[736] in Privacy_Forum

home help back first fref pref prev next nref lref last post

[ PRIVACY Forum ] Blaming Google and Android for Calling ID Spoofing

daemon@ATHENA.MIT.EDU (privacy@vortex.com)
Tue Jun 29 23:02:49 2010

Date: Tue, 29 Jun 2010 19:43:17 -0700
To: privacy-list@vortex.com
Message-ID: <20100630024317.GG15881@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: privacy@vortex.com
Reply-To: PRIVACY Forum Digest mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit



            Blaming Google and Android for Calling ID Spoofing

               http://lauren.vortex.com/archive/000727.html 
                   

Greetings.  An article on Slashdot today ( http://bit.ly/bkwFz1 )
seems to blame Google and Android for the ease with which two Caller
ID spoofing programs can manipulate Caller ID and gain illicit access
to AT&T (and other) voicemail systems.  It even attempts to draw in
the (to my mind irrational) complaining about Google's accidental
Wi-Fi payload data collection.

I've talked about CNID (Calling Number ID) spoofing various times
before, but let's be really clear about this.

CNID spoofing is not the fault of Android or Google, any more than
it's the fault of Time Warner or Comcast when users access Web-based
CNID spoofing services.  The fundamental problem is that the CNID
system was never designed for an environment where, to use the
vernacular, every Tom, Dick, and Harry has access to the underlying
subsystems, a problem that has become much more serious with the
rise of VoIP/SIP-based access mechanisms.

A rather comprehensive history of CNID spoofing and related areas is
at http://bit.ly/9DQUWS (calleridspoofing.info) and makes for useful
reading.  (This falls into the "it takes one to know one" category of
Web sites, apparently.)

As for Voicemail vulnerabilities, it is the unwillingness of various
voicemail services to set reasonable initial passcodes on accounts that
makes them vulnerable to spoofing attacks in the first place, when users
assume (incorrectly) that passcode-less access from their cell phones
is safe.

Google Voice, as an example of the correct approach, makes users
*explicitly* aware of spoofing risks, and requires additional
confirmation steps, if attempts are made to set up accounts without
passcodes.

There are legitimate situations where manipulation of CNID data is
completely reasonable.  Services (like Google Voice, for example) may
want to pass through calling number data so that called parties
have accurate information regarding the origin numbers of callers.
Businesses may want to send their main number as the CNID reference,
not extension numbers, which may not even take incoming calls.  

There are concerns that currently pending U.S. legislation to outlaw
nefarious CNID manipulation might adversely affect legitimate uses.  My
belief is that it should be possible to craft wording in the final
legislation that would protect such honest applications -- this
is indeed important.

I do feel though that it is also important that U.S. federal law be on
record that use of Caller ID spoofing for the purpose of intentionally
*falsifying* the identity of a caller is generally unacceptable and so
would normally be subject to appropriate legal sanctions.

--Lauren--
Lauren Weinstein
lauren@vortex.com
Tel: +1 (818) 225-2800
http://www.pfir.org/lauren
Co-Founder, PFIR
   - People For Internet Responsibility - http://www.pfir.org
Co-Founder, NNSquad
   - Network Neutrality Squad - http://www.nnsquad.org
Founder, GCTIP - Global Coalition 
   for Transparent Internet Performance - http://www.gctip.org
Founder, PRIVACY Forum - http://www.vortex.com
Member, ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Twitter: https://twitter.com/laurenweinstein



_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy


home help back first fref pref prev next nref lref last post