Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

361–370 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#363
Criminal charges need to be filed and class action lawsuit for fraudulent services for all the customers duped into renewing monthly services ignorant of the fact the service is not secure as plainly stated it must be in federal law.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#364

It's ok everyone! Protecting our data is one of AT&T's top priorities. > Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured. > We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you…

Not their fault. Snowflake was breached. And the data was with Snowflake.

That’s not how any shared responsibility model works

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#365

Earlier quoted context omitted.

[flagged]

What do you think would have happened to him if he had stayed here? The last whistleblower the US government got to was imprisoned for seven years and identifies as a woman now. Snowden would be crazy to come anywhere near the US.

He didn't disagree with the need to leave for Snowden, he said it wasn't a defection.

Snowden hasn't defected the US anymore than the Dalai Lama has been deflected Tibet.

I guess "went into exile" would be the proper naming.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#366
At the scale of this kind of incompetent failure, no human being should be on board with the narrative that we should be blaming "criminals" for this

If we don't hold companies accountable for keeping far more access and retention than should be legal, and securing their systems poorly, this situation will never get better

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#367

Isnt this just a legally mandated api for all phone operators in the US? Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.

It doesn't appear to be, though it was speculated that it might be. Companies keep all that data in the hope of making money by mining it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#368

Earlier quoted context omitted.

[flagged]

Why are you booing him? He's right! > to forsake one cause, party, or nation for another often because of a change in ideology I don't think he left because of a change in ideology.

he was not heading to russia. he's just trapped there

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#369

Earlier quoted context omitted.

[flagged]

What do you think would have happened to him if he had stayed here? The last whistleblower the US government got to was imprisoned for seven years and identifies as a woman now. Snowden would be crazy to come anywhere near the US.

The parent wasn't arguing he should come back but saying that "defected" is not the correct word. The correct phrase is probably "took asylum."

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#370
post #319

The root cause (1) is the data store should not have been available on the underlay network. Anything connected to an underlay network is a ticking time bomb. Any servers or admins which need to talk to the data store should instead use a private overlay (2) network. Any users (likely just remote admins) should do the same. (1) Same root cause as 99% of breaches and yet it is too often swept under the rug while we fo…

It seems from the article that AT&T uploaded data to a cloud service, protected by username and password, and someone obtained credentials or breached the cloud service. What does that have to do with 'underlay networks' and wow is that "the root cause of 99% of breaches"?

An attacker who gets username/pw still can't get on the overlay network (the overlay requires credentials which can't easily be stolen or compromised, e.g. a private key signed X.509 certificate).

Yes, because 99% of attacks use the underlay network to access the target and exfiltrate the data. Said the other way, an attacker didn't physically walk into a Snowflake data center, console into the right server, and walk out with all the data.

Post reply on HN