Vodacom number leak - Vodacom responds

"However, Vodacom said that this information was not being shared with all websites..." LIE #1
"Header enrichment is not our default operation..." LIE #2
 
Simple, use a VPN.

This actually made me really start considering a VPN as part of daily life. But because this has been going on for so long and I have not once had some online security incident I'm not going to worry too much. I have received an annoying amount of SMS spam.
 
"Header enrichment"

Nope, that is not an appropriate description for a serious violation of one's privacy.
 
“We use it for a select number of Vodacom and trusted third-party services, such as charge-to-bill.”
And this random blog website thing they pictured in the other article to test it is that a...uhm..."trusted third-party services"? Pretty weak as far as explanations go imo.

Simple, use a VPN.
Ag no man. I'm already paying Vodacom. I should not have to pay another supplier to defend me *against* Vodacom. :(

Thank goodness for ADSL
 
So the update is that are trying to decide which department will take blame, and therefore will take serious steps to rectify. They will then take serious steps to fix the problem, but this might take a while because individuals need to be identified.

Therefore the public must be aware that they are treating this as a serious problem but we must not be alarmed since it is being addressed at the highest level.
 
Yes only about 10 people gets a bite from the OOB shark. Only 2 sites get your info. Blablabla.
And that is why we get calls all bloody day from people wanting to sell you ****.
As for the response......:sick:
 
Yes only about 10 people gets a bite from the OOB shark. Only 2 sites get your info. Blablabla.
And that is why we get calls all bloody day from people wanting to sell you ****.
As for the response......:sick:

Vodacom spin doctors hard at work yet again. Damn can't wait to be done with them
 
So the update is that are trying to decide which department will take blame, and therefore will take serious steps to rectify. They will then take serious steps to fix the problem, but this might take a while because individuals need to be identified.

Therefore the public must be aware that they are treating this as a serious problem but we must not be alarmed since it is being addressed at the highest level.

Are you on crack?
 
Makes sense that they want to use it to charge your for service over the web without login in or registering but I think they did not realize that the http headers are being sent to all websites on the http ports.... Interesting and shocking that they have not picked it up.
 
“Header enrichment is not our default operation,” Vodacom said. “We use it for a select number of Vodacom and trusted third-party services, such as charge-to-bill.”

WASPS
 
Unless I am mistaken, injection is not possible over https. So why isn't mybroadband using https?
 
“Header enrichment is not our default operation,” Vodacom said. “We use it for a select number of Vodacom and trusted third-party services, such as charge-to-bill.”

WASPS


Yeah, covering their ass since you mist likely signed a contract stating they may share your info with "trusted third parties"/affiliates.
 
Yeah, covering their ass since you mist likely signed a contract stating they may share your info with "trusted third parties"/affiliates.
Still doubtful on this front - I mean some random blog site served as a test for the original article...how can they claim its limited to trusted 3rd parties?
 
Still doubtful on this front - I mean some random blog site served as a test for the original article...how can they claim its limited to trusted 3rd parties?

I can guarantee you this was a misconfiguration on Vodacom's behalf. It doesn't absolve them of responsibility or make them right, but this wasn't an act of malice or wilful breach of privacy. You just need to follow the money - they usually charge for this stuff, why would they give it away free? Because someone f*** up, that's why.
 
Top
Sign up to the MyBroadband newsletter
X