Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.
After Equifax debacle, I don’t think anyone cares. It’ll only be a big deal if there’s a huge B2B leak and business-critical data gets exposed, other than the usual name, address and phone number.
AT&T says criminals stole phone records of 'nearly all' customers in data breach
441–450 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#442Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#443AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#444AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Personal data cannot be secured. The only way is to not store it. That will (imaginationaly) cost companies in lost revenue for being unable to mine and sell it. Only government can make laws against a company taking your personal information and selling it. Even passwords shouldn't be stored by a company. The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 mil…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#445Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#446"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#447Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#448Earlier quoted context omitted.
> It cost money to implement security. Yes, but no amount of money will stop the data in a big database being stolen by someone sufficiently motivated to steal it. It's just bits on someone's disk. The only true solution is to not create the database. But then what would all the data scientists and their MBA masters so with their time?
in this case it’s pretty tough because the phone company does need this metadata just to bill people. so they should protect it properly.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#449AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW
In this case, Snowflake was also the cause for the Ticketmaster and Lending Tree breaches according to the article so…
real lack of trust in Snowflake now.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#450Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…
I was under the impression that the government wasn't allowed to create a mandate that a telco has to save all phone records like that, but it doesn't stop a telco from doing it themselves. I think that would fall more under GDPR limitations?
Some service providers in Europe don't even want to save any data. The linked judgement above was the German state suing Telekom, which didn't want to save that data, and losing. Given the state of affairs, the question of "illegal or not" doesn't really come up as much. At least I'm not aware of any high profile judgements.
Besides Telekom, which always tried to minimize they data they keep to the point of fighting it all the way to Europe's highest courts, most other telcos don't really care and pick whichever middle-ground is available between "must" and "must not". Whatever is least-likely to get them into trouble. Right now that just happens to mean "save little".
* It's not stated explicitly in article 2, but the German constitutional court decided that it follows from those personal rights: https://en.wikipedia.org/wiki/Informational_self-determinati...