Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

151–160 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#151
post #103

Earlier quoted context omitted.

Or maybe it's time to turn software engineering into an actual engineering profession. If the people responsible for designing and maintaining the AT&T system were "real" engineers, they could be sued for malpractice or even lose their license to practice.

Do you really think that requiring 4-year degrees and passing a licensing exam would make a big difference? The fact is that, outside of civil engineering which involves a lot of dealing with regulatory agencies, most engineers in the US don't have PEs. I started on the path to get one because, had I stayed on my initial career path, I'd have been sending blueprints etc. to regulatory agencies but I ended up changing…

No, what will make the difference is being personally liable for the vulnerabilities you introduce.

Not the company. You.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#153
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

When I went to college in the late 80s my ssn was automatically used as my student id. When I got my first bank account in 1990, they used my ssn as the account number.

Our class grades with names snd SSNs were posted on the wall after exams in a list of hundreds of students.

Go Jackets.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#154

Earlier quoted context omitted.

That requires people to be rich enough to sue. It takes a lot of money and time to sue. Almost no one has enough resources to do this. The courts are not an effective way to implement this policy. Unless you only want rich people to be able to get justice.

110M people impacted = class action The lawyers work on contingency

Imagine the GDPR fine

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#155
The headline could equally say "AT&T kept data for criminals to steal".

If wiretapping laws didn't exist then most of this data would not be justified to exist. Flat-rate billing doesn't need to keep track of this information. Even usage-based plans could keep cumulative records rather than individual ones, or at least delete them at the end of a billing period.

Where there is a trough, pigs gather.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#156

It's interesting when you have these old, large, sprawling bureaucratic organizations and the employees hardly give a sh!t anymore and allow for these large vulnerabilities. It's not a money issue, it's a caring issue I think.

Tangential, why did you/anybody spell "shit" like they are evading Tiktok language filters?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#157

Earlier quoted context omitted.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

That's what I do. It also slows my roll. It's an extra step I have to take before making that large purchase or applying for anything that requires a credit check.

It's an extra step, but a surprisingly simple one. When I opened a checking account recently the bank told me which credit agency they'd use, and I unfroze that account and ChexSystems (another credit agency you should freeze with that is used specifically for new bank accounts) in five minutes using their automated systems. You can supply a re-freeze date when unfreezing as well so you don't need to remember to do that manually once you're approved.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#158

Earlier quoted context omitted.

A lot of financial things in the US are “secured” or anchored by SSN, that’s the only reason why. That and mother’s maiden name and first vacation and other security questions. It’d be less important with MFA now but SSN is also needed when opening new credit, so having it allows you to pretty easily fake someone else’s identity for credit. KYC hasn’t removed it from the equation.

"Mother's maiden name" won't work for my kids - my wife kept her name and the kids' last name is hyphenated, so you just have to guess whose name we put first.

It's also probably increasing easy to look up.

We need a national (preferably RFID-ish) password system.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#159
post #103

Earlier quoted context omitted.

Do you really think that requiring 4-year degrees and passing a licensing exam would make a big difference? The fact is that, outside of civil engineering which involves a lot of dealing with regulatory agencies, most engineers in the US don't have PEs. I started on the path to get one because, had I stayed on my initial career path, I'd have been sending blueprints etc. to regulatory agencies but I ended up changing…

No, what will make the difference is being personally liable for the vulnerabilities you introduce. Not the company. You.

How many individual engineers do you suppose get prosecuted for making errors--even careless ones? I'm guessing very few in the West. And I'm not even sure lopping off a head here and there to encourage the others is even a good idea.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#160

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

A lot of financial things in the US are “secured” or anchored by SSN, that’s the only reason why. That and mother’s maiden name and first vacation and other security questions. It’d be less important with MFA now but SSN is also needed when opening new credit, so having it allows you to pretty easily fake someone else’s identity for credit. KYC hasn’t removed it from the equation.

One mitigation is to make your mother's maiden name the output of:

    head -c 20 /dev/random | base64
And keep track of the result in your favorite password manager.

Fortunately, fewer and fewer orgs are using security questions, but there are still some important ones that only use that and no MFA.

Post reply on HN