Verizon Once Again Busted Handing Out Sensitive Wireless Subscriber Information To Any Nitwit Who Asks For It

from the hey,-let's-do-absolutely-nothing-about-this-problem dept

Half a decade ago we documented how the U.S. wireless industry was caught over-collecting sensitive user location and vast troves of behavioral data, then selling access to that data to pretty much anybody with a couple of nickels to rub together. It resulted in no limit of abuse from everybody from stalkers to law enforcement — and even to people pretending to be law enforcement.

While the FCC purportedly moved to fine wireless companies for this behavior, the agency still hasn’t followed through. Despite the obvious ramifications of this kind of behavior during a post-Roe, authoritarian era.

Nearly a decade later, and it’s still a very obvious problem. The folks over at 404 Media have documented the case of a stalker who managed to game Verizon in order to obtain sensitive data about his target, including her address, location data, and call logs.

Her stalker posed as a police officer (badly) and, as usual, Verizon did virtually nothing to verify his identity:

“Glauner’s alleged scheme was not sophisticated in the slightest: he used a ProtonMail account, not a government email, to make the request, and used the name of a police officer that didn’t actually work for the police department he impersonated, according to court records. Despite those red flags, Verizon still provided the sensitive data to Glauner.”

In this case, the stalker found it relatively trivial to take advantage of Verizon Security Assistance and Court Order Compliance Team (or VSAT CCT), which verifies law enforcement requests for data. You’d think that after a decade of very ugly scandals on this front Verizon would have more meaningful safeguards in place, but you’d apparently be wrong.

Keep in mind: the FCC tried to impose some fairly basic privacy rules for broadband and wireless in 2016, but the telecom industry, in perfect lockstep with Republicans, killed those efforts before they could take effect, claiming they’d be too harmful for the super competitive and innovative (read: not competitive or innovative at all) U.S. broadband industry.

In fact, any time the FCC proposes doing absolutely anything about lax privacy standards in wireless or broadband, Republicans work in perfect synchronicity with Comcast, Verizon, and AT&T to demonize and crush the effort. They’re currently trying to block an FCC effort requiring that broadband providers do a better, faster job informing customers about hacks and data breaches.

The Republican party not only never has to truly own this dangerous policy decision in the press, you can often watch as cable news outlets present Republicans like Marsha Blackburn, Ted Cruz, or Brendan Carr as good faith privacy reformers (see their performative outrage about TikTok).

At the same time, Congress, as a whole, has proven too corrupt to pass even a basic privacy law for the internet era, despite no limit of problematic scandals. In part because there’s a massive coalition of companies across numerous industries lobbying against it, but also because this lax data-hoovering system we’ve constructed helps the government avoid having to get actual warrants.

So what we get is this steady beat of ugly and avoidable privacy scandals we’ve chosen to do nothing about. Those in power have effectively decided that making money is more important than market health, human safety, or pretty much anything else. Eventually, there will be a scandal at a scale so disturbing it finally shakes Congress out of its corrupt slumber, and it’s going to be a doozy.

Filed Under: , , , , , ,
Companies: verizon

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Verizon Once Again Busted Handing Out Sensitive Wireless Subscriber Information To Any Nitwit Who Asks For It”

Subscribe: RSS Leave a comment
7 Comments
Anonymous Coward says:

This Reminds Me...

Of Bruce Schneier’s excellent essay “Data Is A Toxic Asset, So Why Not Throw It Out?”

Alot of these problems could be solved if these companies would stop hoovering up as much data as possible. If they’re not going to be responsible with it they shouldn’t have it at all.

https://www.schneier.com/essays/archives/2016/03/data_is_a_toxic_asse.html

This comment has been deemed insightful by the community.
Anonymous Coward says:

Verizon Once Again Busted

Busted kinda implies that there will be consequences. But the entire article is all about how there aren’t any consequences. Some, maybe, potential consequences are planned (maybe).

Under the circumstances it’s actually easier and cheaper for Verizon to just hand it over, instead of actually verifying anything.

Until something actually changes, we can expect to see this kind of thing repeated, again, and again….

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...