O2 VoLTE: locating any customer with a phone call
mastdatabase.co.uk
O2 VoLTE: locating any customer with a phone call
1–10 of 80 posts
Re: O2 VoLTE: locating any customer with a phone call
#2This is really poor. And why is a Virgin Media address the closest best thing here? https://www.o2.co.uk/.well-known/security.txt should 200, not 404.
To be clear, I have no problem with disclosure in these circumstances given the inaction, but I'm left wondering if this is the sort of thing that NCSC would pick up under some circumstances (and may have better luck communicating with the org)?
Re: O2 VoLTE: locating any customer with a phone call
#3When I worked there (many years ago) the security team was excellent. When I emaileld them about an issue last year, they were all gone.
Re: O2 VoLTE: locating any customer with a phone call
#4*yes I’m aware that means people you know who have your number could also exploit this
Re: O2 VoLTE: locating any customer with a phone call
#5Re: O2 VoLTE: locating any customer with a phone call
#6I don’t know anything about IMS but I assume they have to stay on the call long enough for the debug headers to be sent (like the tracing the call thing in every spy movie but real) and if that’s the case can this be mitigated by “just”* not answering calls from unknown numbers? *yes I’m aware that means people you know who have your number could also exploit this
Re: O2 VoLTE: locating any customer with a phone call
#7It's disappointing that they didn't reply, but I'm not surprised. O2 seems to be a mess internally. Anything that can't be fixed by someone at a store takes ages to fix (eg: a bad number port). Their systems seem to be outdated, part of their user base still can't use VoLTE, their new 5G SA doesn't support voice and seems to over rely on n28 making it slow for many, their CTO blogs about leaving "vanity metrics behind"[0] even though they are usually the worst network for data, etc.
[0] https://news.virginmediao2.co.uk/leaving-the-vanity-metrics-...
Re: O2 VoLTE: locating any customer with a phone call
#8There are no systems at any point tricked into revealing personal data, which is often illegal, even if the hack is trivial. Even appending something like "&reveal_privat_data=true" to an URL might be considered illegal, because there is clear intent to access data you shouldn't be allowed to access. In this case none of that is done.
Re: O2 VoLTE: locating any customer with a phone call
#9O2 used to have a responsible disclosure address - but they removed it a few years back. When I worked there (many years ago) the security team was excellent. When I emaileld them about an issue last year, they were all gone.
Re: O2 VoLTE: locating any customer with a phone call
#10O2 used to have a responsible disclosure address - but they removed it a few years back. When I worked there (many years ago) the security team was excellent. When I emaileld them about an issue last year, they were all gone.
[flagged]