Vodacom did not sell subscriber info

@jannievanzyl, can you please confirm whether or not Vodacom is supplying cell nrs to Wasps e.g. Mira Networks - you'll recall the case where no SMS was ever sent yet double opt-in confirmation was automatically completed via Vodacom providing cell numbers to them. Thats the only way that Mira can get hold of the cell nr without SMS's being involved.

It's SO easy to get cellphone numbers to target, you don't need to go to have some kind of evil collaboration with an SP. if you just want any valid cellphone numbers. Many of the older ranges - 082, 072, etc are saturated so you have like 95% of choosing a valid random number; you can also buy machines that phone and listen for a pick-up and voice; these machines are on the increase - me and people I know have received a number of calls that if you pick up there's just silence and as soon as you say hello it gets put down.
 
It's SO easy to get cellphone numbers to target, you don't need to go to have some kind of evil collaboration with an SP. if you just want any valid cellphone numbers. Many of the older ranges - 082, 072, etc are saturated so you have like 95% of choosing a valid random number; you can also buy machines that phone and listen for a pick-up and voice; these machines are on the increase - me and people I know have received a number of calls that if you pick up there's just silence and as soon as you say hello it gets put down.

now YOU need to write an article in collaboration with rpm & jan man!
Scary stuff I'm reading
 
This is just all common sense, really low-tech stuff. If this stuff scares you, then you must live in constant terror! :)

I'd have thought there would be measurements against practices like what you mentioned could be accomplished.
But I also lived with the misconception that a double-opt in required a SMS to be sent from a number - which Vodacom merely ignored by providing details in HTTP headers to WASPS.

What you mentioned here, this goes beyond clicking on a link or sending a SMS. If its true, and other guys working for WASPS on mybb have denied any such possibilities in at least on thread, then we are truly sitting ducks and we should be all scared yes :)
 
I'd have thought there would be measurements against practices like what you mentioned could be accomplished.
But I also lived with the misconception that a double-opt in required a SMS to be sent from a number - which Vodacom merely ignored by providing details in HTTP headers to WASPS.

Oh, the actual circumventing of the double opt in was another issue - this would haven't helped in any way. I can't remember exactly the double opt-in issue, but it was just bad systems that weren't enforced right and that was fixed.

What you mentioned here, this goes beyond clicking on a link or sending a SMS. If its true, and other guys working for WASPS on mybb have denied any such possibilities in at least on thread, then we are truly sitting ducks and we should be all scared yes :)

WASPs can really do a lot, but have to sign tons of binding contracts and stuff. Every time you swipe your credit card or take your car in for a service you're trusting people with far more important and damaging details than you can get with an opt in or leaked cellphone number. Despite what people think, the mobile companies really do and keep their WASPs honest, but there are always bad actors in any system that will cause issues from time to time.
 
Oh, the actual circumventing of the double opt in was another issue - this would haven't helped in any way. I can't remember exactly the double opt-in issue, but it was just bad systems that weren't enforced right and that was fixed.

He's referring to this issue: http://mybroadband.co.za/news/cellular/96295-beware-wasps-tricking-you-out-of-airtime.html

Some Wasps were abusing Vodacom's header modification (MSISDN passthrough?) DOI mechanism to trick people into subscribing to a service.
 
Everyone knows that the only reason why you get marketing messages on a new SIM is because it is a recycled number. Doh, how can you not know this :P

Exactly, and sometimes you get banking notifications not just marketing sms, i have seen this happen
 
He's referring to this issue: http://mybroadband.co.za/news/cellular/96295-beware-wasps-tricking-you-out-of-airtime.html

Some Wasps were abusing Vodacom's header modification (MSISDN passthrough?) DOI mechanism to trick people into subscribing to a service.

Thats the one, check all the victims on hellopeter who have fallen prey to it
http://hellopeter.com/mira-networks/compliments-and-complaints

Did this fix have any effect on the ability to double opt in without an SMS?
 
Did this fix have any effect on the ability to double opt in without an SMS?

No, not as far as I know. The fix just made it so your number wasn't being sent randomly to any website you visit.

Trusted third parties, such as WASPs that have gone through the relevant processes (i.e. agreeing with Vodacom's double opt-in terms), still get the MSISDN in the header.

That's how I understand Vodacom's feedback, anyway.
 
Last edited:
No, not as far as I know. The fix just made it so your number wasn't being sent randomly to any website you visit.

Trusted third parties, such as WASPs that have gone through the relevant processes (i.e. agreeing with Vodacom's double opt-in terms), still get the MSISDN in the header.

That's how I understand Vodacom's feedback, anyway.

Great thanks. So Vodacom is still providing details in headers. Thanks VC.
 
He's referring to this issue: http://mybroadband.co.za/news/cellular/96295-beware-wasps-tricking-you-out-of-airtime.html

Some Wasps were abusing Vodacom's header modification (MSISDN passthrough?) DOI mechanism to trick people into subscribing to a service.

Ah okay - that was the "bad actor" scenario I was speaking of. Just reading that article, it seems like the opt-in process happened on a Vodacom-hosted server (the picture's caption supports this), which then redirects back to the page in question. Basically it sounds like the WASP was taking advantage of the way people click "Confirm" without reading prompts.

Vodacom said that only once the double opt-in process is complete do they provide the WASP with a user’s phone number.

My educated guess based on how similar services (OAuth, Payment gateways) work is that Mira would redirect an opt-in request to Vodacom's server, Vodacom would process the yes/no, and if the user said yes, they'd either redirect back to the site that originated the opt-in, or provide a callback in the background with subscriber details.
 
Last edited:
Well I know for a fact that Vodacom sell client's information to other companies.

I've had my sim card for well on 10 years. At the time I was too young and unemployed to get a contract on my own, so My father put the contract in his name. All my friends know the number as mine. Yet I still get smses and phone calls asking to speak to my father, which they'd only know if they could see very specific details.

Since the RICA thing happened, I've been getting less spam and phone calls, but I still get asked if I am my father haha!
 
Everyone knows that the only reason why you get marketing messages on a new SIM is because it is a recycled number. Doh, how can you not know this :P

Everyone knows that? Doh??
I must say, it's quite the coincidence that the person who had that no. before me also had my name & surname. Profound!

Do you even know what digital networking is, or do you you just always make ignorant statements on here?
 
Go get a 'new' pay-as-you-go SIM and I guarantee you it's been used by 20 people before you. And every service they subscribed to and every database they ended up on will now have 'your' number.

Got a new (non-Vodacom) contract number the other day for testing. The poor guy that had that number before me must've run up a LOT of unpaid bills based on the calls and SMSs I'm getting.

For those interested, there is a system in place that alert the WASPs when a number is recycled so they can remove it. How well it's being utilised is clearly another question......

This is either the biggest coincidence that the person(s) who had that no before me had the same FULL FIRST NAME which nobody calls me by, and also the same surname - or you're just lying through your teeth.

Why don't you run an opinion poll to see how many MyBB users actually still trust a single bone in your body, Mr van Zyl?
 
Last edited:
Everyone knows that? Doh??
I must say, it's quite the coincidence that the person who had that no. before me also had my name & surname. Profound!

Do you even know what digital networking is, or do you you just always make ignorant statements on here?

This was actually a tongue-in-cheek comment, as I expected Vodacom to respond with that excuse. Just go back in the thread and you will see what I mean:

My comment first:
Everyone knows that the only reason why you get marketing messages on a new SIM is because it is a recycled number. Doh, how can you not know this :P

VC's response:
Go get a 'new' pay-as-you-go SIM and I guarantee you it's been used by 20 people before you. And every service they subscribed to and every database they ended up on will now have 'your' number.

Got a new (non-Vodacom) contract number the other day for testing. The poor guy that had that number before me must've run up a LOT of unpaid bills based on the calls and SMSs I'm getting.

For those interested, there is a system in place that alert the WASPs when a number is recycled so they can remove it. How well it's being utilised is clearly another question......

Recycling of MSISDNs has become a necessity, but SP's show absolutely no care or interest in trying to "scrub" the MSISDN and force 3rd parties to decommission the MSISDN before reuse. The one thing no SP in this country has yet thought of (and now wait for it - sheer panic) is that once POPI comes in place it will place a tremendous burden on them:
- The MSISDN (or phone number) attached to a SIM is really the users (at least with MNP I could not find any reference that the number belongs to a particular provider, please correct me if I am wrong)
- User A subscribes to a ton of WASPs and 3rd party services and then cancels the service with the SP
- User B gets the recycled MSISDN and gets spammed with all sorts of SMS (ECT act, unsolicited marketing. PAIA, POPI)
- User B requests PAIA from SP and files an ECT and POPI complaint against SP
- SP has no clue who they gave the MSISDN to (but also can not blame User A)
- WASPs and 3rd parties get robed in as part of ECT- and POPI-complaints and the mud-slinging will begin

I honestly can not wait for POPI to come into affect, as in conjunction with ECT many companies bombarding us with unsolicited SMS will be in a world of pain.

The excuse of any SP for recycled numbers, "your number was used by 20 people before you" is weak, as it infringes on your consumer rights and violates a number of regulations with regards to direct marketing and privacy. It does not matter who owned the number before and the onus resides with the SP decommissioning the number. (i.e. if the MSISDN gets cancelled or ported, the SPs should ensure that the number is removed from 3rd party services).

BTW: It is also a weak response when they say "but we do not know to which service a user subscribes", as those SMS/MMS requests travel over their network (otherwise they would be incapable of billing WASPS and SPs via interconnect fees for the transmission of those services).
 
This is either the biggest coincidence that the person(s) who had that no before me had the same FULL FIRST NAME which nobody calls me by, and also the same surname - or you're just lying through your teeth.

Why don't you run an opinion poll to see how many MyBB users actually still trust a single bone in your body, Mr van Zyl?
I actually credit MyBB users with enough knowledge to figure out how these systems work. At least most of them, those who spent 5 minutes critically thinking about it.
 
This was actually a tongue-in-cheek comment, as I expected Vodacom to respond with that excuse. Just go back in the thread and you will see what I mean:

My comment first:


VC's response:


Recycling of MSISDNs has become a necessity, but SP's show absolutely no care or interest in trying to "scrub" the MSISDN and force 3rd parties to decommission the MSISDN before reuse. The one thing no SP in this country has yet thought of (and now wait for it - sheer panic) is that once POPI comes in place it will place a tremendous burden on them:
- The MSISDN (or phone number) attached to a SIM is really the users (at least with MNP I could not find any reference that the number belongs to a particular provider, please correct me if I am wrong)
- User A subscribes to a ton of WASPs and 3rd party services and then cancels the service with the SP
- User B gets the recycled MSISDN and gets spammed with all sorts of SMS (ECT act, unsolicited marketing. PAIA, POPI)
- User B requests PAIA from SP and files an ECT and POPI complaint against SP
- SP has no clue who they gave the MSISDN to (but also can not blame User A)
- WASPs and 3rd parties get robed in as part of ECT- and POPI-complaints and the mud-slinging will begin

I honestly can not wait for POPI to come into affect, as in conjunction with ECT many companies bombarding us with unsolicited SMS will be in a world of pain.

The excuse of any SP for recycled numbers, "your number was used by 20 people before you" is weak, as it infringes on your consumer rights and violates a number of regulations with regards to direct marketing and privacy. It does not matter who owned the number before and the onus resides with the SP decommissioning the number. (i.e. if the MSISDN gets cancelled or ported, the SPs should ensure that the number is removed from 3rd party services).

BTW: It is also a weak response when they say "but we do not know to which service a user subscribes", as those SMS/MMS requests travel over their network (otherwise they would be incapable of billing WASPS and SPs via interconnect fees for the transmission of those services).

As already said, systems are in place to ensure recycled MSISDNs are washed by SPs.

Billing a SMS is NOT done by investigating the source, destination and content of each SMS as you suggest. That really breaks many privacy laws and concerns, you'll agree.
 
Jannie mind commenting on this quote in particular? Scanned through that other thread quick and this is the only selling claim that sounds more substantial than hot air.
I'm in the WASP game, I know that anyone can buy this functionality for their site (headers in question being passed through to certain IPs) - both MTN and Vodacom have it as products, I think it was in the region of R20k/mo last time I saw it priced; probably some time this year.

[...]

They've had this product as far back as I can remember.
 
Jannie mind commenting on this quote in particular? Scanned through that other thread quick and this is the only selling claim that sounds more substantial than hot air.

You are right. MyBB and VC are jumping through hoops here with this and other angry articles.

Nobody said VC was selling customer information openly, except for the quoted part you referenced.

However, they did pass out numbers and IMEI numbers to all websites (this wasn't a sudden problem, it happened over many years, they have been notified many years ago and it still continued and I do not know who benefited here) and there are people out there selling the VC client database, although I suspect this to have been obtained illegally from sources inside their tech department. However, I still suspect, like all banks, retail companies and insurance companies, VC may still be part of the billion rand information selling network.
 
Last edited:
Jannie mind commenting on this quote in particular? Scanned through that other thread quick and this is the only selling claim that sounds more substantial than hot air.
Would love to see proof of this myself. Suspect it's BS but will give elvis the benefit of the doubt to come up with the proof that anyone can just buy Vodacom sub data outright.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X