The Greeks can take credit for plenty of firsts, starting with modern civilization, democracy, mathematics and philosophy. Here's another they might not be in such a hurry to claim: the first known example of illegal wiretapping of phone calls using legally installed software.
No, I'm not making this up. Earlier this year, news broke that unnamed bad guys had been wiretapping the Vodafone cellular network in Greece from just before the Athens Olympics in August 2004 until March 2005. Targets reportedly included Greek Premier Costas Caramanlis, the mayor of Athens and senior state security officials. The leak was ultimately traced to software installed in the switches to enable the lawful intercept of traffic, which had been hijacked by rogue programmers.
That's right: Ericsson put wiretapping software in its switches to comply with legal requirements -- and the bad guys used it in decidedly illegal ways. What a surprise.
As you might expect, plenty of finger-pointing has ensued. Vodafone blames Ericsson, saying it had no idea the switches contained wiretapping software -- a claim adamantly denied by Ericsson's Greek CEO, Bill Zikou, who maintains that Ericsson provided all relevant details.
And everybody blames the Greek government for failing to expose and remediate the situation in a timely fashion. As a journalist pointed out during a briefing by the Greek government earlier this year (well over a year after the event): "It isn't the government that made it public -- it was the CEO of Vodafone."
Disturbingly, nobody seems quite sure of the culprits' identities, let alone their motives (though the selection of targets seems to clearly imply political aims). In one of the funnier moments during the whole episode, the Greek government initially denied the possibility the culprits could be Greek, on the theory that Greek geeks lack the technical knowledge necessary to pull off such a sophisticated hack -- surely news to the many world-class computer scientists and engineers who hail from Hellas.
Whether you're more concerned about unauthorized government intrusion or attacks by criminally minded geeks (and history suggests you should fear both), embedding tapability into the network is a bad idea.
Too bad we've codified this particular bad idea into our law.