[HN Gopher] O2 VoLTE: locating any customer with a phone call
       ___________________________________________________________________
        
       O2 VoLTE: locating any customer with a phone call
        
       Author : kragniz
       Score  : 141 points
       Date   : 2025-05-17 13:08 UTC (9 hours ago)
        
 (HTM) web link (mastdatabase.co.uk)
 (TXT) w3m dump (mastdatabase.co.uk)
        
       | lol768 wrote:
       | > Attempts were made to reach out to O2 via email (to both Lutz
       | Schuler, CEO and securityincidents@virginmedia.co.uk) on the 26
       | and 27 March 2025 reporting this behaviour and privacy risk, but
       | I have yet to get any response or see any change in the
       | behaviour.
       | 
       | This is really poor. And why is a Virgin Media address the
       | closest best thing here? https://www.o2.co.uk/.well-
       | known/security.txt should 200, not 404.
       | 
       | To be clear, I have no problem with disclosure in these
       | circumstances given the inaction, but I'm left wondering if this
       | is the sort of thing that NCSC would pick up under some
       | circumstances (and may have better luck communicating with the
       | org)?
        
       | edent wrote:
       | O2 _used_ to have a responsible disclosure address - but they
       | removed it a few years back.
       | 
       | When I worked there (many years ago) the security team was
       | excellent. When I emaileld them about an issue last year, they
       | were all gone.
        
       | edude03 wrote:
       | I don't know anything about IMS but I assume they have to stay on
       | the call long enough for the debug headers to be sent (like the
       | tracing the call thing in every spy movie but real) and if that's
       | the case can this be mitigated by "just"* not answering calls
       | from unknown numbers?
       | 
       | *yes I'm aware that means people you know who have your number
       | could also exploit this
        
         | dilyevsky wrote:
         | IMS is just SIP core + bunch of gateways + integration with
         | base LTE infra (eNodeB, PCRF, etc) so "signaling messages" are
         | just SIP messages. So depending on whether those compromising
         | headers were included on things like SIP 180 Ringing messages
         | and such it may not be enough to not answer the calls. Source:
         | actually worked on deploying IMS at a telco (not this one)
        
         | andix wrote:
         | I guess this information is already known to the network before
         | the connection is even established. Those seem to be debugging
         | headers, you probably need them for cases where the connection
         | can't be established properly to debug why. If I understand the
         | article correctly, the information is even there if the
         | receiving phone is turned off, then you get the last known
         | cell.
        
       | celsoazevedo wrote:
       | Seems to be a serious problem. It's not that hard to root a
       | phone, install NSG, and look at this info. O2 is also the largest
       | mobile network in the UK and they have contracts with the
       | government...
       | 
       | It's disappointing that they didn't reply, but I'm not surprised.
       | O2 seems to be a mess internally. Anything that can't be fixed by
       | someone at a store takes ages to fix (eg: a bad number port).
       | Their systems seem to be outdated, part of their user base still
       | can't use VoLTE, their new 5G SA doesn't support voice and seems
       | to over rely on n28 making it slow for many, their CTO blogs
       | about leaving "vanity metrics behind"[0] even though they are
       | usually the worst network for data, etc.
       | 
       | [0] https://news.virginmediao2.co.uk/leaving-the-vanity-
       | metrics-...
        
       | andix wrote:
       | The really interesting part of this issue is, that under most
       | jurisdictions it probably won't even qualify as hacking. The data
       | is sent out by the network voluntarily and during normal use.
       | 
       | There are no systems at any point tricked into revealing personal
       | data, which is often illegal, even if the hack is trivial. Even
       | appending something like "&reveal_privat_data=true" to an URL
       | might be considered illegal, because there is clear intent to
       | access data you shouldn't be allowed to access. In this case none
       | of that is done.
        
         | 18172828286177 wrote:
         | > The really interesting part of this issue is, that under most
         | jurisdictions it probably won't even qualify as hacking
         | 
         | You clearly aren't familiar with how broad the Computer Misuse
         | Act is
        
           | andix wrote:
           | > You clearly aren't familiar with how broad the Computer
           | Misuse Act is
           | 
           | No, I'm not familiar with it at all. But usually illegal
           | hacking requires to access devices in a way you aren't
           | allowed to access. As long as making the phone call itself is
           | not an issue, it should be fine. Dumping data from the memory
           | of your phone can't be unauthorized.
           | 
           | It would probably become an issue if you make unusual phone
           | calls, harassing people with constantly calling, or calling
           | just for the purpose of getting the location data and
           | immediately hanging up. But just dumping the diagnostics for
           | regular phone calls should be fine (I'm not a lawyer).
        
       | usr1106 wrote:
       | According to GDPR this is clearly illegal. I am pretty sure their
       | subscriber contracts don't contain consent for sharing your
       | location to any caller.
       | 
       | Now UK has left the EU so GDPR does no longer apply. But it is my
       | understanding they have not changed any fundamental principles in
       | whatever applies now?
        
         | palm-tree wrote:
         | I'm no expert, but I'm fairly sure that UK GDPR applies, which
         | is effectively the same as the EU version
         | https://ico.org.uk/for-organisations/data-protection-and-the...
        
       | cloudref wrote:
       | Could you mitigate this by turning off VoLTE? I can see docs
       | online for turning it off on an iPhone 11 - but my iPhone 15
       | doesn't have that option!
        
         | mdasen wrote:
         | > Disabling 4G Calling does not prevent these headers from
         | being revealed, and if your device is ever unreachable these
         | internal headers will still reveal the last cell you were
         | connected to and how long ago this was.
         | 
         | So it seems like that won't do anything.
        
       | kjellsbells wrote:
       | Also very curious how the call initiator was able to see the call
       | control messages (ie SIP). Arent all these messages wrapped
       | inside an encrypted GRE tunnel between handset and cell tower
       | (and MME)? Being able to unpick GRE tunnel encryption would be a
       | gigantic hole. Perhaps this only works because the OP is running
       | analysis on their device, but even then I'm surprised that the
       | pre-encryption payload is available.
        
         | tguvot wrote:
         | i think you meant GTP tunnel. And GTP tunnel is between enodeb
         | and core network. it's secured only in case that it run inside
         | IPSEC.
        
       | anonymousiam wrote:
       | You can't be serious. Privacy in the UK? It's been gone for
       | years. Don't complain about it though, because you might say
       | something that will get you prosecuted. Free speech is gone too.
       | I pity UK residents, and I hope that Nigel Farage will improve
       | things when he becomes PM, that is if he doesn't get assassinated
       | first.
        
       | ivanvanderbyl wrote:
       | I'm curious to see if this exists on O2 in NZ. I switched to them
       | last week because they do free roaming in Australia, and VoLTE
       | calls.
        
       ___________________________________________________________________
       (page generated 2025-05-17 23:00 UTC)