By Erika Morphy E-Commerce Times
11/21/08 12:10 PM PT
Most large organizations take strong measures to keep outsiders from accessing their customers' data, but when it comes to insiders, they're lackadaisical, to say the least. Verizon Wireless apologized to President-elect Obama after learning that employees had been snooping into his cell phone account records, but whether the company will change its access procedures is unknown.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
President-elect Barack Obama may not find it that hard to give up his BlackBerry after all. Verizon Wireless has announced that some of its employees accessed his personal cell phone account records. The wireless provider apologized to the president-elect and said it would discipline the employees involved.
Verizon apparently realized this week that Obama's records had been breached. The account is linked to a flip phone that does not have e-mail or advanced data capabilities, and it has been inactive for several months. Verizon employees who did not have authorization to view the account will be punished, the company said.
Obama, undoubtedly the most tech-savvy presidential candidate this season, owns a handful of phones including the flip Verizon device, a BlackBerry and an Apple (Nasdaq: AAPL) iPhone. Even if Verizon employees hadn't violated his privacy, he was probably already prepared to give up those devices while in office for security reasons.
Still, the incident serves as a reminder of how loosely guarded customer records are in most organizations.
'Imprudent Curiosity'
Earlier this year, for instance, it was discovered that State Department employees sneaked a peek into the passport records of presidential candidates Obama, Hillary Clinton and John McCain.
At first, the State Department reported that a handful of employees had given in to "imprudent curiosity." Subsequently, the department's inspector general surveyed the records of 150 politicians, athletes and entertainers, and found that 127 had been accessed -- some multiple times. The report found "found many control weaknesses, including a general lack of policies, procedures, guidance, and training relating to the prevention and detection of unauthorized access to passport and applicant information and the subsequent response and disciplinary processes when a potential unauthorized access is substantiated."
If this is the best the State Department can do, it is probably safe to assume that if you are at all well known, either locally or nationally, your records are fair game to curious workers.
Safety Inside
Part of the problem is that most companies concentrate their security efforts on protecting their systems from outside attacks, Matt Shanahan, senior vice president at
AdmitOne Security, told the E-Commerce Times.
"Unfortunately, consumers -- regardless of celebrity status -- do not have control over the privacy practices of a service," he said. "Most privacy policies and practices focus on how customer information will be used across organizational lines or with partners. The controls and monitoring for these policies often do not defend against insiders where standards do not exist regarding background checks, authentication, monitoring and access control."
It is easy enough for a person to get a coworker to share a password or token in the work environment. The good news, Shanahan suggested, is that "high profile breaches such as President-elect Obama's phone records may bring about legislation to better protect consumers."
Telcos may protest, though, mainly because of the costs involved.
"Telco systems are very complex and contain many databases with information about customers, including text messages, voice mail and call records," Slavik Markovich, founder and CTO of
Sentrigo, told the E-Commerce Times.
"Application controls of authentication and authorization are meaningless here, as the insiders have direct access to the databases and have privileges to access all information. The only way to protect the information is to use tools such as database activity monitoring and data encryption," he explained.
Ideally, companies should flag as confidential the accounts of people with unlisted numbers or those who otherwise would need to keep their data confidential -- such as senior politicians, famous athletes or movie stars -- so that they are not accessible by regular staff, said Markovich.
"Additionally, since application-level security is not sufficient when it comes to IT staff, data must be protected at the source: the database in which it is stored. It is often impossible to prevent privileged users from accessing such information," he noted, "but all access by privileged users should be monitored in real time with preventative controls in place to intercept any attempts to access private or confidential data."
Staff Accountability
Even with these safeguards in place, telcos and other service providers would have to implement organizational and institutional changes to fully safeguard information, said Dominique Levin, EVP of marketing and strategy at
LogLogic.
"The reality is that many employees have legitimate access to confidential information to do their jobs," she told the E-Commerce Times. "An executive assistant has access to a CEO rolodex, calendar and e-mail. Your IT guy may see just about all of this information. A phone company worker can trace your calls, and a healthcare worker can look at medical records. The answer to stop leaks may not be technology, but accountability."
Coincidentally, Levin added, "accountability" is a big mandate for the Obama government.
User Behavior
User behavior also has to change if records are to remain secure, Derek Manky, project manager of cyber security and threat research for
Fortinet, told the E-Commerce Times.
For example, it proved very easy to hack into Republican vice presidential candidate Sarah Palin's e-mail account because she was using a public, server-side stored service that anybody could access, should they guess the right password.
"This is an absolute no-no," said Manky. "Communications for any sensitive information should be safeguarded. This means using no third-party services -- especially one that is available to the public via Web mail.
"Additionally, e-mail should always be encrypted so that should it fall into the hands of a malicious source, they will not be able to decrypt its payload," he advised. "Policies should certainly be set up that outline this, so that such an incident is unlikely to occur."
Microsoft May Skunk Google in Verizon Bidding War November 12, 2008
Microsoft is looking to replace Google as the the default search engine on Verizon handsets. Under a deal reportedly in the works, Microsoft would pay Verizon twice what Google does for the honor. Verizon also would make more handsets that run Windows Mobile.
Related Stories
Privacy Crusaders Launch Class Action Against NebuAd November 14, 2008
A controversial technology that tracks Web-users' surfing behavior is at the heart of a lawsuit brought against NebuAd and a group of Internet service providers that use the system. The plaintiffs, who are seeking class-action status, claim NebuAd's deep packet inspection technology violates consumers' privacy rights.
Internet Explorer 8's Privacy Controls Worry Advertisers August 26, 2008
Microsoft will incorporate new privacy-protection features into the upcoming Internet Explorer 8, to the delight of privacy advocates and the consternation of advertisers. In particular, the "InPrivate Blocking" feature has the potential to block some advertisements.
The Freewheeling Web's Privacy Noose July 19, 2008
In the book, The Future of Reputation: Gossip, Rumor, and Privacy on the Internet, author Daniel Solove brings up numerous questions about the state of online privacy. He later addresses the questions, looking to legal approaches for solutions.
Related News Alerts
More by Erika Morphy
Ballmer Gives Shareholders - and Dell - Cause for Optimism November 20, 2009
Microsoft CEO Steve Ballmer was all smiles at the company's shareholders meeting, as he touted the early success of Windows 7. Ballmer's cheer may have been contagious; after posting a massive earnings decline for the third quarter, Dell needed some good news to latch onto, and the prospect of broad enterprise adoption of Windows 7 could spur PC sales.
AA.com Sucks the Fun Out of Trip-Planning November 20, 2009
Using AA.com to book a flight was a painful experience. Densely packed, disorganized information was displayed in an unattractive format. On the plus side, it did seem as though the deals American Airlines advertised were real and not mere bait-and-switch lures. For anyone who wants a travel-planning Web site to inject a little pleasure into the experience, though, I say look elsewhere.
Salesforce.com Pumps Up Volume of Workplace Chatter November 19, 2009
Salesforce.com has developed a collaboration platform that puts social networking to work. Salesforce Chatter facilitates employee collaboration on projects through Facebook-like profiles, status updates, feeds and groups. The question remains whether employees will be as open to social networking in the workplace as they are in their personal lives.