Another facet of this is that the devices can be tracked, whether or not the user is using it or making a call. As long as it is on and available to receive a call (communicating with the base) it can be identified and a coarse location determined. If it were me in the law-enforcement role, the way I would use this is to identify devices in an area of interest (the protest locations) and record the identifiers over a series of days/nights. Eliminating devices which did not appear during a majority of the observed days lets you focus on the core group of people present at the events. (This will include media, people who live/work in the area, police and civil support themselves, etc.) Some careful trimming of the data by time of day will help reduce the "noise". Then you have a subset to focus investigations on. If I were on the other side, I'd make good use of WiFi (fixed and hotspots), VoIP, and "burners" (prepaid phones bought with cash and no ID - don't know if that's possible in all countries). Those are easy protections. Defense can get more technical and fiddle with the device IDs, but that likely crosses a line - and I'd want to be pure as the driven snow if I was at high risk of being arrested at some point.