Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

231–240 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#231

There's no way to make the software perfectly safe from hackers and from social engineering. So, yes, companies should be more careful with the data and, yes, the data shouldn't be kept forever. I agree companies should be doing more to protect the data. I see lots of outrage at the companies and why isn't the government doing more to punish them and how do I get compensated ... But, I feel like everyone is blaming t…

The problem with analogies is that they're a leaky abstraction. You're comparing a single person with maybe a handful of employees to a giant, multinational corporation with corporate offices, hundreds of thousands of employees, enough real-estate to create a small country, and billions of dollars per year in revenue. It's a false equivalence to compare this to door kicking like it was some kind of petty theft.

They literally kept everyone's information in a machine that was connected to the internet and then didn't make any effort to treat that with the gravitas it deserves. They are not the victim here, we are. It's a little shameful that you don't see that.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#232

Earlier quoted context omitted.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

That’s what I do. But it’s a little bit of pain to unfreeze your credit with three bureaus when you want a new credit card. Wish there was a way to do this in one place.

After the first time unfreezing, I put the website URL, unlock pins, and concise instructions for all 3 as a single note in my password vault.

Doing all 3 takes ~5minutes now - which can usually happen in parallel with whatever paperwork the vendor needs to get in order.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#234

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

what app or website do you use? Seems like you have to sign up for all three websites? Equifax Experian TransUnion?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#235

Earlier quoted context omitted.

Well it's starting to feel like data privacy just doesn't exist anymore. I don't know why administrators for big customer databases even bother setting passwords these days.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen. My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere…

If you have at least a fraud watch on your credit which means creditors are supposed to call you on the number they have listed before they open new accounts, then the money is arguably worth protecting more. But if you think it's tough to convince the bank with which you have an existing relationship that you didn't make some withdrawals, imagine trying to convince a bank you've never heard of that you didn't actually approve a loan for 3 Cadillac Escalade Platinums which neither you nor the bank realize are currently in a shipping container on their way to Abu Dabi.

(Nothing against Abu Dabi— I just picked a random place not under US jurisdiction where plenty of people have Escalade Platinum money.)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#236

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

> Somehow knowing that first boy born today will have an ID number of 120702450001X It's even worse. Only post-2011 IIRC births have an algoirthmic SSN. So everyone over the age of 13 still has old fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by 1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location. For example, I can guess what region…

> 1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location.

While the first sentence is true, the second is only true if you were born after the mid-1980s, when a Reagan-era tax reform was enacted. (It required a SSN when claiming dependents.) Prior to that, most people did not get a SSN until they got a job.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#237
post #229

Earlier quoted context omitted.

Or maybe it's time to turn software engineering into an actual engineering profession. If the people responsible for designing and maintaining the AT&T system were "real" engineers, they could be sued for malpractice or even lose their license to practice.

The root cause is not whether engineers are licensed (I'm fine with that idea, but it's not going to resolve this specific problem). Instead, it is a culture of not caring about security because the fines are a cost of doing business is, and which comes from management, and treating personal information as an asset instead of a liability. A Sarbanes-Oxley style law that makes the CEO personally criminally responsible…

When a doctor is negligent, their employer is often also sued if it can be shown that it knew shenanigans were underway and did nothing.

We shouldn't choose between holding engineers or executives responsible. Each should be held responsible for their part.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#238

AT&T bought into a significant amount of DirecTV - so much so that everything that had the DirecTV logo on it was changed to the AT&T logo, such as the invoicing. So the AT&T customer base has included, for several years, the Directv customer base. The article doesn't attempt to clarify who the 'nearly all' customers are, and some people will jump to the conclusion that it is the cell phone customers. But it could in…

AT&T does a lot more than just cell phones. Probably also the largest US ISP behind Comcast, I'd expect. I had AT&T fiber to the home at a previous residence, and that was a great product. Far superior to Comcast.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#239

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

I couldn't find a reference to an app on the linked page, could you share more details on the app you use?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#240
post #76

Earlier quoted context omitted.

The dark web and info stealing malware are the source of the hacks. My worry is not only that consumers get numb to breaches, but they consume rampant misinformation and have no idea how to hold appropriate parties accountable. How many times have you held AWS accountable for stolen access keys? Was it AWS fault when rabbit leaked their own keys? Is it snowflakes fault when you lose your creds to infostealing malware…

Eh, iirc the source of the hack was just regular stealers like Redline, not "the dark web". It was actually Snowflakes fault. The threat actors were able to find a test/demo account they could log into and from there they were able to access prod things they shouldnt have.

This is exactly the kind of comment I'm talking about. You have not read anything from snowflake, mandiant or crowdstrike on this, and you haven't even read the cnn article that has snowflakes response on this. The snowflake demo account has nothing to do with it.
Post reply on HN