AT&T says criminals stole phone records of 'nearly all' customers in data breach
331–340 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#332Isnt this just a legally mandated api for all phone operators in the US? Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.
[flagged]
The last whistleblower the US government got to was imprisoned for seven years and identifies as a woman now.
Snowden would be crazy to come anywhere near the US.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#333Isnt this just a legally mandated api for all phone operators in the US? Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.
[flagged]
> to forsake one cause, party, or nation for another often because of a change in ideology
I don't think he left because of a change in ideology.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#334@dang Could I ask why this topic gets systematically penalized in the HN ranking? There have been 15 submissions so far, I assume partly because previous submissions are not shown on the main page so HN users keep re-submitting it. This topic is both newsworthy and high interest. (I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)
The new HN voting mechanism is broken imo. Useless posts and articles of low value make it to the frontpage but valuable ones get shadowed.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#335Some new news in the article and comment: - [security expert] "This [logs without timestamps] isn’t one of their main databases; it is metadata on who is contacting who. Its only real use is to know who is contacting whom and how many times." - [commenter] "I have a theory that this call log was being used for a national security investigation. Otherwise why would this rise to the level of public safety/national secu…
> Its only real use is to know who is contacting whom and how many times. Which is exactly the type of info that would be used to find evidence of an affair. Though this is specific to SMS so it would not include iMessage or other messaging apps.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#336Earlier quoted context omitted.
> Somehow knowing that first boy born today will have an ID number of 120702450001X It's even worse. Only post-2011 IIRC births have an algoirthmic SSN. So everyone over the age of 13 still has old fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by 1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location. For example, I can guess what region…
> 1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location. While the first sentence is true, the second is only true if you were born after the mid-1980s, when a Reagan-era tax reform was enacted. (It required a SSN when claiming dependents.) Prior to that, most people did not get a SSN until they got a job.
https://www.ssa.gov/policy/docs/ssb/v69n2/v69n2p55.html
tl;dr: If you had a bank account, applied for a federal benefit, were on food stamps, applied for school lunch, or did any number of other financial or government transactions, you needed a SSN starting in the 1970s. That's enough of an incentive that many parents might've just applied at birth, figuring that their kid will eventually need it. Also everyone born 1968-1981 would've likely gotten one in 1986, when the change you mentioned about dependents was enacted, and then after 1988 they started being required for issuance of a birth certificate.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#337Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#338Earlier quoted context omitted.
If you go to court and ask for compensation you would likely be asked to show harm. Could you?
Is there no harm, or is there harm that is hard to show in court?
Most people aren't going to have their identity stolen (or insert w/e crime). Those that do will have trouble proving it was from this leak.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#339did they just enumerate an open web endpoint for it or something?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#340Earlier quoted context omitted.
> How many individual engineers do you suppose get prosecuted for making errors--even careless ones? Not many but is that because they don't get sued or because professionals who face consequences for negligence make fewer stupid decisions?
I would assume that engineers, at least in the US, are far more concerned about getting fired/eased out than prosecuted if they do stupid things given that companies can do so pretty easily.