Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

211–220 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#211
post #200
post #181

Earlier quoted context omitted.

And honestly, I think I'd rather trust cloud providers with the data than the remnants of a decimated IT team in a large enterprise that's struggling to maintain their own on-prem infrastructure that's super old and probably not up to date on patches.

The problem is then you have even fewer technically-competent people internally to actually manage the cloud, and combined with AWS's many documented footguns it's not clear to me the "new normal" is actually any better for security. You go from being a potentially-small-fry target to getting your data collated in massive breaches. There's risks to both.

That’s the thing though - this was a snowflake breach. It’s not an AT&T miss because of their decimated sw engineering teams. Snowflake has much better sw engineering than AT&T.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#212
post #159

Earlier quoted context omitted.

How many individual engineers do you suppose get prosecuted for making errors--even careless ones? I'm guessing very few in the West. And I'm not even sure lopping off a head here and there to encourage the others is even a good idea.

> How many individual engineers do you suppose get prosecuted for making errors--even careless ones? Not many but is that because they don't get sued or because professionals who face consequences for negligence make fewer stupid decisions?

I would assume that engineers, at least in the US, are far more concerned about getting fired/eased out than prosecuted if they do stupid things given that companies can do so pretty easily.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#213
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

It’s priced in.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#214

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

Even the US gov't gave up on the notion the SSN was not to be used as an identifier. My dad's SS card had a phrase printed on it saying so. My SS card did not have that text.

My SS card has that text. I got into an argument at the DMV when they asked for it. I relented because I needed my drivers license.

Congress could solve this by enacting a simple law. Something to the effect of SSNs shall not be used as a means of identification by any party, governmental or otherwise other than the Social Security Administration. Use of an SSN as identification shall be subject to a $100 fine per each SSN used as identification, per day.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#215
post #131

Earlier quoted context omitted.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they pur…

> The security component of communications isn’t built by them

Are you claiming AT&T outsourced security and have contracts to back that up? Buying security equipment surely doesn’t amount to having security, that would be hilariously naïve. Equipment manufactures are not responsible for AT&T’s data security, AT&T is. There are laws around security that can hold AT&T liable, in the US and Europe and elsewhere. Whether they will hold the company liable is another question, but these laws will not accept an excuse that AT&T purchased security equipment from another company.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#216

> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use. And is that going to change?

This is a diversion. Why did they build a system that permitted a bulk database dump of hundreds of millions of rows even with 2FA?

Because that’s what a data warehouse is? You’d think they’d guard them more, though.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#217

Earlier quoted context omitted.

When I went to college in the late 80s my ssn was automatically used as my student id. When I got my first bank account in 1990, they used my ssn as the account number.

Our class grades with names snd SSNs were posted on the wall after exams in a list of hundreds of students. Go Jackets.

I wonder if the schools actually verified the SSN.

Would have been dank to see 666-66-6666 next to your name

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#218

AT&T bought into a significant amount of DirecTV - so much so that everything that had the DirecTV logo on it was changed to the AT&T logo, such as the invoicing. So the AT&T customer base has included, for several years, the Directv customer base. The article doesn't attempt to clarify who the 'nearly all' customers are, and some people will jump to the conclusion that it is the cell phone customers. But it could in…

AT&T didn't just buy into a significant amount of DirecTV, they owned DirecTV. As in, 100% ownership. So yes, all DirecTV customers were AT&T customers, because AT&T and DirecTV were not separate entities. It wasn't until 2021 that DirecTV was spun off into a separate company again, but still with 70% ownership by AT&T.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#219

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

AT&T is a public company. Public company needs to get fined appropriately.

Start issuing multi billion dollar fines for these breaches and suddenly companies are invested in security.

Unfortunately with government agencies getting defanged as part of recent SCOTUS ruling, it’s likely not possible.

Have to rely on civil court to issue fines now (ie, class action lawsuits).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#220

> Snowflake blamed the data thefts on its customers for not using multi-factor authentication to secure their Snowflake accounts, a security feature that the cloud data giant did not enforce or require its customers to use. And is that going to change?

This is a diversion. Why did they build a system that permitted a bulk database dump of hundreds of millions of rows even with 2FA?

> Why did they build a system that permitted a bulk database dump of hundreds of millions of rows

Should all databases be capped at a few million rows total or something? I don't quite understand where you're going with this.

Post reply on HN