My guess is that the tech leaders a AT&T are going to have sore wrists for a few minutes because of this.
AT&T says criminals stole phone records of 'nearly all' customers in data breach
461–470 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#462- guessing it was some GenAI startup looking into consumer tracking, alternate credit scoring, surveillance or other national-security use-case.
- Very unusually, the DOJ ordered two ~month-long "delay periods" in disclosure: ("The Justice Department determined on May 9 and again on June 5 that a delay in providing public disclosure was warranted"). Yet this didn't happen for Ticketmaster or MOVEit breaches revealed around the same time. "Cybersecurity delay period requests" is a new power quietly authorized by the DOJ+SEC+FBI, 18 Dec 2023 [0]. Note that [1] emphasizes this as "Corporate Alert - guidance for delay requests [on SEC 8-K]". Might Congress already have known/suspected, when it authorized the cybersecurity delay request powers, of the Snowflake/AT&T breach? Either way, whoever is involved seems to have very powerful friends. Also, the big FISA renewal vote was Apr 19 2024 [2].
- Seems the cloud instance was set up the same time GPT-4 was released (March 2023), also when Snowflake set up a Telco business unit [3] ("Location data... Alternate credit scoring, hyper-targeted marketing and more... an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries"). This product is not aimed at the telcos' use-cases, but at new revenue streams. (Who might the unnamed Snowflake AI partner(s) be?)
- They set up the Snowflake instance with AT&T/MVNO customers with timestamps removed, but with location data, yet the phone numbers not obscured or removed. Doesn't sound like "internal analytics" or "competitor analysis". What sorts of end-users want to pay for the entire social-graph of 110m, regardless whether those customers never make a phone call again? [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]
[0]: "FBI Guidance to Victims of Cyber Incidents on SEC Reporting Requirements: FBI Policy Notice Summary" https://www.fbi.gov/investigate/cyber/fbi-guidance-to-victim...
[1]: "US Corporate Alert - DOJ, FBI, and SEC provide guidance for delay requests relating to disclosure of cybersecurity incidents under form 8-K" https://www.klgates.com/DOJ-FBI-and-SEC-Provide-Guidance-for...
[2]: US House approves FISA renewal – warrantless surveillance and all https://news.ycombinator.com/item?id=40041784
[3]: Snowflake cloud Telco unit, 4/2023: "Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#463AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Yeah, you're right. Data breaches are essentially just slaps on the wrist to companies like AT&T. Maybe it's possible to fine them based on the proportion of the userbase that was affected and the profits they generated for a certain time period. I wonder if this will push companies to stop using external vendors to store and process data. If companies stored all of their info in house, it would prevent the case wher…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#464Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…
You live in a place where the government is for the people, not for themselves.
The court case I linked is evidence of that. The German state wanted Telekom to save more data, but the telco refused and won in court.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#465This happened in 2022 and they're just disclosing it now? Or did they just find out about it, which is maybe even worse?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#466Earlier quoted context omitted.
> indeed was best practice until recently But we should remember why it's not always considered best practices... you shouldn't assume that your private network is any more secure than the public network. When you have too many devices attached to that private (overlay?) network, it can be at just as much risk as if it was on the public internet. So, the zero-trust model is that you don't trust anything... public...…
yep was trying to avoid word which carry varying connotations, e.g. vpn or zero trust. zero implicit trust is likely the best term? you have to trust something, but enforce (and therefore trust) strong (not network based) identity, authN and authZ. this can be done anywhere via a software-only overlay. a litmus test is server iptables (to use an example) looks like: iptables -P INPUT DROP iptables -P FORWARD DROP and…
I don't think any of this would have mattered to ATT, as the breach was from a third party that wouldn't have been on a private network anyway.
But, that would be a great service bonus -- only being able to connect to a service via a user-configurable private overlay network. It would be nice, but highly impractical... I can't even begin thinking about how customer support would be able to handle a scheme like this.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#467Earlier quoted context omitted.
What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.
The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#468AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW
I never got the impression that the market ever cares about data breaches. It seems most companies are rarely held financially responsible for data breaches anyway. I would bet any effects you’re seeing in stocks is unrelated to this news.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#469AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
I really dislike this attitude.
AT&T were attacked, by criminals. The criminals are the ones who did something wrong, but here you are immediately blaming the victim. You're assuming negligence on the part of AT&T, and to the extent you're right, then I agree that they should be fined in a bigger manner.
But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.
Put another way - you trust a classical bank, with a money, to secure your money from criminals. But you don't expect it to protect your money in the case of an army attacking it. But that's exactly the situation these organizations are in - anyone on Earth can attack them, very much including basically armies. We cannot expect organizations to be able to defend themselves forever, it is an impossible ask in the long run. This has to be solved by the equivalent of a standing army protecting a country, and by going after the criminals who do these breaches.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#470Earlier quoted context omitted.
What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.
The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?
(edited for grammar)