Showing posts with label Carriers. Show all posts
Showing posts with label Carriers. Show all posts

Sunday, October 27, 2013

FCC demands carriers protect customer privacy in declaratory ruling

FCC ACTS TO PROTECT PRIVATE CONSUMER INFORMATION ON WIRELESS DEVICES

Washington, D.C. – The Commission today took action to protect the privacy of consumers of wireless services by clarifying its customer proprietary network information (CPNI) policies in response to changes in technology and market practices in recent years. Today's Declaratory Ruling rests on a simple and fundamentally fair principle: when a telecommunications carrier collects CPNI using its control of its customers' mobile devices, and the carrier or its designee has access to or control over the information, the carrier is responsible for safeguarding that information.

Specifically, the Declaratory Ruling makes clear that when mobile carriers use their control of customers' devices to collect information about customers' use of the network, including using preinstalled apps, and the carrier or its designee has access to or control over the information, carriers are required to protect that information in the same way they are required to protect CPNI on the network. This sensitive information can include phone numbers that a customer has called and received calls from, the durations of calls, and the phone's location at the beginning and end of each call.

Carriers are allowed to collect this information and to use it to improve their networks and for customer support. Carriers' collection of this information can benefit consumers by enabling a carrier to detect a weak signal, a dropped call, or trouble with particular phone models. But if carriers collect CPNI in this manner, today's ruling makes clear that they must protect it.

The Declaratory Ruling does not impose any requirements on non-carrier, third-party developers of applications that consumers may install on their own. The ruling also does not adopt or propose any new rules regarding how carriers may use CPNI or how they must protect it.

The Commission can take enforcement action in the event that a failure to take reasonable precautions causes a compromise of CPNI on a device. This clarification avoids what would otherwise be an important gap in privacy protections for consumers.

Today's action is the latest by the FCC to protect consumer privacy as part of the agency's mission to serve the public interest. By taking action in this area, the Commission reaffirms that it is looking out for consumers in the telecommunications market.

Action by the Commission June 27, 2013, by Declaratory Ruling (FCC 13-89). Acting Chairwoman Clyburn and Commissioner Rosenworcel with Commissioner Pai approving in part/concurring in part. Acting Chairwoman Clyburn, Commissioners Rosenworcel and Pai issuing statements.


View the original article here

Tuesday, April 23, 2013

ACLU: Carriers Leaving Android Users Susceptible to Malware

AndroidLorenzo Franceschi-Bicchierai2013-04-18 19:31:38 UTC

In a world where malware targeting Android phones is used more and more everyday, security updates are fundamental to keep users away from malware and hackers. That's why the American Civil Liberties Union has filed a complaint on Tuesday, accusing mobile carriers of failing to distribute updates and fixes to their Android phones.

In its 16-page complaint filed with the Federal Trade Commission, the civil rights group pointed its finger at AT&T, Verizon, Sprint and T-Mobile, accusing the companies of leaving users vulnerable by providing them with phones running unpatched and outdated versions of the Android operating system, which "rarely receive software security updates."

"The problem isn’t that consumers aren’t installing updates, but rather, that updates simply aren’t available," wrote Chris Soghoian, the ACLU principal technologist and senior policy analyst, in a blog post. "Although Google’s engineers regularly fix software flaws in the Android operating system, these fixes aren’t packaged up and pushed to consumers by the wireless carriers and their handset manufacturer partners."

And that's because the majority of Android phones on the market don't run Google's native Android version but a carrier's customized version. The ACLU notes that these are effectively unique operating systems that need their own updates, and only the companies that modified the original Android source code can issue those updates. And most of the time, they either never do that or do it months later.

Moreover, according to the complaint, the carriers don't even warn the users about these flaws and vulnerabilities. And these failures, according to the ACLU, amount to "deceptive and unfair business practices."

If the carriers can't or are unwilling to issue security updates more frequently, the ACLU is asking the FTC to compel carriers to give their users a way to terminate their contracts early — without having to pay the usual termination fee — or allow them to exchange their insecure phones for newer ones, or to give them a full refund.

In February, the FTC ordered HTC America to patch security vulnerabilities in their phones. But in a tweet, Soghoian notes that with this complaint "we don't ask the FTC to force the carriers to issue updates, merely to tell consumers about flaws."

For Soghoian, putting pressure on the carriers to improve their security practices should be part of the government's commitment to improve the country's cybersecurity. "Cybersecurity threats are real, and improving security and privacy should be an important priority for the government," he wrote. "We think there are plenty of things the government can do to protect the computers and networks that consumers, businesses and government agencies depend upon without violating civil liberties. Investigating the wireless carriers and their role in smartphone security updates would be a great first step."

ACLU - Android Ftc Complaint

Image courtesy of Flickr, Family O'Abé

Topics: ACLU, Android, Apps and Software, FTC, malware, Mobile, U.S., US & World if(window.pageChanged) window.omni({"channel":"us-world","content_type":"article","top_channel":"us-world","content_source_type":"Internal","content_source_name":"Internal","author_name":"Lorenzo Franceschi-Bicchierai","age":"0","pub_day":18,"pub_month":4,"pub_year":2013,"pub_date":"04/18/2013","isPostView":true,"post_lead_type":"Default"}); metaData = {"link":[["canonical","http://mashable.com/2013/04/18/aclu-ftc-android-security/"],["image_src","http://rack.0.mshcdn.com/media/ZgkyMDEzLzA0LzE4L2MzL2FuZHJvaWQuNDUwNzIuanBnCnAJdGh1bWIJNzIweDcyMCMKZQlqcGc/55831739/0c2/android.jpg"]],"meta_property":[["og:url","http://mashable.com/2013/04/18/aclu-ftc-android-security/"],["og:title","ACLU: Carriers Leaving Android Users Susceptible to Malware"],["og:type","article"],["og:site_name","Mashable"],["og:image","http://rack.0.mshcdn.com/media/ZgkyMDEzLzA0LzE4L2MzL2FuZHJvaWQuNDUwNzIuanBnCnAJdGh1bWIJNzIweDcyMCMKZQlqcGc/55831739/0c2/android.jpg"],["og:article:published_time","2013-04-18T19:31:38Z"],["og:article:modified_time","2013-04-18T22:26:15Z"]],"meta_name":[["description","The ACLU asked the FTC to investigate mobile carriers for failing to provide timely security updates to users who own Android phones. "],["keywords",["android","malware","cybersecurity","ftc","aclu","uncategorized","apps-software","mobile","us-world","us"]],["twitter:title","ACLU: Carriers Leaving Android Users Susceptible to Malware"],["twitter:description","In a world where malware targeting Android phones is used more and more everyday, security updates are fundamental to keep users away from malware and hackers. That's why the American Civil Liberties ..."],["twitter:image","http://rack.2.mshcdn.com/media/ZgkyMDEzLzA0LzE4L2MzL2FuZHJvaWQuNDUwNzIuanBnCnAJdGh1bWIJNTYweDc1MAplCWpwZw/256154c7/0c2/android.jpg"],["twitter:site","@mashable"],["twitter:url","http://mashable.com/2013/04/18/aclu-ftc-android-security/"],["twitter:creator","@mashable"],["twitter:card","photo"],["twitter:image:width","560"],["twitter:image:height","750"]],"short_url":[["short_url","http://on.mash.to/11laPvx"]]};

View the original article here