area. So for so, for example, we partner with the Electronic Frontier Foundation in terms of giving free Cape service to journalists, for example. The reason that we require a partner is that we want someone who's like independently from us able to determine, OK, you know, who qualifies for this and who doesn't. We come back to our for free for your discounted Cape Service during one of the so our highest day ever of inquiries for that was in the week leading up to the last No Kings protests. So that's one example of probably just events that are happening in our like current socio political environment where there's a lot more people that value some sort of privacy for their activities.

JONAH: Going back to being venture backed for a second, that's a concern that I see people have as well, especially because it seems like we've seen a lot of venture backed companies in the privacy space in the past kind of get acquired or go bust. It seems like making back that investment has to be a top priority for investors, obviously, and they'll do that through whatever means possible is because I've also seen I don't remember if it was from you, but I believe I've read something from somebody at Cape that the consumer side of things is losing money, which probably makes sense because it's so new and it requires such an upfront investment. But is any of that concerning or should people be concerned about the long term future or why shouldn't they, I guess?

RUDDY WANG: Yeah, I think so. If the consumer side is, yeah, the consumer side is losing money because of fixed cost investment. Right. But in terms of the business model, it's absolutely sustainable. We're seeing really fast growth and really good uptake in terms of the business. We also have a significant enterprise business that's doing really well. And even beyond that, we did you know, early on when we first started the company, we put in the privacy policy if Cape were ever to be required, that the choir needs to respect the same privacy policy and the same privacy promises given to consumers there. At this point, I think we are growing at such a rate that we're growing at such a rate that acquisition is probably not a likely outcome for us. But we are essentially the only player in this space that is set up to be a privacy and security first telecom.

And if you think across the different sectors, not just consumer being one sector, but if you think across all the different other sectors, if you think about enterprise and the amount of potential that's available there, we are the only ones well placed to satisfy that demand. The last thing I'll say is that the mobile market is huge. Every single person, every single adult in the United States has like one or two cell phone plans. I think it's almost like it's getting close to two lines for every American right now. If you took a small sliver of that as being privacy conscious and privacy aware, that is actually a massive market.

JONAH: Let's get back to some of the more technical stuff. I understand that the way you've set up that mobile core you were talking about is pretty unconventional because you are running everything in Amazon Web Services when traditional carriers, to my understanding, everything in like a proprietary hardware stack. A big part of that, I assume, would be for legacy reasons. But also partly I would imagine that gives them some sort of network isolation or maybe air gapping protections. In your case, what's the actual security model that you're relying on with your mobile core?

RUDDY WANG: Yeah, so we really want to treat telecom like software. So that's the basic idea. If you look at modern software, a lot of is cloud based that reduces our overall surface area for attack. We don't have a whole bunch of legacy hardware and protocols. If you look at modern telecoms, they may actually use AWS or other cloud services, but they have to integrate that with a lot of legacy technology. So a lot of legacy on-prem stuff. Any of the major carriers you look at today are the results of decades and decades of mergers and acquisitions. So they have acquired all these different companies, maybe regional carriers, different technologies. It's all this stuff that's gathered up over decades and decades. They've got to stitch all that together and make it all work. And they can't deprecate or retire any of that technology because there's some segment of their population that is still relying on that.

It could be like less than 1 percent, but they're not going to retire that technology until that 1 percent is gone. You can see that, for example, with things like 3G and 4G, it took forever to retire 3G. And there's still tons of mainstream networks that will still use 3G. And so it's just a very hard thing to get rid of that to get rid of that legacy technology. But the result of having all that legacy technology stitch together with like duct tape and string is that there's all these different attack surfaces for attackers to make it in. And you can see that from the record of telecom breaches over the years. So all the major telecoms get breached all the time. And so the fact that we don't have to have all that baggage with us is really positive.

So, for example, our network doesn't support 2G and 3G period. You'll never notice the difference because most of the United States now has 4G coverage. And so but it means that we can eliminate SS7 attacks, for example, from the things that we need to worry about because SS7 relies on 2G, 3G technology. And so that's a huge attack surface that you've just lopped off. The other thing about being cloud first is that we're able to any sort of security updates, we get that right away and supplied uniformly across our entire stack. We get to iterate really quickly and we don't have to worry about, you know, plugging holes and all this other legacy technology. And so for that reason, we're one of the few in terms of like just treating telecom like modern software. We have gotten SOC 2 Type 2 certification for Cape for the Cape consumer business.

If you look at legacy telecoms, they'll get the SOC 2 Type 2 certification, which is a which is like very like normal run of the way run the mill certification if you're buying any sort of enterprise software. Right. So that's quite normal. But if you look at any of the main telecom operators, they will normally have that certification only for their business to business platform. But we're just like, again, treating consumer like regular commercial software. And so there's a whole bunch of other things that we do. For example, we use our user authentication model uses PKI technology. So private public keys. That's fairly common in modern software. If you use a crypto wallet or anything like that, that's common, but totally unique when you bring it over to the telecom space. Most telecoms, they will keep all of your payment information, all your credit card information.

They will store it themselves, even though today we have all these payment gateways that can expose payment by APIs and therefore. So we'll we use Stripe as a payment gateway. Stripe keeps the full payment data and we only get the payment token. And so in that way, we're able to separate payment information from subscriber information. And all those things are, I think, pretty run of the mill for regular software. But when you bring a sort of software model of security and innovation over to telecom, it becomes quite novel.

JONAH: I guess I've used the Stripe dashboard before. I feel like Stripe does give you insight into your customers. How is that data decoupled from what you have?

RUDDY WANG: Yeah, so I think for the so for the default Stripe dashboard, you're not getting the full credit card number. And there is also options to not collect address, the full street address. We have to collect the zip code for tax reporting purposes. And then but beyond that, we can choose to not collect the rest of that information. And so that essentially allows us to separate that data. And we're hoping in the future to add additional payment methods as well. And so right now you could go into a store, buy prepaid card, use that prepaid card, you know, pay cash for the prepaid card and use that prepaid card to sign up for your subscription.

JONAH: You kind of touched on this earlier when we talked about the referral programs, but I saw a few people in some groups that have been still kind of confused about this. I believe your referral program is handled by like coupons or something similar in Stripe. And what insight does that give you into like who's using these coupon codes or like how like accounts might be interconnected basically?

RUDDY WANG: Yeah, so we'd be able to see if those accounts are interconnected. But then and so that's part of why we have framed it as a general referral program that you can share with anybody, including strangers. And therefore they're interconnected, but those connections are less meaningful than if they're just traditional family plans where you're meant to share them where you like log into an admin portal and you share it, you know, you share them specifically with people that you know. And so, you know, the referral program is made a lot easier in that, you know, you get there's a code, there's a link, you can give that link to pretty much anyone. You don't have to attach your name to it. They don't have to be tied to your billing account. So on the back end, those relationships are maintained, but they're less meaningful.

JONAH: Really quick. You also mentioned carriers still using 3G. Is that the case in the US? Because I thought they were phased out.

RUDDY WANG: Yeah, so 3G is not completely deprecated in the US. That's why SS7 attacks are still a thing and still possible. So the latest Citizen Lab report is called Bad Connections. So Citizen Lab is like kind of called like the counterintelligence of civil society. So they're based in I think it's Toronto and they have a whole bunch of kind of top level researchers that help journalists and, you know, other civil society actors. Who are under threat of surveillance combat that. And so one of their recent reports that came out just a month ago talked about signaling attacks and talks about the fact that cross-protocol attacks are still often used. So basically one way that attackers will try to get past firewalls for this is they'll use SS7 attack, which is based off 2G, 3G, and then they'll mix that up with the Diameter attack, which is the signaling language that is used for 4G and 5G.

So signaling protocol is just considered that as like a machine to machine language for machines, for telecom operators to talk to each other on whether this call should be connected, whether it's allowed, you know, things like that. So it's definitely still in use. And it's this kind of thing where there's very practical, very little practical use to keeping it live. But it's very hard to retire legacy technology. Probably there's like some pocket, there's probably some, you know, pockets that's rural pockets that's only still covered by 3G or 2G even that makes operators not want to completely retire it.

JONAH: Yeah, I guess you kind of touched on this a bit. I know a big selling point for Cape is the protections against these network signaling attacks. I think a lot of people heard about that SS7 attack from the Veritasium video that came out, I think like two years ago or something like that. What kind of protections do you have against that? And also, in addition to SS7, you mentioned diameter, which I believe is for 4G networks, is that correct? And does that have similar attacks that can be done against it? Or does that offer additional protection?

RUDDY WANG: Yeah, it has the same attacks. In theory, it's supposed to be a lot more secure. But in practice, all the same attacks are available. There was a public dissent opinion by an employee of CISA, the kind of US cybersecurity agency. And he published this opinion, I think, in 2024. And he basically said, this is still a problem, right? Like, since SS7 and like a lot of, you know, everybody moving over mostly to 4G, 5G, it's still a problem. And you can see it in the Citizen Lab report as well, that a lot of the attacks are actually, you know, the Citizen Lab report mentions both SS7 and Diameter attacks. So Diameter attacks, they're still happening. It's the same kind of attack. So telecoms have put in place firewalls. And the basic way in which telecoms defend against this is what's called a velocity check.

Velocity check is basically, you know, I'm here, let's say, in Virginia right now, and I fly over to, you know, or I'm here in Virginia, and a telecom operator in, let's say, Indonesia says, you know, I'm actually over there. But my last attached data from two hours ago is in Virginia. The velocity check basically says, well, there's no way that I could have flown from here to Indonesia in two hours. And so that's the velocity check. The problem is that in our own Cape research, and there's published research on this on our website, is that a huge number of networks can be included within a standard velocity check. So a lot of times, the last attached information or the last network information can be as old as four hours old. If you are with four hours, there's a huge amount of countries in which, you know, if you spoofed from that country's network, you know, that would actually work.

And I think the Citizen Lab report showed that there's probably like 150 different countries that, you know, if you're in Europe somewhere, there's like 150 different countries in which you could potentially be a potential, like, legit operator and still pass that velocity check. And so what we do is we will check against your actual real location. And so, you know, taking the case, like, let's say, Bahamas, Bahamas is much closer to here, Virginia. Let's say there's an attacker. They've compromised the network in Bahamas. They've released the Bahamas, route me all his SMS and call data. What we will send to the phone of the Cape subscriber is, okay, there's a network in Bahamas requesting your information and location data. Are you actually in the Bahamas? And then it does an on-the-device check and sends back a yes or no. And if it's no, Ruddy's not in the Bahamas.

So we never actually have to know that Ruddy's in Virginia right now. We just have to know that Ruddy's not in the Bahamas and then we can decline that attach. And if you look at the Citizen Lab report shows that cross-country attacks is a common vector. And so there's like all these countries from like Mozambique to Lichtenstein and stuff like that, where like basically they try one attack from here. That gets blocked by a low velocity check. They're going to try another attack from here and eventually one of them makes it in.

JONAH: It's funny because as you're saying that I just realized, like I think a lot of people who are maybe more, we'll say dedicated to privacy will use like Faraday bags or they'll turn off their phones often. But I guess that would make you more susceptible to this sort of thing if your phone is off for a long period of time because the velocity checks if you're not on Cape.

RUDDY WANG: Ironically, yeah, because your last attached data is actually going to be like, you know, if it's like 12 hours old, that could be like, you know, you could be like halfway across it.

JONAH: So I was looking at your network roadmap and it said that you implemented something called a GTP proxy in October of last year. I was trying to look into your documentation and I didn't see a lot of that, but I understand that GTP-C attacks are another documented form of threats that are kind of separate from the SS7 diameter thing. Can you explain like what this GTP proxy feature is and does it provide any sort of protections against this thing?

RUDDY WANG: So the GTP proxy wasn't designed to specifically address these kind of protections. It basically allows us to do many other things. So we have a number of different proxies. So, for example, are the velocity, the location check firewall that I just mentioned that's, for example, operated by a proxy. We're also working on standing up, for example, an IMSI rotation proxy that makes that IMSI rotations smoother. So it isn't geared toward those specific GTP-C attacks, but it allows us to essentially to put in place the instruments that we can address those attacks and to further subscriber obfuscation in the future.

JONAH: Well, that's good news. I hope. Are there any other like big like security focused plans that are on your roadmap? And is your roadmap on your site currently up to date or what does that look like? I've heard conflicting things.

RUDDY WANG: Yeah, we need to update it. It's always constantly going to be iterative as we just progress in terms of our roadmap and get more feedback as well. I think spam filtering is on there. And so we will be launching our own spam filtering solution later this year. We've gotten a lot of feedback in terms of secondary numbers in that people want to be able to port in their existing number as, for example, a secondary number. They want to be able to, we have a lot of folks that started off by signing up with Cape with a new number and they kept their old number. And now they want to switch everything over to Cape. So we've gotten requests for it. Can I keep my account? Rather than having to cancel my account, port in my number and just like swap out my existing primary number.

So that'll be another thing. So all these things in terms of like more dynamic management of primary versus secondary numbers and being able to swap them in and out. That's something that we've gotten a lot more signal on. And so it's probably something that we'll try to include in the roadmap that isn't currently published on the website right now. The being able to switch between the network. So the domestic roaming partner, I think is something that's not currently published on the roadmap, but we are definitely going to do that. I'm trying to think what else is potentially out of date. But we're updating that roadmap every month. And so you should see the new things on there.

JONAH: Cool. I think when it comes to the roadmap and your features, I've seen a lot of people either surprised or kind of disappointed about the not so great support for RCS with Cape at the moment. I believe it only works with iOS if you disable IMSI rotation and it doesn't work at all with Android unless you're using GrapheneOS to my knowledge. Is that true?

RUDDY WANG: Yeah, so basically we wanted to get RCS working much earlier, but we realized that when you mix RCS with certain things like IMSI rotation, it breaks it. And so every time your IMSI rotates, it turns RCS off. And so we've been working through each of those. The issue is that we need to work with essentially each OEM or handset manufacturer. So whether it be like Google or Apple or any of these guys to be able to get our settings as a carrier recognized by them. And so this requires them to prioritize us in some sort of way, fit us into their development cycle, which is often planned a year in advance and to then ingest those settings. The reason it works faster with GrapheneOS is, you know, GrapheneOS is we had already been talking to, they're kind of more nimble and so they're able to just like take our settings in faster.

And that's why RCS with GrapheneOS works faster. For all the others, we do have all that scheduled to be fixed this year. It's just, you know, we got to fall in line with their roadmaps to get those changes accepted. And the fact that we have these additional features like IMSI rotation, it adds another layer of complexity of where things can break. And so that's why it's taking longer.

JONAH: Yeah, I think some people find it unfortunate because you also just deprecated Last Mile SMS encryption, I believe, which wasn't like a perfect security feature, but might have provided some protection, I'd imagine, until like RCS with end-to-end encryption is more widely available.

RUDDY WANG: Yeah. To be clear, we'll bring it back. The Last Mile Encryption is available for all of your secondary numbers. It just won't be available for your primary number anymore. And it was previously like an experimental feature that only worked for iOS. And so the reason for taking away right now is whenever we do one of these things, it basically breaks more things. And so we're just trying to decrease the complexity while we, for example, get RCS working again. We roll out all these different ability to manage numbers and swapping numbers between like, you know, port-in to primary, primary to secondary, things like that. And once we've sorted out a lot of those things and we have our carrier settings recognized by the major manufacturers, that's when it makes sense to look again at Last Mile Encryption for primary number. So that's why it's just basically to simplify things so that we can make the core product features more robust.

But again, for Last Mile Encryption, you still do have it for both of the secondary numbers.

JONAH: Can you explain, I was reading about your disappearing call logs product feature, and you mentioned this earlier, how you only keep some of those for like 24 hours or a matter of days or months or so. I would imagine that all of the all of that data has to be used for like billing purposes, like your upstream carriers would have to bill you for usage and stuff like that. How is all of that data collected? And does any of that, any of those disappearing logs features interfere with that? Or do you have to do some additional logging separately in order to get that data from your carrier? How does all of that work?

RUDDY WANG: Yeah, so the whole billing reconciliation process is basically about like both sides comparing receipts. And so, for example, if we have a roaming partner, the roaming partner says like, you know, your subscribers used 100 gigabytes of data in France. We'll want to look on our side and be like, okay, I also have 100 gigabytes of data used in France. It matches. We don't have any dispute. Or if there's, you know, some big discrepancy, then I want to be able to peel down. Okay, like what went wrong? Why is that? Why has what has gone wrong there? And so that's why, like, some monthly data is useful. So I think you can see in our blog posts, internal CDRs are kept for 30 days. And then what we can glean from individual CDR. So individual CDRs will have a huge amount of data, right?

So we'll have the cell ID that gives the subscriber location, you know, all the identifiers, like the phone number, the device ID, the IMSI and all that. So what we'll do is we'll strip all that data from individual CDRs. And we'll get an aggregate level of data. So by aggregate, how much did how much data was used over the course of the month? And that way we can compare that monthly aggregate data with whatever our roaming partner is reporting to us and thereby resolve any billing dispute. So it's basically a receipts comparison thing. In essence, we strip all identifying information and aggregate. And that's how we can do the billing reconciliation.

JONAH: One last thing that I saw people, at least a couple of people asking about on our Privacy Guides forum is about Apple's Limit Precise Location feature. Have you looked into that at all? Or is that something that Cape is even able to support? Or does that need like hardware support? Or? Yeah, what's going on?

RUDDY WANG: Yeah, it's a very cool feature basically uses a concept like of timing advance and introduces randomness into that timing advance so that you can't so basically that the carrier cannot infer precise location anymore. On our side, the only location data that we have is cell ID. So cell ID is already imprecise data. Right now, Apple is only supporting this for Boost Mobile. And, you know, we'd love to be the second. We'd love to be the second carrier that they support this with. If you look at it, I think they support only a few countries and only one carrier for each of those countries. So, you know, tell Apple to put us in next. So that's something on Apple side of things. Yeah, we would need. Yeah, we would need to be able to work with them to enable it.

JONAH: Interesting. Well, yeah, like I said, I won't take up too much more your time. I think that kind of wraps it up. Is there anything that you wanted to talk about that we didn't discuss here?

RUDDY WANG: I think in general, there's a what's important for people to remember is there's no perfect solution in the cellular network area right now. So if you're used to things like encrypted apps like Signal that can do end-to-end encryption, the cell phone networks were designed for interoperability, right? It's designed so that you know, it works with your bank, you know, you can call your grandma on it and all those things that makes it wonderful in that it's the most interoperable, most universally useful thing that you could use to connect. I can connect with somebody all the way across the world. But that's also its source of weakness. And we're going piece by piece, making things better incrementally to plug up those holes. And so a lot of those things that we're doing is not even really sexy. I think that the things that a lot of customers focus on is like IMSI rotation.

You know, the secondary numbers, the network lock, all the fancy things that we do. Probably the most important thing that we do is that we just take cybersecurity more seriously. It's central to our business model. And it's central to our whole security model. If you go to our trust center, we are way more transparent about our security posture than anybody else that I know of any other carrier that I know of. That's why we got the SOC 2 Type 2 compliance certification. And that's also why, you know, we are building our own mobile core and making it making sure it's cloud first. All these like basic software principles that are familiar to cybersecurity professionals, like bringing that over to telecom. That's going to be what kind of makes the biggest difference in your average, everyday phone user. Because if you think about it, what is most likely going to happen to you?

Your cell phone carrier is going to sell your location data. Because they've done it in the past. They've been fined $200 million for doing so. Or they're going to lose their they're going to lose that data. So I think there's an AT&T hack of their Snowflake instance. And it was basically because they weren't using multi-factor authentication at that point, which is super unsexy. Right? Like just making sure you have that basic cybersecurity hygiene. But that's actually a major that's going to be one of the major benefits of having this different kind of like security focused telecom carrier.

JONAH: Very cool. Yeah, I mean, that cybersecurity focus is just so important. Yeah, I think that's kind of it. For now, I think we covered most of the things that I've seen a lot of people talk about or ask me since we've been talking about Cape recently. So I'm excited to share this with people. And hopefully, it answers questions or prompts more questions. Maybe I'll have to come back to you.

RUDDY WANG: Yeah, totally. I'm up for answering more questions. I think that'll happen. I'll be following Privacy Guides closely and see if I can jump in there. But if I can't just hit me up and be glad to talk again.

JONAH: If you have any more questions, be sure to leave a comment or come join the discussion on our community forum at discuss.privacyguides.net. I'd like to again thank Ruddy from Cape for answering my questions about the service. And I hope it's answered some of the questions you might have had too.

Episode Video

Creators and Guests

Jonah Aragon
Host
Jonah Aragon
Program Director at Privacy Guides
Ruddy Wang
Guest
Ruddy Wang
Head of Consumer at Cape