Corporate Security Practices: Can Verizon Handle Yahoo?
This post describes a specific situation I encountered with Verizon but has some general implications for how individuals should remember to protect their own personal digital security. And how companies should protect customer data.
I start with what prompted me to think about security. I have a an iPhone 7, which like all others, is brand new. This weekend I used mine traveling from DC to NYC and back by train. LTE service dropped regularly and failed automatically to re-connect. This sometimes happened on my prior iPhone but is chronic on the 7. For every LTE drop, I had to go in and out of airplane mode to get LTE back. A coda on this problem is at the end
I had little spare time in NYC so raised this issue with Verizon via the one remaining asynchronous channel, social media, @VZWSupport. Other support channels are synchronous, so more time consuming.
When I posed the problem to VZWSupport, it asked for my “Mobile Number Account PIN”, an access code for Verizon voice support. I was unhappy. I pointed out – as I did in a June 2015 interaction – that while I am not a security expert, asking for passwords is a bad practice. Indeed, many companies routinely say “We never ask for passwords”.
Having my PIN in plain text on a shared Twitter account strikes me as risky. A bad employee might troll direct messages to seek personal information for nefarious purposes.
The lesson for everyone is to remain hyper vigilant in remembering security hygiene. Don’t assume big companies follow best practices. In my opinion, Verizon Wireless engages in a bad security practice.
The lesson for Verizon and Yahoo investors is to consider, if my assessment above is correct, does this signal deeper Verizon security practice problems. And, if so, can Verizon address the massive Yahoo data breach. Having just had to change my Yahoo password and delete security questions and now seeing Verizon ask for a password, I have doubts.
Coda: Had @VZWSupport been properly informed, they would not have needed to access my account. It turns out LTE dropping is a known iPhone 7 issue, explained in this Reddit discussion. Moreover, when I I connected with Verizon by phone and chat, they knew about the issue. So I draw two other lessons: (1) search the web before seeking help from a big company and (2) beware that social media teams may exist more to make nice than to provide real help.
- Alternative Legal Provider (36)
- Artificial Intelligence (AI) (52)
- Bar Regulation (13)
- Best Practices (39)
- Big Data and Data Science (11)
- Blockchain (10)
- Bloomberg Biz of Law Summit – Live (6)
- Business Intelligence (21)
- Contract Management (19)
- Cool Legal Conferences (10)
- Do Less Law (38)
- eDiscovery and Litigation Support (165)
- Experience Management (8)
- Extranets (11)
- General (191)
- Innovation and Change Management (162)
- Interesting Technology (97)
- Knowledge Management (221)
- Law Department Management (14)
- Law Departments / Client Service (113)
- Law Factory v. Bet the Farm (28)
- Law Firm Service Delivery (112)
- Law Firm Staffing (25)
- Law Libraries (5)
- Legal market survey featured (5)
- Legal Process Improvement (24)
- Legal Project Management (26)
- Legal Secretaries – Their Future (17)
- Legal Tech Start-Ups (3)
- Litigation Finance (5)
- Low Cost Law Firm Centers (20)
- Management and Technology (179)
- Notices re this Blog (10)
- Online Legal Services (63)
- Outsourcing (135)
- Personal Productivity (39)
- Roundup (58)
- Structure of Legal Business (1)
- Supplier News (13)