Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

501–510 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#501
Would be great if some of the smart people here could help explain why this is such a big deal to my less tech savvy friends. I know that I don’t know how the data broker to dark web hacker pipeline works, I just know security is important. But my family is like “big deal”.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#502
post #410

Earlier quoted context omitted.

It's not "internal analytics", because a) 90% of the data was former customers and b) it has location data but timestamps were removed, so it's social-graph information plus location. Start asking yourself what sorts of end-users want to pay for the entire social-graph of 77m, regardless whether those customers never make a phone call again. "Alternate credit scoring, hyper-targeted marketing and more... an emerging…

Snowflake PR, from the link above: "What makes telecom service providers unique is that they have access to consumer location data. For most other industries, a consumer can go into their phone’s privacy settings and turn off the location access in the smartphone app. But in the world of telecom, as long as the phone is connected to a network, the telecom provider can use triangulation to find the approximate locatio…

- [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]. This one is 110m customers, presumably all their current customerbase. But it's still unlikely this is "internal analytics" (for telco business-case) given the timestamps were removed but location data included.

- Yes about Snowflake's cloud telco unit explicitly marketing the fact that telco data contains location. See my updated post: https://news.ycombinator.com/item?id=40949640

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#503
post #470

Earlier quoted context omitted.

The NSA shouldn’t need the telcos to retain these records, just hand them over to the NSA to retain right?

Which leads me to wonder - were any of the NSA’s own employee, call and SMS records at AT&T part of the comprised data? (edited for grammar)

Right, if phone records for Congressmen and known (or deduced) DOD were made public would that sway any changes

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#504

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

This kind of system has consistent led to regulatory capture by the licensed industry. Even the mechanism of operation de facto assumes a significant gatekeeping barrier to getting a license, since otherwise companies would just pick one most willing to cut corners to save costs, or pay the license fee to get greenhorns certified because that costs less than adding two years to the development schedule to do it well. Making everything cost quadratically more than it already does is not a good solution.

What you want here is for them not to be holding the data to begin with. The solution to which is to just let customers sue them. Not for $0.30 and "free credit monitoring" but for actual money. Then companies can choose whether they want to mitigate their risk by doing actual security or by not storing the data to begin with, but most likely the second one is their better option.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#505

Earlier quoted context omitted.

In approximately 100% of cases, if your intuition is to say "this company is too large should be fined/regulated more," what you should actually say is "this company is too large and should be broken into many smaller entities."

We should break down AT&T. Oh wait. We tried already and re-consolidated? Ow.

Part of breaking them up is supposed to be not letting them re-consolidate. Mergers involving any entity that already has 15% market share should just be flatly disallowed.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#506
post #368

Earlier quoted context omitted.

Why are you booing him? He's right! > to forsake one cause, party, or nation for another often because of a change in ideology I don't think he left because of a change in ideology.

he was not heading to russia. he's just trapped there

Of course. He accidentally tripped, fell, and landed in Sheremetyevo International Airport with a nice cushy job in the Russian government, with Russian citizenship and a nice estate worth 10s of millions of dollars, and clearly just accidentally mispoke when he swore allegiance to Russia. All the nsa secrets he took with him were irrelevant to that story, typical of any asylum seeker arriving anywhere.

lol, oops, I forgot how triggered some people get for calling it defecting.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#507
post #328

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!" It's not the leak that's the problem; it's the ease with which that leaked…

> Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked. In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from…

Totally agree. It feels like our banking is a decade behind - like transfer money - no direct way to do it between banks - most people use Venmo. Some banks are part of Zelle, but I’ve heard it has fraud issues (weak discovery/confirmation of correct recipient) and the banks won’t refund many fraudulent transfers (“You initiated the transfer! Not our problem you sent to the wrong person!”).

So, do you get a physical OTP generator for every financial institution? I guess that works, but that would mean I’d have a drawer full (2x bank, 1x work, current 401k, past IRA, and a brokerage account - x2 because my wife has about the same).

I was thrilled last year when I discovered I could renew my passport online! In 2023! That should have been available eons ago.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#508

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

Every txt and phone call, every email and letter sent to your address along with every utility bill (list goes on) has been saved since at least 1999/2000 to present day. People like Bernie went to jail because they pushed back and it was all because of this.... Just saying.

... letter?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#510

Earlier quoted context omitted.

According to the article, the data was being made available to other businesses... From the detail level involved, I imagine the NSA has some sweeter deal with telcos... And they have much richer data.

The NSA buys all of the data available from data brokers. 4A? What 4A? With telcos they have the extra advantage of ordering them around with an NSL.

For those not deeply versed in US federal regulations: Part 4a of Title 15 of the Code of Federal Regulations (CFR), which covers the "Classification, Declassification, and Public Availability of National Security Information" for the National Security Agency (NSA).

https://www.ecfr.gov/current/title-15/subtitle-A/part-4a?toc...>

Post reply on HN