pmcnamara
News Editor

AT&T unleashes lawyers — phone-record ‘roaches’ scurry

Opinion
Aug 23, 20063 mins

AT&T filed a lawsuit in San Antonio today designed to unmask the identities of 25 so-called data brokers who the carrier says have ripped off phone-calling records from 2,500 of its customers — a legal countermeasure one expert says may already be paying small dividends. 

AT&T is seeking the court’s permission to identify the flim-flam artists through their e-mail and IP addresses, a legal nicety which in and of itself is somewhat ironic given the brokers’ propensity for using subterfuge — pretexting, in the vernacular — to obtain the personal information of their victims.

According to this Associated Press story: “Once the names are known, AT&T said it would seek an injunction to bar (the brokers) from further tapping phone records. It also said it would seek damages, including the return of any profit from selling customer information.”

Security expert Rob Douglas, who has testified before Congress about phone-records theft, says legal volleys such as the one launched by AT&T today — as well as those of other carriers — hold significant promise for driving data brokers out of business, perhaps more so than the spate of state and federal legislation filed in recent months.

“I forwarded the AP story to a broker I know who continues to steal records — he wrote back and said that he has been laying low for several months and hopes he is not one of the e-mail/IP addresses they are seeking,” Douglas told me this afternoon.  “The civil remedies that the carriers can avail themselves of can bring a pain that many of the brokers will find intolerable.  … Ideally what I’d like to see are the carriers banding together in a concerted effort to go after the brokers.”

However, any such benefit will require persistent pressure, adds Douglas.

“That is why this needs to be an ongoing effort because if this is a one-shot deal on the part of the carriers that have brought suit to date, the roaches will scurry back in when they think the lights have dimmed.”

One factor working in favor of the carriers and their legal efforts is that the number of potential targets is more manageable than, say, the ranks of spammers.

“The number of individuals who are doing the original breach of the customer authentication system at the carriers is finite,” Douglas says.  “My best estimate at this point is that there are fewer than 50 individuals who are doing this full-time.  Crack that group and you may a significant impact.”

As for legislative efforts, particularly in Congress, Douglas holds much less optimism.

“Here it is August and Congress has yet to move a bill on this to the president — even though I can remember promises to do so by the committees I testified before,” he says. “Indeed, the statement was made that they’d have a bill to the president by the end of spring.  To date — nada, nope, zilch, nothing.  And this from an executive and legislative branch in the hands of one party. ”

“The public outrage has been there — and I think continues to be there — but Congress has proven completely impotent.”

It’s a sad state of affairs when the mammoth carriers prove to be our best hope for a modicum of protection against these privacy vultures.