Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

631–640 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#631

Earlier quoted context omitted.

Personal data cannot be secured. The only way is to not store it. That will (imaginationaly) cost companies in lost revenue for being unable to mine and sell it. Only government can make laws against a company taking your personal information and selling it. Even passwords shouldn't be stored by a company. The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 mil…

There are lots of companies that take security seriously and don’t lose their customers data. Which is good, because there are companies that need to hold customer data. Companies that don’t take security seriously and lose peoples data should be punished accordingly. Companies that sell customers data should be identified. But if we treat them all the same, then we let the bad companies off the hook, and punish the…

there are companies that have already had their customers' data exfiltrated and will have it exfiltrated in the future, companies that will only have it exfiltrated in the future, and companies that are about to be dissolved. there is no fourth category. computer security is not currently achievable; the best we can hope for is to contain the damage from the inevitable breaches and reduce their frequency

new security holes get introduced faster than old ones get patched, and that will remain true for the foreseeable future

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#632

Earlier quoted context omitted.

>But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much. This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which…

Its a bug. We now have Instead , we could have 1000s of smaller banks. Tons of smaller banks is the natural state of things, like restaurants. This was true before the banking cartel, TARP, ZIRP, most recently, PPP (genius backdoor to bail out wall st.). In such system, any 1 collapsing bank wont bring the entire system down. Having fewer bridges means that inevitable when they collapse, there will be far more victim…

>Having fewer bridges means that inevitable when they collapse, there will be far more victims and the event will be catastrophic.

I honestly don't even know where to start with this.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#633

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

> Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, On the contrary, many European countries have mandatory data retention periods that meet or exceed the 6 months of records that were supposedly included in this breech. Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records. Saying tha…

> Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records.

No they don't, because it's "suspended" by the federal network agency until courts are through with it. In fact they suspended it three days before the law would've come into force and thus it never was. The current state of affairs is this: the retention was ruled incompatible with German and European law in an injunction and it does not look like that is about to change.

There's a similar picture in many EU countries: There's a law on the books, but it can't be enforced/is being challenged/was already invalidated/is being rewritten/repeat.

Also note that to courts location data/phone records is a different issue than retaining information that merely associates an IP address with the subscriber that used it at some time (knowing which subscriber has what phone number is not an issue either, after all). The latter was ruled to be unproblematic by the ECJ just this year, while for the former the latest ruling is what I outlined earlier.

Besides Germany, some other countries that had data retention laws that were ruled unconstitutional are: Belgium, Bulgaria, Czech Republic, Cyprus, Romania, Slovenia, Slovakia.

In many other places that currently do have mandatory retention in force, it is being challenged.

> Saying that it would be illegal to collect these records in Europe is patently false

It is illegal to mandate in such a manner. There's a difference.

> Billing. You need phone records for billing purposes. You need to keep them for a while longer because people will dispute their bills all the time.

You must've not read the part where I said "beyond what is necessary to operate". Telekom for instance is doing just fine deleting phone records after 80 days - or within 7 days if you use a flat-rate and they're not relevant to billing.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#634

Earlier quoted context omitted.

I’d take it a step further. If a technology is impossible to secure it shouldn’t be used. Maybe it’s time to rethink all the parts of our lives we’ve handed over to software.

What current technologies do you believe are possible to secure? I am sympathetic to the overall sentiment here, but between any web browser + server stack you are looking at hundreds of millions of lines of code written in unsafe languages. Add on the human factor and there is just no hope of really securing this.

sel4, tweetnacl on an avr, pdf/a, html3, gzip, lwip, etc., running on purpose-built hardware. too bad it's not self-hosting yet

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#635
post #578
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the dev…

> Higher ups set the incentive structures that result in dwindling security resources.

What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time.

I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect.

> If their ass is on the line, they will actually listen to the developers and security experts telling them they are vulnerable, instead of brushing them off to divert resources that boost the reports which determine their bonuses.

Again, why are you making this assumption? But let's say, for the sake of argument, that you're right. Now we go implement some draconian, top-down "you must be secure or the C-suite goes to jail" mandate. Corporations, out of fear of liability and prosecution, lock up tight, and refuse any and all changes that might undermine their security posture. Nobody builds anything new, because why take a risk?

Expensive "security expert" consultants start appearing out of nowhere to help with "compliance" with the new rule, and companies pay for them -- because it provides a veil of responsibility for the company, even if the consultant is useless. Worse, a certain percentage of these "experts" will be hucksters (or more likely: morons) themselves, and will always tell people that "they are vulnerable", because that essentially ensures a payday. You can't prove that a system is "secure", so who can say otherwise?

If you doubt that any of this is plausible, I suggest you take a hard look at our existing top-down security rules (e.g. ISO 27000, HIPAA, GDPR, PCI DSS, NIST SP 800-88 and SOC2, just to name a few) and the bureaucratic industrial complex that has erupted around them, and ask yourself it these things actually make you safer. I guarantee that AT&T was "compliant" by any conventional IT standard with these, employed an army of IT staff to document said compliance, and otherwise invested a huge amount of money in that kind of performative nonsense. Because that's what every company does.

But they still got owned.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#636
post #609

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Why they hold it and how they protect it are valuable conversations. But their customers deserve something akin to security regardless of the why.

Spam mitigation and management is a huge bugaboo in wireless networks today.

The big three wireless carriers in the USA today formed a cartel called The Campaign Registry that seeks out TINs/EINs and the SSNs of the owners of Sole Proprietorships and LLCs as part of a lengthy approval process to be allowed to send texts.

It's a great extra judicial rent seeking machine that bans any SHAFT content (sex hate alcohol, tobacco, firearms and anything tangentially related) along with hefty fines for anyone that they feel has crossed said boundaries.

Letting the morality police run amok on our Telecom networks here in the USA is happening, and they also want all the data they can get along with bribes from businesses.

Ajit Pai created the opening for this mess, and the current FCC has done nothing to clean this up (though given recent SCOTUS rulings, who knows if they ever had the authority...)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#637
post #623

wow, a spy agency acquired the entire social network graph of the usa in one intrusion. that's bad news for civil defense; it means they have a good guess at who is the favorite relative of each legislator, governor, police chief, or general. and where they can habitually be found at each hour of the week, since this leak included location data! how can we keep such accumulations of sensitive data from arising in the…

How do you know it was a spy agency? Sounded like just a hacker group. I assume 5 eyes are the only ones who have this already anyway as a matter of course. All they have to do is buy it from AT&T, no hacking necessary.

it seems unlikely that it was just for the lulz. if the intruders are auctioning off the data, do you think the russian fsb, the ministry of state security, hizbullah, mossad, or the usdoj will bid highest?

(the last, hypothetically, to destroy the data rather than use it for leverage in investigations—if not, it's in effect just another spy agency)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#638

Earlier quoted context omitted.

This is the excuse used to justify the regulatory capture. There is a mile of difference between simply having fire exits vs. minimum parking requirements, de jure or de facto minimum unit sizes and density constraints. You need something that can distinguish these things, not something that provides the trash choice between none of them or all of them together.

Using regulatory capture as an excuse why we can't stop babies from eating lead is the most brain dead take from the American left since they replaced class with race.

I'm not American but isn't a fetish for deregulation a hallmark of your political right, not the left?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#640

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data.

There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

Post reply on HN