Experience trumps content in apps monetization http://t.co/iaCY5ebX
4 minutes ago by monetize_me on twitterZDNet is available in the following editions:
Self-professed hacker warns about one operator in every country leaks mobile phone numbers unnecessarily during Web sessions.
A mobile device security researcher who recently announced a privacy loophole in the way data is transmitted during mobile Web surfing sessions, has indicated that the problem is widespread.
At the CanSecWest security conference last month, Collin Mulliner, a PhD student at Technical University Berlin, Germany, said confidential data can be leaked due to the addition of HTTP headers at the operator's HTTP proxy or gateway. Proxies are used to reformat Web pages to suit a smaller screen size.
Data that is commonly revealed include an MSISDN (mobile subscriber integrated services digital network number) or phone number, IMSI (international mobile subscriber identity) or unique SIM card number, IMEI (international mobile equipment identity) or unique phone ID, access point name and customer account number or ID.
Several of the operators cited in his presentation include Orange from the United Kingdom, Bharat Sanchar Nigam of India and Rogers Wireless in Canada.
Mulliner told ZDNet Asia in a follow-up e-mail that the data leakage issue is not limited to those listed in his presentation but affects "more or less" one operator in every country. He did not disclose if any other operator in Asia is on his expanding list.
According to Mulliner, mobile operators normally add the information in order to support third-party service providers, which may use MSISDN to identify and bill customers for services.
"The problem is that some mobile operators don't care if the private information of their customers gets leaked to the whole Internet and therefore they don't configure the Web proxies in the correct way," said Mulliner. "Privacy-aware operators make sure the information is added only when customers connect to these special service providers and not the whole Internet."
The problem, he added, also affects nearly all phones. Common phone brands that emerged during Mulliner's logging of HTTP headers for over a year included LG, Nokia, Samsung and Sony Ericsson. HTC phones running Windows Mobile were also found to be associated with the problem.
Smartphones such as Apple's iPhone or Android-based phones typically don't use proxies by default. But if a proxy was configured and the operator inserts customer data, the same issue would occur, he pointed out.
Onus on operators
Industry observers ZDNet Asia interviewed said operators have a responsibility to protect customer information and privacy.
According to F-Secure's senior security response manager Chia Wing Fei, mobile numbers have the "best returns on investment" for cybercriminals as they are targets for SMS spam.
On the other hand, there are other methods of harvesting mobile phone numbers for SMS spamming, he noted in an e-mail. One way is to offer free wallpapers and ringtones via Web sites, where users can download on the condition that they give out their number.
"Nevertheless, such information should not be leaked by the operator in the first place and I can't seem to think of any good reason why it should be included in the Web requests," he said. "The rule of thumb for securing your network or data would be to first deny all and then allow only what is necessary after doing a proper and thorough evaluation."
John Strand, CEO of Danish analyst firm Strand Consult, added that the problem highlighted by Mulliner is one which "can be easily solved by the operator" as it specifies what information flows through its gateway.
Citing the example of Telenor in Norway, he said a customer who chooses to use the operator's billing system for a premium service providing ringtones or games is assigned a special ID instead. In some cases, the operator would send the MSISDN to the content provider.
However, Strand said the company does not rule out that "there are a lot of operators [that] do not do much" to prevent the MSISDN from being accessible.
Over in Singapore, a SingTel spokesperson told ZDNet Asia that the telco is "aware" of the matter. "SingTel does not share any customer information when they access or browse generic Internet content via a mobile phone. We have put in place stringent measures to safeguard our customers' information," she added.
Fellow mobile operator M1 provided a similar response. "We treat customers' particulars as private and confidential and do not disclose them to external parties," the spokesperson said. "When our customers surf the Web on their mobile devices, their MSISDN, IMEI or IMSI are not revealed."
StarHub did not respond for the story.
![]() "Upon visiting Mulliner's site, an Android-based HTC Hero obtains a red page which signals the customer may have a privacy infringement problem." |
Mulliner, who created a page to let users check if their mobile numbers have been revealed, said there were 12,000 visits to the site in March, and about 1,500 this month. At the time of writing, however, the page was not accessible.
When ZDNet Asia ran Mulliner's Web site for users to check the information captured by HTTP headers on two StarHub-powered smartphones, the results were mixed.
When the site was accessed via an Android-based HTC Hero, this displayed a red page signaling a problem. Entering the same site using Apple's iPhone via both the Safari and Opera Mini browsers showed green. The reason for this may be due to the practice by operators of using different proxies for different customers, a premise outlined in Mulliner's presentation.
Experience trumps content in apps monetization http://t.co/iaCY5ebX
4 minutes ago by monetize_me on twitterMalaysia offers some manufacturing benefits over China http://t.co/bMquIFiX
4 minutes ago by AsianFashionLaw on twitterRT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi
4 minutes ago by GarnieBolling on twitterThats it.Im digging up an old bus plan i wrote around acquisition of #bigdata talent. http://t.co/gpkha5A1 Any investors want2 read/discuss?
19 minutes ago by BigDataInsights on twitterIntegration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 mins ag... http://t.co/aaa0Cb73
34 minutes ago by jamstrit on twitterHomegrown smartphone OSes gaining favor in China http://t.co/lOBVp1T6
34 minutes ago by smartfone on twitterHomegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/gHypbdIY
34 minutes ago by androidnewshome on twitterIntegration, focused investments to propel Windows Phone - ZDNet Asia http://t.co/7sZi6Dhb
49 minutes ago by sonuise on twitterRT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW
1 hour ago by AsiaBites on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi
1 hour ago by MDMGeek on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia: Big data acquisition... http://t.co/r6taCmG1 #ITNews #BigData
1 hour ago by BigDataNetwork on twitterBig data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/d9k21ro5: David G... http://t.co/4JgaOz8g #bigdata #sna
1 hour ago by BigDataSocial on twitterBig data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/fbori8UQ: Incr... http://t.co/nuEeUbj7 #ITNews #BigData
1 hour ago by BigDataNetwork on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/iFQ74xYI #Bigdata #analytics
1 hour ago by ciropuglisi on twitter@ChemarieMonica : Integration, focused investments to propel Windows Phone - ZDNet As... http://t.co/ZVPDpbxH http://t.co/1QrdIsaV #tech
1 hour ago by mcjimmm on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
5 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateThreats and malware know no boundaries. Neither should your web security. See how far Blue Coat Unified Web Security goes to protect your network.
Echelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.