O2 dishing out customer phone numbers to websites?

by Steven Williamson on 25 January 2012, 14:30

Quick Link: HEXUS.net/qabbsf

Add to My Vault: x

O2 is under the cosh today after reports have landed that the service provider has been sharing phone numbers of its customers with every website they visit via their smartphone’s browser.

The issue was flagged up by Twitter user and London-based programmer @lewispeckover who set up a website to expose the flaw showing how mobile phone numbers of O2 customers browsing via 3G are appearing in the 'http' header of the websites they visit. His personal number was embedded inside a 'http' header called HTTP_X_UP_CALLING_LINE_ID.

On the web page, @lewispeckover accuses the company of “transparently proxying HTTP traffic and inserting this header.” There has also been a number of reports suggesting that users of GiffGaff and Tesco, who use the O2 network, are also affected.

It’s currently unclear whether the information posted occurs on every website visited, or whether O2 has a select number of sites that it chooses to share the personal information of its customers with. Either way, #O2 users are up in arms on Twitter demanding answers.

Customer phone numbers embedded in 'http' header

German Phd student, Colin Mulliner, who specialises in smartphone security, has also set up a website that will tell you if your smartphone has transmitted your phone number. Turn your phone’s Wi-Fi off first and then hit this link.

O2 has yet to comment on the issue, which has been gaining momentum throughout the day and has now attracted mainstream media channels, but has said the security breach is being 'investigated as a top priority' The Information Commissioner's Office has told The Guardian that there is no signs that O2 has breached the Data Protection Act, though it is considering investigating further.


HEXUS Forums :: 8 Comments

Login with Forum Account

Don't have an account? Register today!
For what it's worth, I think they've stopped now.
https://twitter.com/#!/O2/status/161872584634408960

O2
@lewispeckover Hi Lewis. The mobile number in the HTML is linked to how the site determines that your browsing from a mobile device #O2Guru

Biscuit
….

My reaction exactly.