Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

221–230 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#221

Is this leak why the spam next messages have gone from “Hi how is your day ?” or “Hi [not my name] please do thing X. Of you’re not [not my name] I’m so sorry perhaps we can be friends.” to “Hi is this [my full name]?” or “Hello [my first name] how is your day ?”

Any leak with your mobile and name pair could have done that. As a non-AT&T customer, I get the my-speecific-name pig butchering texts, too.

True. They’re brand new to me though. I’ve been getting the former for years, the latter for only weeks.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#222

Earlier quoted context omitted.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen. My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere…

As a nobody, I keep wanting a financial product that is a black hole. Money can go in, but cannot come out without significant pain. Seven+ day waiting period, in person visit, physical mail verification, something, anything that means if I do get hacked my accounts are not drained in milliseconds. When I need a legitimate large withdrawal, I can go through the required effort.

This already exists. Withdraw from account to physical cash. Proceed to stash cash in “secret” location.

Most businesses don’t even accept cash anymore. Can’t get “hacked” although it’s prone to many other issues — space, humidity, physical theft.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#223

Earlier quoted context omitted.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

> Totally, way too many people are trying to blame snowflake. Well the _actual_ compromise started from one of their employees, so it's pretty unsurprising that they're getting (some of) the blame.

Ahh. The linked article didn't have that detail.

They attributed it to a lack of 2FA

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#224

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

I keep my credit frozen all the time, but still keep getting alerts about new "no credit check" bank accounts from companies like chime.com. Then I give them my PII again just to verify and close those accounts, even though I don't have any business with them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#225
I find it interesting that in your typical BigCo breach, they are at pains to point out that credit card details were not stolen. I infer from this that something about credit cards, and how they are secured, has real teeth and BigCo's lawyers are trying to stop them biting. Is this PCI-DSS? Maybe someone can comment.

As far as this breach goes, I think it just confirms my gut feel that Snowflake are heading to the wood chipper.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#226

Earlier quoted context omitted.

its not Snowflake's fault their customers used weak passwords and no MFA. Not enforcing MFA does merit some blame on Snowflake, however, I still think its on the customer to secure your own environment.

Totally, way too many people are trying to blame snowflake. ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data. They should be telling Snowflake what best practices to be using, not the other way around!

AT&T is a real-estate company that coincidentally sells telecommunications services. My wife used to work for them and given what she's told me I would never in a million years do any business with them intentionally.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#227
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

> I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway.

This might also explain why there's little visible effect on other cloud database services either. After all, the attack is pretty simple and potentially affects any cloud database that allows access from the Internet.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#228
post #222

Earlier quoted context omitted.

As a nobody, I keep wanting a financial product that is a black hole. Money can go in, but cannot come out without significant pain. Seven+ day waiting period, in person visit, physical mail verification, something, anything that means if I do get hacked my accounts are not drained in milliseconds. When I need a legitimate large withdrawal, I can go through the required effort.

This already exists. Withdraw from account to physical cash. Proceed to stash cash in “secret” location. Most businesses don’t even accept cash anymore. Can’t get “hacked” although it’s prone to many other issues — space, humidity, physical theft.

That sounds like the opposite of what OP wants, because that money can very easily come out, without any pain, and without you even being notified that it's been moved - unless you're re-implementing your own bank-level security, I guess.

For example, let's say you have $100k in savings. I think you would be absolutely bonkers to store that in some secret part of your (flammable! break-in-able!) house.

I guess you could put it in a safety deposit box, and if you needed to spend it in a non-cash way, you could walk it directly to the teller and deposit it and make it available? The equivalent of a cold wallet, I suppose.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#229
post #15

This is the kind of breach that really should be company-ending, but will sadly instead likely result in a slap on the wrist. It is high time for the US to have a privacy law with real teeth, and to enforce it with vigour.

Or maybe it's time to turn software engineering into an actual engineering profession. If the people responsible for designing and maintaining the AT&T system were "real" engineers, they could be sued for malpractice or even lose their license to practice.

The root cause is not whether engineers are licensed (I'm fine with that idea, but it's not going to resolve this specific problem). Instead, it is a culture of not caring about security because the fines are a cost of doing business is, and which comes from management, and treating personal information as an asset instead of a liability.

A Sarbanes-Oxley style law that makes the CEO personally criminally responsible for breaches will be vastly more effective than pursuing individual engineers - many of whom will be on the types of visa where they have no effective route of pushback on orders anyway.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#230
post #103

Earlier quoted context omitted.

Do you really think that requiring 4-year degrees and passing a licensing exam would make a big difference? The fact is that, outside of civil engineering which involves a lot of dealing with regulatory agencies, most engineers in the US don't have PEs. I started on the path to get one because, had I stayed on my initial career path, I'd have been sending blueprints etc. to regulatory agencies but I ended up changing…

No, what will make the difference is being personally liable for the vulnerabilities you introduce. Not the company. You.

Look at Sarbanes-Oxley for precedent. Management has to be made liable for sufficient cultural shift to occur.
Post reply on HN