FCC strengthens rules against pretexting
Chairman Kevin Martin called the practice 'a significant privacy invasion'
IDG News Service - The U.S. Federal Communications Commission (FCC) has prohibited telephone and mobile phone carriers from releasing customer records over the phone without a password in an effort to protect against the practice of pretexting.
The FCC, in rules released yesterday, will also require carriers to notify customers immediately when there are changes to their accounts, such as a new password, a new address or an online account opened.
"The unauthorized disclosure of consumers' private calling records is a significant privacy invasion," FCC Chairman Kevin Martin said in a statement. "Compliance with our consumer protection regulations is not optional for any telephone service provider. We need to take whatever actions are necessary to enforce these requirements to secure the privacy of personal and confidential information of American customers."
The practice of pretexting, or gaining a phone customer's call or account records by pretending to be that customer, has become a major concern of the FCC and Congress in the past year. Early in 2006, Congress began looking into call records being sold online, but then in September Hewlett-Packard Co. announced that it had hired investigators who used pretexting to gain access to reporters' and board members' phone records in an effort to find the source of board leaks.
President George W. Bush signed a bill creating criminal penalties for pretexting in January. Congress is looking at additional legislation that would give the U.S. Federal Trade Commission authority to file lawsuits against pretexters and the people who hire them.
The FCC order also requires carriers to notify customers and law enforcement officials if there's been an unauthorized disclosure of phone records. Carriers will also be required to obtain "explicit consent" from a customer before disclosing phone records.
Providers of traditional voice services, plus providers of voice-over IP service, are covered by the new rules.
Commissioner Michael Copps, while approving most of the new rules, objected to a provision that would allow carriers to withhold a records breach from customers for up to 14 days, and even longer if requested by law enforcement officials.
Those rules would "keep victims of these unauthorized disclosures in the dark even longer, perhaps indefinitely," he said in a statement. "As some have described it, it is akin to not telling victims of a burglary that their home has been broken into because law enforcement needs to continue dusting for fingerprints."



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts