Live data from Hacker News

O2 VoLTE: locating any customer with a phone call

mastdatabase.co.uk

41–50 of 80 posts

Re: O2 VoLTE: locating any customer with a phone call

#41
post #4

I don’t know anything about IMS but I assume they have to stay on the call long enough for the debug headers to be sent (like the tracing the call thing in every spy movie but real) and if that’s the case can this be mitigated by “just”* not answering calls from unknown numbers? *yes I’m aware that means people you know who have your number could also exploit this

IMS is just SIP core + bunch of gateways + integration with base LTE infra (eNodeB, PCRF, etc) so "signaling messages" are just SIP messages. So depending on whether those compromising headers were included on things like SIP 180 Ringing messages and such it may not be enough to not answer the calls. Source: actually worked on deploying IMS at a telco (not this one)

The headers are included in every single downlink message after initiating a call, including the downlink SIP Invite message before 100 Trying, 180 Ringing or 183 Session Progress.

If you're quick enough (or automate this with dedicated software, like an attacker might actually do), it won't even need to ring out. It's really not good.

Re: O2 VoLTE: locating any customer with a phone call

#42
post #27

Earlier quoted context omitted.

> You clearly aren’t familiar with how broad the Computer Misuse Act is No, I'm not familiar with it at all. But usually illegal hacking requires to access devices in a way you aren't allowed to access. As long as making the phone call itself is not an issue, it should be fine. Dumping data from the memory of your phone can't be unauthorized. It would probably become an issue if you make unusual phone calls, harassin…

> Dumping data from the memory of your phone can't be unauthorized. > just dumping the diagnostics for regular phone calls should be fine IANAL, but computer hacking laws like the CMA in the UK and CFAA in the US are written in a manner so vague that even pressing F12 to view the source of a web page could be a violation [0]. From O2's perspective, they could argue that the OP has accessed their internal diagnostic d…

It's tough, but when the people don't respond what do you do?

Do you just sit on the info, hoping noone else sees it and exploits it?

Or do you try and get them to fix it somehow?

Re: O2 VoLTE: locating any customer with a phone call

#43

[flagged]

Using what seems to be a misconfiguration of a network feature to support the opinion that the UK has no privacy is a bit weird. Not only other networks don't seem to have the same issue, but companies and people screw up sometimes. Also, is that Nigel Farage the same one of Brexit fame? The one who ran away when Brexit turned out to be different from what he and his party promised? That guy is going to save UK's pri…

From my experience with the US IC, they "encourage" industry to "leak" data to their advantage. This example stinks of exactly the same tactic.

Re: O2 VoLTE: locating any customer with a phone call

#44

I’m curious to see if this exists on O2 in NZ. I switched to them last week because they do free roaming in Australia, and VoLTE calls.

I doubt it. This is likely O2 UK specific.

This only affects O2, not EE/VF/3, right?

Re: O2 VoLTE: locating any customer with a phone call

#45

Earlier quoted context omitted.

Using what seems to be a misconfiguration of a network feature to support the opinion that the UK has no privacy is a bit weird. Not only other networks don't seem to have the same issue, but companies and people screw up sometimes. Also, is that Nigel Farage the same one of Brexit fame? The one who ran away when Brexit turned out to be different from what he and his party promised? That guy is going to save UK's pri…

From my experience with the US IC, they "encourage" industry to "leak" data to their advantage. This example stinks of exactly the same tactic.

Could be, but considering that you have some police/government departments/public entities using this provider, it wouldn't be wise to leak their own data to everyone in the open like this.

On a side note, it's not the first time I've read a comment like the one you left above here on HN. As someone that lives in the UK, there seems to be a disconnection between what you guys write and what I see and experience daily. You make it look like no one can say anything or that this is a war zone... Don't take this the wrong way, but I recommend checking other news sources too because your view of the UK seems to be a bit "distorted".

Re: O2 VoLTE: locating any customer with a phone call

#46

Earlier quoted context omitted.

> Dumping data from the memory of your phone can't be unauthorized. > just dumping the diagnostics for regular phone calls should be fine IANAL, but computer hacking laws like the CMA in the UK and CFAA in the US are written in a manner so vague that even pressing F12 to view the source of a web page could be a violation [0]. From O2's perspective, they could argue that the OP has accessed their internal diagnostic d…

It's tough, but when the people don't respond what do you do? Do you just sit on the info, hoping noone else sees it and exploits it? Or do you try and get them to fix it somehow ?

First of all, thank you for trying to resolve this with the carrier and finally bringing it up to everyone's attention here. Perhaps public attention is what's needed to push them to address the problem.

To be honest, I personally would be scared to report such vulnerabilities with my real identity to begin with. With big tech companies, no matter how poorly their bug bounty programs are run, I still have this naive expectation that they won't shoot the messenger. At worst they could ban my accounts and maybe send threatening letters, but they probably won't ruin my life as long as I abide by the norms (agreed by technical people).

However, I do not feel the same naive optimism towards "legacy" institutions like telecoms and public services. At best it's thankless work, at worst I get sued [0] or become a scapegoat so some official could score some political points [1]. It's unfortunate - I am acutely aware that this is chilling effect at work, and our systems are collectively less secure because of it.

[0]: https://www.cnbc.com/2024/09/15/dark-web-expert-warned-us-ho... [1]: https://techcrunch.com/2021/10/15/f12-isnt-hacking-missouri-...

Re: O2 VoLTE: locating any customer with a phone call

#47
post #2

> Attempts were made to reach out to O2 via email (to both Lutz Schüler, CEO and securityincidents@virginmedia.co.uk) on the 26 and 27 March 2025 reporting this behaviour and privacy risk, but I have yet to get any response or see any change in the behaviour. This is really poor. And why is a Virgin Media address the closest best thing here? https://www.o2.co.uk/.well-known/security.txt should 200, not 404. To be cle…

This one is actually on us. The email contacted was actually @virginmediao2.co.uk, not @virginmedia.co.uk. It's a typo in the article. I'll update it with a correction.

I have spotted another error:

> is within LAC 0x1003 (decimal: 4009)

It should be decimal 4099.

Re: O2 VoLTE: locating any customer with a phone call

#48

Also very curious how the call initiator was able to see the call control messages (ie SIP). Arent all these messages wrapped inside an encrypted GRE tunnel between handset and cell tower (and MME)? Being able to unpick GRE tunnel encryption would be a gigantic hole. Perhaps this only works because the OP is running analysis on their device, but even then I'm surprised that the pre-encryption payload is available.

Many operators do configure the SIP signaling for VoLTE to use an IPsec transport terminated at the P-CSCF, but most (if not all) of them only configure IPsec to provide integrity protection.

Re: O2 VoLTE: locating any customer with a phone call

#49
post #2

> Attempts were made to reach out to O2 via email (to both Lutz Schüler, CEO and securityincidents@virginmedia.co.uk) on the 26 and 27 March 2025 reporting this behaviour and privacy risk, but I have yet to get any response or see any change in the behaviour. This is really poor. And why is a Virgin Media address the closest best thing here? https://www.o2.co.uk/.well-known/security.txt should 200, not 404. To be cle…

There are several email addresses listed in the privacy policy (a GDPR requirement). Maybe somebody is listening there. E.g. DPO@o2.com

https://www.o2.co.uk/termsandconditions/privacy-policy

Re: O2 VoLTE: locating any customer with a phone call

#50

Earlier quoted context omitted.

This one is actually on us. The email contacted was actually @virginmediao2.co.uk, not @virginmedia.co.uk. It's a typo in the article. I'll update it with a correction.

I have spotted another error: > is within LAC 0x1003 (decimal: 4009) It should be decimal 4099.

How did you spot that?
Post reply on HN