I’m not sure how O2 are still in business - they’re the worst network by far, even Three with their diabolical backhaul situation is better. Only reason I have an O2 SIM along with my EE one is for Priority tickets/signal inside their venues
O2 VoLTE: locating any customer with a phone call
61–70 of 80 posts
Re: O2 VoLTE: locating any customer with a phone call
#62Earlier quoted context omitted.
> Dumping data from the memory of your phone can't be unauthorized. > just dumping the diagnostics for regular phone calls should be fine IANAL, but computer hacking laws like the CMA in the UK and CFAA in the US are written in a manner so vague that even pressing F12 to view the source of a web page could be a violation [0]. From O2's perspective, they could argue that the OP has accessed their internal diagnostic d…
It's tough, but when the people don't respond what do you do? Do you just sit on the info, hoping noone else sees it and exploits it? Or do you try and get them to fix it somehow ?
Re: O2 VoLTE: locating any customer with a phone call
#63Also very curious how the call initiator was able to see the call control messages (ie SIP). Arent all these messages wrapped inside an encrypted GRE tunnel between handset and cell tower (and MME)? Being able to unpick GRE tunnel encryption would be a gigantic hole. Perhaps this only works because the OP is running analysis on their device, but even then I'm surprised that the pre-encryption payload is available.
Re: O2 VoLTE: locating any customer with a phone call
#64Also very curious how the call initiator was able to see the call control messages (ie SIP). Arent all these messages wrapped inside an encrypted GRE tunnel between handset and cell tower (and MME)? Being able to unpick GRE tunnel encryption would be a gigantic hole. Perhaps this only works because the OP is running analysis on their device, but even then I'm surprised that the pre-encryption payload is available.
i think you meant GTP tunnel. And GTP tunnel is between enodeb and core network. it's secured only in case that it run inside IPSEC.
Re: O2 VoLTE: locating any customer with a phone call
#65> Attempts were made to reach out to O2 via email (to both Lutz Schüler, CEO and securityincidents@virginmedia.co.uk) on the 26 and 27 March 2025 reporting this behaviour and privacy risk, but I have yet to get any response or see any change in the behaviour. This is really poor. And why is a Virgin Media address the closest best thing here? https://www.o2.co.uk/.well-known/security.txt should 200, not 404. To be cle…
There are several email addresses listed in the privacy policy (a GDPR requirement). Maybe somebody is listening there. E.g. DPO@o2.com https://www.o2.co.uk/termsandconditions/privacy-policy
Re: O2 VoLTE: locating any customer with a phone call
#66The wild part: this isn’t a theoretical bug. It’s implementation laziness that other UK networks already solved, as the post notes. ECI leaks have been called out since LTE rolled out—see papers like https://arxiv.org/abs/2106.05007—and automated location mapping is trivial given open mast DBs.
Re: O2 VoLTE: locating any customer with a phone call
#67Earlier quoted context omitted.
One annoyance with O2 UK is that they don't support VoLTE for legacy pay-as-you-go customers, only pay-monthly. Now I'm actually kind-of glad for that.
Coming second half of this year!
Re: O2 VoLTE: locating any customer with a phone call
#68Re: O2 VoLTE: locating any customer with a phone call
#69So giffgaff,who also use the O2 network, claim that they are unaffected as they have their own implementation of the service on top of O2s physical network. Which might be true, but I'm a bit suspicious as I know they are actually owned by the same company now,so consolidation is likely. If anyone tries replicating this on a giffgaff sim it would be good to know the result...
Re: O2 VoLTE: locating any customer with a phone call
#70The really interesting part of this issue is, that under most jurisdictions it probably won't even qualify as hacking. The data is sent out by the network voluntarily and during normal use. There are no systems at any point tricked into revealing personal data, which is often illegal, even if the hack is trivial. Even appending something like "&reveal_privat_data=true" to an URL might be considered illegal, because t…
It is, however, a data breach, triggering the requirement for them to report it to the regulator immediately or get fined, etc etc (if such rules exist in the UK)