Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

491–500 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#491

Earlier quoted context omitted.

In this analysis, the effort the bank puts towards defending themselves is relevant. We wouldn't blame the bank for an army attacking them, but if they left the door unlocked and the neighbours kids made off with your money you very rightly would feel differently.

Which does make me wonder why we never really hear of banks being attacked and robbed in such a way? One would think they would be the most obvious targets to throw an army of criminals at.

Banks don't really physically store much money any more.

And more importantly - the police exist. If someone were to actually physically rob a bank, enormous resources would be spent trying to find and capture them, then they'd be thrown in jail.

If they could do the same thing, but also be physically located in another country while doing it, with no chance at all of going to jail... more banks would be robbed!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#492

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow.

Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are found to be at fault, they get criminal penalties.

This, of course, must be coupled with penalties for management personals as well.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#493

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The AT&T app and website are so bad it takes way longer than 1 minute to log in to e.g. pay your bill. The United States needs to raise the bar for large-cap negligent operators and fine the company enough to make shareholders listen.

In approximately 100% of cases, if your intuition is to say "this company is too large should be fined/regulated more," what you should actually say is "this company is too large and should be broken into many smaller entities."

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#494

Earlier quoted context omitted.

The AT&T app and website are so bad it takes way longer than 1 minute to log in to e.g. pay your bill. The United States needs to raise the bar for large-cap negligent operators and fine the company enough to make shareholders listen.

In approximately 100% of cases, if your intuition is to say "this company is too large should be fined/regulated more," what you should actually say is "this company is too large and should be broken into many smaller entities."

We should break down AT&T. Oh wait. We tried already and re-consolidated? Ow.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#495
post #212

Earlier quoted context omitted.

I would assume that engineers, at least in the US, are far more concerned about getting fired/eased out than prosecuted if they do stupid things given that companies can do so pretty easily.

Would you say the same is true for a lawyer? Are they more worried about being fired from a law firm than being sued for malpractice and being disbarred? If not, why would engineers be different?

I would assume that being disbarred has a pretty high standard of misconduct as opposed to simply not making partner or whatever level of action makes maintaining employment at a large law firm practical.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#496

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

It's not so much the NSA as various other government agencies. The NSA is hoovering everything up, but if the local cops call them and want access to it, the NSA is going to tell them that they're not even authorized to know whether or not the NSA has that information. Also, something something due process something something American citizens.

Whereas if they can get the telcos to keep it then the cops can get it using the third party doctrine. This is basically an end run around the constitution, which is why they like it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#497

Earlier quoted context omitted.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

It's a good business decision to make others do your work.

Government is not a business!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#498
post #490
post #482

Earlier quoted context omitted.

I think the implicit assumption is that the vast majority of these breaches are obviously preventable (basic incompetence like leaving a non-password-protected database connected to the public internet is common). A better analogy is not a bank defending against an army, but a bank forgetting to install doors, locks, cameras, or guards. _Yes_, the criminals are the root cause, but human nature being what it is it's n…

> I think the implicit assumption is that the vast majority of these breaches are obviously preventable (basic incompetence like leaving a non-password-protected database connected to the public internet is common). Some breaches are certainly preventable. But is that the case here? I didn't see the technical details, I think they aren't released yet, but this is the conclusion everyone seems to jump to automatically…

Would assume someone would notice all the data that is being transferred.

And if this turns out to be a sophisticated attack then who’s to say they didn’t backdoor a bunch of systems? I heard a talk from a big Norwegian company that got attacked. Every single server, every single switch, every single laptop, all had to be reformatted and reinstalled. I assume that AT&T would have to end up doing the same.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#499
post #491

Earlier quoted context omitted.

Which does make me wonder why we never really hear of banks being attacked and robbed in such a way? One would think they would be the most obvious targets to throw an army of criminals at.

Banks don't really physically store much money any more. And more importantly - the police exist. If someone were to actually physically rob a bank, enormous resources would be spent trying to find and capture them, then they'd be thrown in jail. If they could do the same thing, but also be physically located in another country while doing it, with no chance at all of going to jail... more banks would be robbed!

Crypto Exchange has entered the chat.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#500

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

Every txt and phone call, every email and letter sent to your address along with every utility bill (list goes on) has been saved since at least 1999/2000 to present day. People like Bernie went to jail because they pushed back and it was all because of this....

Just saying.

Post reply on HN