(I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)
AT&T says criminals stole phone records of 'nearly all' customers in data breach
321–330 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#322Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.
Is there any reason not to keep credit frozen permanently , only unfreezing it when you're making a large purchase that requires it?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#323Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#324Earlier quoted context omitted.
That doesn't excuse this. If these records only existed so they could give them to the NSA at a later time, that further illustrates the dangers of accommodating the agency's desire for access to data generated from the U.S. Telecom backbone.
It does explain it though. By coincidence they also get billions of dollars in federal subsidies
Did you know that AT&T has a commercial product where they sell Metadata of websites visited (unclear if it's only Netflow or if it includes DNS lookups too) to law enforcement and private investigators?
AT&T is a blight on the privacy of U.S. citizens.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#325Some new news in the article and comment: - [security expert] "This [logs without timestamps] isn’t one of their main databases; it is metadata on who is contacting who. Its only real use is to know who is contacting whom and how many times." - [commenter] "I have a theory that this call log was being used for a national security investigation. Otherwise why would this rise to the level of public safety/national secu…
Which is exactly the type of info that would be used to find evidence of an affair.
Though this is specific to SMS so it would not include iMessage or other messaging apps.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#326Earlier quoted context omitted.
The problem is then you have even fewer technically-competent people internally to actually manage the cloud, and combined with AWS's many documented footguns it's not clear to me the "new normal" is actually any better for security. You go from being a potentially-small-fry target to getting your data collated in massive breaches. There's risks to both.
That’s the thing though - this was a snowflake breach. It’s not an AT&T miss because of their decimated sw engineering teams. Snowflake has much better sw engineering than AT&T.
AT&T was not using MFA, while it was possible. Someone leaked credentials and this is the result. Only thing Snowflake could have done was to force MFA for everyone.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#327@dang Could I ask why this topic gets systematically penalized in the HN ranking? There have been 15 submissions so far, I assume partly because previous submissions are not shown on the main page so HN users keep re-submitting it. This topic is both newsworthy and high interest. (I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#328Earlier quoted context omitted.
I never understood the american secrecy about SSN... it should be a "username" not a "password"... In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business. Somehow k…
I never understood the american secrecy about SSN... it should be a "username" not a "password"... The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!" It's not the leak that's the problem; it's the ease with which that leaked…
In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from your bank.
Brazilian banks before that used to provide a card of 50-100 tokens you'd use for authenticating, which is obviously dangerous as people would carry them in their wallets with their cards (and associated banking details). Since the early 2010s banks have instead provided a physical OTP generator that you associate with your account.
In Sweden if I lose access to my phone with my digital identification app (BankID) I can fall back to my hardware OTP generator to login into my account, and authorise a new BankID installation in case I need a new phone.
It's a solved problem, even though the US developed a lot of the tech industry it feels like digital infrastructure is still in the late 90s for a lot of stuff; banking is a clear case, and government systems are another good example, e.g.: the DHS website for visa application is atrocious, we are in 2024 and applying for a visa feels like an experience from when I navigated the web on Netscape in the early 2000s.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#329Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.
I was unable to get any of the three to verify my identity last I did this, and one of the three has never once in my 15 years of trying to get my free credit report let me actually get it.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#330Isnt this just a legally mandated api for all phone operators in the US? Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.