Vodafone India is exposing website surfer/user's phone
number to the partner website when using mobile data plan. It might be offering hidden API to those partner websites to uniquely identify users. I have noticed it around
1-year before, thought about blogging, but forgot it at that time. Now, I have got some time and
so thought of explaining the issue.
How I noticed the issue?
Sometime ago, I've bought SanDisk microSD card. In the
wrapper, they've mentioned about some offer about hungama (Still available in SanDisk website at www.sandisk.in/campaign/landing/hungama/offer_three). The URL mentioned
was offers.hungama.com/sandisk3/ and when I opened that in my mobile browser, it
was prompting with Welcome, 91-98XXXXXXXX.
I was shocked as I never seen anything like that
before. So, I immediately opened the same URL in my desktop browser and got
completely different page:
Desktop version of the same page |
And, again I tried to open the same page in mobile browser
with Wi-Fi alone (by disabling Mobile Data), and now also they couldn't identify
my mobile number. So, I realized that it might be something to do with the
network (Vodafone). Initially I thought that they may be decoding the phone
number from IP address. So, I asked Heleena (my wife) to figure out some
pattern for that. Then it turn out that there is no definite pattern. I have
also analyzed HTTP headers when browsing through Vodafone internet. Then,
realized that hungama might be utilizing some hidden API from Vodafone to
decode user's IP to mobile number.
Privacy Issue
At least for me, this looks like a serious privacy issue.
hungama at least openly exposes the phone number to users, so that users can know that hungama can read their numbers/identity. But, there may be many sites--especially
many social media sites such as Facebook, Twitter, Google, etc may still be uniquely
identifying users without revealing it at all.
Comments
Welcome back :)
Hope you agree, nothing is private in online...