Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

391–400 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#391

Big breaches like this are gonna be wild with advanced GenAI. Combing through the shit for the diamonds provided some degree of limitation on the impact of big breaches in the past but all those calls are going to be accurately transcribed and mined by AI and the attackers are going to have a buffet of products and targets laid at their feet.

It's just metadata, no transcription of calls can take place. In the future, please read the article before engaging in the discussion of its content.

> It's just metadata

That's what they always say, honey, before calling the police. /s

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#392
post #359

"It remains unclear why so many major corporations persist in the belief that it is somehow acceptable to store so much sensitive customer data with so few security protections." It's because there are almost no consequences to them if they lose the customer data, beyond a day or two of bad press. If they faced significant fines, fines that get worse the more sensitive the data is, then they'd have an incentive to do…

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#398
post #379

Earlier quoted context omitted.

Who is the "we" here? And how should companies be held accountable? It's very rare for someone at the highest level to be held to any kind of liability, and paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them. Strictly speaking about the US here.

Needs to be at the level of enforcement by regulatory agencies, large scale lawsuits backed by state governments, and maybe even congressional action These companies have scale as their moat and that's called a monopoly. We need to be aggressively pursuing corporate malfeasance, closing loopholes, and breaking up companies. In my ideal world the entire doctrine of the "corporate veil" would be overturned, but that se…

These companies are so massively large that they price in the risk of databreaches as a cost of doing business.

Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections.

I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#399

"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…

This would probably be no different if someone like Salesforce had a breach and a large customer of theirs being impacted. There are large companies using SaaS services for a chunks of their back office stuff.
Post reply on HN