Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

251–260 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#251

Earlier quoted context omitted.

The Mandiant report said that some Snowflake customers declined to use MFA AND had passwords in place for 4+ years[1]. Maybe Snowflake should have pushed for MFA harder but at the end of the day, this is AT&T's fault. [1] https://cloud.google.com/blog/topics/threat-intelligence/unc...

I'd say the blame lies halfway between AT&T and Snowflake. If you let your customers have poor security practices, and you have the power to ensure a heightened security level, you're also partly to blame...

Snowflake also made it hard to have good practices, giving them further culpability. There was no setting for customers to force their entire tenant to enforce MFA. Customers had to depend on each person with access to do the right thing, something that is unlikely to be universally true.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#252
post #197

Earlier quoted context omitted.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

One interesting thing I ran into with frozen credit, is that you cannot sign up for USPS informed delivery without them running your credit as a method of address verification IIRC. If it is frozen the process gets stuck in limbo (at least it did many years ago when I ran into this situation)

This is no longer the case. I signed up for Informed Delivery last year with frozen credit with no issues.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#254

Earlier quoted context omitted.

Do you exclusively use signal? Do your friends also use signal? Do you have friends who only use signal to communucate with you?

I am working on this with mine, but even Signal is too weaksauce in my book. Ownerless (and ideally decentralized) p2p chat is what I am after. If everyone in my group used Android then it'd be Briar or Cwtch hands down for primary text/picture msg and SimpleX or Session or Jami as voice/video call and backup. Because there's an iphone upsetting everything that scratches Briar and Cwtch, so it's SimpleX reinforced wi…

Do you make it like a fun game? Like when me and my friends in school would pass eachother coded notes and the cipher was an inside joke?

I'm genuinely curious: what was the pitch that you used to get others to start using signal?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#255
post #24

Earlier quoted context omitted.

Do you exclusively use signal? Do your friends also use signal? Do you have friends who only use signal to communucate with you?

Yes.

Do you make it like a fun game? Like when me and my friends in school would pass eachother coded notes and the cipher was an inside joke?

I'm genuinely curious: what was the pitch that you used to get others to start using signal?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#257

Earlier quoted context omitted.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen. My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere…

If you have at least a fraud watch on your credit which means creditors are supposed to call you on the number they have listed before they open new accounts, then the money is arguably worth protecting more. But if you think it's tough to convince the bank with which you have an existing relationship that you didn't make some withdrawals, imagine trying to convince a bank you've never heard of that you didn't actual…

I often choose Abu Dhabi as an "example destination", because that's where Garfield kept mailing Nermal in the comics.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#258
post #241
post #170

Earlier quoted context omitted.

Most breaches are because of developper incompetence. Throwing money at it won't really help. You need better basic security skills.

No two people are incompetent in exactly the same way. Hiring two developers to review each other's code leads to better code because they will often find problems that the other one didn't see. In a well managed organization (admittedly not a trivial caveat these days), more people working on security leads to better security.

Certainly, but for instance no sane developer should concatenate a string in a sql query unless there is absolutely certainty the string is safe. This should be reflex, not a matter of money or time.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#259

It's ok everyone! Protecting our data is one of AT&T's top priorities. > Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured. > We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you…

Not their fault. Snowflake was breached. And the data was with Snowflake.

Your contractor being breached means you were breached.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#260

I find it interesting that in your typical BigCo breach, they are at pains to point out that credit card details were not stolen. I infer from this that something about credit cards, and how they are secured, has real teeth and BigCo's lawyers are trying to stop them biting. Is this PCI-DSS? Maybe someone can comment. As far as this breach goes, I think it just confirms my gut feel that Snowflake are heading to the w…

I think it's a desperate attempt to downplay the severity in any way plausible, taking advantage of the fact that credit card numbers and social security numbers have been mythologized in the American consciousness as nearly-mystical totems of identity and security, as part of the "identity theft" meme, even though they play little role in actual information security or privacy.
Post reply on HN