Hidden method of stealing your airtime?

Its kinda pathetic that the cellphone providers can't keep this BS in check. Billion rand companies...one would imagine they could manage basic airtime management & keep some semblance of control over WASPs & what they charge to airtime...
 
Well in this case it would constitute theft and or fraud. People should lay criminal charges, irrespective of the amount...
 
As usual MTN and Cell C are mum about WASP isssues.. They must be making millions from the monies stolen from their customers that they are not willing to introduce double opt-in..
 
Its kinda pathetic that the cellphone providers can't keep this BS in check. Billion rand companies...one would imagine they could manage basic airtime management & keep some semblance of control over WASPs & what they charge to airtime...

They can but they won't. If a subscriber defaults on payments, the providers are quick to provide figures & are swift with threats if payments aren't made. They make a killing with WASPS stealing airtime, especially when most suckers have no idea how the airtime vanishes in the first place & just buy more airtime.

Look at how the providers in the america are so against the kill switch option for smartphones. They know it's going to eat into their cellular insurance profits, hence the opposition.
 
I had this problem on MTN some time ago, could be a year or 2 I can't remember. At least I haven't had this problem yet on Telkom Mobile/8ta.
 
MTN, Cell C mum on unauthorised billing, MSISDN pass-through

Well, I'll vote with my wallet. Porting away from MTN and to Telkom Mobile.

FU MTN and Cell C.
 
An operators would probably not consciously promote dishonest billing but since none of their staff stand to gain from halting the abuse, it is unlikely anything will happen soon.
 
They can but they won't. If a subscriber defaults on payments, the providers are quick to provide figures & are swift with threats if payments aren't made. They make a killing with WASPS stealing airtime, especially when most suckers have no idea how the airtime vanishes in the first place & just buy more airtime.

Look at how the providers in the america are so against the kill switch option for smartphones. They know it's going to eat into their cellular insurance profits, hence the opposition.
I'm not convinced this is true. People are spending 500+ bucks on cellphone usage...and occasionally someone gets scammed for a couple of bucks. I don't see the profits coming from the WASPS.

Sure we hear about people getting scammed out of more than a couple of bucks...but those stories make the news because they are unusually large.
 
Proof that Vodacom is facilitating SCAM transactions.

Here's irrefutable proof that Vodacom is sharing your mobile number with certain websites in order to facilitate scam transactions.

The transaction themselves appear to be hidden behind what seems at first to be an innocuous advert offering some form of assistance, for example "Your cellphone has a virus, click for help", "Your cell is too slow? Improve browsing here!", etc...

Whilst visiting various forums I have noticed these types of ads. Here's an example of the process followed all the way through:

Advert
IMG_1133.jpg

Page2 after clicking on the advert
IMG_1135.png

Page 3, after clicking on "Test cell speed"
IMG_1137.jpg

The 3rd page whilst appearing fine at first, has been specifically designed to hide the terms and conditions
you are indirectly agreeing to if you click on "CONTINUE TO TEST".

If you don't scroll down you won't see this:
IMG_1138.jpg

And just to prove that your number is being shared I clicked on this final link.

Immediately (within a few seconds), I received this SMS, confirming my subscription to Bempix:
Welcome:Bempix Click 2 Start http://bzm.tv/s/60ad753572 Pass:61am1cmk [email protected] subscription service R7/Day unsub sms stop to 43035 help:0105002341

Naturally I immediately unsubscribed, and here's the follow up SMS response:
You have unsubscribed from Bempix. We're sorry to see you go. Here's a gift of 5 Credits, click to claim http://bzm.tv/ec/17/60ad753572 [email protected]

Clearly this type of behavior skirts in the area of fraudulence:
as none of the advertised services offered in the 3 pages were ultimately provided, and at no point was I asked to acknowledge that by clicking a button to "test my speed" actually meant that I wanted to subscribe to a paid "social" website (the real intentions were of course hidden from view; you have to scroll to see these).

Technically inclined users would naturally tend to avoid such promises in the first place, and/or be inclined to scroll to see any subsequent bits of info on the page; average users would most likely fall for this scam without seeing the "terms and conditions".

Just to confirm:
At no point was I asked to enter my mobile number, and at no point did I provide any of my details; they of course didn't need it as Vodacom was providing it to them, and there was no double opt-in process.

Potentially a bigger issue:
So if they can process an automatically reoccurring transaction against my mobile number, without me typing in my number, and without any second confirmation?
What stops them from capturing your number as you surf sites where their adverts are displayed. i.e. Assuming of course that Vodacom is injecting your number for their URLs; basically an advert served from their website would also have access to your number, and an unscrupulous company like the example above could process transactions without consent.

BTW here's what Vodacom said in this article about this practice:
Vodacom said that Vodacom disabled MSISDN forwarding almost 2 years ago. “The only way to subscribe via any one of the carriers (e.g. SMS, WAP, USSD) is to complete a double opt-in process,” Vodacom spokesman Richard Boorman said.

To sign up for WAP services via mobile, said Boorman, the customer has to enter their mobile number into the WAP gateway for the WASP.

“We then check that against the MSISDN of the phone being used to make sure that nobody is able to randomly sign someone else up for services. If the two numbers don’t match then the subscription process stops,” Vodacom said.

Boorman added that they are not aware of problems related to MSISDN swapping, but will be happy to investigate it if they are provided details about this.


Don't you think we need Vodacom's response on this?
 
Last edited:
Its kinda pathetic that the cellphone providers can't keep this BS in check. Billion rand companies...one would imagine they could manage basic airtime management & keep some semblance of control over WASPs & what they charge to airtime...

why, they get 50% of the profit either way, why would they "care"

[)roi(];11601125 said:
At no point was I asked to enter my mobile number

Lemme just mention it is possible to get your number without your input if using the device :whistle: I know from some of the WASPS

but yeah that is fraudulent and the companies are clearly involved "negligently"
 
Last edited:
Lemme just mention it is possible to get your number without your input if using the device :whistle: I know from some of the WASPS

but yeah that is fraudulent and the companies are clearly involved "negligently"
That's what my post demonstrates, however the mobile device's browser is specifically designed to not expose any of your personal information (European and US privacy laws have ensured this).

Clearly what is happening here is that Vodacom is injecting your details into the http packets exchanged with specific sites (URLs).

Both Vodacom and Vodafone were on a previous occasion shown to be revealing this detail to all sites that you visited. What is different now; is that they have turned off the globally setting and are now controlling which sites will receive your details.

Either way it's unethical as it's being used to facilitate scam transactions by stripping away your privacy, and even allowing these companies to track your activity across any sites running their adverts.
 
Last edited:
The truth is the WASPA code of conduct is written in such a way that allows them to bypass any sort of requirement for SMS or Actual user input as authentication. And the average user including myself will never know that they are on a double opt in page.

You can click on misleading banner which throws you to a landing page, if you click on the wrong spot on the page, you get subscribed. No need to enter a number on anything, even if there's space to enter one. These sites basically has 3 ways of registration, the enter number, respond to SMS to verify method is normally the one people would expect, that one's on the homepage. The landing page method, something similar to what [)roi(] posted is the one screwing people over.

Check the wording carefully.

By clicking the "Call to Action" button.
That's the double Opt, clicking a button.

That Call to Action button basically gives them your MSISDN number, so immediately it's verified.

There needs to be another step of security, Vodacom themselves must send you a SMS to which you must reply in order to verify that you knowingly "called to action".

Kind of like how the other authentication methods work...
 
Last edited:
I should also mention some of the apps the wasps use automatically reply sms to double opt in without you knowing or seeing.
 
There needs to be another step of security, Vodacom themselves must send you a SMS to which you must reply in order to verify that you knowingly "called to action".

Kind of like how the other authentication methods work...
I'd prefer they never share my details without my consent; basically if I never type my number then no transaction should be permitted; however considering anyone could use my number, or Vodacom system could fail and incorrectly inject my number for someone else, there should also be no transaction without something like a 1 time password, SMS'd by the operator to your phone to validate your approval of that transaction.

In any case, I don't like the fact that Vodacom is tagging my web traffic with my number, in effect contravening my privacy.
 
Last edited:
[)roi(];11601125 said:
Here's irrefutable proof that Vodacom is sharing your mobile number with certain websites in order to facilitate scam transactions.
Don't you think we need Vodacom's response on this?
Waiting in anticipation for Vodacom's response!!!!
 
Wasps were the reason why I ported 4 contracts away from MTN to CellC pay as you go with dumb phones.

If you now bother me I simply throw away the simcard and email my new number to the ten people that really need to know.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X