Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

401–410 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#401
post #385

Earlier quoted context omitted.

So do other ISPs. Yet AT&T is by far the worst of all of them with regards to customer privacy. Did you know that AT&T has a commercial product where they sell Metadata of websites visited (unclear if it's only Netflow or if it includes DNS lookups too) to law enforcement and private investigators? AT&T is a blight on the privacy of U.S. citizens.

> Did you know that AT&T has a commercial product where they sell Metadata of websites visited (unclear if it's only Netflow or if it includes DNS lookups too) to law enforcement Do you think that only AT&T does it ? Welcome to democracy, my friend. /s

For their landline customers? I'm not aware of any other ISP that's so shamelessly brazen about the practice.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#402
post #326

Earlier quoted context omitted.

That’s the thing though - this was a snowflake breach. It’s not an AT&T miss because of their decimated sw engineering teams. Snowflake has much better sw engineering than AT&T.

> this was a snowflake breach AT&T was not using MFA, while it was possible. Someone leaked credentials and this is the result. Only thing Snowflake could have done was to force MFA for everyone.

They added a feature recently to make it easy to force mfa

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#403
post #379

Earlier quoted context omitted.

Needs to be at the level of enforcement by regulatory agencies, large scale lawsuits backed by state governments, and maybe even congressional action These companies have scale as their moat and that's called a monopoly. We need to be aggressively pursuing corporate malfeasance, closing loopholes, and breaking up companies. In my ideal world the entire doctrine of the "corporate veil" would be overturned, but that se…

These companies are so massively large that they price in the risk of databreaches as a cost of doing business. Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections. I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.

It seems that we agree that regulatory enforcement is a great framework through which to make this happen. I think we should regulate both security and data retention far more aggressively, and be willing to destroy companies if they fail to comply. The lack of an existential risk makes it easier for them to maneuver around other solutions

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#404

Earlier quoted context omitted.

That requires people to be rich enough to sue. It takes a lot of money and time to sue. Almost no one has enough resources to do this. The courts are not an effective way to implement this policy. Unless you only want rich people to be able to get justice.

110M people impacted = class action The lawyers work on contingency

Class action suits regularly end up getting you "$5" worth of credit monitoring from the exact company who lost your data. It's a joke. Class action suits as they exist today in the US are an abject failure of justice.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#405

Freeze your credit people! It's super easy. It's not a perfect fix but it's so trivial to do and it will help. https://www.usa.gov/credit-freeze You can unfreeze through an app whenever you want/need to.

You can also freeze your non-credit banking: https://www.chexsystems.com/security-freeze/place-freeze It was recommended that I do this after a checking account was opened using my identity. As others have stated, my default is "frozen." I put temporary thaws on when applying for credit, though in some cases, you'll be informed exactly which agency/agencies will be queried, and may not need to unfreeze all of them.

This is a great tip as most people only know of the big 3, thanks for sharing

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#406
I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations.

Does anybody have any advice? Proving damages means showing actual monetary harm.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#407
post #366

At the scale of this kind of incompetent failure, no human being should be on board with the narrative that we should be blaming "criminals" for this If we don't hold companies accountable for keeping far more access and retention than should be legal, and securing their systems poorly, this situation will never get better

Who is the "we" here? And how should companies be held accountable? It's very rare for someone at the highest level to be held to any kind of liability, and paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them. Strictly speaking about the US here.

> paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them.

That means the fines aren’t big enough. They should probably be scaled according to the business’ revenue.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#408
post #379

Earlier quoted context omitted.

Needs to be at the level of enforcement by regulatory agencies, large scale lawsuits backed by state governments, and maybe even congressional action These companies have scale as their moat and that's called a monopoly. We need to be aggressively pursuing corporate malfeasance, closing loopholes, and breaking up companies. In my ideal world the entire doctrine of the "corporate veil" would be overturned, but that se…

These companies are so massively large that they price in the risk of databreaches as a cost of doing business. Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections. I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.

> These companies are so massively large that they price in the risk of databreaches as a cost of doing business.

Just make the fine a % of the annual revenue and that will change.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#409

I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations. Does anybody have any advice? Proving damages means showing actual monetary harm.

IANAL but this would seem like a “class action” situation.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#410
post #382

"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…

ATT could be using Snowflake for internal analytics

It's not "internal analytics", because a) 90% of the data was former customers and b) it has location data but timestamps were removed, so it's social-graph information plus location. Start asking yourself what sorts of end-users want to pay for the entire social-graph of 77m, regardless whether those customers never make a phone call again.

"Alternate credit scoring, hyper-targeted marketing and more... an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries." was the blurb for the unit Snowflake specially set up for Telco data in early 2023 touting "location data", but this product is not aimed at the telco's use-case; coincidentally this was also around the time Snowflake was touting integration with GenAI.

(It's not "competitor analysis" either, because if it was they would have obscured the 68m former phone numbers to prevent abuse by direct-marketing.)

[0]: "Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/

Post reply on HN