The FCC unanimously approved an anti-robocall proposal requiring telecoms and VoIP providers to verify user identities before activating service. The rule aims to combat robocalls but raises privacy concerns.
The new FCC requirement marks a significant shift in how phone services operate. Telecommunications companies and VoIP providers must now confirm customer identities during account setup, eliminating anonymous phone number activation.
The measure targets the robocall epidemic, which has plagued consumers with unwanted calls. By linking phone numbers to verified identities, the FCC hopes to deter bad actors from using spoofed numbers for scams and spam.
However, privacy advocates argue the rule creates risks. Centralizing identity data across telecom networks could expose personal information to breaches. Activists worry the verification requirements may disproportionately affect marginalized groups seeking communication privacy, including abuse survivors and journalists.
The proposal doesn't specify how much data providers must collect or how long they retain it. Implementation details remain unclear as the telecom industry develops compliance frameworks.
The rule represents the FCC's most aggressive anti-robocall action to date, following years of consumer complaints about malicious calling campaigns.
A browser extension with 30,000 installs available on Chrome and Firefox stores transmits users' Twitch OAuth session tokens to a commercial bot service, exposing sensitive authentication credentials.
OpenAI's web-crawling bots were aware of a significant caching vulnerability in RubyGems before public disclosure, raising questions about vulnerability discovery and responsible disclosure practices.
Attackers compromised HBO Max's official Reddit account to distribute malicious ads using ClickFix exploits. The campaign targeted Windows and macOS users with information-stealing malware.
OpenAI has hundreds of contract workers reviewing real ChatGPT conversations and rating them to improve the model. The practice is enabled by default, requiring users to manually opt out.