April 02, 2007

FCC strengthens rules against pretexting

New regulation prohibits telephone, VoIP, and mobile providers from disclosing customer records over the phone without a password

The U.S. Federal Communications Commission (FCC) has prohibited telephone and mobile phone carriers from releasing customer records over the phone without a password in an effort to protect against the practice of pretexting.

The FCC, in rules released Monday, will also require carriers to notify customers immediately when there are changes to their accounts, such as a new password, a new address, or an online account opened.

"The unauthorized disclosure of consumers' private calling records is a significant privacy invasion," FCC Chairman Kevin Martin said in a statement. "Compliance with our consumer protection regulations is not optional for any telephone service provider. We need to take whatever actions are necessary to enforce these requirements to secure the privacy of personal and confidential information of American customers."

The practice of pretexting, gaining a phone customer's call or account records by pretending to be that customer, has become a major concern of the FCC and the U.S. Congress in the past year. Early in 2006, Congress began looking into call records being sold online, but then in September, Hewlett-Packard announced that it had hired investigators who used pretexting to gain access to reporters' and board members' phone records in an effort to find the source of board leaks.

U.S. President George Bush signed a bill creating criminal penalties for pretexting in January. Congress is looking at additional legislation that would give the U.S. Federal Trade Commission (FTC) authority to file lawsuits against pretexters and the people who hire them.

The FCC order also requires carriers to notify customers and law enforcement officials if there's been an unauthorized disclosure of phone records. Carriers will also be required to obtain "explicit consent" from a customer before disclosing phone records.

Providers of traditional voice services, plus providers of VoIP service, are covered by the new rules.

Commissioner Michael Copps, while approving most of the new rules, objected to a provision that would allow carriers to withhold a records breach from customers for up to 14 days, and even longer if requested by law enforcement officials.

Those rules would "keep victims of these unauthorized disclosures in the dark even longer, perhaps indefinitely," he said in a statement. "As some have described it, it is akin to not telling victims of a burglary that their home has been broken into because law enforcement needs to continue dusting for fingerprints."

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.