Live data from Hacker News

UK network o2 send your number to every site you visit

lew.io

11–20 of 180 posts

Re: UK network o2 send your number to every site you visit

#14

Just tested on o2 Germany, and no such header was inserted. It would probably be illegal here anyway.

I would sodding hope it's illegal in the UK to! Altho as IANAL I can't think of which law exactly would cover it. Anyone know? I'm envious, you Germans have great privacy laws.

Re: UK network o2 send your number to every site you visit

#15
You should be able to bypass the proxy that inserts the HTTP headers with the following APN on O2:

  apn: mobile.o2.co.uk
  username: bypass
  password: password
Worked in 2008 when I tried it (http://www.edandersen.com/2008/07/13/iphone-o2-fix-the-image...) as they used to screw with images on the App Store. I don't have access to O2 anymore, can someone try this and see if it still works?

Edit: It still includes your phone number, thanks msmithstubbs.

Re: UK network o2 send your number to every site you visit

#16

Confirmed on a Google Nexus. In his webpage he also says "They downgrade all images and insert a javascript link into the HTML of each page." The image downgrading has been know about for ages, the JS I have not heard about before. I have asked for more info on Twitter but will investigate myself if I can find time today.

https://twitter.com/#!/O2/status/161872584634408960 says "@lewispeckover Hi Lewis. The mobile number in the HTML is linked to how the site determines that your browsing from a mobile device #O2Guru" As Lewis replies, "@O2 User-agent header ID's the device. Passing mobile number to third party sites is not ok! Seems like a data protection act breach to me?" Being charitable, that could be clueless support rather than…

From the oracle (Wikipedia), Data must not be disclosed to other parties without the consent of the individual whom it is about, unless there is legislation or other overriding legitimate reason to share the information (for example, the prevention or detection of crime). It is an offence for Other Parties to obtain this personal data without authorisation.

It is in fact illegal for the website to obtain this information... Lew, you're going down... Only joking.

Re: UK network o2 send your number to every site you visit

#17

Just tested on o2 Germany, and no such header was inserted. It would probably be illegal here anyway.

I would sodding hope it's illegal in the UK to! Altho as IANAL I can't think of which law exactly would cover it. Anyone know? I'm envious, you Germans have great privacy laws.

Data protection act - Data must not be disclosed to other parties without the consent of the individual whom it is about, unless there is legislation or other overriding legitimate reason to share the information (for example, the prevention or detection of crime). It is an offence for Other Parties to obtain this personal data without authorisation.

Re: UK network o2 send your number to every site you visit

#18

You should be able to bypass the proxy that inserts the HTTP headers with the following APN on O2: apn: mobile.o2.co.uk username: bypass password: password Worked in 2008 when I tried it ( http://www.edandersen.com/2008/07/13/iphone-o2-fix-the-image... ) as they used to screw with images on the App Store. I don't have access to O2 anymore, can someone try this and see if it still works? Edit: It still includes your p…

Just tried it. The phone number header is still being included.

Re: UK network o2 send your number to every site you visit

#19
A lot of mobile network operators wash this information about or have it hashed into some other form (which means it can still be used as a unique identifier)

Some popular headers to check

X-UP-CALLING-LINE-I

X_NOKIA_MSISDN

X_H3G_MSISDN

MSISDN

X_MSISDN

X_NETWORK_INFO

X-WAP-MSISDN

X-UP-SUBNO

Post reply on HN