<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>RISKS &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/risks/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Sun, 22 Sep 2024 07:27:43 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>RISKS &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[Vodafone Exposes Users' Email Addresses]]></title>
		<link>https://shkspr.mobi/blog/2010/09/vodafone-exposes-users-email-addresses/</link>
					<comments>https://shkspr.mobi/blog/2010/09/vodafone-exposes-users-email-addresses/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 22 Sep 2010 14:23:03 +0000</pubDate>
				<category><![CDATA[mobile]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[RISKS]]></category>
		<category><![CDATA[vodafone]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=2554</guid>

					<description><![CDATA[(Disclaimer - I used to work for Vodafone.  I don&#039;t any more.)  A rather nasty flaw with Vodafone&#039;s &#34;My Account&#34; service was recently pointed out by Denny de la Haye.  Vodafone will quite happily tell you the email address of any customer who has set up the &#34;My Account&#34; facility.  Denny@dennyUgh.  @VodafoneUK&#039;s website exposes my email address to anyone who knows (or randomly enters) my phone…]]></description>
										<content:encoded><![CDATA[<p>(Disclaimer - I <em>used</em> to work for Vodafone.  I don't any more.)</p>

<p>A rather nasty flaw with Vodafone's "My Account" service was recently pointed out by <a href="http://shinyideas.co.uk/">Denny de la Haye</a>.  Vodafone will quite happily tell you the email address of <strong>any</strong> customer who has set up the "My Account" facility.</p>

<blockquote class="social-embed" id="social-embed-25210040342" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/denny" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRlgCAABXRUJQVlA4IEwCAADwCwCdASowADAAPrFMnUmnJKKhMdmaAOAWCWcAyveoKwiyX8B9i8o5gfpO2ejzzgsle8vSZjMXUOAUa5qszhx5Nx7QeRmzq7+tEABSZubPTl5T5rvDGar7bbamv+28p1IA7OftPT82tgD+7Ucxi3Dh/pg1QEImAKgUH0uJ3E4vVArmeVPpj3/NVUNM2/ArvAGoYY2f8atEvkpK+vhA9Y/NHUSLZ4mEYT7Mba2PgFRzm1ChPJJ8Y4fDSBhLzKrU5+vPMZceJaO5oc3Xyzk94dc+9JGawAWMNmHQYuiZkbvFbPDZ1GjE8HrM3MJAwqbs4qvHcdZK06r1zgWynTpKRhL/+3sGUFKSxypnPAEujg2d4A5XBYyW70RZQCQfBIChWzvtxEeUW8hAgwo9IOmPDAKyCFJWc9MCEsrvgfJOlHp8PflLd/spOV2nG8JD5x9/e5YXiLOPqqrBFKbFn2rJmZI06tYlqiWZPAPsqpbTJEErjzfVLK/uzfvwinKG45q93KMGg646DgdqElTR0FOlRPrMaOYNSx8g1Lj4hLVTiHzJ9ppQWJc0Q+AhPjiRZFkEjivngqLaOBTSxw4frb+8zoAoyy6+o9JUX+YMnAzGMnLmWOpQ/U1LMdlVDq7iNrgdJmiYZQm261BXz3M4SxSzUTkOI42Tw6XP65MD3s49teNj3iD++dCst1z6Az+XeV7PZoC74iKpkB4/7ASo3blNYn96fWtCEZHlVMauznxAFxMDhzgyHXldV6BYfZYP9vRGYlqxR5VVJIU+EmLoAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Denny</p>@denny</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Ugh.  <a href="https://twitter.com/VodafoneUK">@VodafoneUK</a>'s website exposes my email address to anyone who knows (or randomly enters) my phone number on the 'forgot password' page.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/denny/status/25210040342"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2010-09-22T13:14:38.000Z" itemprop="datePublished">13:14 - Wed 22 September 2010</time></a></footer></blockquote>

<p>Vodafone offer a "My Account" facility - <a href="http://vodafone.co.uk/myaccount">http://vodafone.co.uk/myaccount</a> - you can use it to check your bills, manage your price place, etc.  All very handy.
<a href="https://shkspr.mobi/blog/wp-content/uploads/2010/09/my-acc.jpg"><img src="https://shkspr.mobi/blog/wp-content/uploads/2010/09/my-acc.png" alt="Vodafone's My Account Facility" title="Vodafone's My Account Facility" width="878" height="508" class="aligncenter size-full wp-image-2558"></a></p>

<p>As with many services, a user needs a username and password.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2010/09/forgot.png" alt="Login" title="Login" width="505" height="428" class="aligncenter size-full wp-image-2557"></p>

<p>Again, as usual, it will allow you to recover your password.
<a href="https://shkspr.mobi/blog/wp-content/uploads/2010/09/remind.png"><img src="https://shkspr.mobi/blog/wp-content/uploads/2010/09/remind.png" alt="Reminder" title="Reminder" width="763" height="343" class="aligncenter size-full wp-image-2555"></a></p>

<p>This is where the problem begins.  To recover your password, you need to enter your mobile phone number.</p>

<p>This leads to this nasty privacy-busting screen.  (I've obfuscated my email address).
<a href="https://shkspr.mobi/blog/wp-content/uploads/2010/09/exposed.png"><img src="https://shkspr.mobi/blog/wp-content/uploads/2010/09/exposed.png" alt="Exposed" title="Exposed" width="767" height="318" class="aligncenter size-full wp-image-2556"></a></p>

<p>All you need is someone's phone number.  Now, there are several ways you could get a person's email address if you already know their phone number - ringing them up and asking them, for one - but Vodafone really needs to be more cautious with their customers' data.</p>

<p>There is nothing to stop a determined spammer from entering thousands of numbers and getting a long list of email addresses.  Nothing to stop a fraudster from sending you an email to an address you only use with Vodafone.  Nothing to stop you finding out that your boss's email is IlikeBigButts@example.com.</p>

<p>I'm sure that Vodafone will be closing this hole shortly - but it goes to show that even using unique email addresses is no protection from spammers when your private data is treated so poorly.</p>

<h2 id="update"><a href="https://shkspr.mobi/blog/2010/09/vodafone-exposes-users-email-addresses/#update">Update</a></h2>

<p>A <a href="http://forums.theregister.co.uk/forum/1/2010/09/22/vodafone_email_address_giveaway/">commenter on The Register</a> notes that this trick also works with usernames.  Now, you may not know a target's name - but trying a few common usernames reveals many email addresses.  So now a potential spammer has your email address <em>and</em> your username.  More than enough to make a convincing phishing attempt.</p>

<h2 id="update-23-09-2010"><a href="https://shkspr.mobi/blog/2010/09/vodafone-exposes-users-email-addresses/#update-23-09-2010">Update 23/09/2010</a></h2>

<p>At some point this morning, around 1130, the website was finally taken down.  Users are seeing this holding page.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2010/09/better.png" alt="Holding Page" title="Holding Page" width="580" height="256" class="aligncenter size-full wp-image-2574"></p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=2554&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2010/09/vodafone-exposes-users-email-addresses/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
	</channel>
</rss>
