FCC strengthens rules against pretexting
Chairman Kevin Martin called the practice 'a significant privacy invasion'
April 3, 2007 12:00 PM ETIDG News Service - The U.S. Federal Communications Commission (FCC) has prohibited telephone and mobile phone carriers from releasing customer records over the phone without a password in an effort to protect against the practice of pretexting.
The FCC, in rules released yesterday, will also require carriers to notify customers immediately when there are changes to their accounts, such as a new password, a new address or an online account opened.
"The unauthorized disclosure of consumers' private calling records is a significant privacy invasion," FCC Chairman Kevin Martin said in a statement. "Compliance with our consumer protection regulations is not optional for any telephone service provider. We need to take whatever actions are necessary to enforce these requirements to secure the privacy of personal and confidential information of American customers."
The practice of pretexting, or gaining a phone customer's call or account records by pretending to be that customer, has become a major concern of the FCC and Congress in the past year. Early in 2006, Congress began looking into call records being sold online, but then in September Hewlett-Packard Co. announced that it had hired investigators who used pretexting to gain access to reporters' and board members' phone records in an effort to find the source of board leaks.
President George W. Bush signed a bill creating criminal penalties for pretexting in January. Congress is looking at additional legislation that would give the U.S. Federal Trade Commission authority to file lawsuits against pretexters and the people who hire them.
The FCC order also requires carriers to notify customers and law enforcement officials if there's been an unauthorized disclosure of phone records. Carriers will also be required to obtain "explicit consent" from a customer before disclosing phone records.
Providers of traditional voice services, plus providers of voice-over IP service, are covered by the new rules.
Commissioner Michael Copps, while approving most of the new rules, objected to a provision that would allow carriers to withhold a records breach from customers for up to 14 days, and even longer if requested by law enforcement officials.
Those rules would "keep victims of these unauthorized disclosures in the dark even longer, perhaps indefinitely," he said in a statement. "As some have described it, it is akin to not telling victims of a burglary that their home has been broken into because law enforcement needs to continue dusting for fingerprints."
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
FCC
Additional Resources



White Papers & Webcasts
Southern Company
Download Now
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Defending Against the Storm
Download Now
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
