MTN shuts down e-billing portal

MTN South Africa has shut down its e-billing portal until security concerns have been addressed. By Duncan McLeod.

MTN--640

MTN South Africa has shut down its e-billing portal until security concerns have been addressed, the mobile operator said on Friday.

“This has been implemented with immediate effect and customers will receive their bills via e-mail as an interim measure,” a spokesman said.

The decision to shut down the e-billing website follows a report published by TechCentral on Thursday, which revealed that lack of proper security meant anyone could randomly access the confidential details of the operator’s customers, including their itemised billing information.

The problem was brought to TechCentral’s attention by an alert reader, who asked to remain anonymous.

The reader identified two main problems. The first was that the e-billing platform was not encrypted. This was quickly fixed by MTN after TechCentral brought the issue to its attention.

The second problem was that no login or confirmation of identity was required — just a simple hash string was appended to the e-billing website address — meaning anyone could guess the string and potentially bring up user information at random.

As a temporary fix, MTN had planned to increase the length of the hash string dramatically to make it much more difficult to make random guesses and in that way get access to customer information. This would be ahead of a permanent solution involving the implementation of a username and password login system.

The company has now decided to take the system offline until a secure solution has been developed.

TechCentral’s reader had warned that MTN was in breach of its own privacy policy, which states that “access to your personal information on MTN websites, mobile applications, products and services will be password protected”.

“Since the documents available online include addresses, cellphone numbers and most importantly itemised billing, this is potentially a major breach of their customers’ privacy and confidentiality,” he said.  — (c) 2015 NewsCentral Media

Share this article

  • The Emperor has no clothes…

    Incompetence or arrogance? Most likely both!

Why TechCentral?

We know that as a prospective advertiser, you are spoilt for choice. Our job is to demonstrate why TechCentral delivers the best return for your advertising spend.

TechCentral is South Africa’s online technology news leader. We don’t say that lightly. We believe we produce the country’s best and most insightful online tech news aimed at industry professionals and those interested in the fast-changing world of technology.

We provide news, reviews and comment, without fear or favour, that is of direct relevance to our fast-expanding audience. Proportionately, we provide the largest local audience of all technology-focused online publishers.

We do not constantly regurgitate press releases to draw in search engine traffic — we believe websites that do so are doing their readers and advertisers a disservice. Nor do we sell “editorial features”, offer advertising “press offices” or rely on online bulletin-board forums of questionable value to advertisers to bolster our traffic.

TechCentral, which is edited and written by award-winning South African journalists, cares about delivering top-quality content to draw in the business and consumer readers that are of most interest to technology advertisers.

We’d like the opportunity to demonstrate the value of directing a portion of your advertising budget to TechCentral, whether your company is in the technology field or not. Numerous opportunities exist for companies interested in reaching our audience of key decision-makers in South Africa’s dynamic information and communications technology sector. We offer packages that will deliver among the best returns on investment available in the online technology news space.

For more information about advertising opportunities, and how your organisation can benefit by publicising itself on TechCentral, please call us on 011-792-0449 during office hours. Or send us an e-mail and ask for our latest rate card and brochure.