Security of critical phone database called into question
washingtonpost.com
washingtonpost.com
In fact, NP databases typically won't have access to all phone numbers anyways, only those for customers who have changed providers. Everything else would be covered by the default routing rules.
In the US, the central database is not involved in call control (I've never seen a design that was). Since phone companies are very risk averse, they don't generally allow software they don't control into the middle of their interactions with the customer. Phone companies will have their own mirrors of the database and purchase (typically bespoke, typically outsourced) systems to perform the in-call lookups.
Reading up how the US works, it's an exception based system, with records only for ported numbers [1]. A typical record will look like:
(408) 555 1212 -> (715) 555 1212
The destination number is not a phone number, and has the granularity of a single switch. No names, or anything else.
I'm guessing this isn't about information leakage, because there's no information to leak. This isn't about DOS because the national database isn't involved in call control. This isn't about serving warrants either, it's operated locally.
I can only imagine that this is a trade barrier masquerading as security, since switch software is produced offshore, and that's riskier.
I hope they didn't use an open source database because otherwise the bad guys will have access to that too!
Seriously how stupid are the people in charge of this kind of thing if they can't differentiate between programs and data? Now having a fear that there may be back doors somewhere in there is a valid concern, but the answer to that is sunlight on the code and layers of least privilege on the execution environment.
This may seem a small thing and may be somewhat conceptually similar to DNS. But in reality it is an entire ecosystem of it's own with complexities that are not readily apparent. The incumbent (Neustar) has no obligation to share it's IP with Telcordia.
"The database is significant because it tracks nearly every phone number in North America, making it a key tool for law enforcement agencies seeking to monitor criminal or espionage targets."
This statement is potentially very misleading. The NPAC does not "live" route telephone calls. The NPAC is the database of ported phone number and various characteristics about them. The database is replicated to LSMS databases at the service providers. When you make a call it does not route through the NPAC. It routes through the service providers, period.
While the NPAC could be helpful to law enforcement for knowing which SP manages a particular number and various other characteristics about that number, it would not be helpful as some sort of one-stop shop for wire tapping.
From the NPAC site: "LSMS (Local Service Management System): The system owned by a service provider and which receives data broadcast from the NPAC/SMS. The LSMS provisions the service provider's downstream systems, such as its LNP call routing database. The LSMS is a mechanized system used (primarily) to receive data broadcasts from the NPAC/SMS."
I mean seriously what could any person do to such a project. You can't add a backdoor because your code gets reviewed (if it doesn't, then that's where you should start worrying about the integrity of the program). Furthermore, I hope that the programmers (foreign or not) do not have access to any real data.
Apparently it's OK if it's a Swedish company or there are British people working on it, but not them Chinese!
is 'compel' a synonym for 'paid'?