Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

481–490 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#481
WHY IS THIS DATA EVEN AVAILABLE TO BE DOWNLOADED??? Why do we not have protection in place so that hackers can't even download this data even if they wanted to?? What purpose does 2 year old data serve AT&T except to monitor us and to create social networks of people and associations?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#482
post #469

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

I think the implicit assumption is that the vast majority of these breaches are obviously preventable (basic incompetence like leaving a non-password-protected database connected to the public internet is common).

A better analogy is not a bank defending against an army, but a bank forgetting to install doors, locks, cameras, or guards. _Yes_, the criminals are the root cause, but human nature being what it is it's negligent to leave a giant pile of money and data completely unprotected.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#483

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

I was under the impression that the government wasn't allowed to create a mandate that a telco has to save all phone records like that, but it doesn't stop a telco from doing it themselves. I think that would fall more under GDPR limitations?

Historically we handled this with fiber taps at AT&T, as well as other ISPs. Some of them even knew about it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#484

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Personal data cannot be secured. The only way is to not store it. That will (imaginationaly) cost companies in lost revenue for being unable to mine and sell it. Only government can make laws against a company taking your personal information and selling it. Even passwords shouldn't be stored by a company. The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 mil…

There are lots of companies that take security seriously and don’t lose their customers data. Which is good, because there are companies that need to hold customer data.

Companies that don’t take security seriously and lose peoples data should be punished accordingly.

Companies that sell customers data should be identified.

But if we treat them all the same, then we let the bad companies off the hook, and punish the responsible companies unfairly.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#485
post #469

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

If a breach is so inevitable like you say, then it's negligent to store the information in the first place. They're accumulating and organizing data with the inescapable conclusion of handing it out to criminal organizations.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#486

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

According to the article, the data was being made available to other businesses... From the detail level involved, I imagine the NSA has some sweeter deal with telcos... And they have much richer data.

The NSA buys all of the data available from data brokers. 4A? What 4A? With telcos they have the extra advantage of ordering them around with an NSL.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#487
post #476

It's one more reason to use an end to end encrypted messaging app like iMessage or Telegram. Even WhatsApp is end to end encrypted. Don't use SMS/RCS.

unless I'm misunderstanding, the same data could be pulled from those services.

the message content wasn't leaked here

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#488
post #469

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

I am sure LEOs will do what they are paid to do and catch criminals. In the meantime, I would like to focus on service provider not being able to provide a reasonable level of privacy.

I am blaming a corporation, because for most of us here it is an ongoing, recurring pattern that we have recognized and corporations effectively codified into simple deflection strategy.

Do I assume the corporation messed up? Yes. But even if I didn't, there is a fair amount of historical evidence suggesting that security was not a priority.

Honestly, if average person saw how some of those decisions are made, I don't think a sane person would.

Ahh, yes. Poor corporation has become too big of a target. Can you guess my solution to that? Yes, smaller corporation with MUCH smaller customer base and footprint so that even if the criminal element manages to squeeze through those defenses that the corporation made such a high priority ( so high ), the impact will be sufficiently minimal.

I have argued for this before. We need to make hoarding data a liability. This is the only way to make this insanity stop.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#489

Earlier quoted context omitted.

The data was from 2022. The breach was from april of this year.

Who was the data being kept for?

Likely the NSA

https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-new-...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#490
post #482
post #469

Earlier quoted context omitted.

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

I think the implicit assumption is that the vast majority of these breaches are obviously preventable (basic incompetence like leaving a non-password-protected database connected to the public internet is common). A better analogy is not a bank defending against an army, but a bank forgetting to install doors, locks, cameras, or guards. _Yes_, the criminals are the root cause, but human nature being what it is it's n…

> I think the implicit assumption is that the vast majority of these breaches are obviously preventable (basic incompetence like leaving a non-password-protected database connected to the public internet is common).

Some breaches are certainly preventable. But is that the case here? I didn't see the technical details, I think they aren't released yet, but this is the conclusion everyone seems to jump to automatically, without necessarily good reason.

More importantly - these companies employ thousand of employees, all of whom could be doing something wrong that is causing a security threat. And there are thousands, maybe tens of thousands of people trying to find their way in. my point is that even without any negligence, if you have thousands of people trying to hack your company every day for years, it's easy to slip up, even if it's preventable-in-hindsight.

One of the first things you learn in working in security is that there is no perfect security, and you have to understand the nature of the threat you are facing. For these companies, the threat might very well be "North Korea decides to dedicate state-level resources to breaking into your company, plus thousands of criminals are doing the same every day". How is any company supposed to protect against that?

Post reply on HN