Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

301–310 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#301

Earlier quoted context omitted.

Who was the data being kept for?

ATT did not answer this question. I would expect them to keep phone records going back a ways, but 2022 seems pretty far. I'd guess for law enforcement.

I think there is a requirement to keep them 18 months. Any reasons to keep them in bulk for longer than that are probably bad.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#302
post #5

This is another consequence of the surveillance state. The same data that can be used to surveil us by the government can be stolen by who-knows-who. We’d all (mostly) be far better off, IMO, if companies didn’t retain such records.

My wet dream would be a dump of all SMS or Meta or iMessage messages for a multiyear period for nearly 90% of users. Only when Normie Norman's private chats to his mistress and other little relationship trust disrupting secrets become uncensorably hosted on the darknet and freely searchable, only then will Normie Norman get a clue and install SimpleX/Briar/Cwtch/any other owner-free decentralized p2p chat.

Not unrealistic. I used to have a tail of all SMS texts running 24/7 and was required to grep for specific terms for certain agencies until they eventually had their own access. This was only SS7 based texts and was long before RCS existed. I could have saved it all to my workstation but knew better than to do that. Either way SS7 and text messages are very insecure.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#303

"While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number" In other words, your phone number and name is likely in a public record somewhere. It's not that private. The info leak should not have happened but in the grand scheme of things it's not that big a deal. "The content of the calls and messages was…

That metadata was can be terrible for many people like politicians, those having affairs, drug dealers or buyers, those with sensitive healthcare providers, and so on.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#304
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.

My reading is that the market thinks Snowflake takes the majority of the blame, and the content of the linked article seemed to suggest as much despite having only AT&T in the headline.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#305

"While the data does not include customer names, there are often ways, using publicly available online tools, to find the name associated with a specific telephone number" In other words, your phone number and name is likely in a public record somewhere. It's not that private. The info leak should not have happened but in the grand scheme of things it's not that big a deal. "The content of the calls and messages was…

That metadata was can be terrible for many people like politicians, those having affairs, drug dealers or buyers, those with sensitive healthcare providers, and so on.

This. If you're in an abusive relationship and your abuser sees that you're calling a lawyer, a helpline, a family member etc, bad things can happen quite quickly. This information is non-public for a reason, and you don't have to be a drug dealer to be protected by it either.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#306

Big breaches like this are gonna be wild with advanced GenAI. Combing through the shit for the diamonds provided some degree of limitation on the impact of big breaches in the past but all those calls are going to be accurately transcribed and mined by AI and the attackers are going to have a buffet of products and targets laid at their feet.

It's just metadata, no transcription of calls can take place. In the future, please read the article before engaging in the discussion of its content.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#307
post #287

Earlier quoted context omitted.

They keep all records for 7 years because the US Federal Government asked them to, not because they legally have to, but same with T-Mobile and Verizon: https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...

Wasn't there some telco executive that was tossed in jail not long after 9/11 because he didn't want to play along with the government and keep data around forever?

https://en.wikipedia.org/wiki/Joseph_Nacchio

> Joseph P. Nacchio was the only head of a communications company to demand a court order, or approval under the Foreign Intelligence Surveillance Act, in order to turn over communications records to the NSA.[11]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#308
post #288

You would effectively be able to cross reference this meta data with 2 factor authentication services. It’s probably time to start removing this option entirely.

How would cross-referencing be useful? You’d just find out what services people use?

If GitHub always uses the same number(s) for 2fa and there are outgoing texts to your number then the connection is obvious. I’ve read that sim jacking is somewhat common and this would be a good data point.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#309

It's ok everyone! Protecting our data is one of AT&T's top priorities. > Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured. > We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you…

There may be no "good" telcos or big tech firms, but some are absolutely worse than others. AT&T is actively hostile in a way others aren't.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#310

Earlier quoted context omitted.

Well it's starting to feel like data privacy just doesn't exist anymore. I don't know why administrators for big customer databases even bother setting passwords these days.

My mother was concerned that some of her information, and mine, leaked because she signed up for another bank account from a place she decided she didn't trust. She said she wasn't worried about the money being stolen, but she was worried about our identities being stolen. My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere…

Classic Mitchell and Webb skit[0]:

Bank: "No, you see it was your identity that they stole!"

Customer: "Well I don't know because I seem to have my identity whereas you seem to have lost several thousands of dollars. I'm not clear why you think it's my identity that was stolen rather than your money."

0: https://www.youtube.com/watch?v=CS9ptA3Ya9E

Post reply on HN