Feeds

BT Cellnet PUKs up phone security

A mobile unblocking free-for-all

  • alert
  • submit to reddit

HP ProLiant Gen8: Integrated lifecycle automation

Updated A new BT Cellnet automated phone service has left security observers and mobile operators despairing. The company has brought out a touch-tone service that will give you the PUK for any BT Cellnet phone - all you need is the mobile's phone number.

PUK stands for Personal Unblocking Key, and is the eight-digit number you get on your SIM card certificate when you buy your phone. If you've got the PUK, then you have the ability to insert a new PIN number.

Which is useful if you've locked your PIN by getting it wrong three times, or if - just say - you didn't know the number in the first place.

So if someone had your phone and knew its calling number, they could easily override PIN security and then insert their own PIN. By making the PUK numbers for any phone instantly available to anyone and everyone, BT Cellnet has put a big question mark over phone security.

As an indication of the sensitivity of the PUK number, we have been unable to find any other mobile operator in Europe which will admit to providing it without significant evidence that the caller is the owner of the phone. In the UK, Vodafone assured us that someone will have to pass a full ID check, including various passwords, to be given their PUK number.

Orange and One2One have so far failed to get back to us, but the advice on their respective Web sites asks for the same form of identification.

BT Cellnet has yet to respond to our queries. We'll keep you informed.

Update

Contrary to what Vodafone told us above, it does have an automated service that will give you the PUK number if you tap in the mobile number. But only if it’s a Pay-as-you-talk phone, so the potential for running up fraudulent bills is greatly reduced. ®

Related Stories

IMEI numbers no antidote to mobile fraud
Jack Straw shoots back in the Net
How to get back your nicked mobile

Reducing security risks from open source software

More from The Register

next story
Sysadmin Day 2014: Quick, there's still time to get the beers in
He walked over the broken glass, killed the thugs... and er... reconnected the cables*
Amazon Reveals One Weird Trick: A Loss On Almost $20bn In Sales
Investors really hate it: Share price plunge as growth SLOWS in key AWS division
Auntie remains MYSTIFIED by that weekend BBC iPlayer and website outage
Still doing 'forensics' on the caching layer – Beeb digi wonk
SHOCK and AWS: The fall of Amazon's deflationary cloud
Just as Jeff Bezos did to books and CDs, Amazon's rivals are now doing to it
BlackBerry: Toss the server, mate... BES is in the CLOUD now
BlackBerry Enterprise Services takes aim at SMEs - but there's a catch
The triumph of VVOL: Everyone's jumping into bed with VMware
'Bandwagon'? Yes, we're on it and so what, say big dogs
Carbon tax repeal won't see data centre operators cut prices
Rackspace says electricity isn't a major cost, Equinix promises 'no levy'
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.