Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

171–180 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#171
post #7

The real problem is that data needs to be deleted over time. There is not much of a use case for customers for go back last year and see who called them and obviously there are use cases like criminal investigations or spying. But customer has no power or ability to dictate how long their records are store and how they are used. Companies should provide tools and features to their customers empowering them with their…

They have a financial incentive to never delete your data. Storing old data forever creates a perfect paper trail to sell to advertisers and perfect the shadow profile they keep on all of us.

I agree that deleting all your data after a year makes sense practically, but they'll never do it because it makes them too much money to keep it around.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#172

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

I open credit cards for the bonuses frequently enough that freezing my credit would be more inconvenience than it’s worth.

Also, all the big bank websites seem to offer real time credit history monitoring for free, so I am betting I’ll just deal with any problem if/when they happen.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#174
post #131

Earlier quoted context omitted.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they pur…

It’s unclear what you’re arguing. That AT&T isn’t capable of securing customer data, and we shouldn’t expect that of them? That they shouldn’t be held liable?

If they don’t have the core competency, they need to obtain it as a requirement of doing business.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#175

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

That’s what I do. But it’s a little bit of pain to unfreeze your credit with three bureaus when you want a new credit card. Wish there was a way to do this in one place.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#176
post #141

Earlier quoted context omitted.

Really should be up to the government to fine these companies and pay out to those effected to disincentivize lax security standards.

How would such damages be assessed or proven?

They would be assessed according to rules written by people who are skilled at writing such rules. The rules would be evaluated by looking at data over time and revised as needed by experts in the industry who are as neutral as possible, maybe with some feedback from the public. The courts exist for any contention regarding responsibility.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#177
It's ok everyone! Protecting our data is one of AT&T's top priorities.

> Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured.

> We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you. We invest in our network’s security using a broad array of resources including people, capital, and innovative technology advancements.

I hope there's an enormous fine for this kind of negligence

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#178
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

It's because it happened gradually / naturally / semi un intentionally, because:

1) SSN was not intended as a national ID, but it so happened to fit the shape of one, in that almost everyone has one and they're unique.

2) It has never been possible to institute an intentional national ID system in the US for political reasons

That is the recipe for the problem we have now. Strong demand for a national ID from many business purposes, the existence of something that looks a lot like, but is an imperfect form of, national ID, and the refusal to create a proper national ID, has naturally led to a de facto system of abusing the SSN as a national ID and just kind of everyone being a little annoyed and sketched out about it but putting up with it anyway for lack of alternatives.

Incidentally, did you know anyone can generate a valid new EIN (which is a lot like an SSN, and can be used where an SSN can be used for some but not all purposes, specifically filing taxes and ) at this page https://www.irs.gov/businesses/small-businesses-self-employe... ? This isn't legal advice and I'm not a lawyer and I don't know in what situations you personally would be legally permitted to use this (it's meant for businesses, absolutely not some kind of personal alias) -- but technologically, it's just honor system, and anyone can certify they need and are entitled to a new EIN and the IRS web site will provide you with a new unique one. I don't think you even need a legal entity, since you don't need a legal entity to run a business in the US.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#179

Is this leak why the spam next messages have gone from “Hi how is your day ?” or “Hi [not my name] please do thing X. Of you’re not [not my name] I’m so sorry perhaps we can be friends.” to “Hi is this [my full name]?” or “Hello [my first name] how is your day ?”

Any leak with your mobile and name pair could have done that. As a non-AT&T customer, I get the my-speecific-name pig butchering texts, too.
Post reply on HN