44 ms·
I work with major carriers in North America - This is not industry standard practice here. At most, we will send area code to partners (mostly for ad targeting
by executive 15y ago
I work with major carriers in North America - This is not industry standard practice here.
At most, we will send area code to partners (mostly for ad targeting) but this is never exposed in wap headers.
If we are doing age verification, we send age range to partners.. likewise never exposed in headers.
Never full phone number. If for some reason a partner needs access to this, they would have a local database corresponding to scrambled wap signatures - which ARE sent in headers.
- otoburb 15y agoThis is where the interpretation of the statement comes into play. It's certainly commonplace throughout the wireless carrier industry to send the mobile number to "trusted sites" within the carrier network (such as a ringtone/download portal), or over a pre-arranged VPN tunnel. And when I say "commonplace", I'm referring to multiple carriers around the world, including North America. However, the level of trust that a site qualifies for may necessitate a more nuanced or out-of-band approach similar to what you've experienced, where a 3rd party partner may receive the scrambled identifier and request the mobile number mapping for billing purposes. There are lots of ways to skin a cat. My only point here is that there are multiple carriers around the world that routinely use this method of sending the mobile number in plaintext to sites they trust, typically over communication channels that they trust (i.e. over network gear they either own or have secured). I've seen this from both sides (working at and with carriers). But there are a heck of a lot more 3rd party partner sites that do not usually receive full mobile numbers in the clear, so from that perspective, there is a point to be said about this not being "industry practice". Semantics.