Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

131–140 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#131

Earlier quoted context omitted.

its not Snowflake's fault their customers used weak passwords and no MFA. Not enforcing MFA does merit some blame on Snowflake, however, I still think its on the customer to secure your own environment.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they purchase from. There are no strong penalties for involuntary data leaks - why would they do more?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#132

Earlier quoted context omitted.

During the last decade, ATT’s leaders decided to burn tens of billions of dollars by overpaying for obviated businesses like DirecTV and Time Warner. I can only imagine the quality of mobile and fiber networking we could have had if that money was spent on telecommunications. And maybe they would have spent a few million on having proper security.

Not only that they blew $8 billion/year on dividends that could've gone into the business or to employees instead of being extracted and given to people who have nothing to do with the business.

When people invest in a business, whether it be your sibling’s business, or a local business, or a publicly traded business, they do it because they expect a return on investment.

An infrastructure utility such as ATT typically has to offer dividends because it is not going to experience the type of growth that would result in a return via share price increase.

Of course, ATT’s prices are not regulated like a proper utility, even though they should be, but it is still subject to the same market forces that prevent it from growing like a tech company would, who would have the option of foregoing dividends (or share buybacks).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#133

Earlier quoted context omitted.

Or a lawsuit go through where someone can win quite a bit from from data leaks. If each person affected sued and won 100k or so, or even 1k, AT&T would definitely be spending money on security. But it appears $5 or credit monitoring from an agency that also gets hacked is sufficient for class action lawsuits.

That requires people to be rich enough to sue. It takes a lot of money and time to sue. Almost no one has enough resources to do this. The courts are not an effective way to implement this policy. Unless you only want rich people to be able to get justice.

110M people impacted = class action

The lawyers work on contingency

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#134

Earlier quoted context omitted.

Or a lawsuit go through where someone can win quite a bit from from data leaks. If each person affected sued and won 100k or so, or even 1k, AT&T would definitely be spending money on security. But it appears $5 or credit monitoring from an agency that also gets hacked is sufficient for class action lawsuits.

That requires people to be rich enough to sue. It takes a lot of money and time to sue. Almost no one has enough resources to do this. The courts are not an effective way to implement this policy. Unless you only want rich people to be able to get justice.

And rich people usually do deals off-court. You will pay me this and we are ok. Because its faster and both sides know they capabilities usually.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#136
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

There is some evidence that it does hurt stock prices:

https://www.comparitech.com/blog/information-security/data-b...

"Stocks of breached companies on average underperformed the NASDAQ by -3.2% in the six months after a breach disclosure"

That said, it's not clear what the long term impact is on stock price (if there is any).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#137
post #94

Earlier quoted context omitted.

The Mandiant report said that some Snowflake customers declined to use MFA AND had passwords in place for 4+ years[1]. Maybe Snowflake should have pushed for MFA harder but at the end of the day, this is AT&T's fault. [1] https://cloud.google.com/blog/topics/threat-intelligence/unc...

Non-expiring passwords is probably no more or less secure, unless you are a rampantly terrible employer known for setting ablaze every bridge ever to the point of atomic annihilation.

Are you suggesting a disgruntled former employee could use the password and do things? At that point, I have questions. How is the former employee accessing the cloud service? If your cloud is allowing public access without a VPN, then you've done something wrong there. If the former employee is still accessing your VPN, again, you've done something wrong. Many other things still come to mind but point back to you well before password rotation rules.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#138

Key point of the article: "Snowflake allows its corporate customers, like tech companies and telcos, to analyze huge amounts of customer data in the cloud. It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say." Finally journalists are asking the question why customer data must be stored with third party cloud providers. AT&T is a long way from Bell Labs, shame…

All companies use third party cloud providers. A lot of legacy companies have been shutting down data centers to move to the cloud. So there isn’t a question of whether why your data is in the cloud. It’s going to be in the cloud.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#139

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

It’s a great idea! I only unfreeze my credit for big purchases like buying a house or car.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#140
post #7

The real problem is that data needs to be deleted over time. There is not much of a use case for customers for go back last year and see who called them and obviously there are use cases like criminal investigations or spying. But customer has no power or ability to dictate how long their records are store and how they are used. Companies should provide tools and features to their customers empowering them with their…

Non-murder criminal offenses typically have very short statutes of limitations. A lot of this could also be solved by encouraging the federal government to enforce federal privacy law as written more aggressively. A good incentive would be to amend the privacy statutes to permit the FTC to keep the funds extracted from settlements and penalties in-house. This would allow them to increase staffing and create a positiv…

That's another bandaid. The root cause is customer data collection mandated by outdated regulation. People should be able to digitally sign or provide a public key for their personal information without providing the raw text to 3rd parties. Various 1970's style government tax and regulatory rules need to be updated as well.
Post reply on HN