If an image is loaded from a third-party site then presumably that request's header also includes the phone number. Can anyone confirm? That would mean that it's not just the website you're visiting that's getting your phone number, but advertisers too. Here comes the SMS spam...
UK network o2 send your number to every site you visit
81–90 of 180 posts
Re: UK network o2 send your number to every site you visit
#82Re: UK network o2 send your number to every site you visit
#83http://www.bbc.co.uk/blogs/watchdog/2010/04/mobile_spoofing....
Nothing has been done about it.
Re: UK network o2 send your number to every site you visit
#84I'm on Giffgaff, which is a daughter company of O2, same problem. Started a support thread on the website, let's see what they say.
On giffgaff too, any chance you could link to that thread?
Re: UK network o2 send your number to every site you visit
#85I'm filing a Data Protection complaint now. I'd encourage other UK HNers to do the same: http://www.ico.gov.uk/complaints/data_protection.aspx
Re: UK network o2 send your number to every site you visit
#86Re: UK network o2 send your number to every site you visit
#87I'm filing a Data Protection complaint now. I'd encourage other UK HNers to do the same: http://www.ico.gov.uk/complaints/data_protection.aspx
Re: UK network o2 send your number to every site you visit
#88Earlier quoted context omitted.
> For instance with your banking example, yes, I may have given my number and probably have if I'm a customer. But what if I'm just browsing a banks website thinking about opening an account? Sorry I wasn't clearer. I was referring to the use-case where you have an HTTPS connection open with the banking site, and the carrier has agreed to send your mobile number to the banking site only under these conditions (perhap…
>Sorry I wasn't clearer. I was referring to the use-case where you have an HTTPS connection open with the banking site, and the carrier has agreed to send your mobile number to the banking site only under these conditions (perhaps for security/tracing/auditing purposes). I'm confused, how do they insert headers in to HTTPS? > Yes. This is the same grey area with the potential for abuse that every single company must…
A few of possible methods of inserting a mobile number into a HTTPS connection:
1) Instead of negotiating a TLS end-to-end tunnel with the banking site, have the device negotiate the tunnel with the proxy, and then the proxy initiates a second tunnel with the banking site. This require[d|s] a lot of finangling with the trusted certs on the device (usually burned in via firmware for older phones). I don't know anybody that does this today; I only list it here as a possibility.
2) Believe it or not, some older devices actually sent the mobile number as part of the HTTP headers originating from the device browser user-agent. For these devices, content sites using HTTPS connections were almost always guaranteed to receive the mobile number (the irony is rich). In these scenarios, carrier proxies would actually strip the mobile number or other identifying characteristics from the outbound HTTP requests.
3) More straight-forward, a bank installs a native user-agent on the device (e.g. banking app) that injects the mobile number after negotiating an e2e TLS tunnel.
#2 didn't admittedly answer your question, but I threw it in there for the sake of completeness.
Re: UK network o2 send your number to every site you visit
#89I'm filing a Data Protection complaint now. I'd encourage other UK HNers to do the same: http://www.ico.gov.uk/complaints/data_protection.aspx
Can you post what you send and then we can all forward it?
-------------------------
SECTION 4:
Name: Telefonica O2 UK Address: 260 Bath Road Postcode: SL1 4DX Phone: 0800 089 0202 email: peter.erksine@o2.com website: http://www.o2.co.uk
SECTION 6:
When users of their network visit a site O2 inject the mobile phone number of the user into the request. This is then available to the website host, which raises obvious data protection issues. O2 does this by modifying the HTTP request and inserting the number in the 'x-up-calling-line-id' HTTP header.
Alarmingly, it does this to all unencrypted site visits (i.e. 'http' not 'https'), and these end-sites can trivially harvest the mobile numbers of visitors and link these to content visited.
This can be verified by visiting http://lew.io/headers.php on an O2 mobile device. The site serves as a tool to show the visitor the HTTP headers received by the server when the user requests that particular page.
SECTION 10:
Online utility that will show you the headers sent in your page request: http://lew.io/headers.php
Discussion on technical forum 'hacker news': http://news.ycombinator.org/item?id=3508857
Official O2 Twitter responding to (and misunderstanding/misrepresenting) the problem: https://twitter.com/#!/O2/status/161872584634408960
-------------------------
COVERING LETTER WITH EMAIL TO casework@ico.gsi.gov.uk:
To whom it may concern,
Please find attached my complaint against O2 under the Data Protection Act.
When users of their network visits a site O2 inject the mobile phone number of the user into the request. This is then available to the website host, which raises obvious data protection issues.
Regards,