Live data from Hacker News

O2 VoLTE: locating any customer with a phone call

mastdatabase.co.uk

71–80 of 80 posts

Re: O2 VoLTE: locating any customer with a phone call

#71

Earlier quoted context omitted.

Could be, but considering that you have some police/government departments/public entities using this provider, it wouldn't be wise to leak their own data to everyone in the open like this. On a side note, it's not the first time I've read a comment like the one you left above here on HN. As someone that lives in the UK, there seems to be a disconnection between what you guys write and what I see and experience daily…

The strategy is a bit more complex than you assume. The "accidental" leak of information in this case will now be "fixed" because a researcher discovered and disclosed it. Plausible deniability is maintained. It's unlikely that any "bad actors" were tracking police/government entities with this exploit, because if they had been, their own communications would have revealed their activity to the surveillance state, an…

But in the PRC it's illegal to say you don't like the government, while in the UK it's illegal to say you're going to blow up a mosque because Muslims are rats.

Yes, in every country (including the USA) (excluding North Korea because it doesn't have social media) it's possible to get arrested based on a social media post. However, that's overly reductive. Has anyone paid attention to which posts get people arrested? No, because that wouldn't make the UK look nearly as evil as the people saying this stuff want it to look.

Re: O2 VoLTE: locating any customer with a phone call

#72
post #37

Earlier quoted context omitted.

> Dumping data from the memory of your phone can't be unauthorized. > just dumping the diagnostics for regular phone calls should be fine IANAL, but computer hacking laws like the CMA in the UK and CFAA in the US are written in a manner so vague that even pressing F12 to view the source of a web page could be a violation [0]. From O2's perspective, they could argue that the OP has accessed their internal diagnostic d…

I don't have a lot of knowledge about US and UK law, but I hear a lot of bad things. "good faith security research" is a different ballpark though. Some laws catch all unauthorized access, even if the intent is not in a bad faith (which is probably a very bad idea, but that's how it is). But it also makes sense to some point: if your neighbor has a really bad lock that can be opened just by hitting the door frame a f…

Legally, using any tool that allows you to view raw cellphone traffic from your own phone is already unauthorized access (probably).

Famously, in Germany, it's illegal to be carrying a laptop on which nmap is installed. Everyone (who has a laptop and knows how to use nmap) still does it. It's one of those crimes which they get you for if they don't like you but you didn't commit any actual crime.

Re: O2 VoLTE: locating any customer with a phone call

#73
post #68

So giffgaff,who also use the O2 network, claim that they are unaffected as they have their own implementation of the service on top of O2s physical network. Which might be true, but I'm a bit suspicious as I know they are actually owned by the same company now,so consolidation is likely. If anyone tries replicating this on a giffgaff sim it would be good to know the result...

I've tested this on the giffgaff network, and it does have an impact. I'm not sure how they came to a different conclusion.

Re: O2 VoLTE: locating any customer with a phone call

#74

Earlier quoted context omitted.

IMS is just SIP core + bunch of gateways + integration with base LTE infra (eNodeB, PCRF, etc) so "signaling messages" are just SIP messages. So depending on whether those compromising headers were included on things like SIP 180 Ringing messages and such it may not be enough to not answer the calls. Source: actually worked on deploying IMS at a telco (not this one)

The headers are included in every single downlink message after initiating a call, including the downlink SIP Invite message before 100 Trying, 180 Ringing or 183 Session Progress. If you're quick enough (or automate this with dedicated software, like an attacker might actually do), it won't even need to ring out. It's really not good.

that's wild. did you also try any callees connected to a different PLMN?

Re: O2 VoLTE: locating any customer with a phone call

#76
post #60

The wild part: this isn’t a theoretical bug. It’s implementation laziness that other UK networks already solved, as the post notes. ECI leaks have been called out since LTE rolled out—see papers like https://arxiv.org/abs/2106.05007—and automated location mapping is trivial given open mast DBs.

Probably panicking and waiting to be told what to do by the security services that have been using this.

All of the information leaked in the headers is already readily available through lawful interception.

Re: O2 VoLTE: locating any customer with a phone call

#77

Earlier quoted context omitted.

Using what seems to be a misconfiguration of a network feature to support the opinion that the UK has no privacy is a bit weird. Not only other networks don't seem to have the same issue, but companies and people screw up sometimes. Also, is that Nigel Farage the same one of Brexit fame? The one who ran away when Brexit turned out to be different from what he and his party promised? That guy is going to save UK's pri…

Lots of these incels are surprised that the UK has different free speech laws to the US and are outraged that posting incendiary things on social media (racist violence-inciting anti-migrant comments) can lead to a visit from the police, arrest, and conviction... Their genius is thinking posting things in public is related to "privacy"...

These days you get arrested and thrown in jail just for sending death threats to politicians.

Re: O2 VoLTE: locating any customer with a phone call

#79

O2 has claimed that the problem is now fixed: https://www.ispreview.co.uk/index.php/2025/05/o2-uk-fixes-vo...

The submitted post was updated this morning

>O2 reached out to me via email to confirm that this issue has been resolved. I have validated this information myself, and can confirm that the vulnerability does appear to be resolved.

Re: O2 VoLTE: locating any customer with a phone call

#80

O2 has claimed that the problem is now fixed: https://www.ispreview.co.uk/index.php/2025/05/o2-uk-fixes-vo...

From their statement "Our engineering teams have been working on and testing a fix for number of weeks". Can you image if a database was knowingly left unsecured for that long with data that sensitive and seemingly without telling anyone. It will be interesting to see how the ICO deal with this.
Post reply on HN