Live data from Hacker News

UK network o2 send your number to every site you visit

lew.io

131–140 of 180 posts

Re: UK network o2 send your number to every site you visit

#131
post #54

I'm filing a Data Protection complaint now. I'd encourage other UK HNers to do the same: http://www.ico.gov.uk/complaints/data_protection.aspx

I am in the process of doing this now, also my contract expires this month with them and I will be moving to another provider - do we know it if only affects 02?

It also affects GiffGaff, a "virtual network operator" that uses O2's network.

Re: UK network o2 send your number to every site you visit

#135

You should be able to bypass the proxy that inserts the HTTP headers with the following APN on O2: apn: mobile.o2.co.uk username: bypass password: password Worked in 2008 when I tried it ( http://www.edandersen.com/2008/07/13/iphone-o2-fix-the-image... ) as they used to screw with images on the App Store. I don't have access to O2 anymore, can someone try this and see if it still works? Edit: It still includes your p…

You need to reboot after changing the APN + username (going into airplane mode, etc, isn't enough), then it stops sending the password, or at least did for me.

Thanks

Re: UK network o2 send your number to every site you visit

#136

Mobile networks seem to do all sorts of horrendous shit to peoples Internet connections. I found out this morning that T-Mobile UK's transparent web proxy breaks web sockets. They also break some websites by minifying javascript badly. This is exactly why my phone has a VPN to my Linode server and routes out all Internet traffic over it. Mobile phone companies don't provide a clean Internet connection.

What they do is traffic shaping / policy management / caching to reduce the amount of traffic delivered to the device via the mobile network.

The issues here are part of the overall network neutrality theme besides privacy & user experience issues.

Key technologies used are DPI (deep packet inspection) and PCRF (policy & charging rule function) within their IMS and even on the edge of their networks (mostly caching plus location capture etc). There are whole application ecosystems around these providing specialized solutions depending on the infrastructure (provider) used by the TelCom.

Leaders of the pack providing such technology are Sandvine, Ericsson, NSN, Cisco, Procera, Allot & Arbor Networks. CDN providers like Akamai or Level3 are tmk also active here.

Beyond the above there are pure HW players that e.g. provide TCP/ IP processing equipment which allows real-time inspections of 10/100Gbps streams together with development stacks - typical development providers include Continuous Computing (they have some nice posters to familiarize you with normal TelCom infrastructure) and smaller ones like Cavium Networks.

Besides all of the above commercial tools there is the so-called Lawful-Inspection where who-god-knows is peeking into the telcom traffic with special installations (now also in almost all western countries) so that even the Telcos don't know where the data is going to.

To get an overview what is happening in that industry segment have a look at http://broabandtrafficmanagement.blogspot.com/ - be aware that the TelComs are using a special lingo and acronym soup!

Re: UK network o2 send your number to every site you visit

#137

Earlier quoted context omitted.

Three (UK) don't do it, and it's worth also noting that @O2 has been in overdrive about trying to contain the twitter outrage. Good to see a large corp paying attention for once.

Have you examined all the Three headers to ensure that they are not sending a hashed version of the phone number?

Three's headers contain my phone make and model as a wap profile header - nothing personal apart from that.

Re: UK network o2 send your number to every site you visit

#139

Apart from the obvious data protection issues, perhaps an even more interesting and frightening aspect of the issue is that that phone number is probably there for a reason. It's entirely possible that some O2 or O2 partner sites use that header field to associate a visitor with an O2 customer. It would be interesting to see if that could be abused somehow, e.g. fake a phone number header to see if it's possible to "…

This is done inside the TelCom core - you have no control over that on the device.

That's also why headers from normal (non-mobile) endpoints including WiFi are considered unreliable for such information.

All that might soon change with the use of IP6 addresses.

Re: UK network o2 send your number to every site you visit

#140

I don't find my number. Galaxy Nexus with a contract on O2 (uk) using HDSPA connection. 1.2.3.50/ups/ shows just "This is a personalization server index page created by Bytemobile" but the rest of the page is blank. Nothing to setup...

I do on mine. What apn have you got set? Mine is mobile.o2.co.uk username o2web. Maybe some apns are different?
Post reply on HN