Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

451–460 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#451

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Yeah, you're right. Data breaches are essentially just slaps on the wrist to companies like AT&T. Maybe it's possible to fine them based on the proportion of the userbase that was affected and the profits they generated for a certain time period.

I wonder if this will push companies to stop using external vendors to store and process data. If companies stored all of their info in house, it would prevent the case where compromising one vendor compromises everyone's data. But it would also mean that each individual company needs to do a good job securing their data, which seems like a tall ask.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#452

I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations. Does anybody have any advice? Proving damages means showing actual monetary harm.

You likely cannot file in small claims and would need to pursue arbitration instead. > Please read this Agreement carefully. It requires you and AT&T to resolve disputes through arbitration on an individual basis rather than jury trials or class actions. https://www.att.com/legal/terms.consumerServiceAgreement.htm...

- AT&T will usually pay all of the arbitration fees (with some exceptions).

That could get pretty expensive for them quickly.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#453

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

According to the article, the data was being made available to other businesses... From the detail level involved, I imagine the NSA has some sweeter deal with telcos... And they have much richer data.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#454
post #345
post #75

And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life. Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

It’s okay, will no longer be problem after Social Security Admin itself fails in next decade for being unsustainable

Why would that happen?

(Payouts are expected to drop in about ten years if no action is taken, but that doesn’t render the SSA irrelevant or cause it to suddenly collapse and shut down, so I assume you mean something else)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#456

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

You live in a place where the government is for the people, not for themselves.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#457

I would like to sue AT&T in small claims for this and for leaking my Social Security number. But it's difficult to prove damages in these situations. Does anybody have any advice? Proving damages means showing actual monetary harm.

IANAL but this would seem like a “class action” situation.

Very difficult to run these days. Since 2018, federal courts have ground away many of the legal routes needed to run a successful class action suit against a national or multinational corporation.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#458
post #410
post #382

Earlier quoted context omitted.

ATT could be using Snowflake for internal analytics

It's not "internal analytics", because a) 90% of the data was former customers and b) it has location data but timestamps were removed, so it's social-graph information plus location. Start asking yourself what sorts of end-users want to pay for the entire social-graph of 77m, regardless whether those customers never make a phone call again. "Alternate credit scoring, hyper-targeted marketing and more... an emerging…

Snowflake PR, from the link above: "What makes telecom service providers unique is that they have access to consumer location data. For most other industries, a consumer can go into their phone’s privacy settings and turn off the location access in the smartphone app. But in the world of telecom, as long as the phone is connected to a network, the telecom provider can use triangulation to find the approximate location of a consumer. This is why there is an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries from competitor intelligence, alternate credit scoring, hyper-targeted marketing and more."

That pretty much says it.

It's disappointing that TechCrunch didn't point this out. Nor did the New York Times.[1] Yet it's right there on Snowflake's site.

[1] https://www.nytimes.com/2024/07/12/business/att-data-breach....

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#459

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#460

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The AT&T app and website are so bad it takes way longer than 1 minute to log in to e.g. pay your bill. The United States needs to raise the bar for large-cap negligent operators and fine the company enough to make shareholders listen.
Post reply on HN