Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

111–120 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#111

How has Snowflake felt ANY recourse for being the source of all of these hacks?

its not Snowflake's fault their customers used weak passwords and no MFA. Not enforcing MFA does merit some blame on Snowflake, however, I still think its on the customer to secure your own environment.

Totally, way too many people are trying to blame snowflake.

ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data.

They should be telling Snowflake what best practices to be using, not the other way around!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#113

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently, only unfreezing it when you're making a large purchase that requires it?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#114
post #18

Earlier quoted context omitted.

> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use. So AT&T put all our call information somewhere and hid it probably behind a weak password with no additional factors. IMO that's actionable negligence and I hope they get sued to oblivion.

I'm more stunned that AT&T knew back on Apr 19 [UPDATE: Mar 20] yet feels it had neither an SOX violation or SEC obligation (share price effect) to notify timely. Like, by Apr 22. Not three months later [UPDATE: 4 months later]. Remember the massive Yahoo 2014 hack which Yahoo management failed to notify its own users for 2 years? If SOX violation only literally covers users' own passwords getting breached, but not 2…

Subsequent reporting reveals that the DOJ ordered two ~month-long "delay periods" in disclosure:

> The Justice Department determined on May 9 and again on June 5 that a delay in providing public disclosure was warranted, so the company is now timely filing the report.

> The company [AT&T] is working with law enforcement and believes at least one person has been apprehended, according to the filing. It does not expect the event to have a material impact on its financials.

MarketWatch: [https://www.marketwatch.com/story/at-ts-stock-slides-2-9-aft...]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#115

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

Well it's starting to feel like data privacy just doesn't exist anymore. I don't know why administrators for big customer databases even bother setting passwords these days.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen.

My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere, bundled with 10,000 other identities. But if money gets stolen, that's a whole rigamarole, with banks wringing their hands and saying "identity theft" as if that clears them from any responsibility.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#117
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

A lot of financial things in the US are “secured” or anchored by SSN, that’s the only reason why. That and mother’s maiden name and first vacation and other security questions. It’d be less important with MFA now but SSN is also needed when opening new credit, so having it allows you to pretty easily fake someone else’s identity for credit. KYC hasn’t removed it from the equation.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#118

Earlier quoted context omitted.

I agree. This is precisely why breaches keep happening and will keep happening. It cost money to implement security. There's no cost benefit to spending that time and money since there are no consequences. Businesses do not spend money unless it will make them money or save them money. There needs to be a hefty federal fine on a per-affected-user basis for data breaches. Also a federal fine for each day a breach is u…

Or a lawsuit go through where someone can win quite a bit from from data leaks. If each person affected sued and won 100k or so, or even 1k, AT&T would definitely be spending money on security. But it appears $5 or credit monitoring from an agency that also gets hacked is sufficient for class action lawsuits.

That requires people to be rich enough to sue. It takes a lot of money and time to sue. Almost no one has enough resources to do this. The courts are not an effective way to implement this policy. Unless you only want rich people to be able to get justice.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#119

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

I think many companies think they can solve this issue by throwing money at their cyber security teams. It just happens that cyber security teams are often ineffective.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#120
post #43

Earlier quoted context omitted.

While I share the sentiment, Normie Norman is not at fault. Meta and other BigCorps are the perpetrators and Norman the Victim.

I have to disagree. He is a fault. Ultimately, you are the only person who really should care about your own security. When you delegate that responsibility, you are still the one who made that choice.

Having a mobile phone is necessary to securing employment, shelter and sustenance in many cases, yet somehow it’s an individuals fault for choosing to have a phone account when a pair of multibillion dollar companies breach that data through lax security practices?
Post reply on HN