Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

411–420 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#411

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

I think many companies think they can solve this issue by throwing money at their cyber security teams. It just happens that cyber security teams are often ineffective.

It's hard for a CyberSecurity team to be effective when the Execs keep failing the phishing tests and IT does not have the authority to fire them for it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#412
this breach is of course appalling. But nearly as appalling is the experience of _explaining why this matters_ to non-technical friends who stare at you with blank, distracted eyes, but only for a second; for their phone (yes, the very phone that just exposed them to uncountable future ills) has chimed.

I have nearly given up; like smoking, it will be decades before the harms are understood. We have to wait for your neighbour's brother to have died in a targetted political killing, because someone didn't like his Substack and borrowed the number and likeness of a friend; for his daughter's credit score to have been crushed by an anti-abortioneer who borrowed her face and likeness and number knew her first-grade teacher; for his son to die a death of despair, after making the wrong friends, and getting doxxed along with the rest of them.

This should be a five-foot headline moment. But no; CNN will lead with Biden-mumbles or Trump-grumbles.

How is it that the things that are killing us --- inequality, climate change, privacy collapse -- all have this same shape? Hamlets, all of us.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#413

I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations. Does anybody have any advice? Proving damages means showing actual monetary harm.

And look for Arbitration clause in your contract. Might limit your options.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#414
post #319

The root cause (1) is the data store should not have been available on the underlay network. Anything connected to an underlay network is a ticking time bomb. Any servers or admins which need to talk to the data store should instead use a private overlay (2) network. Any users (likely just remote admins) should do the same. (1) Same root cause as 99% of breaches and yet it is too often swept under the rug while we fo…

It seems from the article that AT&T uploaded data to a cloud service, protected by username and password, and someone obtained credentials or breached the cloud service. What does that have to do with 'underlay networks' and wow is that "the root cause of 99% of breaches"?

OP is using weird terminology. It would probably be clearer to say "Anything connected to the Internet is a ticking time bomb. Any servers or admins which need to talk to the database should instead use a VPN." which indeed was best practice until recently.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#415

Earlier quoted context omitted.

I agree. This is precisely why breaches keep happening and will keep happening. It cost money to implement security. There's no cost benefit to spending that time and money since there are no consequences. Businesses do not spend money unless it will make them money or save them money. There needs to be a hefty federal fine on a per-affected-user basis for data breaches. Also a federal fine for each day a breach is u…

Or a lawsuit go through where someone can win quite a bit from from data leaks. If each person affected sued and won 100k or so, or even 1k, AT&T would definitely be spending money on security. But it appears $5 or credit monitoring from an agency that also gets hacked is sufficient for class action lawsuits.

“12 months free credit monitoring with auto-renewal”.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#416
AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time.

Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#417

I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations. Does anybody have any advice? Proving damages means showing actual monetary harm.

IANAL but this would seem like a “class action” situation.

I also ANAL but if I recall correctly, you can decline to be represented in the class, and file your own lawsuit

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#418
post #407

Earlier quoted context omitted.

Who is the "we" here? And how should companies be held accountable? It's very rare for someone at the highest level to be held to any kind of liability, and paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them. Strictly speaking about the US here.

> paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them. That means the fines aren’t big enough. They should probably be scaled according to the business’ revenue.

From a justice perspective, it should be scaled according to the number of customers impacted (and how bad the impact was). Which is likely to be about the same as scaling with revenue.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#420
post #62

Earlier quoted context omitted.

its not Snowflake's fault their customers used weak passwords and no MFA. Not enforcing MFA does merit some blame on Snowflake, however, I still think its on the customer to secure your own environment.

Snowflake is saying they knew of unusual activity "around mid-April 2024", confirmed "May 23, 2024", around which time they made MFA mandatory (although their customer AT&T say they knew of the breach "Mar 20"; these timelines keep shifting back): "Mandatory MFA option unveiled by Snowflake" - Jul 11, 2024 https://www.scmagazine.com/brief/mandatory-mfa-option-unveil... > "US cloud storage firm Snowflake has already r…

It's not mandatory, I still have Snowflake user accounts that don't use MFA.
Post reply on HN