In our previous guide, we covered how airplane mode can protect you by creating gaps in location tracking. But here's what it doesn't solve: the moment you reconnect, your SIM card resumes broadcasting your location to telecommunications networks worldwide, and that data is far less secure than most people realize.
For most people, using any kind of SIM card, even an anonymous one, results in their location being tracked and recorded continuously. This tracking data is then made available to organized crime, corrupt officials, or anyone else willing to pay for it through various channels.
This guide explains why, and makes the case for reconsidering how you connect to the internet.
The SS7 Problem
The core vulnerability is the SS7 (Signaling System No. 7) protocol, a set of telephony signaling protocols used by carriers worldwide to route calls and text messages. SS7 was designed in the 1970s with no security considerations, operating on the assumption that only trusted telecommunications companies would have access to it. That assumption is now dangerously outdated.
Real-time location tracking: Through SS7 exploits, attackers can query the cellular network to determine the real-time location of any phone number. The network responds with the location of the nearest cell tower currently serving that device, often accurate to within a few hundred meters in urban areas.
Widely available: SS7 access is no longer limited to telecommunications companies. Criminal organizations, corrupt insiders, private investigators, and even sophisticated individual attackers have demonstrated the ability to exploit these vulnerabilities. SS7 access is bought and sold on underground markets.
No indication to the target: When someone tracks your location via SS7, your phone shows no indication that it's happening. There are no notifications, no battery drain, no suspicious behavior. The surveillance is completely invisible to you.
Global reach: Because SS7 is a global protocol used for international roaming, an attacker anywhere in the world can potentially track a phone number anywhere else in the world, as long as they have SS7 access.
Countries with Stronger SS7 Protections
A handful of countries have implemented technical measures that make SS7 exploitation significantly more difficult. Germany, Ukraine, and the Netherlands have deployed systems that filter and validate SS7 queries, making it much harder for unauthorized parties to track SIM cards registered in those countries.
However, even in these countries, protections are not absolute. They raise the difficulty level for attackers but don't eliminate the risk entirely.
Everywhere else: In the vast majority of countries, SS7 protections are minimal or nonexistent. As soon as you insert a SIM card and connect to the cellular network, it becomes trivial for organized crime or other adversaries to track your location in real-time from anywhere in the world.
Note: Country policies and technical implementations change. Verify current protections before relying on this information for operational security.
Baseband Vulnerabilities
Modern smartphones contain a separate processor called the baseband, which handles all cellular communication. This baseband processor runs its own firmware, often proprietary and poorly audited, creating a significant attack surface.
Remote exploitation: Sophisticated attackers, including nation-states and well-funded criminal organizations, have developed exploits that target baseband vulnerabilities. These exploits can potentially allow remote code execution, surveillance, or tracking, all without the user's knowledge.
Bypassing OS security: Because the baseband operates independently of your phone's main operating system (Android, iOS, etc.), baseband exploits can sometimes bypass security features implemented by the OS. Even a fully updated, well-secured phone can be vulnerable if its baseband firmware has unpatched vulnerabilities.
Wi-Fi avoids the baseband: When you use Wi-Fi instead of cellular connectivity, most baseband vulnerabilities become irrelevant. The baseband is only active when you're connected to cellular networks. By keeping your device in airplane mode with Wi-Fi enabled, you eliminate the baseband as an attack vector for most practical purposes.
The Wi-Fi Alternative
This is fundamentally not true if you use Wi-Fi instead of a SIM card. When you connect to Wi-Fi networks, your location is not broadcast to a global telecommunications network. An attacker cannot simply query a network to find out where you are. They would need to either physically follow you, compromise the specific Wi-Fi networks you connect to, or exploit your device directly, all significantly more difficult than purchasing SS7 access.
Putting it in perspective: Yes, using Wi-Fi instead of a SIM card means you still have to worry about:
- Nation-state actors with sophisticated capabilities
- Physical surveillance (someone following you in person)
- Attackers creating fake Wi-Fi networks in your vicinity
- Accidentally connecting to a network operated by a skilled attacker
But these threats are orders of magnitude less common than the SIM card threat model: "Anyone with the right contacts can track my location continuously without me ever knowing."
For many threat models, avoiding SIM cards entirely and relying on Wi-Fi connections (combined with a VPN for additional privacy) provides substantially better protection against the most accessible and widely abused surveillance methods.
Public Wi-Fi: Real Risks in Context
Public Wi-Fi networks do carry security risks, but they're often overstated. Understanding the actual threats helps you make informed decisions.
Man-in-the-Middle (MitM) Attacks: An attacker intercepts communication between your device and the Wi-Fi network, potentially stealing sensitive data transmitted over the connection.
Evil Twin Hotspots: Criminals set up fake networks that mimic legitimate ones ("Free Airport Wi-Fi" or "Starbucks Wi-Fi"). When you connect, the attacker gains access to your traffic.
Auto-Reconnect Exploitation: When you connect to a public Wi-Fi network once, your phone may automatically try to reconnect later. Attackers can create fake networks with the same name to trick your device into connecting automatically.
However: Modern HTTPS encryption means that attackers on the same network cannot see the content of your communications with properly secured websites. They can see which domains you visit (metadata), but not your passwords or the content of forms you submit.
The genuine risks are credentials sent to sites without HTTPS (increasingly rare), your device auto-connecting to malicious networks, and attackers exploiting vulnerabilities in your device's network stack. For everyday use, a reputable VPN addresses most public Wi-Fi concerns while letting you stay connected.
Choosing Safer Public Wi-Fi Networks
Not all public Wi-Fi networks carry equal risk. When you must use public Wi-Fi, strategic selection significantly improves your security:
Prefer WPA2 password-protected networks: The key distinction is whether the network requires a WPA2 password to connect, not just a login on a captive portal after you've connected. WPA2 password authentication encrypts wireless traffic between your device and the access point, making it significantly harder for attackers to intercept your data.
Avoid wide-open networks: Networks with no password requirement offer zero encryption of wireless traffic. Anyone within range can potentially monitor all unencrypted data being transmitted.
Think strategically about network targets: Not all networks are equally attractive to attackers. Conference Wi-Fi at security conferences or hacker conventions represents much higher risk than the Wi-Fi at your neighborhood coffee shop. Networks frequented by high-value targets attract more sophisticated attackers.
Captive portals don't provide encryption: Many public networks appear "secure" because they require a webpage login after connecting. This does not encrypt your wireless traffic. The critical security feature is WPA2 password authentication before you connect, not what happens after.
Disable auto-join: This single setting prevents your phone from connecting to remembered networks (or evil twins using those names) without your explicit approval.
MAC Address Randomization
Modern smartphones include MAC address randomization, which changes the hardware identifier your device broadcasts when scanning for Wi-Fi networks. This prevents tracking across locations based on your device's unique identifier.
Ensure this feature is enabled in your device settings. On iOS, it's on by default for networks you haven't joined. On Android, the setting location varies by manufacturer but is typically found in Wi-Fi preferences.
Conclusion
Your SIM card connects you to a global telecommunications infrastructure designed in the 1970s with no security considerations. That infrastructure is now routinely exploited by criminals, corrupt officials, and anyone willing to pay for access.
Wi-Fi connectivity, while not without risks, removes you from this vulnerable system entirely. Combined with a VPN and good network hygiene, it provides substantially better protection against the most common and accessible surveillance methods.
The solution isn't to stop using mobile data. It's to compartmentalize your connectivity so that your network identity is separated from your personal identity.
In our next guide, we walk through building a private mobile connectivity setup using the clean/dirty device model.
If you found this advice valuable consider sharing with others. For personalized advice on implementing these security layers for you, your team, or your family, book a consultation with one of our experts
Gart Research