O2 are sending your number in HTTP headers

Soldato
Joined
2 Aug 2004
Posts
7,905
Location
Buckinghamshire
A friend of mine discovered this, what a massive lapse in security.


There's a link on the tweet to check to see if your network includes any personal information.
http://lew.io/headers.php

https://mobile.twitter.com/O2/status/161872584634408960

The absolute toerags!

Your friend also discovered that O2 compress images too, which explains my bad experiences:

Well this is extremely weird.

To identify if it was an APN issue driving the poor picture quality, I changed the APN settings to that of the iPhone (I actually have an iPhone simplicity 20 SIM with unlimited data still) and cleared the data of the Facebook application.

Previously, on the new feed of the Facebook application, contacts photos would look bigger and so would the picture thumb nails they would post although everything was very compressed and blotchy.

However, after changing the APN settings and clearing the data, the contact thumbnails were smaller and so were the thumbnails of the pictures they had posted. Not only this but the comment and like details were no longer on a baby blue background and also, there was no posts regarding XYZ friend and 20 others changed their profile photo.

It was if the Facebook application had changed versions, just from wiping APNs.

However, I've just opened it again, and it's gone back to larger pictures, larger thumb nails, the like and comment links being on a baby blue background. However, all the images are now better quality!
 
Man of Honour
Joined
13 Oct 2006
Posts
91,128
Just checked from Vodafone and its not doing anything sinister on there... unfortunatly out of data on my O2 phone (I think).

EDIT: Tried on O2 and while its sending more information about my phone it doesn't seem to be sending the mobile number.
 
Last edited:
Caporegime
Joined
26 Aug 2003
Posts
37,506
Location
Leafy Cheshire
EDIT: Tried on O2 and while its sending more information about my phone it doesn't seem to be sending the mobile number.

You weren't on a WiFi network were you?

I've tried from a 3 handset, and got no nasties. I then tried from an o2 handset and the x-up-calling-line-id: is there and populated with my phone number.
 
Soldato
Joined
26 Mar 2010
Posts
4,635
Location
M4 Corridor
Its a Nokia Gateway header option, it will just get removed from the header as soon as someone technical sees it assuming they don't use it for anything else.
 
Back
Top Bottom