4 ms·
I'm sorry but this sounds like bullshit. As someone who has access to such data at a telco: - Very few people have legit business cases requiring access to enr
by hocuspocus 5mo ago
I'm sorry but this sounds like bullshit. As someone who has access to such data at a telco:
- Very few people have legit business cases requiring access to enriched network telemetry, at least non aggregated.
- Of which, only a handful have any reason to see the MSISDN in clear.
- Of which, none can get access to clear CRM data.
- Lawful interception and emergency services use completely separate paths, exposed via user interfaces that aren't available to employees.
And obviously, a simple email to the data governance and privacy office would be taken extremely seriously.
Also why not simply switch to a different phone operator?
- hnthrow0287345 5mo agoI'm sure every single telco in the world is perfectly in line with this
- hocuspocus 5mo agoEven in pretty dysfunctional countries, or pro-business ones like the US, where nothing like the GDPR exists, telcos management have a strong interest in not letting just any rank and file employee spy on subscribers.
- throwawaysleep 5mo agoMost breaches are not in the interests of management, but they happen anyway as management wants to save money or doesn't understand how it could happen.
- lostlogin 5mo agoStalker terrorises woman, she reports it, nothing happens, stalker kills her. Queue hand wringing. It’s played out a lot of times, in a lot of places, I don’t know why everyone here is so cynical.
- mistrial9 5mo agoyou are close to a system in a way that those guardrails are clear and present; the story is from the point of view of a victim, and it is possible that they were indeed a victim. Therefore the means of the stalking is not known at all via this story, but somehow, something did occur. It is not surprising on either side, and they do not necessarily contradict each other IMHO
- hocuspocus 5mo agoI'm specifically talking about the technical aspect. Even with non-existent separation of concerns, and abysmal practices related to data governance which would be breaking the law in most of the developed world, the story sounds like bullshit. Extracting points of interest and reconstructing paths from raw network telemetry isn't trivial. The likelihood a random employee could run a quick SQL join to stalk someone based on their name is zero.
- throwawaysleep 5mo ago> And obviously, a simple email to the data governance and privacy office would be taken extremely seriously. What is this based on? I used to work for a data governance and privacy vendor that supplied data for audits. Tons and tons of customers asked us to fudge their data. This is after the Delve scandal, where the hottest tech compliance company was completely fraudulent and numerous other hot tech companies also had completely fraudulent audits. This is not a reasonable assumption.
- aetherspawn 5mo agoSo what you’re saying is if you were secretly a psycho and wanted to stalk your ex-girlfriend, you work at a Telco and basically have access to the tools to do it? So putting aside the fact you’re a reasonable person, anyone who works themselves up to a similar seniority and job description in a Telco as you, could in fact do exactly what the article is saying is an issue for the victims.
- subscribed 5mo agoI'm glad to hear that your random telco's governance and influence has spread around the entire world to every other telco. FYI: from the fact it's hard (not impossible) to see the data mentioned and it's possible (not guaranteed) that the caught offender would be punished is a VERY long way to "you lie". Theirs was anecdata, yours is anecdata but you're additionally rude.
- NitpickLawyer 5mo agoAh, I remember back in the day when "trust me I work in a telco and this is just dumb" people were really really silent after the room 641a stuff got leaked.
- hocuspocus 5mo agoSo now the random ex-boyfriend has access to the same tools as 3 letter agencies, got it. If you live in a country where you cannot trust law enforcement then there isn't much your telco can do. But specifically, these surveillance tools are not available to us.
- mtve 5mo ago50M+ subs operator, at least 10 employees can have both location and CRM data, I guess it's pretty typical. > As someone who has access to such data at a telco so you do have access :) > - Lawful interception and emergency services use completely separate paths, exposed via user interfaces that aren't available to employees. correct for LI, not for emergency. > Also why not simply switch to a different phone operator? yes, the only solution.
- hocuspocus 5mo ago> 50M+ subs operator, at least 10 employees can have both location and CRM data, I guess it's pretty typical. This shouldn't be the case anywhere in Europe or regions with similar laws. And we have a lot less than 50M subscribers. Anyway, there's really nothing that justifies having access to both. If you work on network quality and need enriched traces, personal data is completely useless. Most business cases don't even need stable, let alone clear IMSI. Very few people will need to look at a clear MSISDN for troubleshooting, and if you do things properly they shouldn't get blanket access to terabytes of daily telemetry. Aggregated CRM data can be useful to more high-level business cases, nothing that can be used to identify someone personally. Our data governance office doesn't even let us correlate anonymized and GDPR compliant data that we buy from third parties when the IDs are too stable, as it'd be fairly easy to match raw network traces. > so you do have access :) No I don't. Sometimes people move to different teams you know, and access to datasets I had in the past is mutually exclusive with some that I do have now. > correct for LI, not for emergency. If people that can see E112 payloads with GNSS locations exist, then I don't know they are, but I'm sure they can't have access to stuff relevant to the discussion here. On the network telemetry side, our job is monitoring and quality assurance. Anyway this kind of data is too sparse to be abused by a stalker.