Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

161–170 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#161

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

I think many companies think they can solve this issue by throwing money at their cyber security teams. It just happens that cyber security teams are often ineffective.

Maybe this is how it is at some places, but in my experience, it is not the case. I have friends who have worked in cyber-security for Fortune 500 companies and almost all of those companies would short-change (or outright ignore) the recommended spend and suggestions of their cyber-security employees, contractors, and advisors.

Where are you getting your information from? The levels of security negligence I hear about aren't even a big ask. Huge companies neglect to do basic things like "don't store your passwords in plain text" or "make sure you salt and hash your passwords".

I don't think it's fair to say cyber security teams are failing if companies are blatantly doing the worst and most obviously wrong things on the daily at the highest levels.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#162

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

Yep. This is what I did after the first Experian data breach, for peace of mind. I am probably financially lucky enough that I don't need to constantly be checking or using my credit... but honestly it seems like this is what everyone needs to be doing.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#163

Earlier quoted context omitted.

When I went to college in the late 80s my ssn was automatically used as my student id. When I got my first bank account in 1990, they used my ssn as the account number.

Our class grades with names snd SSNs were posted on the wall after exams in a list of hundreds of students. Go Jackets.

Ah it was a different time. Societal trust was greater. Without global internetification, the only people who could ever have any opportunity to exploit this information were your fellow campus denizens (students, professors, etc).

Without global internetification, there was not as much an average person could really do or would know to do with an SSN alone to exploit it.

This story is a good parable for so much of what has changed in the world the last couple decades -- we had a world built for less globalization, then we globalized, and we've been gradually adapting to / dealing with the unintended consequences since then.

A real life door can only be picked by your neighbors or anyone else nearby -- attack surface is limited by the nature of physical distance.

A virtual door can be picked at by 7 billion people.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#164
post #131

Earlier quoted context omitted.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they pur…

ATT has a rich history of being a technology company. They invented UNIX! That's in the past, fair enough.

So they used to develop cutting edge technology, they sell technology, they buy technology, they operate technology, they work with manufacturers to develop new technology, they operate the infrastructure underpinning the modern technology economy, but they aren't a technology company?

Even if you want to argue that they aren't a technology company, they sure spend enough time doing everything a technology company does to hold them accountable for their technology failures.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#165
There's no way to make the software perfectly safe from hackers and from social engineering. So, yes, companies should be more careful with the data and, yes, the data shouldn't be kept forever. I agree companies should be doing more to protect the data.

I see lots of outrage at the companies and why isn't the government doing more to punish them and how do I get compensated ...

But, I feel like everyone is blaming the victim. Is it the home owners fault when someone breaks in and steals stuff?

Where's the outrage at the hackers breaking into these accounts? Where's the "why aren't the governments tracking these people down?" Why is no one demanding that the hackers be brought to justice?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#166

Earlier quoted context omitted.

Well it's starting to feel like data privacy just doesn't exist anymore. I don't know why administrators for big customer databases even bother setting passwords these days.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen. My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere…

As a nobody, I keep wanting a financial product that is a black hole. Money can go in, but cannot come out without significant pain. Seven+ day waiting period, in person visit, physical mail verification, something, anything that means if I do get hacked my accounts are not drained in milliseconds.

When I need a legitimate large withdrawal, I can go through the required effort.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#167

So where/what is my compensation? (I know there is no recourse). When no one is on the hook for secure practices, like enabling MFA on your effin data stores that contain massive amounts of customer PII, this is the result. Not even an apology, just report it and move on. woops! those gosh darned cyber criminals.

I've received checks over the years for various things like this. You end up having to fill out a claim form and then wait about 5 years and one day, you get this check in the mail for some tiny amount of money.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#168
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

I never understood the american secrecy about SSN... it should be a "username" not a "password"...

The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!"

It's not the leak that's the problem; it's the ease with which that leaked data is used to either obtain fraudulent credit or access accounts.

I don't have a good answer, because at some point, a financial institution needs to trust people to do business. Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#169

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

After Equifax debacle, I don’t think anyone cares. It’ll only be a big deal if there’s a huge B2B leak and business-critical data gets exposed, other than the usual name, address and phone number.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#170

Earlier quoted context omitted.

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

I agree. This is precisely why breaches keep happening and will keep happening. It cost money to implement security. There's no cost benefit to spending that time and money since there are no consequences. Businesses do not spend money unless it will make them money or save them money. There needs to be a hefty federal fine on a per-affected-user basis for data breaches. Also a federal fine for each day a breach is u…

Most breaches are because of developper incompetence. Throwing money at it won't really help. You need better basic security skills.
Post reply on HN