Michael Kleeman, a communications network expert at the University of California
, San Diego, explained that AT&T should never have stored the information on a publicly accessible Web site. But he added that the damage was likely to be limited. "You could in theory find out where the device is," Mr. Kleeman stated. "But to do that, you would have to gain access to very secure databases that are not generally connected to the public Internet."