HomeWAV, a video visitation provider used by prisons across the US, exposed private calls of inmates with their families and attorneys, on an unprotected server
What distinguishes the HomeWAV incident is the content at stake: video visitation calls between inmates and their families and attorneys, sitting open on an unsecured server. With three major prison-telecom vendors now tied to public exposures in five years, the question shifts from any single company's hygiene to whether correctional facilities can vet the security of the vendors they contract for privileged communications.
First-order effects
Inmates and their families and attorneys face immediate harm: private visitation calls were exposed on an open server, and prisons relying on HomeWAV must decide whether to suspend or audit the service.
Second-order effects
Rival vendors Securus and Telmate — both already linked to prior exposures — now compete under a cloud, pushing corrections departments toward security requirements in procurement contracts rather than price alone.
Third-order effects
If the pattern holds across HomeWAV, Telmate, and Securus, prison telecom is headed toward regulated security standards and independent audits for systems carrying attorney-client communications, since market discipline has repeatedly failed to prevent basic misconfigurations.
The trend:US prison telecommunications is consolidating around a small set of vendors whose repeated data exposures are turning correctional communications from a contracting afterthought into a security-regulation problem.
Also see: payment provider to send money to prison. HomeWAV, a video visitation provider used by prisons across the US, exposed private calls of inmates with their families and attorneys, on an unprotected server (Zack Whittaker/TechCrunch) https://techcrunch.com/...
“Anytime I have a client who calls me from a jail, I'm very conscious and aware of the possibility not only of security breaches, but also the potential ability to access these phone calls by the county attorney's office.” - Daniel Repka (via @TechCrunch) https://techcrunch.com/.…
ICYMI: A prison video visitation company exposed thousands of inmate calls, including calls with their lawyers meant to be protected by attorney-client privilege. @ACLU said the rights of prisoners “are the first to be trampled when the system fails.” https://techcrunch.com/...
ACLU's @SomilBTrivedi told me: “Technology cannot fix the fundamental failings of the criminal legal system — and it will exacerbate them if we're not deliberate and cautious.” https://techcrunch.com/...
A company called HomeWAV operates video software for lawyers and their clients in prison—helpful during #COVID. Then it transcribes the privileged convos and doesn't password protect them—less helpful. Also, as I told @TechCrunch, illegal. https://twitter.com/...
New: A security lapse at a prison video visitation company exposed thousands of inmate phone calls to the open internet. Some of the calls were between inmates and their defense lawyers, and protected by attorney-client privilege, the lawyers told me. https://techcrunch.com/...
Recording attorney-client conversations is **very** illegal. Some —if not multiple— state attorneys general need to start an investigation https://twitter.com/...
I spoke with two lawyers whose conversations were found on the exposed system. Both were alarmed that their calls, which they said were protected by attorney-client privilege, were recorded. More: https://techcrunch.com/... https://twitter.com/...