[HN Gopher] O2 VoLTE: locating any customer with a phone call
___________________________________________________________________
O2 VoLTE: locating any customer with a phone call
Author : kragniz
Score : 141 points
Date : 2025-05-17 13:08 UTC (9 hours ago)
(HTM) web link (mastdatabase.co.uk)
(TXT) w3m dump (mastdatabase.co.uk)
| lol768 wrote:
| > Attempts were made to reach out to O2 via email (to both Lutz
| Schuler, CEO and securityincidents@virginmedia.co.uk) on the 26
| and 27 March 2025 reporting this behaviour and privacy risk, but
| I have yet to get any response or see any change in the
| behaviour.
|
| This is really poor. And why is a Virgin Media address the
| closest best thing here? https://www.o2.co.uk/.well-
| known/security.txt should 200, not 404.
|
| To be clear, I have no problem with disclosure in these
| circumstances given the inaction, but I'm left wondering if this
| is the sort of thing that NCSC would pick up under some
| circumstances (and may have better luck communicating with the
| org)?
| edent wrote:
| O2 _used_ to have a responsible disclosure address - but they
| removed it a few years back.
|
| When I worked there (many years ago) the security team was
| excellent. When I emaileld them about an issue last year, they
| were all gone.
| edude03 wrote:
| I don't know anything about IMS but I assume they have to stay on
| the call long enough for the debug headers to be sent (like the
| tracing the call thing in every spy movie but real) and if that's
| the case can this be mitigated by "just"* not answering calls
| from unknown numbers?
|
| *yes I'm aware that means people you know who have your number
| could also exploit this
| dilyevsky wrote:
| IMS is just SIP core + bunch of gateways + integration with
| base LTE infra (eNodeB, PCRF, etc) so "signaling messages" are
| just SIP messages. So depending on whether those compromising
| headers were included on things like SIP 180 Ringing messages
| and such it may not be enough to not answer the calls. Source:
| actually worked on deploying IMS at a telco (not this one)
| andix wrote:
| I guess this information is already known to the network before
| the connection is even established. Those seem to be debugging
| headers, you probably need them for cases where the connection
| can't be established properly to debug why. If I understand the
| article correctly, the information is even there if the
| receiving phone is turned off, then you get the last known
| cell.
| celsoazevedo wrote:
| Seems to be a serious problem. It's not that hard to root a
| phone, install NSG, and look at this info. O2 is also the largest
| mobile network in the UK and they have contracts with the
| government...
|
| It's disappointing that they didn't reply, but I'm not surprised.
| O2 seems to be a mess internally. Anything that can't be fixed by
| someone at a store takes ages to fix (eg: a bad number port).
| Their systems seem to be outdated, part of their user base still
| can't use VoLTE, their new 5G SA doesn't support voice and seems
| to over rely on n28 making it slow for many, their CTO blogs
| about leaving "vanity metrics behind"[0] even though they are
| usually the worst network for data, etc.
|
| [0] https://news.virginmediao2.co.uk/leaving-the-vanity-
| metrics-...
| andix wrote:
| The really interesting part of this issue is, that under most
| jurisdictions it probably won't even qualify as hacking. The data
| is sent out by the network voluntarily and during normal use.
|
| There are no systems at any point tricked into revealing personal
| data, which is often illegal, even if the hack is trivial. Even
| appending something like "&reveal_privat_data=true" to an URL
| might be considered illegal, because there is clear intent to
| access data you shouldn't be allowed to access. In this case none
| of that is done.
| 18172828286177 wrote:
| > The really interesting part of this issue is, that under most
| jurisdictions it probably won't even qualify as hacking
|
| You clearly aren't familiar with how broad the Computer Misuse
| Act is
| andix wrote:
| > You clearly aren't familiar with how broad the Computer
| Misuse Act is
|
| No, I'm not familiar with it at all. But usually illegal
| hacking requires to access devices in a way you aren't
| allowed to access. As long as making the phone call itself is
| not an issue, it should be fine. Dumping data from the memory
| of your phone can't be unauthorized.
|
| It would probably become an issue if you make unusual phone
| calls, harassing people with constantly calling, or calling
| just for the purpose of getting the location data and
| immediately hanging up. But just dumping the diagnostics for
| regular phone calls should be fine (I'm not a lawyer).
| usr1106 wrote:
| According to GDPR this is clearly illegal. I am pretty sure their
| subscriber contracts don't contain consent for sharing your
| location to any caller.
|
| Now UK has left the EU so GDPR does no longer apply. But it is my
| understanding they have not changed any fundamental principles in
| whatever applies now?
| palm-tree wrote:
| I'm no expert, but I'm fairly sure that UK GDPR applies, which
| is effectively the same as the EU version
| https://ico.org.uk/for-organisations/data-protection-and-the...
| cloudref wrote:
| Could you mitigate this by turning off VoLTE? I can see docs
| online for turning it off on an iPhone 11 - but my iPhone 15
| doesn't have that option!
| mdasen wrote:
| > Disabling 4G Calling does not prevent these headers from
| being revealed, and if your device is ever unreachable these
| internal headers will still reveal the last cell you were
| connected to and how long ago this was.
|
| So it seems like that won't do anything.
| kjellsbells wrote:
| Also very curious how the call initiator was able to see the call
| control messages (ie SIP). Arent all these messages wrapped
| inside an encrypted GRE tunnel between handset and cell tower
| (and MME)? Being able to unpick GRE tunnel encryption would be a
| gigantic hole. Perhaps this only works because the OP is running
| analysis on their device, but even then I'm surprised that the
| pre-encryption payload is available.
| tguvot wrote:
| i think you meant GTP tunnel. And GTP tunnel is between enodeb
| and core network. it's secured only in case that it run inside
| IPSEC.
| anonymousiam wrote:
| You can't be serious. Privacy in the UK? It's been gone for
| years. Don't complain about it though, because you might say
| something that will get you prosecuted. Free speech is gone too.
| I pity UK residents, and I hope that Nigel Farage will improve
| things when he becomes PM, that is if he doesn't get assassinated
| first.
| ivanvanderbyl wrote:
| I'm curious to see if this exists on O2 in NZ. I switched to them
| last week because they do free roaming in Australia, and VoLTE
| calls.
___________________________________________________________________
(page generated 2025-05-17 23:00 UTC)