Live data from Hacker News

Claimed AT&T hack of 70M customer records including SSN, name, address

9to5mac.com

21–30 of 167 posts

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#21
post #8

It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...

I guess that website admins dont really care as it is a sufficiently good measure to reduce spam/spam accounts/new registrations.

Yes, I am a pessimist and I believe that. Why should website x care that there is a probability that the ISP is going to be hacked.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#22
post #16

I'm usually skeptical about denials, like AT&T is doing here. But in this case, there would be some incentive for the hackers to misrepresent the source/freshness/etc of the data. Given the recent T-Mobile hack, if they can tag the data as coming from AT&T and being fresh, it might fetch a higher price either from AT&T, or data buyers. In other words, it could be a re-label of some older exposed data.

The hackers selling the info are well known for providing fresh data, to the point that they’ve given away old data for free. I doubt they’d risk their reputation on reselling a different leak.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#23
post #12

Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.

I received the exact same thing. I was also a customer of AT&T around 4 or so years ago.

The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#24
post #11

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

This situation could be greatly improved if these companies didn't have or need to have this data in the first place. Prepaid mobile plans carry a lot of stigma with them - perceived to be "low-class", or even criminal by many. But at least your SSN and address won't be in their database.

I don't know about the US, but here in the UK prepaid mobile isn't necessarily looked down upon, but it's significantly more expensive than a contract. It's the main reason why people just go with a contract despite being locked in for 2 or more years. Even sim-only contracts are considerably cheaper.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#25
post #23
post #12

Interestingly, I stopped being an AT&T customer 4 years ago but just this morning I received a phishing SMS containing my real name and a mention of AT&T overpayment or some-such. Could be a coincidence, or it could be the data is already out and being used.

I received the exact same thing. I was also a customer of AT&T around 4 or so years ago. The odd thing to me was the phishing text said to CALL ATT's very own number. No links or anything.

Mine included a link. I already removed it so can't look at it now, but it definitely included one of those minified links that immediately scream "phishing".

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#26

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

A converstation earlier this week pointed out the EU system: eIDAS [0]. it looks pretty interesting how its decentralized.

I could see something like this running from each state's DMV (or the postal service if you didn't want to use your local state DMV) to help ensure you are you.

It would be interesting to hear what people that use it say, because i'm sadly stuck in a very US world :)

[0] https://en.wikipedia.org/wiki/EIDAS

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#27

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

if the cost of identity theft, i mean bank fraud, was put on the banks this would be less of an issue.

all companies do not need better security. banks need better processes so my ssn and address cant be used to mess up my life.

the banks have the money to fix this.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#28

When does this end? When do our useless governments put a stop, once and for all, to these ridiculous lax security practices in corporations? I feel like I'm being forced to become a luddite--not because I don't love technology but because it's being used for such evil and potentially life-destroying purposes.

Our government is run by a gerontocracy born decades prior to PCs and the internet. They have no idea what the root problem is or how to fix it. How many of them even know the absolute basics? What a for loop is? Or Postgres? Or http vs https? Anything they actually do will be written by lobbyists on behalf of tech giants and other multinational corporations and big donors.

Between that and the increasingly fundamentalist, censorious, puritan, social justice takeover of tech companies, I also feel like I'm being forced to become a luddite despite my life long love for technology.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#29
As I've said before, it's time to wipe the slate on SSN's. They are de facto public anyway. A date should be announced when the entire database will be published. After that date all liability for fraud perpetrated using an SSN as a shared "secret" will be assigned to the party who accepted the SSN as "authentication". That would solve the problem.

As an aside: When it comes to an authentication source to take the place of silly shared public "secrets" I think it would be great if the United States Postal Service "pivoted" into issuing digital certificates to individuals. They already have infrastructure and procedures in place for identity verification and physical delivery. I suppose that's too much like a federally-issued ID to ever fly, though our "REAL ID" drivers licenses are, in effect, a federal ID anyway. I'd rather have a digital certificate out of the deal too.

Re: Claimed AT&T hack of 70M customer records including SSN, name, address

#30
post #16

I'm usually skeptical about denials, like AT&T is doing here. But in this case, there would be some incentive for the hackers to misrepresent the source/freshness/etc of the data. Given the recent T-Mobile hack, if they can tag the data as coming from AT&T and being fresh, it might fetch a higher price either from AT&T, or data buyers. In other words, it could be a re-label of some older exposed data.

The hackers selling the info are well known for providing fresh data, to the point that they’ve given away old data for free. I doubt they’d risk their reputation on reselling a different leak.

Ah, thanks...not mentioned in the linked article. There's more info in the source article: https://restoreprivacy.com/att-data-breach-70-million-custom...

The hacker group is "ShinyHunters".

Post reply on HN