Congress may soon vote on pretexting legislation
A vote could come in the House this weekend
IDG News Service - Legislation that would allow the U.S. Federal Trade Commission to seek civil penalties against businesses that obtain personal data under false pretenses may soon get a vote in the U.S. House of Representatives.
The full House could vote on Prevention of Fraudulent Access to Phone Records Act by sometime Saturday, Rep. Joe Barton (R-Texas), chairman of the House Energy and Commerce Committee, said Friday. Barton asked the House leadership to move forward with the bill after lawmakers ripped into Hewlett-Packard Co. officials for allowing the practice during an investigation into board leaks.
HP President and CEO Mark Hurd and former HP Chairman Patricia Dunn both testified yesterday that they did not know the details of how the leak investigation was conducted.
The pretexting legislation has been stalled since the House Energy and Commerce Committee unanimously approved it in March. The bill would allow the FTC to seek civil penalties against so-called pretexters, those who masquerade as a customer to gain access to phone records or other personal information.
Representatives of five mobile phone service carriers raised no objections to the bill during today's hearing.
Lawmakers questioned whether more businesses than HP have used pretexting or other questionable investigatory methods. "How do we, and how does corporate America, break this ethos that, if someone thinks that illegal or unethical activity ... is acceptable, everybody else in a corporation goes along with it?" said Rep. Diana DeGette (D-Colo.).
DeGette will explore ways to add new requirements to the Sarbanes-Oxley financial reporting law, she said.
Christopher Bryon, a columnist for the New York Post, told lawmakers that he was a victim of pretexting four years ago, long before the HP investigation came to light. A facial-recognition software company hired a pretexter to gain access to his sources after he wrote a column about the company, Bryon said.
Pretexting appears to be a widespread practice among U.S. businesses, Bryon said. "This is not something I wanted my family to grow up with ... wondering if your mail is being read, if your phone is tapped, if there's a bug in your bedroom," he said.
The FTC has filed five lawsuits against alleged pretexters, but the agency lacks the legal authority to seek civil damages, said Joel Winston, associate director of privacy and identity protection at the FTC. The FTC sought to recover pretexting-related profits in those cases, but additional civil penalties would give the agency an additional tool to use against identity thieves, he said.
A second pretexting bill, the Telephone Records and Privacy Protection Act, has passed the House, but the measure is hung up in the Senate over disagreements over the best approach. The House bill would make pretexting a crime, with a penalty of up to 10 years in prison.
Congress is scheduled to adjourn by early next week until after the Nov. 7 general election. Congress may come back into session late in the year to address unfinished business.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts