TeleSign profiles half of the world’s mobile phone users
noyb.eu
noyb.eu
Pepperidge Farm remembers
What can we say about a corporation doing a trust score for half of the connected population in the world ? I wonder about their ego, or what went wrong in their management.
I'm getting seriously disillusioned with all this surveillance stuff. At first I thought, you know, these were isolated incidents falling through the cracks, but in truth it's become pervasive and global. The scariest aspect is how individual actors have the ability these days to gather, interpret and isolate individuals from massive datasets, anonymising the data seems pie in the sky.
I don't see much stopping it either, in society it seems to be the extremes, some wrongly think GDPR applies to everything and others are so sophisticated they can bypass it completely. Have we gotten too advanced, whereby only experts understand the impacts of our actions? Sorry I'm getting all philosophical.
Well, literally billions of people accept their privacy agreements and actively provide them with data from their phones by using their software. That's quite different from an unknown party telling other companies whether you're reliable without your knowledge based on data neither you nor your provider ever agreed to give them.
A translated complaint is available at https://noyb.eu/sites/default/files/2023-06/DRAT%20TELESIGN%...
https://onezero.medium.com/google-ads-targeted-at-literally-...
The article didn't insinuate that data is being used to objectively harm users. It's being used to generate "trust scores" for anti-fraud systems. The specific example given in their piece is allowing a user to attach a certain number for SMS verification.
Rather, the point here is that such data could be used to objectively harm users, so those users should have to provide consent. Second to that is that BICS doesn't appear to inform users requesting GDPR data that their data was shared.
I'm not sure I'd label that failures in ego, it smells like failures in process and compliance, which also need to be dealt with in lawsuits.
You may ask: Then why do banks not protect me from losses better? I say: They're already doing something (invisible as it may be). They can definitely do a better job. But without companies such as Telesign, fraud losses would far, far worse.
You may ask: What if my data gathered is used for nefarious purposes? I say: In my experience, data such as this is not allowed to be used for marketing purposes but strictly for consumer protection. I'm not specifically speaking about TeleSign but similar vendors. The worst that should happen is that you get a transaction declined, or get denied for a credit card etc. But no marketing or any other manipulative practice is allowed, in theory.
Happy to answer any questions you may have :)
Until banks accept that they got defrauded, not you, whatever they do will be too little.
True. Regardless of accepting responsibility, I think they're spending a good bit of money in preventing fraud from happening [1]. Maybe some regulation around banks taking fraud losses would do the trick but the flipside would be that simple financial flows of legitimate customers would become full of friction as banks race to lock down fraud losses. Fraud detection is a really hard fraud problem for even a human, let alone models.
[1] https://bankingjournal.aba.com/2022/01/study-banks-see-rise-...
Virtually most of the fraud is happening due to customer's own fault, not strictly bank's fault:
1. installed malware and got all saved CC data stolen
2. website you ordered your widgets got hacked and your CC stolen
3. clicked phish linked and lost your online bank credentials
4. got scammed and sent zelle to a scammer
5. used shady website to order deeply discounted electronics / signed up for adult membership website - and gave your CC data right into hands of fraudsters
6. used shady third party ATM in tourist place like Cancun and got your card skimmed etc
7. used same user/pass credentials for online banking, as your email account, and your online bank got taken over
Sure all of us can learn to be more careful with tech, but the way banks frame fraud against them as identity theft against you is slimy doublespeak.
Disable online banking, use checkbook and write checks everywhere or carry cash. I still see older people use checkbooks from time to time, even shopping groceries.
Problem solved.
We require drivers license to operate vehicle, it is time we should require infosec101 training before handing over credit cards and or online banking accounts.
So that you cannot blame the bank for your own fault.
Or migrate to something Apple Pay, but that also does not guarantee 100% fraud prevention
Let's flip the omelette: no one forces banks to do business online; if a bank can't build secure online banking, they can default to checkbooks and cash. They have the means and motive to build solutions that are actually secure and usable, so they should bear the burden of dealing with fraud when their solutions fail to be secure.
I always used online banking and never got scammed. It is pretty secure for me.
Combination of user & password with enough entropy, and basic brute-force defense that blocks after 3-4 attempts is the industry minimum standard.
User is the weakest link always, you cannot fix the "stupid" user that downloads malware, warez, adult content and gets infected and loses everything.
These people need life lesson to learn how to operate technology safely.
Although I agree that online banking could be made more secure, but the threat model will immediately evolve and adapt because scammers/fraudsters are still there and they want to eat.
Ok, granted, I spent the last 23 years of my life working in IT security across consulting, government, finance, and tech companies, but this is just garbage. Banks only invest in security to the degree that: - they are legally required to - they have contractual obligations to - that the risk of loss for a specific class of incident exceeds their self-insurance threshold
That's not a hypothetical comment, that is something that was explained to me as an AppSec lead when running into walls trying to get some issues fixed at one of the largest banks in the world. For the record, the issues that I was trying to have remediated would have had to exceeded an annualized loss expectancy for the region I was operating in of 10 million dollars per year to be considered risky.
Your definition of a bank being pretty secure and mine are probably radically different.
> Combination of user & password with enough entropy, and basic brute-force defense that blocks after 3-4 attempts is the industry minimum standard.
Sure, users should choose strong passwords. Banks should also require multi-factor authentication (real 2fa, not the SMS based weaksauce that a bunch use). But, that increases support and transaction costs. So, instead, blame the user! Beyond password selection, there is also the issue of how passwords are hashed, salted, stored, and brokered into a more reliable back-end credential that can be used, absolutely none of which the user has input into or control over, but sure, blame the user.
> User is the weakest link always, you cannot fix the "stupid" user that downloads malware, warez, adult content and gets infected and loses everything.
sigh you really like banging that drum.
> These people need life lesson to learn how to operate technology safely. > Although I agree that online banking could be made more secure, but the threat model will immediately evolve and adapt because scammers/fraudsters are still there and they want to eat.
There is absolutely no way to train average users to operate modern internet technologies safely because the average user has no effective control over the software and hardware they use (yes, Linux is a thing, and so is open source hardware, but users of those OS and hardware are not average users)
The primary reason the incidence of fraud is so high in the finance sector is because business has chosen to optimize for high transaction volume, and has accepted the risks of doing so. Stop trying to blame end users.
The reality of any non-trivial issue is that we have to consider potential improvements from all angles. I want to improve tech for grandma and for the bank, doesn't that seem like a goal worth working towards? And let's please not pretend that banks are infallible in all of this, they also have opportunities to improve.
People must adapt, because it is unreasonable to expect the world to adapt to the most naiive user. You either will get mugged every day, or you learn your lesson and move out to safe neighborhood, or you buy a gun and solve mugging problem for everybody else one shot at a time.
same with fraud - user will continue getting defrauded and scammed until user learns the lesson and either abandons tech he.she is unable to use securely, or adapt and learn how to use it
It's almost cute how you think people living in places with high crime rates wouldn't jump at the chance to move to a nicer neighborhood with lower crime rates, and that the reason they don't is because they haven't "learned their lesson".
Everyone buying guns and then going around shooting criminals is not a solution to crime, but if you're convinced it's a good idea, why not try it for yourself and "learn your lesson"
I grew up in high crime third world country and all young with half a brain folks emigrated as soon as they could.
The rest had to adapt and cope, due to different life choices and trade offs.
Yes you can blame the government for being unable to fix high crime, and sit helplessly while waiting for the same government to fix the problem.
Or you can get matter in your own hands and solve it the way you can.
Fraud problem cannot be attributed to banks 100%, given that users are at fault
Sure. Why not start with an outline for what infosec101 should look like. Include estimates for how long the training should take, what the cadence for testing should be, and which agency should be responsible for validating that training. Do be sure to accurately communicate the degree to which an end user with a chip enabled bank or credit card has the ability to distinguish and disambiguate what constitutes a 'safe' or 'legitimate' online business. Also, include some details about how individuals who have been certified as completing this class and/or licensing scheme should procure insurance to protect themselves in case of an accidental data breach (for example, they leak their card info), and outline the process by which that same licensee can file an insurance claim against the insured party downstream of the physical point of payment or online payment portal that allowed a breach to happen. After all - if we are going to require online safety training, and licensing, then we should create another insurance scheme to facilitate resolution of those claims and resolve the costs.
It is really easy to point the fingers at a customer and say "problem exists between chair and keyboard", but the reality is that in the modern economy, the end user has almost no control over the security of their transactions, and little ability to influence how their purchase is handled beyond the question of "cash or card".
The only incentive that retailers, online stores, payment processors, and financial institutions have to resolve this is the simple fact that they own the liability for this, and it's only through the myth of the idiot user that they have been able to shift that liability, to varying degrees, back to the consumer.
2. That is not the customers fault. Full stop. Yes, some sites are more shady than others, but there is nothing a consumer can do to determine if a service provider will get hacked.
3. Yes. Unfortunately, phishing is really easy. Despite the prevalence of this attack, training users to effectively detect and avoid being a victim is almost impossible.
4. See #3.
5. See #2.
6. How is a customer supposed to validate the security of an ATM against modern skimming technology, many of which are virtually indistinguishable from normal bank machines.
7. Yep, not great. Why don't banks require 2FA? Because it creates friction and increases costs. Better to just externalize the risk.
Your entire blame the user argument is bunk that has been packaged up and recirculated by the finance community for almost 20 years (and I have been using these arguments against them for nearly that long, granted it's close to ~12 years since I worked in infosec at a bank).
That's fraud prevention right there.
Which, in a cashless society, can mean you have no money since you can't spend it
How come all online VISA transactions don't have to completed through a redirect to visa.com or master.com (or may bank website), but instead we're typing card numbers into sketchy websites? (I guess EU 2FA requirements are pushing the boundary, but very slowly and often in ways that still appear remarkably sketchy).
Trust scores of IPs and phones numbers is a tool, but when physically hardened security tokens aren't widely supported, I'd argue the essential tools simply aren't available to users.
[1] Before smartphones a hardware token that requires your physical card was used.
I support your argument about Yubikeys - I myself use them for any financial site that allows it. A lot of companies do use them to check for fraudulent logins. But the friction of it is high enough that companies would much rather take the loss than force their customers to authenticate every time a transaction has to be made. Also, I think until it is normalized in the industry, there is a consumer perception of physical keys being too technically difficult to obtain, set up and manage. Not to mention, all the Yubikeys in the world still don't help if one goes and gets phished/socially engineered :)
The question here isn't (primarily at least) whether this is a good or bad thing, the important question is if this arrangement is legal under EU law. It can be the most beneficial thing in the world and still be illegal.
1. The former is likely using a throwaway phone number, the latter is using an established phone number. You can tell the difference with the number of completed calls over time, call duration etc. Burner phones will have bursts of high intensity activity to several different phone numbers whereas legitimate phones will have lots of successfully completed phone calls over a long period of time to repeating phone numbers.
2. The former will likely place calls all over the country or world as they attempt to raid several bank accounts digitally. The latter will probably have more local calls since they're calling their doctors, schools, etc. This is probably where range activity plays a role.
I'm not defending Telesign or how they collect data - I'm merely saying this data has value in account protection.
However, I do think there is room for protocols that verify phone numbers in a way. The spam and fraudulent calls that people receive and are hard to distinguish from “good” calls is a problem that deserves more attention.
Scam calls are almost unheard of in Europe. Why is it such a problem in the US?
So, just because you can in theory, doesn't mean you can in practice. Let us know how it works out for you!
Of course there is: sign up and use their API.
For many years I had the "Ekata Reverse Phone" API enabled in my Twilio account which allowed me, for 8 cents or something, to query a phone number and see subscriber history, "related subscribers", address history, etc.
Kind of a neat party trick.
It also allowed me to verify and re-verify that the fictional nyms my SIM cards and phone numbers belong to have almost zero history or identification ...
I got randomly assigned a "troubled" phone number once. It was a PITA. It should probably be illegal for phone companies to recycle numbers from old users with certain types of legal or financial problems, to innocent random new users who are literally paying for the privilege of inheriting a hot mess.
These are mostly behemoth created as a consequence of the West rising at the time.
By asking to have your data through a GDPR request you are effectively giving to the receiver of the request:
1) your full name
2) your phone number
3) your e-mail
i.e. basically a confirmation that both the phone number and e-mail are good/active/attended and that they are yours (and that you "exist"), while the data they may already have likely is only the telephone number and the patterns of its usage.
I have no idea how it could be possible to make a valid request without providing this kind of info (i.e. providing only the phone number, which they already have).
Maybe a sort of (public/certified) authorization service?
I use different names/email on every site, but phone numbers are always these 2~3 numbers. If I'm going to send a deletion request under GDPR alike laws, it would be under different names.
Pretty much. Only your person has rights, not the fake identities you created. They can actually request a copy of an ID or something comparable to confirm your identity. You might have a hard time removing your data, in some cases, when using fake names since then your identity can't be confirmed.
And when you (if asked/needed by the procedure) provide a copy of your ID, you are actually giving them other data points, like your birth date, often nationality, and in some cases even the address of residence.
But if they only know u/lucb1e to own +31612345678, then it's all good and well that you're requesting data as Luc Lastname but that's not going to match their records anyway; that doesn't prove you're the legitimate person to send this data to.
> They can actually request a copy of an ID or something comparable to confirm your identity.
When I called the Dutch DPA about this, specifically about MAC address tracking (I got an email "welcome to ikea!", sent to anothercompany@lucb1e.com, when I connected to ikea's free wifi), and they said that supplying the MAC address is the identifier to use because that's the only thing they can match anyway. This was in 2018-ish so I may misremember details, to be fair.
As far as I know, this is similar to copyright under a pseudonym. If you can't prove it's yours, sucks, but if you can, then your rights are yours to exercise.
Then, your phone number and emails are in any of your resumes, business card, subscription forms, contact details for any web service... They're not exactly private information anyway
And I'm sure anyone can call your phone number and listen to the message of the voicemail, in which most ppl say their name out loud anyway. Lastly, isn't your email address firstname.lastname@gmail.com, as for most folks ?
I'm going to guess that for 'most folks' there's probably someone else with the same name and therefore this way of guessing someone's email address is far from reliable.
It's actually so unreliable that one email address I have receives mail for others who for some reason think it's their email. This includes plane tickets, accounts for phone contracts and order confirmations.
Ask me about the Brazilian teenager with my name who keeps using my email to open facebook accounts that I keep recovering the password for and closing.
There's also the fact that the law does say that this personal data can only be use for the purpose of providing user data and must then be deleted. But we also know that there's little chance companies like this will do that.
It's a double edged sword, but I'm going to err on the side of danger and send in a data request anyway. My curiosity is much bigger than my fear of providing them my e-mail address.
I feel defenseless against these sophisticated international corporation mass surveillances. Sending GDPR to each of them when you have learned their existence is like whac-a-mole.