O2 Privacy Flaw Sends Users' Mobile Numbers to Visited Websites

o2 logoAs noted by think broadband, a privacy flaw in the way UK carrier O2 handles web traffic on mobile devices has resulted in users' mobile numbers being sent to any website visited from the device as part of the headers in the HTTP requests. While O2 is apparently still investigating the situation, it appears to have the potential for significant privacy-related issues.

If you're reading this news article using your O2 mobile phone, you'll be pleased to know that O2 have already sent us your mobile phone number within the HTTP headers which normally contain information about how content can be displayed on your device. These headers are not normally seen by users, and usually not logged by most websites, but the flaw allows malicious sites to get more personal information about you than you may be willing to share.

For example, if you open an e-mail which includes references to external images, the mere action of opening the e-mail would divulge your phone number. This could be used by anyone undertaking a phishing attack or other scam to get more information from you. The opportunity to abuse this is potentially endless.

The issue was discovered by Twitter user @lewispeckover, who then set up a website to allow users to see what headers are being sent as part of their HTTP requests to websites.

He now notes that the headers coming from his device appear to have stopped showing his mobile phone number, although O2 has yet to issue an official statement on the matter. The company's Twitter account is continuing to blast out responses to concerned users, noting only that the company is looking into the situation and will issue an update when it knows more.

The issue is not exclusive to the iPhone and has the potential to affect all mobile data on the second-largest carrier in the UK, although some users have reported that they are not seeing their mobile numbers appearing in their HTTP request headers. The issue has the potential to for a significant impact on UK iPhone users, as O2 has proven to be a popular choice for iPhone users dating back to its status as the exclusive iPhone carrier in the UK when the device originally launched back in 2007.

Those familiar with the UK's privacy laws have indicated that mobile phone numbers are not considered protected information, but the disclosure of such numbers as part of standard HTTP requests does have the potential to carry implications for users.

Top Rated Comments

Elijahg Avatar
146 months ago
I've really not been impressed by O2 in recent years. I first joined them in 2006, but ever since then, their network coverage in the 20 mile radius of here (near Bath) hasn't improved one bit. The 3G coverage is absolutely awful. If you aren't in a major town or a city, you have no chance of 3G with O2, only dial-up speed GPRS. Not even EDGE in most cases.

Everything Everywhere are very good, but Three (in the south of England at least) are best by far for 3G coverage.

Perhaps if O2 spent more money on, well, being a service provider and improving their network, rather than all that "priority moments" crap, they might increase their 3G coverage.
Score: 6 Votes (Like | Disagree)
Elijahg Avatar
146 months ago
Not so in my o2 account with an iPhone using iOS 5.0.1 via Safari.

It wasn't inserted into the user agent, it was a separate header: "x-up-calling-line-id".
Score: 4 Votes (Like | Disagree)
japanime Avatar
146 months ago
The "O" is for "Oops!"
Score: 4 Votes (Like | Disagree)
0098386 Avatar
146 months ago
I'm appalled they let this in.

I'm thrilled they fixed it so quickly.

I'm going to treat o2 with a bit more suspicion from here on out.
Score: 2 Votes (Like | Disagree)
The Phazer Avatar
146 months ago
I am now intrigued though as to who the "trusted partners" are. O2 themselves and BT Openzone are the only ones I can think of.

One is Bango, the company that runs O2's adult verification software and thought sending credit card numbers in plaintext over http was a good idea.

O2 might "trust" them. I don't.

Phazer
Score: 2 Votes (Like | Disagree)
4D4M Avatar
146 months ago
I'm perfectly happy with O2, I've found the coverage decent and I don't get loads of junk text messages from them like I did from Vodafone*. This latest gaffe is a bit annoying, but whatever, as a business owner my details are well and truly 'out there' for all the lowlife to exploit anyway. Bring it on scumbags.

*The junk texts don't stop when you leave Vodafone. The other day I received a text that said "Come back to Vodafone and we'll give you a free Windows 7 laptop". If there's one thing that would be guaranteed to STOP me going back to them, it's the threat of a crappy low end piece of junk with a crappy low end OS turning up at my house.
Score: 2 Votes (Like | Disagree)

Popular Stories

iPhone 15 Pro Mock Feature Buttonless

iPhone 15 Pro Max to 'Break Record' for Thinnest Bezels on a Smartphone

Friday March 17, 2023 2:59 am PDT by
The iPhone 15 Pro Max will have the thinnest bezels of any smartphone, beating the record currently held by the Xiaomi 13. That's according to the leaker known as "Ice Universe," who has divulged accurate information about Apple's plans in the past. Both iPhone 15 Pro models are expected to have thinner, curved bezels compared to the iPhone 14 Pro, potentially resulting in an Apple...
iPhone 12 Pro vs iPhone 15 Pro Feature

iPhone 12 Pro vs. 15 Pro: New Features to Expect if You've Waited to Upgrade

Friday March 17, 2023 10:29 am PDT by
While year-over-year iPhone upgrades are not always groundbreaking, new features can begin to stack up over multiple generations. For example, the iPhone 15 Pro will be a notable upgrade for those who still have a three-year-old iPhone 12 Pro. If you are still using an iPhone 12 Pro and are considering upgrading to the iPhone 15 Pro when it launches later this year, we have put together a...
iphone 14 pro max deep purple feature purple

iPhone 15 Pro Launching This Year With These 11 New Features

Monday March 13, 2023 6:47 am PDT by
While the iPhone 15 lineup is around six months away, there have already been plenty of rumors about the devices. Many new features and changes are expected for the iPhone 15 Pro models in particular, including a titanium frame and more. Below, we have recapped 11 features rumored for iPhone 15 Pro models that are not expected to be available on the standard iPhone 15 and iPhone 15 Plus:A17...
top stories 18mar2023

Top Stories: iPhone 15 Pro Pricing, New iOS 16.4 Beta, Siri vs. ChatGPT, and More

Saturday March 18, 2023 6:00 am PDT by
Apple's high-end iPhone models have started at $999 in the U.S. since they first launched back in 2017 with the iPhone X, but could this finally be the year that starting price sees an increase? This week also saw some more rumors about Apple's upcoming headset and the company's explorations in the booming AI industry as well as the release of a new round of beta updates, so read on for all...
iphone 14 pro max deep purple feature purple

iPhone 15 Pro Predicted to See First Price Increase Since iPhone X

Wednesday March 15, 2023 7:49 am PDT by
Apple's next-generation iPhone 15 Pro and iPhone 15 Pro Max will likely be more expensive than previous Pro models, according to Jeff Pu, a tech analyst at Hong Kong-based investment firm Haitong International Securities. In a research note this week, Pu predicted the iPhone 15 Pro models will see a price increase due to several rumored hardware upgrades, including a titanium frame,...
original iphone auction

Factory-Sealed Original iPhone Sells for $55,000 at Auction

Friday March 17, 2023 1:08 pm PDT by
A first-generation iPhone still sealed inside its box sold for $54,904 at auction, which is more than $54,000 over the original $599 price tag of the device when it was released in 2007. The original iPhone was put up for sale by RR Auction on behalf of a former Apple employee who purchased it back when it first came out. Back in February, an original, sealed iPhone sold for over $63,000,...