O2 statement on the mobile number issue
blog.o2.co.uk
blog.o2.co.uk
The problem here is not that it was only the mobile number, rather that these sites are able to link your mobile number to the content that you have viewed. There's a scenario here in which sites that had collected this information could publish (or otherwise leak, i.e. through hacking) lists of mobile numbers to URLs visited.
In an age of lax privacy protections and data-sharing it's not hard to obtain people's mobile numbers. What would happen when a potential employer googles your mobile phone number and finds the crawled data?
Steps we now need to take:
1) Some kind of request to get the full list (Subject Access Request under DPA, as pointed out below?)
2) If there is no opt-out process, lodge a Data Protection complaint to the ICO
Although (as far as I know) the FOI Act only applied to public bodies (government and organisations like universities). So O2 wouldn't need to comply with a request under that act. Not sure if the ICO could force them to disclose that info, but I doubt it.
http://en.wikipedia.org/wiki/Freedom_of_Information_Act_2000...
2.) People probably opted in to this without realising. Do they need to supply an opt out, if it was a condition of signing up in the first place?
Secondly, however, this statement smells faintly of fluffy language and PR speak:
> When you browse from an O2 mobile, we add the user's mobile number to this technical information, but only with certain trusted partners. This is standard industry practice.
Is it really industry practice? Can anybody in this field confirm this? I can see why it would be useful for billing as they mention, but is this really an effective way to do age verification?
> in addition to the usual trusted partners, there has been the potential for disclosure of customers’ mobile phone numbers to further website owners.
Woah, there's nothing "potential" about it - this was right there in the HTTP headers. Saying "there has been the potential..." implies the website owner would have had to do some hacking to get hold of this information, which is not the case, right?
If I send a secret to you in the post, and you put the envelope in the recycling unopened, have I disclosed a secret to you?
They might have put the envelope in the recycling, but they never have it emptied and someone just told them it contains a £20 note.
People seemed to be reacting as if every website an O2 customer visited was going to add their phone number to their files, and that's not the case.
Yes. Intent and the fact you did it is what matters here.
Oh god yes. Everyone who reads your comment is hoping you don't work with financial, personal, confidential or (eek) classified information.
I'm in the field, and this is indeed standard industry practice. It is useful for many purposes, billing and age verification being just two, but the main root reason being that wireless carriers typically use the mobile number as the root identity for a subscriber profile that is shared across multiple backend systems.
It's an effective way to do age verification provided the carrier has implemented some type of process during sign-up or via some other (in)direct method, mainly by leveraging the identity of the subscriber and running a check against it.
Granted, there are still several ad-testing companies that store a variety of mobile cookies for tracking impressions, but this is much different from permanent, header-based tracking that used to occur with Verizon and possibly others.
I'm with 3 (one of O2's rivals) and if I access my account information from my handset connected to their network, it takes me straight to the relevant info without a pesky login. (If I try the same via wi-fi, I get a page asking me to disconnect from the hotspot and go back online via 3G.)
I always did wonder how they achieved this--sending the mobile number in the HTTP headers is likely.
Of course, it's also possible that at least one operator isn't following appropriate measures to make this secure.
Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
In my view, mobile phone companies have my phone number so they can connect my calls. Providing age verification with "trusted partners" would seem to be a step beyond that specified purpose.
The act also says:
Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
If you just want to verify age, or verify the customer uses O2, then providing their entire phone number seems excessive to me. Even if they want to bill the user, a UUID could be used that's unconnected to the user's phone number.
Even if O2 were just sharing the data with "trusted partners", it doesn't look like they were acting legally.
Agreed 100% on the UUID - authorisation does not have to mean identification.
Instead, I'd rather argue about whether this piece of personal data is 'relevant'. It obviously isn't. As you say, they could easily replace it with a UUID or, to use something permanent already at their disposal, your O2 customer-id (which might arguably also be personal information, but at least not something anyone with wireshark can immediately use to get you on the bloody phone).
It's an example of sheer laziness to send the telephone number itself instead of doing a lookup and sending something less sensitive. I've dealt with a similar situation with zipcode verification and you can bet I refused to send the zipcode straight up or hashed (the number of zipcodes is rather limited).
Sending your name in clear text is not a digital signature.
(There are so many good ways to authenticate users of a network that it makes me sad to see "tack on a phone number" was even considered, much less implemented, pushed to production, and accidentally turned on for the Entire Internet. Doh.)
The SMS spoofing issue (which has been around forever) is far worse as it's not proxied anywhere. Some SMS-controlled devices use the SMS from number as an authentication scheme which is much much more dangerous as that can be spoofed easily.
It's all about trust and it appears that trusting proprietary networks is an issue.
Headers that can be used to identify the end user:
Header name What it means
x-drutt-portal-user-msisdn The mobile phone number.
x-h3g-msisdn the phone number.
x-imsi: The imsi number. Identifies the end user.
x-msisdn The end users phone number
x-wsb-identity End users phone number
x-wte-msisdn: Indicates that the value is a phone number. Does not look like that...
x-nokia-imsi: Imsi value
x-nokia-alias The end users phone number. encrypted.
x-nokia-msisdn: The users phone number in plain text.
x-up-calling-line-id: End user identifier
Gleaned from:
http://mobiforge.mobi/developing/blog/useful-x-headers?dm_sw...Edit: fixed the formatting.
From this I'm assuming that the company they used for this (Bango I believe) would have been sent my mobile number in the past if I ever tried to access content they thought should have been verified. There has not previously been any messaging from o2 around this. Disquieting indeed. I would not have agreed to that transfer of information (nothing to hide, but it's MY information).
I wonder if this means that Age verification can be spoofed by changing that header or if it's just one of several methods they use.
O2 also sell data plans for iPads, do email/webmail services, sell home ADSL connections, as well as provide cellphones. It would be bad if they left people believing their phone number was sent out on their O2 broadband when web browsing (are tethering users affected?), or perhaps it is only parts of the country which are affected, maybe some infrastructure was acquired from buyouts and phones connected to that weren't affected?
Covering their ass is a non-deceptive reason to say that - it's not all so they shouldn't say it. Maybe "many".
At most, we will send area code to partners (mostly for ad targeting) but this is never exposed in wap headers.
If we are doing age verification, we send age range to partners.. likewise never exposed in headers.
Never full phone number. If for some reason a partner needs access to this, they would have a local database corresponding to scrambled wap signatures - which ARE sent in headers.
And when I say "commonplace", I'm referring to multiple carriers around the world, including North America.
However, the level of trust that a site qualifies for may necessitate a more nuanced or out-of-band approach similar to what you've experienced, where a 3rd party partner may receive the scrambled identifier and request the mobile number mapping for billing purposes.
There are lots of ways to skin a cat. My only point here is that there are multiple carriers around the world that routinely use this method of sending the mobile number in plaintext to sites they trust, typically over communication channels that they trust (i.e. over network gear they either own or have secured). I've seen this from both sides (working at and with carriers).
But there are a heck of a lot more 3rd party partner sites that do not usually receive full mobile numbers in the clear, so from that perspective, there is a point to be said about this not being "industry practice". Semantics.
I also wonder what use "age verification" is on the Internet. There's no shortage of "adult content" up on the torrent sites.
Hmmm.... not sure I believe them on that part.
This is a factual inaccuracy in the statement from O2.
O2's position is clearly that they normally only share mobile numbers with these unspecified "trusted partners". However, this configuration glitch has led to the mobile number being shared with everyone.
I think most people reading the statement would understand that.
A: Only where absolutely required by trusted partners who work with us on age verification, premium content billing, such as for downloads, and O2's own services, have access to these mobile numbers."
But those trusted partners may share your mobile phone number with their "trusted" partners. I know Ericsson IPX does this at least in Germany.
It usually works via several http redirects and is unnoticeable even to the client application using the usual http client APIs.
You can prevent this by using a http proxy.
Does anyone else get the feeling this could be exploited to make unauthorized purchases which would be billed to <random_O2_customer>. I've want to think they have this covered, but with a config glitch leaking your phone number on the net who knows what kind of security they have in place.
Does anyone know how this billing process works?
And how many people think such a list is going to be useful at all? It won't be three companies you've heard of, it will be pages and pages of sites and background services companies and test sites and so on.
Mr or Mrs "I want to make a considered decision, I might not trust them", are you really going to make a considered decision if your number is passed to, say, "TechElbonia UK Services, O2 portal processing for connections passing through dept 17 routes, and URLs matching the following 10 line regex (..)"?
But it is used for age verification and billing...
I don't trust O2 as a bearer, so I use a VPN instead, which also comes in handy for hotel room/café wireless hotspots.
http://news.ycombinator.com/item?id=3509228
This is certainly bad, but SMS spoofing has the potential to do a lot more damage. People trust SMS too much.
There are also a lot of services which rely on "legitimate spoofing" e.g. skype allowing you to send text messages from it's service which appear to be from your actual mobile number (so they can be replied to etc).
"Hello o2, this is your trusted partner acme!
Can you please add our ips to the MSISDN whitelist? It's 0.0.0.0/0
thanks"