Skip to main content

O2 sending phone number to websites via headers

Users on the O2 network who make use of the data network to visit websites will be interested to learn that their phone number is sent as part of the HTTP header. This has been discovered by @lewispeckover. He has set up a website which when visited shows all of the header information that is sent by your device/network to the website. Apparently O2 users will see a line in the header showing their phone number.

This is pretty bad from a privacy perspective - users on the O2 network who visit websites will be easily identifiable from their phone number. Not every website will log this information but it is possible to do so. I'm on T-Mobile and am not seeing this thankfully.