{"id":2200,"date":"2012-11-27T13:32:35","date_gmt":"2012-11-27T13:32:35","guid":{"rendered":"http:\/\/www.ispreview.co.uk\/?p=2200"},"modified":"2012-11-27T13:34:42","modified_gmt":"2012-11-27T13:34:42","slug":"bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details","status":"publish","type":"post","link":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html","title":{"rendered":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse"},"content":{"rendered":"<p><a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/britishtelecom\" rel=\"nofollow\" target=\"_blank\">BT<\/a> has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to personal customer account names and <strong>add unwanted services<\/strong> to another user\u2019s phone line without their permission.<\/p>\n<p><!--more--><\/p>\n<p>The flaw, which we were easily able to verify with a friends service, allows anybody with the <strong>phone number<\/strong> and <strong>postcode<\/strong> of a particular property to change the subscription service and gain access to additional personal details (full name of the account holder) through <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/britishtelecom\" rel=\"nofollow\" target=\"_blank\">BT<\/a>&#8217;s online &#8220;<em>Upgrade your Calling Plan<\/em>&#8221; service.<\/p>\n<p>It goes without saying that such an easily accessible system with no firm security checks, except a basic check-box,\u00a0could be <strong>abused for malicious purposes<\/strong>, although so far <a href=\"https:\/\/www.ispreview.co.uk\/index.php\/go\/britishtelecom\" rel=\"nofollow\" target=\"_blank\">BT<\/a> have only agreed to remove the account holders name from its public display.<\/p>\n<blockquote class=\"bq1\"><p><strong>A BT Spokesperson said (<a href=\"http:\/\/www.theregister.co.uk\/2012\/11\/27\/bt_phone_call_plan_privacy\/\" target=\"_blank\">The Register<\/a>):<\/strong><\/p>\n<p>&#8220;<em>Different levels of security apply to different products. Where judged as appropriate, for the purpose of customer convenience we do allow a limited number of services to be ordered online using the phone number and postcode.<\/em><\/p>\n<p><em>It should not have been possible to view the name of the account holder by entering just the phone number and postcode. Thank you very much for bringing this to our attention, we have taken the appropriate action to close this issue<\/em>.&#8221;<\/p><\/blockquote>\n<p>Apparently knowing the phone number and postcode of a property, which can easily be found via the <strong>phone directory<\/strong>, is all the security that customers need. So far as we&#8217;re aware the vast majority of other telecoms operators and broadband ISPs tend to require at least a username and password before allowing anybody to make similar changes to\u00a0their services, which is a more sensible approach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to personal customer account names and add unwanted services to another user\u2019s phone line without their permission.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[474,109,479],"class_list":["post-2200","post","type-post","status-publish","format-standard","hentry","category-uk_isp_news","tag-bt","tag-internet-privacy","tag-security"],"share_on_mastodon":{"url":"","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK<\/title>\n<meta name=\"description\" content=\"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK\" \/>\n<meta property=\"og:description\" content=\"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\" \/>\n<meta property=\"og:site_name\" content=\"ISPreview UK\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ispreview\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/ispreview\" \/>\n<meta property=\"article:published_time\" content=\"2012-11-27T13:32:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2012-11-27T13:34:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mark Jackson\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ispreview\" \/>\n<meta name=\"twitter:site\" content=\"@ispreview\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Jackson\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"NewsArticle\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\"},\"author\":{\"name\":\"Mark Jackson\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/person\\\/de66a8b4e937c21c80e443d1bf9c35d5\"},\"headline\":\"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse\",\"datePublished\":\"2012-11-27T13:32:35+00:00\",\"dateModified\":\"2012-11-27T13:34:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\"},\"wordCount\":300,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\"},\"keywords\":[\"BT\",\"Internet Privacy\",\"Security\"],\"articleSection\":[\"ISP News\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\",\"name\":\"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#website\"},\"datePublished\":\"2012-11-27T13:32:35+00:00\",\"dateModified\":\"2012-11-27T13:34:42+00:00\",\"description\":\"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/2012\\\/11\\\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ispreview.co.uk\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#website\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/\",\"name\":\"ISPreview UK\",\"description\":\"Top Broadband ISP and Mobile Provider Information Site\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ispreview.co.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#organization\",\"name\":\"ISPreview.co.uk\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/ispreview_uk_logo.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/ispreview_uk_logo.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"ISPreview.co.uk\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/ispreview\",\"https:\\\/\\\/x.com\\\/ispreview\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mjack\\\/\",\"https:\\\/\\\/bsky.app\\\/profile\\\/ispreview.bsky.social\",\"https:\\\/\\\/mastodon.social\\\/@ispreview\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/#\\\/schema\\\/person\\\/de66a8b4e937c21c80e443d1bf9c35d5\",\"name\":\"Mark Jackson\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ispreview.co.uk\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/nggallery_import\\\/Mark-Jackson-96x96.jpg\",\"caption\":\"Mark Jackson\"},\"description\":\"By Mark Jackson Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and Linkedin.\",\"sameAs\":[\"http:\\\/\\\/www.ispreview.co.uk\",\"https:\\\/\\\/www.facebook.com\\\/ispreview\",\"https:\\\/\\\/x.com\\\/ispreview\"],\"url\":\"https:\\\/\\\/www.ispreview.co.uk\\\/index.php\\\/author\\\/markj\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK","description":"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html","og_locale":"en_GB","og_type":"article","og_title":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK","og_description":"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to","og_url":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html","og_site_name":"ISPreview UK","article_publisher":"https:\/\/www.facebook.com\/ispreview","article_author":"https:\/\/www.facebook.com\/ispreview","article_published_time":"2012-11-27T13:32:35+00:00","article_modified_time":"2012-11-27T13:34:42+00:00","og_image":[{"width":1000,"height":1000,"url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","type":"image\/jpeg"}],"author":"Mark Jackson","twitter_card":"summary_large_image","twitter_creator":"@ispreview","twitter_site":"@ispreview","twitter_misc":{"Written by":"Mark Jackson","Estimated reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#article","isPartOf":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html"},"author":{"name":"Mark Jackson","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/person\/de66a8b4e937c21c80e443d1bf9c35d5"},"headline":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse","datePublished":"2012-11-27T13:32:35+00:00","dateModified":"2012-11-27T13:34:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html"},"wordCount":300,"commentCount":2,"publisher":{"@id":"https:\/\/www.ispreview.co.uk\/#organization"},"keywords":["BT","Internet Privacy","Security"],"articleSection":["ISP News"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html","url":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html","name":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse - ISPreview UK","isPartOf":{"@id":"https:\/\/www.ispreview.co.uk\/#website"},"datePublished":"2012-11-27T13:32:35+00:00","dateModified":"2012-11-27T13:34:42+00:00","description":"BT has been accused of negligence after one of its customers discovered that the national telecoms operator had made it easy for anybody to gain access to","breadcrumb":{"@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ispreview.co.uk\/index.php\/2012\/11\/bt-shuns-phone-privacy-bug-that-exposes-uk-customer-details.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ispreview.co.uk\/"},{"@type":"ListItem","position":2,"name":"BT Shuns Phone Privacy Bug that Exposes UK Customers to Abuse"}]},{"@type":"WebSite","@id":"https:\/\/www.ispreview.co.uk\/#website","url":"https:\/\/www.ispreview.co.uk\/","name":"ISPreview UK","description":"Top Broadband ISP and Mobile Provider Information Site","publisher":{"@id":"https:\/\/www.ispreview.co.uk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ispreview.co.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.ispreview.co.uk\/#organization","name":"ISPreview.co.uk","url":"https:\/\/www.ispreview.co.uk\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/logo\/image\/","url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","contentUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2020\/07\/ispreview_uk_logo.jpg","width":1000,"height":1000,"caption":"ISPreview.co.uk"},"image":{"@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/ispreview","https:\/\/x.com\/ispreview","https:\/\/www.linkedin.com\/in\/mjack\/","https:\/\/bsky.app\/profile\/ispreview.bsky.social","https:\/\/mastodon.social\/@ispreview"]},{"@type":"Person","@id":"https:\/\/www.ispreview.co.uk\/#\/schema\/person\/de66a8b4e937c21c80e443d1bf9c35d5","name":"Mark Jackson","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","url":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","contentUrl":"https:\/\/www.ispreview.co.uk\/wp-content\/uploads\/2023\/01\/nggallery_import\/Mark-Jackson-96x96.jpg","caption":"Mark Jackson"},"description":"By Mark Jackson Mark is a professional technology writer, IT consultant and computer engineer from Dorset (England), he also founded ISPreview in 1999 and enjoys analysing the latest telecoms and broadband developments. Find me on X (Twitter), Mastodon, Facebook, BlueSky, Threads.net and Linkedin.","sameAs":["http:\/\/www.ispreview.co.uk","https:\/\/www.facebook.com\/ispreview","https:\/\/x.com\/ispreview"],"url":"https:\/\/www.ispreview.co.uk\/index.php\/author\/markj"}]}},"_links":{"self":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/2200","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=2200"}],"version-history":[{"count":0,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/posts\/2200\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=2200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/categories?post=2200"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ispreview.co.uk\/index.php\/wp-json\/wp\/v2\/tags?post=2200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}