Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

291–300 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#291
post #258
post #241

Earlier quoted context omitted.

No two people are incompetent in exactly the same way. Hiring two developers to review each other's code leads to better code because they will often find problems that the other one didn't see. In a well managed organization (admittedly not a trivial caveat these days), more people working on security leads to better security.

Certainly, but for instance no sane developer should concatenate a string in a sql query unless there is absolutely certainty the string is safe. This should be reflex, not a matter of money or time.

People are alway going to make bad decisions. Sometimes that is out of a lack of experience or knowledge which can be fixed by better training (which also requires money). Other times it is out of apathy, laziness, or something else that can't be easily fixed. Either way, time and money can provide extra sets of eyes to find and fix those mistakes before they lead to a breach.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#292
post #288

You would effectively be able to cross reference this meta data with 2 factor authentication services. It’s probably time to start removing this option entirely.

How would cross-referencing be useful? You’d just find out what services people use?

I guess after mapping the services used you would find the accounts worth going for and those become SIM swap targets

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#294

Earlier quoted context omitted.

Unfortunately, that analysis seems to have made absolutely no attempt to check whether the results are statistically significant. Pick 118 random companies at 118 random points in time. It's vanishingly unlikely that the average returns of that group will exactly track the NASDAQ returns over the following 60 days. It might underperform, or it might overperform. An underperformance of 3.2% could easily just be the re…

My hypothesis would be that companies with poor operational practices are more likely to underperform the index and have data breaches - in other words, that the study confuses cause and effect. This wouldn't be that hard to test. I suspect that the breached companies underperformed in the six months before the breach as well as the six months after.

Also, events which are not "just" data-leaks but also interruptions or degradation in regular operations. I suspect investors may be more sensitive to those events and their fallout, and such events more likely to either be caused by bad-practice or to be somehow connected to data-leaks.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#295

This happened in 2022 and they're just disclosing it now? Or did they just find out about it, which is maybe even worse?

The data was from 2022. The breach was from april of this year.

Who was the data being kept for?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#297

Earlier quoted context omitted.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

This is how I have operated ever since the Equifax breach. Once that happened, none of the others seemed to matter, everything important for identity theft is out there. I've had no problems. Someone will try to run my credit, it will fail, then I ask which one they're trying to use, and I unfreeze it for a day. Some of them have the option to unfreeze for a single pull with a 1 time code (if I remember correctly), b…

Credit is a weird ad-how system.

At some point, I wonder if folks will realize that having an unfrozen credit report is a sign of imprudence.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#298

"AT&T reveals it has records of cellular customers calls and texts" These records should have been deleted at the latest at the point where they're no longer relevant for billing. (Which also means that for customers with unlimited calling/texting, there shouldn't be any records in the first place.)

I wish that were the world we live in.

This is from the Snowflake breach, meaning this database was an "AI Powered Unified Data Platform." It almost feels like the erosion of our privacy is fueling the growth of allot companies.

I really hope that the boogeyman is real and all this was worth it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#299
post #292
post #288

Earlier quoted context omitted.

How would cross-referencing be useful? You’d just find out what services people use?

I guess after mapping the services used you would find the accounts worth going for and those become SIM swap targets

Seems like there's a lot of cross referencing well beyond MFA that this'll likely be used for.

Way easier to target phish people's bank logins, if you know what banks they are regularly communicating with.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#300

Earlier quoted context omitted.

The data was from 2022. The breach was from april of this year.

Who was the data being kept for?

ATT did not answer this question. I would expect them to keep phone records going back a ways, but 2022 seems pretty far. I'd guess for law enforcement.
Post reply on HN