Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

11–20 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#11

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place.

Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#12
Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such.

Could be a coincidence, or it could be the data is already out and being used.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#13
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

Just this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#14
post #3

> Here is the data that is available in this leak: Name Phone number Physical address Email address Social security number Date of birth Not only the phone number but the physical address? If this is true, absolutely outrageous. > The hacker has said he is willing to reach “an agreement” with AT&T to remove the data from sale. Might as well pay the hacker's ransom, AT&T to remove the data from sale otherwise if leake…

> a massive fine (probably larger than the hacker's ransom) awaits you.

If you mean, massive executive bonuses, and zero policy response by the government, then yes.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#15
post #11

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

With AT&T at least if you want the highest priority on their towers you have to be on their Elite plan (QCI 7 I believe), which is post-paid only

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#16
I'm usually skeptical about denials, like AT&T is doing here. But in this case, there would be some incentive for the hackers to misrepresent the source/freshness/etc of the data.

Given the recent T-Mobile hack, if they can tag the data as coming from AT&T and being fresh, it might fetch a higher price either from AT&T, or data buyers. In other words, it could be a re-label of some older exposed data.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#20
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

+1.

And orgs (gov and private) will continue to just ask for completely unnecessary information because, why not? Throw it in some database with root:root as the pw and shrug when it gets breached. It really needs to stop. The only person that loses is the person that now has to potentially deal with identity theft or getting doxxed for the rest of their life...

Post reply on HN