Follow this blog:
RSS

How phone hacking works (and other lessons from the News Corp. scandal)

By | July 21, 2011, 4:28 AM PDT

Anyone who’s paid attention to the news lately has likely been bombarded with round-the-clock-updates on the phone hacking scandal that has ensnared Ruport Murdoch’s News Corp empire.

But if you looked past the melodrama being played out before the entire world, or even beyond the often-discussed concerns over press ethics and journalists’ unsavory ties to government officials, the unfolding scandal brings to light, in my opinion, an equally disturbing (if not worse) threat to the public at large: phone hacking.

How did the reporters do it? And since just about everyone these days has a voicemail enabled cell phone, how vulnerable are we?

Before we get to these questions, here’s a brief rundown in case anyone needs to get up to speed:

The crisis, which erupted earlier this month, has revealed that employees at the company’s British tabloid News of the World illegally accessed and tampered with the voicemail accounts of  terrorist victims, deceased British soldiers and Milly Dowler, a 13-year-old girl who was murdered in 2002. There also has been allegations suggesting that the illegal activity was not just an isolated case of a few rogue staffers misbehaving, but an elaborate and covert operation involving senior executives at News Corp., Scotland Yard and even the Prime Minister David Cameron.

The investigation is still ongoing so a more comprehensive picture of what transpired will take shape as more details come to light. But what we do know, at least in a technological sense, is that there are essentially three main tactics the intruders likely used to access private voicemail accounts, according to an in-depth report published by the popular tech blog Gizmodo. And to give you a well-informed idea of how this whole shady business of phone hacking works, here are the quick and dirty blueprints of these methods:

Tactic #1

1. The phone company provides an external number customers can use to access their inbox.
2. The service gives access to the caller dailing in if it recognizes that the customer is calling in from an approved phone number, like their cell phone.
3. The loophole in this system is that the service makes this determination by reading the incoming caller ID.
4. Crooks can easily spoof a user’s Caller ID using Voice Over IP and some software.

Tactic #2

1. Most of the time, the service offers an additional barrier of protection by requiring that the person calling in enter a four digit password.
2. The problem is that users are initially given a default password, which they can change once they access the system.
3. Typically, the default password is the last four digits of the person’s phone number.
4. Customers often don’t take the extra step to create a personalized password. Hackers know this and are more than happy to take advantage what can amount to be a serious lapse in judgement.

Tactic #3

1. For the sake of convenience, another way users can often access their voice mailbox is by dialing their own number and entering a secure password.
2. Hackers, too, have a way of mimicking this sequence, but it requires that they first have somebody occupy the user’s phone line.
3. While the line is being held up, a call to that number — with the correct spoofed caller ID –  goes directly to voice mail .
4. To get past the security password barrier, hackers would sometimes reset the code by calling the provider’s customer service department and successfully impersonating the user.

The report also highlights one of the major reasons why voicemail in particular has become such an easy target for hackers. It’s a scheme that can be pulled off repeatedly without rousing any sort of suspicion; no one knows if a message has been accessed if the hacker remembers to categorize the accessed recordings as new, a feature that’s also used with email.

Although there isn’t a 100 percent foolproof way to protect against such transgressions, most instances of phone hacking can be prevented simply by activating a personal security code that no one else knows. Steven Rambam, an investigator and director of Pallorium, Inc., told Gizmodo that “90 percent voicemail-specific problems can be prevented if strong passwords are put into place.”

To fortify security measures, companies can also require more stringent criteria to verify the identity of customers requesting sensitive information, says SPP Blue security expert Hemanshu Nigam, in an interview with the Washington Post.

If as a society we learn anything from this, it’s that the more barriers put in the place, the more we can deter the bad guys from making us targets.

Major hat tip: Gizmodo

Related on SmartPlanet:

Learn more about crime fighting tech:

Start your week smarter with our weekly e-mail newsletter. It's your cheat sheet for good ideas. Get it.

Tuan C. Nguyen

About Tuan C. Nguyen

Tuan C. Nguyen was a contributing editor for SmartPlanet from 2011 to 2013.

Tuan C. Nguyen

Tuan C. Nguyen

Contributing Editor

Tuan C. Nguyen is a freelance science journalist based in New York City. He has written for the U.S. News and World Report, Fox News, MSNBC, ABC News, AOL, Yahoo! News and LiveScience. Formerly, he was reporter and producer for the technology section of ABCNews.com. He holds degrees from the University of California Los Angeles and the City University of New York's Graduate School of Journalism.

Follow him on Twitter.

Tuan C. Nguyen

Tuan C. Nguyen

Tuan C. Nguyen does not hold any investments in the technology companies he covers.

He writes for SmartPlanet and is not an employee of CBS.

If you liked this, don't miss...
2
Comments

Join the conversation!

Follow via:
RSS
+3 Votes
+ -
Security isn't valued.
The biggest problem is that nobody values security--until it's broken.

It's not usually a priority with either consumers or corporations ore even government.

This has encouraged vendors to ignore security too. The modern marketing model cares only about what will get the customer to purchase--what the customer may need that they are unaware of, is sold only based upon it's known marketing value.

ATM's ran for 5 years without even loss insurance, much less encrypted traffic.

The default system should be secured, you should have to actively unsecure your system (of whatever type computer, phone whatever.)

This hacking is merely an extension of the cellphone monitoring which used to be the common way to intercept cell calls.

To date, there are no unspoofable systems (though some biometrics are close,) but then, security is always a matter of who is willing to spend the most...any security can be beaten by someone with enough resources.

The unfortunate truth is that most information is not at all secure--taking almost no investment to circumvent.

How can anyone be surprised that journalists (who are paid based upon their ability to create sales--to deliver unique data,) would use the same methods that the government routinely use, often with even less probable cause?

I'm fairly certain that few if any truly secure systems will be developed & sold until the law requires system security.... Like insurance, security is way down on the list of things people consider.
Posted by wizoddg
21st Jul 2011
+1 Vote
+ -
thanks for sharing
Great!!! thanks for sharing this information to us!
sesli chat sesli sohbet
Posted by yarinsiz
Updated - 24th Aug 2011
Join the conversation
Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

Join the SmartPlanet community and join the conversation! Signing up is fast and free. Don't wait -- we want to hear your opinion!