Live data from Hacker News

UK network o2 send your number to every site you visit

lew.io

161–170 of 180 posts

Re: UK network o2 send your number to every site you visit

#161
post #94
post #31

Using Opera Mini seems to disable this "feature". Of course, doing so means all of my web traffic goes via Oslo. And of course, any apps using an http API are presumably affected too. I'm rather disappointed to hear about this.

> Of course, doing so means all of my web traffic goes via Oslo. Which probably means that your phone number is going to Oslo instead. At least it's not being proxied onwards from there.

Opera Mini uses its own protocol to talk to the proxy. HTTP is quite chatty, so there's a lot of mileage in reducing the headers by simply omitting a lot of unneeded information and compressing the rest.

Re: UK network o2 send your number to every site you visit

#163
Sadly I can say this is true for at least two US carriers.

One had obfuscated the number by padding it in a unique identifier header, and the other would send it along in some cases (i can't remember if it was on a partner by partner basis).

Also, almost every HTTP request on a mobile phone still passes through a HTTP Proxy. Generally, so avoiding opera, won't do any good. That is what the APN does.

What typically will get you off the carriers proxies is to use wi-fi, despite what the author says. They tend to get out of the loop if you're using someone else's network.

Re: UK network o2 send your number to every site you visit

#164

Glad this is being brought to attention finally (as it seems it's been discovered before), but this is just yet another case of a UK mobile operator losing my trust. O2: Send number in plain-text to every website visited. [1] Orange: Increase fixed contract price by RPI through use of dodgy contract clause. [2] Three: Place a non-payment flag on my credit report for no apparent reason. When I realise years later, the…

Let's not forget Vodafone, who released an update for Android at about the same time 2.2 was arriving. Only it wasn't 2.2, it was a whole load of Vodafone-branded cruft for 2.1 that couldn't be removed.

http://www.itpro.co.uk/625774/vodafone-no-froyo-android-upda...

Re: UK network o2 send your number to every site you visit

#165

The link insertion reminds me of an ISP in another country that was rewriting HTML before sending it. If we want to get very technical, if this happened in the US, couldn't an ISP be dinged for creating a "derived work" of a copyrighted page without permission?

I think that is opening up a can of worms I would rather not see opened. Technically caching could be seen as copyright infringement.

Quite a few ISP's run transparent proxies for caching and technically every time you visit a website you are creating a copy of it on your local drive. If I disable javascript or run other scripts (like via grease-monkey) I am also technically creating "derived work".

Re: UK network o2 send your number to every site you visit

#166

Here's a statement from the Information Commissioner's Office: "When people visit a website via their mobile phone they would not expect their number to be made available to that website. "We will now speak to O2 to remind them of their data breach notification obligations, and to better understand what has happened, before we decide how to proceed." http://news.sky.com/home/technology/article/16156276 O2 are in trou…

Odd they said something different to the Guardian http://www.guardian.co.uk/technology/2012/jan/25/02-mobile-p... "The Information Commissioner's Office said it is considering whether to investigate further, although a spokesman said there was no immediate breach of the Data Protection Act. A mobile phone number on its own is not classed as "personally identifying information" (PII), because it does not identify an i…

Even if it doesn't technically violate the DPA there must be something this violates?

I wonder if this was in the T&C when I signed the contract?

Re: UK network o2 send your number to every site you visit

#167
O2 have responded

http://blog.o2.co.uk/home/2012/01/o2-mobile-numbers-and-web-...

Selected highlights:

Q: How long has this been happening?

A: In between the 10th of January and 1400 Wednesday 25th of January, in addition to the usual trusted partners, there has been the potential for disclosure of customers’ mobile phone numbers to further website owners.

Q: Has it been fixed?

A: Yes. It was fixed as of 1400 on Wednesday 25th January 2012.

[edited to add]

I find this a bit weaselly:

Q: Which websites do you normally share my mobile number with?

A: Only where absolutely required by trusted partners who work with us on age verification, premium content billing, such as for downloads, and O2's own services, have access to these mobile numbers.

Re: UK network o2 send your number to every site you visit

#169
post #160

Earlier quoted context omitted.

What are you guys sending as "supporting evidence"?

I put links to the lew.io tool, this thread and O2's official twitter response. They seem to have taken down the header now though.

O2 have responded, admitting the issue existed, and stating they've now fixed it.

http://blog.o2.co.uk/home/2012/01/o2-mobile-numbers-and-web-...

Re: UK network o2 send your number to every site you visit

#170

The link insertion reminds me of an ISP in another country that was rewriting HTML before sending it. If we want to get very technical, if this happened in the US, couldn't an ISP be dinged for creating a "derived work" of a copyrighted page without permission?

I think that is opening up a can of worms I would rather not see opened. Technically caching could be seen as copyright infringement. Quite a few ISP's run transparent proxies for caching and technically every time you visit a website you are creating a copy of it on your local drive. If I disable javascript or run other scripts (like via grease-monkey) I am also technically creating "derived work".

English law has exemptions for caching.
Post reply on HN