Can You Actually Have a Private Phone Plan? w/ Ruddy Wang - Head of Consumer at Cape
Today, I'm sitting down with Rudy Wang,
head of consumer at Cape, a
cellular company that's been the subject
of much discussion in our spaces lately.
Cape promises to go above and beyond
the privacy and security that
other phone carriers in the US provide.
Full disclosure, I published some of
my own initial impressions of
Cape on my channel back in May, and Cape
did send me a mobile phone
afterwards that I've used to test
their service for the last month or so.
As always, we never publish interviews
at a company's request,
share our questions, or edit them
on their behalf or accept
compensation in exchange for our
content on this channel.
I wanted to sit down with them here
to get some of the technical
questions I had answered, and also to
answer some common questions
I've been seeing on our forum and in our
exclusive signal chat for
channel supporters.
If you want to see more videos like
this, remember to subscribe.
Unfortunately, my own video feed when
we recorded this had some
issues, so I apologize if that's a
bit distracting, but my audio
should be fine and all of his stuff
should be fine, so hopefully
it's not too bad.
Anyways, here's the interview.
Rudy, thank you for joining me here.
Why don't we start out by you just giving
people who listen to this
overview of Cape for people who
haven't heard of it and
what you do there.
Yeah.
Cape is a privacy-first mobile carrier.
By mobile carrier, I think AT&T
Verizon is mobile,
except that we're an MVNO.
We don't own our own towers, but we
own the entire mobile core.
That's all the
telecom infrastructure minus the towers.
You would sign up for us like a
regular cell phone plan subscription.
Except it's more private and secure.
That means we practice minimal
data collection
and then we also have a bunch
of features that
improves your privacy and just
makes it harder to track you over time.
Very cool.
Yeah, I want to get into some of
that mobile core stuff in a minute.
But first, who would you say
Cape is actually for?
What kind of customers do
you sell for and
what's the threat model that
it's designed around?
Yeah, so Cape was started and
designed for everyone.
It's designed so that
I think the basic philosophy is using
your cell phone shouldn't
involve a compromise in your
privacy and security.
Right now, if you use any existing
option, that is what you're doing.
I think we all benefit from the convenience
of having a smartphone
in a pocket all the time that we
can do amazing things with.
But as a sort of underlying trade-off
for being able to have that
connectivity, we are basically carrying
a tracking beacon around
with us all the time and entrusting
an industry that has a pretty
poor cybersecurity record for
protecting that data.
That's kind of the overall
vision for Cape.
In the
present day, today, and now, the folks
who are interested in Cape
and who we're speaking most to are
people who are already privacy aware
and already using, for
example, things like encrypted chat apps
and other types of solutions
that allow you
to opt out of the overall surveillance
economy.
And so that's definitely the folks
that we're speaking to right now.
But the overall vision is this is
just how cell phone service should work.
It shouldn't work as a way to
essentially
leak data about yourself 24-7.
Yeah, absolutely.
So you mentioned your current
audience is more privacy-focused people.
I know you've recently announced some
pricing changes and I feel
like I've seen a lot more talk about
Cape since that happened.
Do you think that that's expanding your
audience a bit more or how's that going?
Yeah, definitely.
I think the pricing change.
So the context here is that we have
one standard $99 plan.
Recently, we announced that if you
sign up this year or earlier, you get
all of our features for $70 forever.
So that means your price is
never going to change.
And that definitely makes Cape
available to more people.
And that's part of the overall goal
for us is to make privacy
shouldn't be purely a premium product
that only people who can
pay for it get it.
And so I think that does expand
the audience.
Part of the reason why we did it this way
right now is because we don't
have multiple plans.
A typical cell phone carrier has,
if you go to the website,
immediately you'll see lots and
lots of different plans.
And actually, on the back end of all
that, they have hundreds and
hundreds of plans because they're using
data about you to try to
predict, OK, what's Jonah's marginal
willingness to pay?
And this is the plan based off all
the data I've collected about
him and I'm collecting about
him in real time.
This is when he's most likely to churn.
So I'm going to give him this exact
offer so I can price Jonah's
plan at exactly as marginal willingness
to pay and extract maximum
value from that.
So we don't have any of that because
we're building the entire
software stack of telco from scratch.
We actually don't have multiple plans.
Our focus this year is
adding value through privacy
and security features.
And eventually we want to be able
to support multiple plans.
Those multiple plans might include things
like lower gigabytes and
things like that.
But that just hasn't been
a focus right now.
And so this ends up being a good
compromise in that if you join
this year, you get that lower price.
And we get to continue to
focus on building
privacy and security features
in the future.
Hopefully, we'll not hopefully not too
far in the future, we'll be
able to roll out multiple tier plans just
to make that available for
more more folks.
But it is for us a heavy research
and development type work.
And so
that's why the price point that we're at.
Very cool.
I assume when you do have multiple
plans, you're going to avoid
those privacy problems that you
mentioned with the other
telecom carriers.
Yeah, totally.
So just by nature, we collect less
information about our customers.
Obviously, we minimize the amount
of information that
we collect.
We're not buying it from other kind of
data brokers and trying to combine that.
And so it's just going to be a very
simple, straightforward plan.
The other thing you'll notice
about our plan is that,
formerly $99, now $70, all taxes
and fees are included.
So here's one fact, like I forget which
carrier it was, but I think it was AT&T.
They hired a whole team and a
specialist that at the store
explains your
first bill to you when you sign up
because the first bill always
looks different from other bills because
you have activation fee.
They add on insurance package
that you can
only call in later to remove
and things like that.
And so as part of that commitment to
transparency, we just keep it at $99,
or now $70 all the doesn't matter
where you live.
We will
take the taxes
off on our part and all the fees
and things like that.
And so it's predictable and it's the
same all the time and there's
no bill shock.
So that includes global roaming.
And again, you're not going
to end up like
suddenly with this huge
like roaming bill.
And so that's the idea just to keep
it simple and transparent.
Before we continue, I want to remind
you that Privacy Guides is a
nonprofit project that's focused on
privacy advocacy and delivering
the best consumer technology rights
advice on the internet.
Please consider supporting our mission
at privacyguides.org donate
and getting subscribed to the channel.
That is very cool because I know some
carriers used to do taxes and
fees included like T-Mobile and I
don't think any of them do anymore.
But it seems like taxes and fees are
a way for other carriers to
kind of increase the prices over time.
I don't know where some of
those fees come from.
But speaking of your $70 plan currently,
you also have this set up
with referral programs where if you use
a referral code to sign up,
you would get another $20 off,
which brings it to $50.
And as far as my understanding is both
of those promotions, the
referral code thing and the $70
thing are for life.
But I think a concern that I see
people have is with sustainability.
I'm wondering because it seems like
you're giving out a lot of
fairly cheap plans or even free plans
in some cases because you
only need, I believe, three referrals
right now if you were
referred yourself to get a
completely free plan.
So what is your what is your
math look like on that?
Because I don't know.
Some people think, yeah, that's
not sustainable.
Yeah.
So just to be just to be
specific on that,
you get a referral, brings you down to
50, and then you refer three
other people.
Right.
And so each of each one of
those knocks off $20.
But for the asterisk on the forever
part, if one of those three
people leaves Cape, that
discount goes away.
So so, you know, I think
that's one thing.
If you if you
imagine a model whereby
100 percent of all
Cape subscribers are maxing
out their referrals.
So essentially, when you add an additional
Cape subscriber, you're
you're basically you're basically
taking off $40.
Right.
So if every every single Cape subscriber
was on a referral,
basically that would converge to
that would converge to $30 eventually.
Like, you know, if you had an infinite
number of Cape subscribers,
that is not sustainable
for the long term.
And that's why the early adopter
promotion is going to be is
going to be temporary.
We will keep the we will keep
the referral plan
forever.
It works a lot like, you know, when
we first started, a lot of
people asked us about family plans.
So something like 70 to 80 percent of
postpaid mobile subscribers
in the U.S. are on some sort
of family plan.
So that's a very common ask.
And our idea was we're going
to do something
a little bit more simple than
the family plan,
but that you can kind of
like post anywhere.
You can post it on social media or and
like get Reddit strangers to sign up.
And that ends up basically being a group,
not necessarily of your
family that's associated with each
other, but like a random
group of strangers.
And I think that's also a little bit
more private than traditional
family plans.
So the $70 plan currently is going to
be going away at the end of the year.
You say referral plans are
sticking around.
Are you planning to keep it at the same
like discount as it is now in same terms?
Because I believe I don't know when you
change this exactly, but it
used to be ten dollars a month
off for each referral.
And then you change it to this.
Do you think the 20 is something
you can stick with or?
Yeah, I think that's totally sustainable.
If you think about at the $99 price
point, if every Cape user was
using it, it would converge to $60 and
not everyone is going to use it.
And so 60 would be the absolute floor
in terms of in terms of like
if every single user was using it.
So it is it's sustainable.
Cool.
Well, I think that sounds
that sounds good.
I think people will be happy
to hear that.
Let's get into some of the more
technical questions.
I think one of the things you were
telling me about and you kind of
make a big deal about this on your
site is that Cape is a heavy
MVNO that runs its own mobile core as
opposed to a light MVNO like
most other ones.
Can you explain what the difference or
distinction is between those
and why that matters for
people's privacy?
Yeah, so a light MVNO.
So
first, the distinction between M&O and
MVNO in the U.S., basically,
there's three basic three basic
M&O's team over rising.
AT&T, they own all the towers.
And MVNO is somebody who uses their
towers but can still sell
cell phone service.
So think of your like mobile, Boost
Mobile, Consumer Cellular, all those guys
are going to be relying on the
infrastructure of somebody of
one of the main M&O's.
And in fact, it's become so easy
to spin up new MVNO's that
like I think Mr.
Beast has an MVNO coming out.
There's one of my favorites
is Meow Mobile.
So it's a mobile carrier for cat owners.
I think Progers, the grocery store,
has a mobile carrier.
It's very easy to spin up an MVNO because
basically you're using
all the same core infrastructure, but
you're putting a marketing
spin over and some like billing and
customer support over it.
What we have is the mobile core.
And so the mobile core is basically like,
I don't know how to, it's
maybe like the brain or the the brain or
the central nervous system of a telecom.
And it's what decides what calls
get routed where.
It determines user authentication.
So basically, are you allowed to
use this network right now?
If you're allowed to use it, how much
data are you allowed to use?
And
it generates, for example, call logs.
And so it allows us a lot more control
over a bunch of privacy and
security aspects of the experience than
just having a light MVNO.
And so that is a pretty significant
difference.
There are very few heavy MVNO's
in the United States.
One example of another MVNO would be a
heavy MVNO would be like Boost
Mobile or DISH.
So DISH was an M&O.
So they had they had spectrum.
And so they were out there to compete
with the other ones.
And then eventually they sold off all
their spectrum holdings and
therefore kind of defaulted from
M&O into a heavy MVNO.
And so the fact that we own the
mobile core allows us to
do special things.
And so I mentioned the fact that
when you own that infrastructure,
you produce call logs.
So we can now determine how long
do we keep those call logs.
A light MVNO would just have to default
to the retention period of
the of the M&O, whereas we can define
a different period.
And so we were able to define 24 hours
for that instead of years.
There's other things like so I mentioned
that the mobile core is
what decides where calls are routed.
So think in your mind of
of like those old style telephone
switchboards where like there's
women switching like little gear boards
around to actually connect those calls.
So that all happens in the
mobile core today.
And one of the attacks or ways to one
of the vulnerabilities of
telecom is that you can actually
hijack that system.
So those are called SS7 or
signaling attacks.
I think you've covered them
a little bit before.
But basically that allows you to decide,
hey, instead of switching
this to the right person, switch
it to me, the attacker.
And so I can intercept calls, SMS
and metadata like location.
So we have control over that layer
so we can implement protections there.
And there's you know, there's a
whole bunch of lists of other things that
we're able to do as a heavy MVNO that
as a light MVNO, your your
options are really limited and your hands
are kind of tied behind your
back in terms of
in terms of in terms of what you can do.
Cool.
I definitely want to get into more
of the specifics about the
mobile core and some of those
attacks you mentioned.
But first, you talked about call logs.
And I think that that's something
that will maybe confuse some
people who are less familiar
with how this works.
I mean, I've looked at some
privacy focused
carriers in the past, which
can go unnamed.
But a big concern that I have with
a lot of them is that so much
data that they collect gets shared with
their underlying upstream
carrier to the extent that even some
of those carriers that I've
looked at will say in their privacy
policies that all of your
usage or all of the.
Yeah, all of the usage on their networks
is going to be subject to
their upstream carriers privacy policy
as well, which sort of, I
think, defeats the purpose of a lot
of those privacy protections.
You're handling a lot more in house,
but at the end of the day, all
of Kape subscribers are going
to be attaching to
whatever carrier partners towers
are out there.
So say I'm communicating with an AT&T
tower, for example, what is
it that AT&T is actually able to see
about me in terms of data
being shared in terms of identifiers
or metadata or anything else
that their infrastructure might
be able to access?
Yeah, so AT&T will still be able
to see quite a bit.
We'll have to share information with
AT&T just in order for
the service to be able to work.
So you would still, they would see the MZ
number, otherwise known as the
subscriber ID number.
They'd see the device ID number,
also known as the IMEI.
They'd be able to see if it's
a data session,
they'd be able to see how many
gigabytes are used.
They'd be able to see a cell ID.
Cell ID would be basically
think of that as like
an abstraction of like cell phone towers.
And those can vary in size between
like miles to, you know, if
you're in a rural area, it could
be like many, many miles.
If you're in an urban area, it
might be like a smaller
radius there.
So they'd be able to see all
of those things.
What they wouldn't be able to get is
they wouldn't be able to match
up that information with, for example,
subscriber information since
we don't collect name, address,
things like that.
We do things that add noise to the
ability to track things.
So we do that by rotating the IMZ number,
the subscriber ID number.
Typically, that number will be static
for as long as you have the
same SIM.
So basically, as long as you're a
subscriber of a particular
mobile carrier, but we will
rotate that daily.
We're able to do that again, not only
because we have our mobile
core, but we also produce our own SIM.
So that's another thing.
Like, MVNOs don't produce their own SIMs.
A SIM is basically
think of that as like an operating
environment
that the telecom has access to
on your phone itself.
So because we have our own SIMs, we
can basically change the IMZ
number that is shared to the
telecom network.
Other things that they'll be able to
see
is the phone number that you're
using as well.
If you use a secondary phone number
of CAPEs, so if you're a CAPE
subscriber, you get one primary
phone number
and you also get two secondary
phone numbers.
If you're using a secondary phone
number to, let's say, like
communicate with a bank or something
to that effect,
the AT&T, you know, if it was on an
AT&T tower, AT&T still would
not be able to see the secondary
phone number.
They would only be able to see the
primary phone number, even if
you're communicating with the secondary.
I don't know if that makes sense.
But basically,
we make it a lot harder to breadcrumb
together all the different
bits of information, since we're feeding
in a lot more noise and a
lot more friction.
And the overall thought is that
when these carriers have an abundance
of clean data, that's the
data that they're going to prioritize
in terms of monetizing.
If there's a whole bunch of data that
has sand in it, it becomes a lot harder.
The last thing I'll mention is that
we do have more than one
carrier partner, so we're able to switch
traffic between the two.
Right now, in practice, you'll mostly
default to one of our carrier
partners, but before the end of the year,
we'll be rolling out something where
you'll have a little bit more
control in terms of being able to swap
traffic between more than one network.
Very cool.
That preemptively answers the question
that I had about your new
carrier partnership.
So that's exciting.
What is that going to look like?
Do you have any set plans?
I was wondering if that'll be tied to
any of the MZ rotation stuff
that you do or if it'll just be like
a switch in the app or...
Yeah, I mean, it'd be really cool if
basically your MZ rotates and
your network rotates at the same time.
That won't be a V0 for us
in the beginning.
Essentially, you'll just be able to
opt between the two different networks.
You'll default to one of the
networks, but then
you'll be able to switch to
the other network.
And that would be completely unique.
It'd be completely unique like
any other carrier.
If they have a deal with more
than one of the
MNOs, the only way to switch would
be to get a new SIM.
That takes a couple of minutes
and it's not
particularly reversible and
things like that.
This will just happen in
real time.
We've had
my employees, including myself,
testing it already.
And basically, when the network switches,
I don't even notice.
I don't have any drop calls
or anything like that.
It just happens in the background,
which is going to be pretty unique.
In 2024,
when I think CAPE was just beginning
to be public, you shared a
device with 404 Media that would rotate
more than the MZ number.
It would rotate the IMEI and stuff.
And I understand that that device is
not being sold to the public anymore.
A lot of people
are hoping to see those identifiers
rotated too.
And I guess thinking about what the
carrier themselves can see is
the IMEI number something that AT&T,
for example, could see when
I'm connecting with their towers.
Or is that something that's
encrypted between
the device and the mobile
core or something?
Yeah, the AT&T can see the IMEI number.
And so who would not be able to see
the IMEI number at first would
be, for example, like a Stingray.
A Stingray that gets the IMEI, they can
only get that after mutual
authentication.
And a Stingray is, by definition,
a fake base station.
And therefore, it shouldn't be able
to authenticate with the user.
And so in general, Stingrays don't get
the IMEI or if they can get
it, they can only get it after
getting the IMZ.
Whereas, you know, like a domestic
growing partner, if it was like
AT&T Verizon, etc., they would
be able to see the IMEI.
And, you know, we have had
customers express interest
in this product.
The reason we haven't rolled it out is
because it's very expensive.
And so we do make it available for
essentially our enterprise customers.
And it's $500 per month.
And at that price point,
the
consumer market for that is pretty small.
And we'd have to do a whole
bunch of work to
be able to support billing
and things like that,
billing, onboarding and all those things.
And so we do want to make it
available and we want to bring
the price down.
But that's going to be a future thing.
That's
not going to be a this year thing
that we're going to make that available.
Yeah.
Is the main challenge
with that finding like a hardware partner
that can support that or
like what makes that so expensive
on your end?
Yeah, it's it's expensive in that
you do need a hardware partnership.
And so you have to actually work with
the manufacturer for that.
There's a whole bunch of IP rights
involved in that.
And then IMEI themselves are also are
also not are also limited.
They're they're actually
a scarce resource.
So differently from from MZ numbers,
there's actually like a limited
number of them.
And all of that basically costs
a lot more money.
Got it.
Going back to what you said about
owning your own SIM cards.
There are some I mean, some cards are
an interesting thing because
I think a lot of people don't think
about them as like their own
computers or like operating
system in your phone.
I remember in 2019,
an exploit and SIM cards called
SIPJACKER was discovered.
I think it was only applicable
to carriers
in a handful of countries,
not everywhere.
But I think it demonstrates that sort
of innocuous things that you
don't think about like your SIM card
can be exploited by attackers.
Does owning your own SIM card allow
you to harden against these
type of exploits like a theoretical one
in the future or reduce the
attack surface of your SIM
card in any way
compared to what other carriers
might be using?
Yeah, yeah, absolutely.
The SIMJACKER report, I think
that was put out by
by a telecom security outfit named INIA.
And so, yeah, we've we've
talked with them
multiple times about how to
harden SIM security.
And in general, and it's not
just SIM cards, right?
It's like everything about telecom has
really low standards for
for cybersecurity.
So there's a huge there's
a huge amount of
area in which we can make
things more secure.
And that's what makes our that's what
makes CAPE as a telecom really
different from
from any other company.
So if you look at a regular
telecom operator,
their R&D budget is only three percent
of their entire budget,
which is incredibly, incredibly low.
So like a regular software company, that
number will be more like 16, 17 percent.
And the reason for that is that what
a telecom operator is doing,
what their whole business model is, is I
have this sort of I have
this sort of like
monopoly control over a bunch of
spectrum that I've bid on and bought.
And now I'm going to outsource
all the actual
R&D to all these other vendors
to do for me.
And so I'm going to have
my SIM vendor here.
I'm going to have like some mobile
core vendors here.
I'm going to have like other vendors
doing other key parts of infrastructure
here.
And if you look at the org chart as
an actual telecom operator,
even if they have the like the title
of engineer or architect,
there's very few people who are
actually hands on keyboard writing code.
It's very, very different for us.
So we've internalized a lot
of these functions.
So in bringing in bringing the SIM in
house and things like that,
we have a lot more control over it.
And, you know, it just fits our it fits
our business model better
and it allows us to innovate
better like that.
And so for us, we are our company
is mostly engineers who are
actually hands on keyboard writing
code for for our actual telecom network.
Can you share like how much of your
budget is R&D percentage?
It's the majority.
It's majority.
I mean, you can you could probably
back into it just from our LinkedIn.
Yeah, you probably just check
our check our LinkedIn.
We have over over 100 employees
right now.
And I think the majority are technical
in some fashion.
So either an engineer,
you know, a wireless solutions architect,
some sort of solutions
architect or product person, like
definitely over 50 percent is that.
And that's our that's our
biggest expense.
It's funny.
I think I made this video about
Cape on my channel.
And I feel like I heard from a lot
of different people at Cape.
It seems like you do have
a lot of employees.
And I just mentioned Cape to a friend
who said that they had a
friend who was also applying at Cape.
So is this something that
are you expanding
pretty quickly or what's what's
that looking like?
Yeah, we're definitely expanding
pretty quickly.
So we are we are venture backed.
We've raised over one hundred
ninety million dollars.
And the reason and the reason that we
need to be venture backed is
because it's a huge amount of
fixed investment to be
really like full stack software
telecom operator.
So it's it's just it's just
a big R&D heavy
kind of kind of venture.
But I think the good thing about that
for us is that once we once
we make this investment, it'll become
easier to scale to more and
more customers.
And so we do see like there's
just I think
you've probably seen from
your own viewers.
I think there's a huge growth
and interest
in this kind of in this kind
of technology.
And if you look even beyond
if you look even beyond,
you know, cell phone carriers, there's
interest overall in.
A
privacy related technology or basically
ways to participate in the
modern Internet without also like giving
up all your privacy and
giving over all of all of your data.
And so I think we've seen that
with with the rise
of AI, a lot more people are
concerned about that.
I think like Dr.
Go, for example, had a huge surge in
in interest as soon as Google
changed its search
privacy policy and in terms
of prioritizing AI.
And I think even prior to that, like
signal, one of their biggest
boosts was when WhatsApp changed
their privacy policy.
So I think there's I think
a general trend in
terms of there's more interest
in the space.
And so it's a huge, huge and
growing area that
we want to place ourselves as central
in being able to serve.
Are there any specific moments in the
past where you've seen like a
boost in your subscribers because
of some event?
Yeah, it's it's interesting.
It's interesting in that
maybe like in a specific area.
So for so, for example, we
partner with the
Electric Electronic Frontier
Foundation in terms of
giving free service to free Cape
Service to journalists, for example.
The reason that we require
a partner is that
we want someone who's like independently
from us able to determine,
OK, you know, who qualifies for
this and who doesn't.
We come back to our for free for your
discounted Cape Service
during one of the so our highest day
ever of inquiries for that was
in the week leading up to the
last No Kings protests.
So that's one example of probably
probably just events that
are happening in
in our in our like current
socio political environment where
there's where there's a lot more people
that value some sort of
privacy for for their activities.
Going back to
being venture backed for a second,
that's a concern that I see
people have as well, especially
because it
seems like we've seen a lot
of venture backed
companies in the privacy space in the
past kind of get acquired or go bust.
It seems like making back that investment
has to be a top priority
for investors, obviously, and they'll do
that through whatever means possible is
because I've also seen I don't remember
if it was from you, but I
believe I've read something from somebody
at Cape that the consumer
side of things is losing money, which
probably makes sense because
it's so new and it requires such
an upfront investment.
But is any of that concerning or should
people be concerned about
the long term future or why shouldn't
they, I guess?
Yeah, I think so.
If the consumer side is, yeah, the
consumer side is losing money
because of fixed cost investment.
Right.
But but in terms of terms of the
business model, it's absolutely
sustainable.
We're seeing really fast
growth and really
good uptake in terms of in terms
of the business.
We also have a significant
enterprise business that's
doing really well.
And even beyond that, we did
you know, early on when we first started
the company, we put in the
privacy policy if Cape were ever to
be required, that the choir needs to
respect the same privacy, the same
privacy policy and the same
privacy promises given to
consumers there.
At this point, I think we are we are
growing at such a rate that
we're growing at such a rate that
acquisition is probably not a
likely outcome for us.
But we are essentially
we are essentially the only player in
this space that is set up to
be a privacy and security first telecom.
And if you think across the different
sectors, not just consumer,
consumer being one sector, but if you
think across all the all the
different other sectors, if you
think about enterprise and the amount of
the amount of potential that's available
there, we are the only
ones well placed to to satisfy
that demand.
The last thing I'll say is that
the mobile market is huge.
Every single person, every single adult
in the United States has
like one or two cell phone plans.
I think it's I think it's almost like
it's getting close to two
lines for every American right now.
If you took a small sliver of that
as being
privacy conscious and privacy aware,
that is actually a massive,
massive market.
Let's get back to some of the
more technical stuff.
I understand that the way you've set
up that mobile core you were
talking about is pretty unconventional
because you are running
everything in Amazon Web Services when
traditional carriers, to my
understanding, everything in like a
proprietary hardware stack.
A big part of that, I assume, would
be for legacy reasons.
But also partly I would imagine that
gives them some sort of
network isolation or maybe air
gapping protections.
In your case, what's the actual security
model that you're relying on
with your mobile car?
Yeah, so we really want to treat
telecom like software.
So that's that's the basic idea.
If you look at modern software,
a lot of is cloud based
that reduces our overall surface
area for for attack.
We don't have a whole bunch of legacy
hardware and protocols.
If you look at modern telecoms, they
may actually use AWS or other
cloud services, but they have to
integrate that with a lot of
legacy technology.
So a lot of a lot of legacy
on-prem stuff.
Any of the major carriers you look
at today are the results of
decades and decades of mergers
and acquisitions.
So they have they have acquired all
these different companies,
maybe regional carriers, different
technologies.
It's all this stuff that's gathered
up over decades and decades.
They've got to stitch all that together
and make it all work.
And they can't deprecate or retire any
of that technology because there's some
there's some segment of their
population that is still relying on that.
It could be like less than 1 percent,
but they're not going to
retire that technology until
that 1 percent is gone.
You can see that, for example, with with
things like 3G and 4G, it took
forever to retire 3G.
And there's still tons of
mainstream networks that
will still use 3G.
And so it's just a very hard
thing to get rid
of that to get rid of that
legacy technology.
But the result of having all that legacy
technology stitch together
with like duct tape and and string
is that there's all these
different attack surfaces for attackers
to attackers to make it in.
And you can see that from the record
of telecom breaches over the years.
So all the major telecoms get
breached all the time.
And so the fact that we
don't have to have
all that baggage with us
is really positive.
So, for example, our network doesn't
support 2G and 3G period.
You'll never notice the difference
because most of the United
States now has 4G
coverage.
And and so but it means that we can
eliminate SS7 attacks, for
example, from the things that
we need to worry
about because SS7 relies on
2G, 3G technology.
And so that's a huge attack surface
that you've just lopped off.
The other thing about being cloud
first is that we're able to
any sort of security updates, we get
that right away and supplied
uniformly across our entire stack.
We get to iterate really quickly and
we don't have to worry about,
you know, plugging holes and all this
other legacy technology.
And so for that reason, we're
one of the few
in terms of like just treating telecom
like modern software.
We have gotten SOC 2 Type
2 certification for
for Cape for the Cape consumer business.
If you look at legacy telecoms, they'll
get the SOC 2 Type 2
certification, which is a which is like
very like normal run of the
way run the mill certification if you're
buying any sort of enterprise software.
Right.
So that's quite normal.
But if you look at any of the main
telecom operators, they will
normally have that certification only
for their business to business platform.
But we're just like, again, treating
consumer like regular commercial
software.
And so there's a whole bunch of
other things that we do.
For example, we
use our user authentication model
uses PKI technology.
So private public keys.
That's fairly common in modern software.
If you use a crypto wallet or
anything like that,
that's that's common, but totally unique
when you bring it over to
the telecom space.
Most telecoms, they will keep all of your
payment information, all your
credit card information.
They will store it themselves, even
though today we have all these
payment gateways that can expose payment
by APIs and therefore.
So we'll we use Stripe as
a payment gateway.
Stripe Stripe keeps the full payment
data and we only get the payment token.
And so in that way, we're
able to separate
payment information from subscriber
information.
And all those things are, I think,
pretty run of the mill for
regular software.
But when you bring a sort of software
model of security and
innovation over to telecom, it
becomes quite novel.
I guess I've used the Stripe
dashboard before.
I feel like Stripe does give you insight
into your customers.
How is that data decoupled
from what you have?
Yeah, so I think for the so for the
default Stripe dashboard,
you're not getting the full
credit card number.
And there is also options to not collect
to not collect address,
the full street address.
We have to collect the zip code for
tax reporting purposes.
And then but beyond that,
we can choose to
not collect the rest of that information.
And so that essentially allows
us to separate that data.
And we're hoping in the future to
add additional payment methods as well.
And so right now you could go into a
store, buy prepaid card, use
that prepaid card, you know, pay cash
for the prepaid card and use
that prepaid card to sign up
for your subscription.
You kind of touched on this earlier
when we talked about the
referral programs, but I saw a few people
in some groups that have
been still kind of confused about this.
I believe your referral program
is handled by
like coupons or something
similar in Stripe.
And what what insight does that
give you into like who's using these
coupon codes or like how like
accounts might be interconnected
basically?
Yeah, so we'd be able to see if those
accounts are interconnected.
But then and so that's part of why we
have framed it as a general
referral program that you can share
with anybody, including strangers.
And therefore they're interconnected,
but those connections are
less meaningful than if they're just
traditional family plans where
you're meant to share them where you
like log into an admin portal
and you share it, you know, you share
them specifically with people
that you know.
And so, you know, the referral program
is made a lot easier in
that, you know, you get there's a code,
there's a link, you can
give that link to pretty much anyone.
You don't have to attach your name to it.
They don't have to be tied to
your billing account.
So on the back end, those
those relationships
are maintained, but they're
less meaningful.
Really quick.
You also mentioned carriers
still using 3G.
Is that the case in the US?
Because I thought they were phased out.
Yeah, so 3G is not completely
deprecated in the US.
That's why SS7 tax are are still a
thing and and still possible.
So the latest Citizen Lab report
is called Bad Connections.
So Citizen Lab is like kind
of called like
the counterintelligence of civil society.
So they're based in I think it's
Toronto and they have a whole bunch of
kind of top level researchers that help
journalists and, you know, other
civil society actors.
Who are under threat of surveillance
combat that.
And so one of their recent reports that
came out just a month ago
talked about signaling attacks and talks
about the fact that cross
protocol tax are still often used.
So basically one way that attackers
will try to get past firewalls
for this is they'll use SS7 attack,
which is based off 2G, 3G, and
then they'll mix that up with the
diameter attack, which is the
signaling language that is
used for 4G and 5G.
So signaling protocol is just considered
that as like a machine to
machine language for machines, for
telecom operators to talk to
each other on whether this call should
be connected, whether it's
allowed, you know, things like that.
So it's definitely still in use.
And it's this kind of thing where
there's very practical, very
little practical use to keeping it live.
But it's very hard to retire
legacy technology.
Probably there's like some pocket,
there's probably some, you know,
pockets that's rural pockets that's only
still covered by 3G or 2G even that makes
operators not want to completely
retire it.
Yeah, I guess you kind of touched
on this a bit.
I know a big selling point
for CAPE is the
protections against these network
signaling attacks.
I think a lot of people heard about
that SS7 attack from the
Veritasium video that came out, I think
like two years ago or something
like that.
What kind of protections do
you have against that?
And also, in addition to SS7, you
mentioned diameter, which I
believe is for 4G networks,
is that correct?
And
does that have similar attacks that
can be done against it?
Or does that offer additional protection?
Yeah, it has the same attacks.
In theory, it's supposed to
be a lot more secure.
But in practice, all the same
attacks are available.
There was a public dissent opinion
by an employee of CISA, the kind
of US cybersecurity agency.
And he published this opinion,
I think, in 2024.
And he basically said,
this is still a problem, right?
Like, since SS7 and like
a lot of, you know, everybody moving
over mostly to 4G, 5G, it's
still a problem.
And you can see it in the Citizen Lab
report as well, that a lot of
the attacks are actually, you know,
the Citizen Lab report
mentions both SS7 and diameter attacks.
So diameter attacks, they're
still happening.
It's the same kind of attack.
So telecoms have put in place firewalls.
And the basic way in which
telecoms defend
against this is what's called
a velocity check.
Velocity check is basically, you know,
I'm here, let's say, in
Virginia right now, and I fly over to,
you know, or I'm here in Virginia, and a
telecom operator in, let's
say, Indonesia says,
you know, I'm actually over there.
But my last attached data from two
hours ago is in Virginia.
The velocity check basically says,
well, there's no way that I
could have flown from here to
Indonesia in two hours.
And so that's the velocity check.
The problem is that in our own CAPE
research, and there's published
research on this on our website, is
that a huge number of networks
can be included within a standard
velocity check.
So a lot of times, the last attached
information or the last
network information can be as
old as four hours old.
If you are with four hours, there's
a huge amount of countries in which,
you know, if you spoofed from
that country's network,
you know, that would actually work.
And I think the Citizen Lab
report showed that
there's probably like 150 different
countries that,
you know, if you're in Europe somewhere,
there's like 150 different
countries in which you could
potentially be
a potential, like, legit operator
and still pass that velocity check.
And so what we do is we will check
against your actual real location.
And so,
you know, taking the case,
like, let's say,
Bahamas, Bahamas is much closer
to here, Virginia.
Let's say there's an attacker.
They've compromised the network
in Bahamas.
They've released the Bahamas,
route me all his SMS and call data.
What we will send to the phone,
to the phone of the CAPE subscriber
is, okay, there's a network in
Bahamas requesting your information
and location data.
Are you actually in the Bahamas?
And then it does an on-the-device check
and sends back a yes or no.
And if it's no, Rudy's not
in the Bahamas.
So we never actually have to know
that Rudy's in Virginia right now.
We just have to know that
Rudy's not in the
Bahamas and then we can decline
that attach.
And if you look at the citizen lab report
shows that cross-country tax
is a common vector.
And so there's like all these countries
from like Mozambique to
Lichtenstein and stuff like that, where
like basically they try one
attack from here.
That gets blocked by a low
velocity check.
They're going to try another attack from
here and eventually one of
them makes it in.
It's funny because as you're saying
that I just realized, like I
think a lot of people who are maybe
more, we'll say dedicated to
privacy will use like Faraday Vakes
or they'll turn off their phones often.
But I guess that would make you
more susceptible to
this sort of thing if your phone is
off for a long period of time
because the velocity checks
if you're not on CAPE.
Ironically, yeah, because your last
attached data is actually going
to be like, you know, if it's like
12 hours old, that could be
like, you know, you could be
like halfway across it.
So I was looking at your network roadmap
and it said that you
implemented something called a GTP proxy
in October of last year.
I was trying to look into your documentation
and I didn't see a lot
of that, but I understand that GTP
see attacks are another
documented form of threats that are kind
of separate from the S07 diameter thing.
Can
you explain like what this GTP proxy
feature is and does it provide
any sort of protections against
this thing?
So the GTP proxy wasn't designed to
specifically address these
kind of protections.
It basically allows us
to do many other things.
So we have a number of different proxies.
So, for example, are the velocity, the
location check firewall that
I just mentioned that's, for example,
operated by a proxy.
We can also, we're also working on
standing up, for example, an MZ
rotation proxy that makes that
MZ rotations smoother.
So it's not geared towards that
specific attack, but
the GTP proxy attack.
But it allows us to essentially to
put in place the instruments
that we can address those attacks and to
further scriber off the station
in the future.
Well, that's good news.
I hope.
Are there any other like big like
security focused plans that
are on your roadmap?
And is your roadmap on your site
currently up to date or what
does that look like?
I've heard conflicting things.
Yeah, we need to update it.
It's always constantly
going to be iterative as
we just progress in
terms of our roadmap and get
more feedback as well.
I think spam filtering is on there.
And so we will be launching our own
spam filtering solution later this year.
We've gotten a lot of feedback
in terms of
secondary numbers in that people
want to be able to
port in their existing number as, for
example, a secondary number.
They want to be able to, we have a lot
of folks that started off by
signing up with Cape with a new
number and they kept their old number.
And now they want to switch everything
over to Cape.
So we've gotten requests for it.
Can I keep my account?
Rather than having to cancel my account,
port in my number and just
like swap out my existing primary number.
So that'll be another thing.
So all these things in terms of like
more dynamic management of
primary versus secondary numbers and
being able to swap them in and out.
That's something that we've gotten
a lot more signal on.
And so it's probably something that
we'll try to include in the
roadmap that isn't currently published
on the website right now.
The
being able to switch between the network.
So the domestic roaming partner, I
think is something that's not
currently published on the roadmap,
but we are definitely going to do that.
I'm trying to think what else
is potentially out of date.
But we're
updating that roadmap every month.
And so you should see the
new things on there.
Cool.
I think when it comes to the roadmap
and your features, I've seen a
lot of people either surprised or kind
of disappointed about the
not so great support for RCS with
Cape at the moment.
I believe it only works with iOS if
you disable IMSI rotation and
it doesn't work at all with Android
unless you're using GrapheneOS
to my knowledge.
Is that true?
Yeah, so basically
we wanted to get RCS working much
earlier, but we realized that
when you mix RCS with certain
things like IMSI rotation, it breaks it.
And so every time your IMSI rotates,
it turns RCS off.
And so we've been working through
each of those.
The issue is that we need to work with
essentially each OEM or handset
manufacturer.
So whether it be like Google or Apple
or any of these guys to be
able to get our settings as a carrier
recognized by them.
And so this requires them to prioritize
us in some sort of way, fit
us into their development cycle, which
is often planned a year in
advance and to then ingest
those settings.
The reason it works faster with
GrapheneOS is, you know, GrapheneOS is
we had already been talking to, they're
kind of more nimble and so
they're able to just like take
our settings in faster.
And that's why RCS with GrapheneOS
works faster.
For all the others, we are,
we do have all that scheduled
to be fixed this year.
It's just, you know, we got
to fall in line
with their roadmaps to get those
changes accepted.
And the fact that we have these
additional features like IMSI
rotation, it adds another layer of
complexity of where things can break.
And so that's why it's taking longer.
Yeah, I think some people find it
unfortunate because you also just
deprecated Last Mile SMS
encryption, I believe, which wasn't
like a perfect security
feature, but might have provided some
protection, I'd imagine,
until like RCS with end-to-end encryption
is more widely available.
Yeah.
What was that?
To be clear, yeah, to be clear,
we'll bring it back.
The Last Mile encryption is
available for all of your
secondary numbers.
It just won't be available for your
primary number anymore.
And it was previously like an
experimental feature that
only worked for iOS.
And
so the reason for taking away right
now is whenever we do one of
these things, it basically
breaks more things.
And so we're just trying to decrease the
complexity while we, for example,
get RCS working again.
We roll out all these different ability
to manage numbers and
swapping numbers between like, you
know, port-in to primary,
primary to secondary, things like that.
And once we've sorted out a lot of
those things and we have our
carrier settings recognized by the major
manufacturers, that's when
it makes sense to look again at Last
Mile encryption for primary number.
So that's why it's just basically to
simplify things so that we can
make the core product features
more robust.
But again,
for Last Mile encryption, you still do
have it for both of the
secondary numbers.
Can you explain, I was reading about
your disappearing Colog's
product feature, and you mentioned this
earlier, how you only keep
some of those for like 24 hours or
a matter of days or months or so.
I would imagine that all of the all of
that data has to be used for
like billing purposes, like your upstream
carriers would have to
bill you for usage and stuff like that.
How is how is all of that data collected?
And does any of that, any of those
disappearing logs features
interfere with that?
Or do you have to do some
additional logging
separately in order to get that
data from your carrier?
How does all of that work?
Yeah, so the whole billing reconciliation
process is basically
about like both sides comparing receipts.
And so, for example, if we have if we
have a roaming partner, the
roaming partner says like, you know,
your subscribers used 100
gigabytes, 100 gigabytes
of data in France.
We'll want to look on our side and be
like, okay, I also have 100
gigabytes of data used in France.
It matches.
We don't have any dispute.
Or if there's, you know, some big
discrepancy,
then then I want to be able to peel down.
Okay, like what what went wrong?
Why is that?
Why has what has gone wrong there?
And so
that's why, like, some monthly
data is useful.
So I think you can see in our blog
posts, internal CRs are kept for 30 days.
And then what we can glean
from individual CDR.
So individual CDRs will have a huge
amount of data, right?
So we'll have the cell ID that
gives the subscriber,
subscriber location,
you know, all the identifiers, like the
phone number, the device ID,
the MZ and all that.
So what we'll do is we'll strip all that
data from individual CDRs.
And we'll get an aggregate level of data.
So by aggregate, how much did how much
data was used over the course
of the month?
And that way we can compare that
monthly aggregate data with
whatever our roaming partner
is reporting to
us and thereby resolve any
billing dispute.
So it's basically a receipts
comparison thing.
In essence, we strip all identifying
information and aggregate.
And that's how we can
do the, do the
billing reconciliation.
One last thing that I saw people,
at least a couple of people
asking about on our Privacy
Guides form is
about Apple's limit precise
location feature.
Have you looked into that at all?
Or is that something that Cape
is even able to support?
Or does that need like hardware support?
Or?
Yeah, what's going on?
Yeah, yeah, it's a very, it's a very
cool feature basically uses a
concept like of timing advance and
introduces randomness into that
timing advance so that you can't so
basically that the carrier
cannot infer precise location anymore.
On our side, the the only location
data that we have is cell ID.
So cell ID is already in precise data.
Right now, Apple is only supporting
this for boost mobile.
And, you know, we'd love we'd
love to be the second.
We'd love to be the second carrier
that they support this with.
If you look at it, I think they support
only a few countries and
only one carrier for each of those
countries.
So, you know, tell, tell Apple to,
to put us put us in next.
So that's something on that's something
on Apple side of things.
Yeah, we would need.
Yeah, we would need to be able to
work with them to enable it.
Interesting.
Well, yeah, like I said, I won't I
won't take up too much more your time.
I think that kind of wraps it up.
Is there anything that you wanted to
talk about that we didn't discuss here?
I think in general, there's a what's
important for people to
remember is there's no perfect solution
in in the cellular network
area right now.
So if you're used to things
like encrypted
apps like like signal that can
do into encryption,
the the cell phone networks were
designed for interoperability, right?
It's designed so that you know, it works
with your bank, you know,
you can call your grandma on it and
all those things that makes it
wonderful in that it's the most interoperable,
most universally
useful thing that you could
use to connect.
I can connect from somebody
here all the way.
Across the world.
But that's also its source of weakness.
And we're going piece by piece.
Making things better.
Incrementally to plug up those holes.
And so a lot of so a lot of those
things that we're doing
is not even really sexy.
I think that the things that a lot of
customers focus on is like ems rotation.
You know, the secondary numbers, the
network lock, all the fancy
things that we do.
Probably the most important
thing that we do is
that we just take cybersecurity
more seriously.
It's central to our business model.
And it's central to our whole
security model.
If you go to our trust center, we
are way more transparent
about our security posture than anybody
else that that that I know
of any other carrier that I know of.
That's why we got the SOC 2 Type
2 compliance certification.
And that's also why, you know, we are
building our own mobile core and
making it making sure it's cloud first.
All these like basic
software principles that are familiar
to cybersecurity
professionals, like bringing
that over to telecom.
That's going to be what kind of makes
the biggest difference in
your average, everyday phone user.
Because if you think about it,
what is most likely going
to happen to you?
Your cell phone carrier is going
to sell your location data.
Because they've done it in the past.
They've been fined $200 million
for doing so.
Or they're going to lose their they're
going to lose that data.
So I think there's an AT&T hack of
their snowflake instance.
And it was basically because they
weren't using multi factor
authentication at that point,
which is super unsexy.
Right?
Like just making sure you have that
basic cybersecurity cybersecurity
hygiene.
But that's actually a major that's
going to be one of the major
benefits of of having this different kind
of like security focused telecom carrier.
Very cool.
Yeah, I mean, that cybersecurity
focus is just so important.
Yeah, I think that's kind of it.
For now, I think we covered most of the
things that I've seen a lot
of people talk about or ask me since
we've been talking about cave recently.
So I'm excited to share this with people.
And hopefully,
it answers questions or prompts
more questions.
Maybe I'll have to come back to you.
Yeah, yeah.
Yeah,
totally.
I'm up.
I'm up for I'm up for answering
more, more questions.
I think that'll happen.
I'll be following privacy guides closely
and see if I can see if I
can jump in there.
But if but if I can't just hit me up and
be be glad to talk again.
If you have any more questions, be sure
to leave a comment or come
join the discussion on our community
forum at discuss privacy guides.net.
I'd like to again thank
Rudy from Cape for
answering my questions about the service.
And I hope it's answered some of
the questions you might have had to