Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

281–290 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#281

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

You can also freeze your non-credit banking:

https://www.chexsystems.com/security-freeze/place-freeze

It was recommended that I do this after a checking account was opened using my identity.

As others have stated, my default is "frozen." I put temporary thaws on when applying for credit, though in some cases, you'll be informed exactly which agency/agencies will be queried, and may not need to unfreeze all of them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#285

It's ok everyone! Protecting our data is one of AT&T's top priorities. > Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured. > We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you…

Not their fault. Snowflake was breached. And the data was with Snowflake.

Snowflake was "breached" by AT&T users using the same password in Snowflake and another system that was breached.

This is just trivial pivoting done with some guesswork done fairly well.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#287

"AT&T reveals it has records of cellular customers calls and texts" These records should have been deleted at the latest at the point where they're no longer relevant for billing. (Which also means that for customers with unlimited calling/texting, there shouldn't be any records in the first place.)

They keep all records for 7 years because the US Federal Government asked them to, not because they legally have to, but same with T-Mobile and Verizon: https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...

Wasn't there some telco executive that was tossed in jail not long after 9/11 because he didn't want to play along with the government and keep data around forever?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#288

You would effectively be able to cross reference this meta data with 2 factor authentication services. It’s probably time to start removing this option entirely.

How would cross-referencing be useful? You’d just find out what services people use?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#289

These are all security nightmares aren't they? It smells as if all the resources went into delivering billing, then barely enough for technically working service, and then is there even anything leftover for security (instead of this being part of the foundation of a service)?

Something happens when you tune your business only to the things you can measure.

I still (or at least try to still) have this naive opinion that if you make a good product, the money will come.

We sometimes spend too much time counting the beans and not enough time growing them. Not saying you don't need to count the beans, you do, but when your whole team is counting, they may forget to water them.

Also - to be on topic - don't forget to protect the beans!

Post reply on HN