Vodacom number leak fix being implemented

Awesome stuff Vodacom, for working with the spotters, in resolving this issue.
May our Government someday have the same level of openness and willingness to get stuff done and not treat it's clients like fools.
 
Obviously it's against policy, so no such thing will happen officially. I can honestly say I've not ever seen this happen in any way and at one point I was hell-bent to find out. So far, never found a trace but if you have a story, please make contact and I'll pick it up.

Thanks very much for clearing that up officially. No I don't have any stories, thank you for clearing the air.
 
Jannie, there have been lots of allegations thrown around about of how Vodacom has been selling off client information to other companies. I am not just talking about companies under the Vodacom umbrella per say, but selling it off to anyone that is willing to pay.

Can you elaborate possibly on this? Has this stuff ever happened, is it ongoing or are people making up stories?

Apoarently they are giving it away for free....
 
Last edited:
The software upgrade which introduced the bug – which leaked phone numbers and device identifiers to other websites – was intended to make this process more secure, he said.

I don't understand, how injecting a cellphone number into a HTTP header request can make anything more secure? :wtf:

IMO that is a false sense of security, and soooo easy to impersonate.
 
I don't understand, how injecting a cellphone number into a HTTP header request can make anything more secure? :wtf:

IMO that is a false sense of security, and soooo easy to impersonate.

I think from all the security issues reported over the last year we can agree that irrespective of the organisation security issues happen. In my opinion, all of the reported ones are due to inexperience and lack of skill. Companies like Vodacom have enterprise architecture teams, data architects, security it staff, compliance teams and changes like this would have too go through proper change management and testing and yet all those gatekeepers failed their jobs.

If every IT person had read OWASP, issues like this would not happen.

I just don't get why companies can be honest about it.
 
The problem actually started more than a decade ago. Vodacom was informed by the media about 7 years ago. It was still ongoing up to now.

I too am wondering did this start only now after their transition to LDAP or it's been there for ages?
 
Top
Sign up to the MyBroadband newsletter
X