Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

191–200 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#191

Unfortunate as it is, nobody genuinely cares about: 1. Preventing data breaches 2. Properly anonymizing aggregated personally identifiable data 3. Having and using a secure ID and verification system

They don't care because they don't know how the systems they use daily work, much less the costs and risks involved.

If they knew, they would care, and that's why representatives care on their behalf.

You could say the same about health and nutrition, but people very much do care when a medical issue tangibly affects them negatively.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#192

Earlier quoted context omitted.

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

There is some evidence that it does hurt stock prices: https://www.comparitech.com/blog/information-security/data-b... "Stocks of breached companies on average underperformed the NASDAQ by -3.2% in the six months after a breach disclosure" That said, it's not clear what the long term impact is on stock price (if there is any).

Unfortunately, that analysis seems to have made absolutely no attempt to check whether the results are statistically significant.

Pick 118 random companies at 118 random points in time. It's vanishingly unlikely that the average returns of that group will exactly track the NASDAQ returns over the following 60 days. It might underperform, or it might overperform. An underperformance of 3.2% could easily just be the result of random chance, and have nothing to do with data breaches.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#193
post #169

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

After Equifax debacle, I don’t think anyone cares. It’ll only be a big deal if there’s a huge B2B leak and business-critical data gets exposed, other than the usual name, address and phone number.

I'm still upset the government hasn't started work on a new national ID program after the Equifax breach. The SSN is not a suitable ID number in this day and age. We need something better that can withstand these kind of things without screwing people for life. My credit will be frozen for the rest of my life, and everyone else should do the same.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#194
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

> Somehow knowing that first boy born today will have an ID number of 120702450001X

It's even worse. Only post-2011 IIRC births have an algoirthmic SSN. So everyone over the age of 13 still has old fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by

1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location. For example, I can guess what region of the US you were born in (or lived in when you immigrated) by the first digit. 0 or 1 is probably northeast. 4 or 5 is probably near Texas. 7 might be near Arkansas. Etc.

2) YY-ZZZZ is sequential by date! So by knowing just birth day, can be guessed to within a range. In practice, this means it's easy to guess YY alone, but harder to get all 4 digits of ZZZZ

3) For some stupid reason it got popular to print SSNs with all but the last four digits masked. This is horribly bad because those four are ACTUALLY THE MOST SECRET PART! It's the only part that might not be guessable. But since it's common to be more lax with securing them..... it is super easy to recover the full SSN if you find a piece of paper that says something like

JOHN SMITH

123 Main St

Alabama City, AL 76543

In ref acct: XXX-XX-1234 (2001-03-14)

Dear Mr Smith,

Your account is overdrawn. Have a nice day.

Thinking of you,

The Bank

It also means if someone is personally known to me, even vaguely, I may be able to reconstruct their social seeing nothing but a scrap of paper that has just the last four, if I can guess approximately where and when they were born or first entered the US. If I'm in a situation where I can try several guesses, it's even easier.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#195

Unfortunate as it is, nobody genuinely cares about: 1. Preventing data breaches 2. Properly anonymizing aggregated personally identifiable data 3. Having and using a secure ID and verification system

I am seeing this mentality as well, and it's disheartening. My company manufactures and sells a privacy-first, fully autonomous, on-prem, video security system for home and SMB. Yet, some people choose a cloud based service (convenient) and are surprised when their private data is either a) hacked, or b) abused by the provider's own employees (see the latest Amazon Ring settlement).

With the latest scandals and breaches though, I feel it's gradually starting to change.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#196
> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use.

And is that going to change?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#197

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

One interesting thing I ran into with frozen credit, is that you cannot sign up for USPS informed delivery without them running your credit as a method of address verification IIRC. If it is frozen the process gets stuck in limbo (at least it did many years ago when I ran into this situation)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#199
post #159

Earlier quoted context omitted.

No, what will make the difference is being personally liable for the vulnerabilities you introduce. Not the company. You.

How many individual engineers do you suppose get prosecuted for making errors--even careless ones? I'm guessing very few in the West. And I'm not even sure lopping off a head here and there to encourage the others is even a good idea.

> How many individual engineers do you suppose get prosecuted for making errors--even careless ones?

Not many but is that because they don't get sued or because professionals who face consequences for negligence make fewer stupid decisions?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#200
post #181

Earlier quoted context omitted.

All companies use third party cloud providers. A lot of legacy companies have been shutting down data centers to move to the cloud. So there isn’t a question of whether why your data is in the cloud. It’s going to be in the cloud.

And honestly, I think I'd rather trust cloud providers with the data than the remnants of a decimated IT team in a large enterprise that's struggling to maintain their own on-prem infrastructure that's super old and probably not up to date on patches.

The problem is then you have even fewer technically-competent people internally to actually manage the cloud, and combined with AWS's many documented footguns it's not clear to me the "new normal" is actually any better for security.

You go from being a potentially-small-fry target to getting your data collated in massive breaches. There's risks to both.

Post reply on HN