Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

141–150 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#141
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

Really should be up to the government to fine these companies and pay out to those effected to disincentivize lax security standards.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#142
post #60
post #17

Earlier quoted context omitted.

The reports said celltower-level location data associated with calls and texts (but not datestamps). That would allow inferring their homes, job location, commute, family members, social graph.

You can still recover that without timestamps. It also looks like if anyone interacted with an ATT customer or used an MVNO your data is in there too.

It even said land lines had their numbers in the data if an ATT customer contacted one.

Edit: I must have read that from a different article than the TFA though.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#143

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

A lot of financial things in the US are “secured” or anchored by SSN, that’s the only reason why. That and mother’s maiden name and first vacation and other security questions. It’d be less important with MFA now but SSN is also needed when opening new credit, so having it allows you to pretty easily fake someone else’s identity for credit. KYC hasn’t removed it from the equation.

"Mother's maiden name" won't work for my kids - my wife kept her name and the kids' last name is hyphenated, so you just have to guess whose name we put first.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#144
post #141

Earlier quoted context omitted.

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

Really should be up to the government to fine these companies and pay out to those effected to disincentivize lax security standards.

How would such damages be assessed or proven?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#146
post #93

Earlier quoted context omitted.

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

They are very much related to the news, that's precisely why I linked to the stock charts: AT&T was flat overnight but opened (9am ET) with a -2.6% spike down, but has been recovering since. Their press release appears to have been Friday 7am ET shortly before market open [ https://about.att.com/story/2024/addressing-illegal-download... ]. Also as corroboration here's MarketWatch: "AT&T’s stock slides 3% after compan…

I'm not saying there's no way the stock pullback wasn't caused by the hack, but it's also important to note that MarketWatch article only establishes correlation, not causation.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#147

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

I think many companies think they can solve this issue by throwing money at their cyber security teams. It just happens that cyber security teams are often ineffective.

How could they? Everything related to computers is designed to exfiltrate data nowadays.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#149
Is this leak why the spam next messages have gone from “Hi how is your day ?” or “Hi [not my name] please do thing X. Of you’re not [not my name] I’m so sorry perhaps we can be friends.” to “Hi is this [my full name]?” or “Hello [my first name] how is your day ?”

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#150

Earlier quoted context omitted.

Non-murder criminal offenses typically have very short statutes of limitations. A lot of this could also be solved by encouraging the federal government to enforce federal privacy law as written more aggressively. A good incentive would be to amend the privacy statutes to permit the FTC to keep the funds extracted from settlements and penalties in-house. This would allow them to increase staffing and create a positiv…

> Non-murder criminal offenses typically have very short statutes of limitations. There's a hidden assumption here. The expectation is that data retention and potential privacy violations are a necessary evil because anyone may later be under investigation for a crime. The data could go uncollected, it isn't AT&Ts job to retain private information on all of us just in case an investigator wants it. Take telecoms out…

Many civil claims have short statutes of limitation as well. It's not really that good for these companies to maintain regular business records going back to infinity that are subject to discovery in disputes that are not even related to anything the telecom company did. Complying with the discovery requests and subpoenas is expensive. The fetish for the somewhat imagined benefits of big data creates open-ended liabilities for these companies. But the pressure that law enforcement and the spy agencies put on the telecom companies to facilitate this has been an open secret for a long time now.

A lot of this is on the federal government and Congress for leaving an area in which it has power dormant and within its relatively exclusive control. Thanks for the conversation.

Post reply on HN