Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

321–330 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#321
@dang Could I ask why this topic gets systematically penalized in the HN ranking? There have been 15 submissions so far, I assume partly because previous submissions are not shown on the main page so HN users keep re-submitting it. This topic is both newsworthy and high interest.

(I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#322

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?

As someone else mentioned, some authentication schemes require your credit to be unfrozen. This can include insurance companies (really any company that needs to verify your identity)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#324

Earlier quoted context omitted.

That doesn't excuse this. If these records only existed so they could give them to the NSA at a later time, that further illustrates the dangers of accommodating the agency's desire for access to data generated from the U.S. Telecom backbone.

It does explain it though. By coincidence they also get billions of dollars in federal subsidies

So do other ISPs. Yet AT&T is by far the worst of all of them with regards to customer privacy.

Did you know that AT&T has a commercial product where they sell Metadata of websites visited (unclear if it's only Netflow or if it includes DNS lookups too) to law enforcement and private investigators?

AT&T is a blight on the privacy of U.S. citizens.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#325
post #313

Some new news in the article and comment: - [security expert] "This [logs without timestamps] isn’t one of their main databases; it is metadata on who is contacting who. Its only real use is to know who is contacting whom and how many times." - [commenter] "I have a theory that this call log was being used for a national security investigation. Otherwise why would this rise to the level of public safety/national secu…

> Its only real use is to know who is contacting whom and how many times.

Which is exactly the type of info that would be used to find evidence of an affair.

Though this is specific to SMS so it would not include iMessage or other messaging apps.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#326
post #200

Earlier quoted context omitted.

The problem is then you have even fewer technically-competent people internally to actually manage the cloud, and combined with AWS's many documented footguns it's not clear to me the "new normal" is actually any better for security. You go from being a potentially-small-fry target to getting your data collated in massive breaches. There's risks to both.

That’s the thing though - this was a snowflake breach. It’s not an AT&T miss because of their decimated sw engineering teams. Snowflake has much better sw engineering than AT&T.

> this was a snowflake breach

AT&T was not using MFA, while it was possible. Someone leaked credentials and this is the result. Only thing Snowflake could have done was to force MFA for everyone.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#327
post #321

@dang Could I ask why this topic gets systematically penalized in the HN ranking? There have been 15 submissions so far, I assume partly because previous submissions are not shown on the main page so HN users keep re-submitting it. This topic is both newsworthy and high interest. (I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)

The new HN voting mechanism is broken imo. Useless posts and articles of low value make it to the frontpage but valuable ones get shadowed.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#328

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…

I never understood the american secrecy about SSN... it should be a "username" not a "password"... The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!" It's not the leak that's the problem; it's the ease with which that leaked…

> Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked.

In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from your bank.

Brazilian banks before that used to provide a card of 50-100 tokens you'd use for authenticating, which is obviously dangerous as people would carry them in their wallets with their cards (and associated banking details). Since the early 2010s banks have instead provided a physical OTP generator that you associate with your account.

In Sweden if I lose access to my phone with my digital identification app (BankID) I can fall back to my hardware OTP generator to login into my account, and authorise a new BankID installation in case I need a new phone.

It's a solved problem, even though the US developed a lot of the tech industry it feels like digital infrastructure is still in the late 90s for a lot of stuff; banking is a clear case, and government systems are another good example, e.g.: the DHS website for visa application is atrocious, we are in 2024 and applying for a visa feels like an experience from when I navigated the web on Netscape in the early 2000s.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#329
post #248

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

I was unable to get any of the three to verify my identity last I did this, and one of the three has never once in my 15 years of trying to get my free credit report let me actually get it.

I think you can go the paper route and mail something in to freeze
Post reply on HN