And how is this information different then an IP adress that they also have with each request?
UK network o2 send your number to every site you visit
21–30 of 180 posts
Re: UK network o2 send your number to every site you visit
#22Earlier quoted context omitted.
I would sodding hope it's illegal in the UK to! Altho as IANAL I can't think of which law exactly would cover it. Anyone know? I'm envious, you Germans have great privacy laws.
Data protection act - Data must not be disclosed to other parties without the consent of the individual whom it is about, unless there is legislation or other overriding legitimate reason to share the information (for example, the prevention or detection of crime). It is an offence for Other Parties to obtain this personal data without authorisation.
Re: UK network o2 send your number to every site you visit
#23Isn't this information used as an extra security layer when using your mobile phone for payments or bank transactions? Here in The Netherlands when I want to use my mobile phone to log in to my bank account and do transactions, I first need to confirm my phone number and a special code. I can imagine that then they need the phone number in the header to verify it is my phone. And how is this information different the…
Unscrupulous marketers can't do much with your IP address. They can do a lot more evil with your mobile number: SMS spam, cold calls, re-sell your data, etc, etc...
Re: UK network o2 send your number to every site you visit
#24Additional write-up on another site here: http://www.thinkbroadband.com/news/4990-o2-shares-your-mobil...
x-up-calling-line-id (and similar headers from other gateway vendors) are typically not meant to be sent in the clear beyond internal sites. Perhaps a certain set/class of URL ACLs were (mis)configured during a maintenance window that caused this to happen.
Similar to how websites leave cookies, carriers have always had the ability to send certain identifying information to external sites. Usually, such identifying information is munged in some way that doesn't make it possible to determine the mobile number of the subscriber.
The funny thing is that people are often surprisingly willing to provide their phone number on more and more sites, which then makes it trivial for such services to link the anonymized identifier with the actual mobile number.
Regarding the customer support folks, it's highly unlikely that they know anything about HTTP headers, since they are typically level 1 support. This type of query/complaint would be filtered up to level 2 or 3 usually quite quickly once enough customers start calling in, or if somebody happens to be reading certain media outlets (e.g. HN).
Re: UK network o2 send your number to every site you visit
#25Earlier quoted context omitted.
Data protection act - Data must not be disclosed to other parties without the consent of the individual whom it is about, unless there is legislation or other overriding legitimate reason to share the information (for example, the prevention or detection of crime). It is an offence for Other Parties to obtain this personal data without authorisation.
I suspect any legal case would hinge on whether your mobile phone number counted as personal data or not. Again, IANAL, but the Data Protection Act is not specific on what counts as personal data and instead leaves it up to case law and I think the data registrar(?) to clarify.
However, I think it is generally percieved as personal.
Re: UK network o2 send your number to every site you visit
#26Isn't this information used as an extra security layer when using your mobile phone for payments or bank transactions? Here in The Netherlands when I want to use my mobile phone to log in to my bank account and do transactions, I first need to confirm my phone number and a special code. I can imagine that then they need the phone number in the header to verify it is my phone. And how is this information different the…
Re: UK network o2 send your number to every site you visit
#27Isn't this information used as an extra security layer when using your mobile phone for payments or bank transactions? Here in The Netherlands when I want to use my mobile phone to log in to my bank account and do transactions, I first need to confirm my phone number and a special code. I can imagine that then they need the phone number in the header to verify it is my phone. And how is this information different the…
Also, just because this can be used for good does not mean A) it can't be used for bad B) it is sharing private data that should only happen with your knowledge and consent
Re: UK network o2 send your number to every site you visit
#28*edit scratch that it is happening now. Both attempts were on 3G only. Seems it doesn't always happen.
Re: UK network o2 send your number to every site you visit
#29Re: UK network o2 send your number to every site you visit
#30Additional write-up on another site here: http://www.thinkbroadband.com/news/4990-o2-shares-your-mobil...
The write-up is more charitable when it comes to the possible reason why this may be happening. The specific quote: " Our suspicion is that the feature is used by internal O2 websites to identify the user trying to make changes to the account, but that one or more of O2's proxy servers have been misconfigured." x-up-calling-line-id (and similar headers from other gateway vendors) are typically not meant to be sent in…
However, amusing it's a honest mistake being fixed, this still SHOULD NOT HAPPEN in the first place. Companies dealing with personal data need to be more careful when the ramifications of "honest mistakes" can be so serious. It's right that people are making a fuss about this and pressuring O2 to fix this.
> The funny thing is that people are often surprisingly willing to provide their phone number on more and more sites, which then makes it trivial for such services to link the anonymized identifier with the actual mobile number.
Sure, but that still doesn't excuse this.