PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Researcher: Mobile number leaks common but inappropriate

Posted on April 19, 2010 by pogowasright.org

Vivian Yeo reports:

At the CanSecWest security conference last month, Collin Mulliner, a PhD student at Technical University Berlin, Germany, said confidential data can be leaked due to the addition of HTTP headers at the operator’s HTTP proxy or gateway. Proxies are used to reformat Web pages to suit a smaller screen size.

Data that is commonly revealed include an MSISDN (mobile subscriber integrated services digital network number) or phone number, IMSI (international mobile subscriber identity) or unique SIM card number, IMEI (international mobile equipment identity) or unique phone ID, access point name and customer account number or ID.

[…]

“The problem is that some mobile operators don’t care if the private information of their customers gets leaked to the whole Internet and therefore they don’t configure the Web proxies in the correct way,” said Mulliner. “Privacy-aware operators make sure the information is added only when customers connect to these special service providers and not the whole Internet.”

The problem, he added, also affects nearly all phones. Common phone brands that emerged during Mulliner’s logging of HTTP headers for over a year included LG, Nokia, Samsung and Sony Ericsson. HTC phones running Windows Mobile were also found to be associated with the problem.

Smartphones such as Apple’s iPhone or Android-based phones typically don’t use proxies by default. But if a proxy was configured and the operator inserts customer data, the same issue would occur, he pointed out.

Read more on ZDNet Asia.

Category: BreachesMisc

Post navigation

← Privacy and Cloud Computing Challenges
Applying the Fourth Amendment to the Internet: A General Approach →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism
  • Kenyan court orders Worldcoin to delete all biometric data
  • Virginia Governor Signs into Law Bill Restricting Minors’ Use of Social Media

RSS Recent Posts on DataBreaches.net

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy