AT&T last week filed a lawsuit in San Antonio, Texas, designed to unmask the identities of 25 so-called data brokers who the carrier says ripped off phone-calling records from 2,500 of its customers – a legal countermeasure one expert says may already be paying small dividends.
AT&T is seeking the court’s permission to identify the flim-flam artists through their e-mail and IP addresses, a legal nicety that is somewhat ironic given the brokers’ propensity for using subterfuge – pretexting, in the vernacular – to obtain the personal information of their victims.
According to an Associated Press story: “Once the names are known, AT&T said it would seek an injunction to bar [the brokers] from further tapping phone records. It also said it would seek damages, including the return of any profit from selling customer information.”
Security expert Rob Douglas, who has testified before Congress about phone-records theft, says legal volleys such as the one launched by AT&T – as well as earlier ones from other carriers – hold significant promise for driving data brokers out of business, perhaps more so than state and federal legislation.
“I forwarded the AP story to a broker I know who continues to steal records – he wrote back and said that he has been laying low for several months and hopes he is not one of the e-mail/IP addresses they are seeking,” Douglas told me. “The civil remedies that the carriers can avail themselves of can bring a pain that many of the brokers will find intolerable. . . . Ideally what I’d like to see are the carriers banding together in a concerted effort to go after the brokers.”
However, any such benefit will require persistent pressure.
“That is why this needs to be an ongoing effort because if this is a one-shot deal on the part of the carriers that have brought suit to date, the roaches will scurry back in when they think the lights have dimmed,” Douglas says.
One factor working in favor of the carriers is that the number of potential targets is more manageable than, say, the ranks of spammers.
“The number of individuals who are doing the original breach of the customer authentication system at the carriers is finite,” Douglas says. “My best estimate at this point is that there are fewer than 50 individuals who are doing this full-time. Crack that group and you make a significant impact.”
As for legislative efforts, particularly in Congress, Douglas is much less optimistic.
“Here it is August and Congress has yet to move a bill on this to the president – even though I can remember promises to do so by the committees I testified before,” he says. “Indeed, the statement was made that they’d have a bill to the president by the end of spring. . . . The public outrage has been there – and I think continues to be there – but Congress has proven completely impotent.”
It’s a sad state of affairs when the mammoth carriers prove to be our best hope for a modicum of protection against these privacy vultures.
Philly Wi-Fi maven cashes out, trashes rep
There is no evidence of wrongdoing in Philadelphia CIO Dianah Neff’s decision to accept a job with a consulting firm that her department awarded $302,700 worth of contracts as part of the city’s much-ballyhooed municipal Wi-Fi project, at least according to a spokesman for Mayor John Street.
I suppose that assessment depends on what the definition of wrongdoing is, because what Neff did is wrong on its face, even if it proves to be perfectly legal. The city’s Board of Ethics will investigate.
By the way, Neff was named one of the 50 most powerful people in networking last year by no less of an authority than Network World.
The formulation of that list isn’t my responsibility, but I’ll go out on a limb and venture a guess that Neff won’t be on the next one.
Comments, questions and dubious job offers to buzz@nww.com.




