Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      South Africa needs a national 'quantum defence strategy'

      South Africa needs a national ‘quantum defence strategy’

      20 January 2026
      AI moves from pilots to production in South African companies - Nazia Pillay SAP

      AI moves from pilots to production in South African companies

      20 January 2026
      Chinese brands tighten grip on South Africa's used car market

      Chinese brands tighten grip on South Africa’s used car market

      20 January 2026
      Severe geomagnetic storm hits Earth, Sansa confirms

      Severe geomagnetic storm hits Earth, Sansa confirms

      20 January 2026
      South Africa's new fibre broadband battle

      South Africa’s new fibre broadband battle

      20 January 2026
    • World
      Taiwan, US strike strategic AI and chip supply-chain pact - TSMC

      Taiwan, US strike strategic AI and chip supply-chain pact

      20 January 2026
      Oracle sued as bondholders allege AI debt plans were hidden - Larry Ellison

      Oracle sued as bondholders allege AI debt plans were hidden

      15 January 2026
      Activists call for X, Grok to removed from app stores - Elon Musk

      Activists call for X, Grok to removed from app stores

      14 January 2026
      Uganda shuts down internet ahead of pivotal election

      Uganda shuts down internet ahead of pivotal election

      14 January 2026
      Taiwan seeks arrest of OnePlus CEO - Pete Lau

      Taiwan seeks arrest of OnePlus CEO

      14 January 2026
    • In-depth
      Digital authoritarianism grows as African states normalise internet blackouts

      Digital authoritarianism grows as African states normalise internet blackouts

      19 December 2025
      TechCentral's South African Newsmakers of 2025

      TechCentral’s South African Newsmakers of 2025

      18 December 2025
      Black Friday goes digital in South Africa as online spending surges to record high

      Black Friday goes digital in South Africa as online spending surges to record high

      4 December 2025
      DStv dodges channel blackout in last-minute deal with Warner Bros

      Canal+ plays hardball – and DStv viewers feel the pain

      3 December 2025
      Jensen Huang Nvidia

      So, will China really win the AI race?

      14 November 2025
    • TCS
      TCS+ | Africa's digital transformation - unlocking AI through cloud and culture - Cliff de Wit Accelera Digital Group

      TCS+ | Cloud without culture won’t deliver AI: Accelera’s Cliff de Wit

      12 December 2025
      TCS+ | How Cloud on Demand helps partners thrive in the AWS ecosystem - Odwa Ndyaluvane and Xenia Rhode

      TCS+ | How Cloud On Demand helps partners thrive in the AWS ecosystem

      4 December 2025
      TCS | MTN Group CEO Ralph Mupita on competition, AI and the future of mobile

      TCS | Ralph Mupita on competition, AI and the future of mobile

      28 November 2025
      TCS | Dominic Cull on fixing South Africa's ICT policy bottlenecks

      TCS | Dominic Cull on fixing South Africa’s ICT policy bottlenecks

      21 November 2025
      TCS | BMW CEO Peter van Binsbergen on the future of South Africa's automotive industry

      TCS | BMW CEO Peter van Binsbergen on the future of South Africa’s automotive industry

      6 November 2025
    • Opinion
      ANC's attack on Solly Malatsi shows how BEE dogma trumps economic reality - Duncan McLeod

      ANC’s attack on Solly Malatsi shows how BEE dogma trumps economic reality

      14 December 2025
      Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

      Netflix, Warner Bros deal raises fresh headaches for MultiChoice

      5 December 2025
      BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

      BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

      3 December 2025
      ANC's attack on Solly Malatsi shows how BEE dogma trumps economic reality - Duncan McLeod

      Your data, your hardware: the DIY AI revolution is coming

      20 November 2025
      Zero Carbon Charge founder Joubert Roux

      The energy revolution South Africa can’t afford to miss

      20 November 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Editor's pick » Telkom denies putting Web users at risk

    Telkom denies putting Web users at risk

    By Duncan McLeod9 July 2015
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    ethernet-640

    Telkom has rejected claims that it is employing the same techniques used by malicious hackers in so-called “man in the middle” attacks to edit code on websites in order to serve the telecommunications operator’s own content to end users.

    Johannesburg-based software developer Robert MacLean warns in a recent blog post that Telkom is adding JavaScript code to websites without the permission of website owners or of Telkom customers.

    The code, which MacLean says in only added on non-secure (that is, non-HTTPS) websites, is used to show subscribers to Telkom’s Internet service provider who also use its broadband ADSL service how much bandwidth they have left before they are capped.

    “Telkom is very cleverly intercepting certain calls and redirecting them, so that unless you are actively looking for this, it appears transparent to the website and the user. What they are doing is watching for JavaScript files to be requested, and then appending additional code into those files,” he says. This code is then used to manipulate Web pages, he adds.

    “Admittedly this is a relatively benign addition and in fact it may be seen as useful, and I can see it being sold that way to non-technical managers and executives,” MacLean writes. “Do not be fooled, though. Even this simple addition can cause major issues for you. It is impossible for Telkom to know what this addition will do to every website on the Web.”

    In short, Telkom is adding JavaScript code to each page and that code could interfere with the existing code and Web pages in unforeseen ways and ultimately can break a Web page, MacLean says. “The sheer size and complexity of the Internet says that it is impossible for them to know for sure that they are not breaking a single website.”

    Telkom, he says, is exposing its users to potential security risks, which he explains in greater technical detail in his blog post.

    Worse still, he says, having a server that can manipulate what traffic users are sending and receiving provides a “very easy point for someone to capture traffic” and see what Telkom’s users are doing on the Internet.

    This screenshot shows the Telkom Internet notification (image c/o Robert MacLean)
    This screenshot shows the Telkom Internet notification (image c/o Robert MacLean)

    “While I am sure they will tell you they take security very seriously and that they do not allow that type of access to employees, what is stopping an executive at a later stage from using this to prevent adverts from MTN showing up or causing Web pages that support the EFF or the DA to not load at all? Nothing, and they have the power to do that, without oversight and without your permission. Do you trust Telkom enough to not abuse that?”

    Lastly, the image displayed on users’ screens, alerting them of how much bandwidth they have left, is an extra overhead. “They are making you download more than 84,8kB of extra code and 120kB of extra images, plus the manipulation of the Web page slows down rendering,” MacLean writes. “In short, they are making the Web slower for you and helping use more of your bandwidth.”

    Asked to respond to MacLean’s claims, Telkom has denied that it is using a technique similar to a “man in the middle” attack.

    “In technical terms, we refer to it as an HTTP redirect, which injects JavaScript to overlay the [bandwidth usage] notification once the pre-determined threshold has been reached,” Telkom says.

    “HTTP redirect is a common mechanism used in service provider networks for content caching and to optimise video streaming and does not alter the Web service content. In this instance, it overlays a notification on usage that can be done on SMS or e-mail as well.

    “The in-browser notification has been purpose-built to inform the customer when they have reached 100% of the service threshold on their ‘soft cap’ product. As a result, it does not interfere with the customer’s browsing, is not a security risk, will not ‘break’ a website and poses no threat to the browser’s privacy. Telkom places the highest priority on the security and privacy of its customers.”  — © 2015 NewsCentral Media



    Robert MacLean Telkom
    WhatsApp YouTube Follow on Google News Add as preferred source on Google
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleFighting crime, with an app
    Next Article Cosatu slams Uber’s business model

    Related Posts

    South Africa's telecoms sector enters a new growth phase

    South Africa’s telecoms sector enters a new growth phase

    19 January 2026
    The top-performing South African tech shares of 2025

    The top-performing South African tech shares of 2025

    12 January 2026
    Why Solly Malatsi was right to bury the Post Office monopoly

    Why Solly Malatsi was right to bury the Post Office monopoly

    4 January 2026
    Company News
    How Norton is protecting digital lives in a hostile online world - Avert ITD Avert IT Distribution

    How Norton is protecting digital lives in a hostile online world

    20 January 2026
    Beyond the hype: trust is the first step to generative AI ROI

    Beyond the hype: trust is the first step to generative AI ROI

    19 January 2026
    New Planet Energy and Span Africa launch landmark solar project

    New Planet Energy and Span Africa launch landmark solar project

    19 January 2026
    Opinion
    ANC's attack on Solly Malatsi shows how BEE dogma trumps economic reality - Duncan McLeod

    ANC’s attack on Solly Malatsi shows how BEE dogma trumps economic reality

    14 December 2025
    Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

    Netflix, Warner Bros deal raises fresh headaches for MultiChoice

    5 December 2025
    BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

    BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

    3 December 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    South Africa needs a national 'quantum defence strategy'

    South Africa needs a national ‘quantum defence strategy’

    20 January 2026
    AI moves from pilots to production in South African companies - Nazia Pillay SAP

    AI moves from pilots to production in South African companies

    20 January 2026
    Taiwan, US strike strategic AI and chip supply-chain pact - TSMC

    Taiwan, US strike strategic AI and chip supply-chain pact

    20 January 2026
    How Norton is protecting digital lives in a hostile online world - Avert ITD Avert IT Distribution

    How Norton is protecting digital lives in a hostile online world

    20 January 2026
    © 2009 - 2026 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}