craig mathias
Principal

The Phone Hacking Scandal: The Answer is in Infrastructure

Opinion
Jul 14, 20113 mins

News regarding the hacking of handsets in the UK is everywhere, and there are simple countermeasures that users can take to prevent problems in this area. The real answer, though, is in needed changes to infrastructure, and questions abound as to why so many vulnerabilities exist in the first place.

You can’t turn on the TV these days without hearing more about how Rupert Murdoch’s News of the World newspaper (I user the term newspaper loosely here, just as I would for the National Enquirer) was shut down after certain staffers illegally (well such should be the case; I’m not really sure about the law here) accessed and even modified an individual’s (actually that of a number of individuals) cellular voice mail. I hope no one was surprised about how easy this is to do; simple countermeasures that few seem to take would have likely done their job here. The bigger question is why operators of telecommunications infrastructure aren’t doing a better job in helping their users and customers to stay secure.

First of all, my usual proviso here: there is no such thing as absolute security; anything can be hacked. Successful hacking, however, requires two key elements: a vulnerability, and, of course, a hacker. With respect to the latter, I still contend we are much too tolerant of those who knowingly and willfully cause harm (of any form) to others, and the penalties for such need to be toughened. At the very least, while a given act might or might not be criminal, it may very well be unethical, the test of which is whether or not the perpetrator of a given act would find public knowledge of the act embarrassing. If one doesn’t care if the whole world knows, one is likely behaving ethically or, rarely anyway, with reckless disregard to one’s reputation.

Good practice, like setting PINs and passwords and such, is usually an effective countermeasure to any form of hacking, but it’s often difficult for the unwashed masses to put these in place (or, in many cases, to even know that such capabilities exist). And network operators should be stepping up here, with easy-to-follow guides and required password settings and changes, as well as ID checks when calling customer service, enforced in the infrastructure. But such is uncommon, and numerous vulnerabilities exist because the carriers could care less. This needs to change; the carriers need to take responsibility for the functionality and complexity and ultimate vulnerabilities of their implementations. And such should be embodied in law.

But, then, perhaps governments around the world are content with keeping all those vulnerabilities in place, just in case they should need to hack, I mean, um, explore, a given user’s information. Naw, that can’t be it. Sorry I brought it up.

craig mathias

Craig J. Mathias is a principal with Farpoint Group, an advisory firm specializing in wireless networking and mobile computing. Founded in 1991, Farpoint Group works with technology developers, manufacturers, carriers and operators, enterprises, and the financial community. Craig is an internationally-recognized industry and technology analyst, consultant, conference speaker, author, columnist, and blogger. He regularly writes for Network World, CIO.com, and TechTarget. Craig holds an Sc.B. degree in Computer Science from Brown University, and is a member of the Society of Sigma Xi and the IEEE.

More from this author