The FCC unanimously approved an anti-robocall proposal requiring telecoms and VoIP providers to verify user identities before activating service. The rule aims to combat robocalls but raises privacy concerns.
The new FCC requirement marks a significant shift in how phone services operate. Telecommunications companies and VoIP providers must now confirm customer identities during account setup, eliminating anonymous phone number activation.
The measure targets the robocall epidemic, which has plagued consumers with unwanted calls. By linking phone numbers to verified identities, the FCC hopes to deter bad actors from using spoofed numbers for scams and spam.
However, privacy advocates argue the rule creates risks. Centralizing identity data across telecom networks could expose personal information to breaches. Activists worry the verification requirements may disproportionately affect marginalized groups seeking communication privacy, including abuse survivors and journalists.
The proposal doesn't specify how much data providers must collect or how long they retain it. Implementation details remain unclear as the telecom industry develops compliance frameworks.
The rule represents the FCC's most aggressive anti-robocall action to date, following years of consumer complaints about malicious calling campaigns.
Pharmaceutical giant Amgen confirmed a data breach affecting multiple cloud systems operated by third-party providers. Threat actors accessed both patient health information and proprietary corporate data.
Arch Linux has temporarily disabled the adoption feature for Arch User Repository (AUR) packages following a spike in malicious takeovers. The move aims to prevent attackers from seizing control of unmaintained packages.
Tailscale's security network failed to prevent an intrusion at Hugging Face, according to a new blog post from the company. The incident highlights limitations in network-based security approaches.
Advertising platform Adform fell victim to a supply-chain attack that injected malicious code into its ad scripts, redirecting cryptocurrency wallet addresses from users' clipboards to attacker-controlled accounts.