pmcnamara
News Editor

FCC action on ‘pretexting’ might have saved HP from itself

Opinion
Apr 3, 20074 mins

Had regulators taken this action a couple of years ago there’s a good chance the HP spy scandal never would have happened.

Yesterday, in an effort to minimize the type of “pretexting” (read: stealing of private information) that got HP in hot water, the FCC announced new rules governing the release of landline and mobile telephone records. We’re talking simple stuff here.

First of all, carriers will now be required to institute password systems and their customer service reps will only be allowed to give account information to those who know their password.

And, in an equally commonsense move, carriers will be required to notify their customers any time a change is made to their account.

The benefit of the first step is obvious: While passwords are by no means the last word in security, they do afford a solid measure of protection against the less sophisticated flimflam artists who now simply bamboozle customer service reps into coughing up the personal info of others. (And might not HP executives have been more inclined to call off the dogs if they knew the hunt involved stealing passwords? Techies understand passwords.) The carriers could do themselves and their customers are great additional service here by making the release of information without the proper password a fireable offense.

The second move – alerting customers to any account changes – also makes great sense. If you didn’t authorize the change, you know someone’s monkeying with your account.

“The unauthorized disclosure of consumers’ private calling records is a significant privacy invasion,” FCC Chairman Kevin Martin said in a statement. “Compliance with our consumer protection regulations is not optional for any telephone service provider. We need to take whatever actions are necessary to enforce these requirements to secure the privacy of personal and confidential information of American customers.”

But what took so long? Why didn’t regulators insist on these simple security measures earlier, and, more to the point, why didn’t carriers implement them voluntarily?

Oh, c’mon, you know the reason: money. It’s always money.

As experts have explained to me, carriers were afraid of imposing such “restrictions” unilaterally on their customers for fear that their competitors would torture them with claims of “hassle-free” account management. And let’s face it: Another password to deal with is not exactly something that a lot of customers are going to welcome.

The FCC would seem to have less of an excuse. It’s their job to protect the consumer even in the face of industry opposition (sometimes I regret that blogs don’t have a laugh track). The guess here is that public and legislative heat simply became too intense for the FCC to ignore and it finally faced up to doing what’s best for the consumer. Thing is, it’ll also be best for the carriers in the long run.

Will these changes put an end to pretexting as applied to phone records? Of course not. The truly skillful con artists will continue to ply their trade and customers – including law enforcement – will continue to pay handsomely for their illicit services.

But progress is progress.

Welcome regulars and passersby. Here are a few more recent Buzzblog items. And, if you’d like to receive Buzzblog via e-mail newsletter, here’s where to sign up.

Google TiSP a blatant rip-off.

TJX data theft called largest ever: 45.7M credit card numbers.

$20 billion can’t buy a conference call.

Newspaper pulls plug on “Anti-Christ” contributor.

Here’s how the contest winner found my address.

More than 1 in 10 Brits victimized online? … Not bloody likely.

Blogger’s screwup, lemming-like media spread false report about Edwards campaign.

Maker of anti-Clinton ‘Net ad revealed, linked to Obama, now jobless

The Onion tees up Vista … hilarity fails to ensue.