Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

511–520 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#512

Earlier quoted context omitted.

In this analysis, the effort the bank puts towards defending themselves is relevant. We wouldn't blame the bank for an army attacking them, but if they left the door unlocked and the neighbours kids made off with your money you very rightly would feel differently.

Which does make me wonder why we never really hear of banks being attacked and robbed in such a way? One would think they would be the most obvious targets to throw an army of criminals at.

It's pretty much the definition of a functional state that the police can gather more resources faster than any group of criminals. By the time you gather enough criminals to hold off the police for even a few minutes, most of the time, combined with the sibling's point of not that much physical money being stored at banks, there's not much money to go around to that many people.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#513
post #508

Earlier quoted context omitted.

Every txt and phone call, every email and letter sent to your address along with every utility bill (list goes on) has been saved since at least 1999/2000 to present day. People like Bernie went to jail because they pushed back and it was all because of this.... Just saying.

... letter?

Anything you receive via post office. Sender/Receiver address is scanned. Post office uses OCR's for sortation and that information is captured.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#514
post #508

Earlier quoted context omitted.

... letter?

Anything you receive via post office. Sender/Receiver address is scanned. Post office uses OCR's for sortation and that information is captured.

Ah. The metadata. Inconsequential, then, to a degree.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#515

Earlier quoted context omitted.

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

Every txt and phone call, every email and letter sent to your address along with every utility bill (list goes on) has been saved since at least 1999/2000 to present day. People like Bernie went to jail because they pushed back and it was all because of this.... Just saying.

who's Bernie?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#516

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

If AT&T had spent more on security, this would not have happened. I absolutely do not believe individual engineers should be held liable.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#517
I cancelled my AT&T account over 10 years ago, yet they still stored my (old) address, full name, and SSN in the previous hack in March.

The fact we don't have decent legislation to materially punish incompetent organizations is beyond absurd.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#518
post #508

Earlier quoted context omitted.

Every txt and phone call, every email and letter sent to your address along with every utility bill (list goes on) has been saved since at least 1999/2000 to present day. People like Bernie went to jail because they pushed back and it was all because of this.... Just saying.

... letter?

This is probably a reference to US postal or mail covers.

The USPS takes images of most or all postal mail as part of its delivery and postal sorting/routing processes. Those covers are retained for a limited period of time, and actually have, so far as I understand, significant privacy protections associated with them, of the sort notably absent in most electronic communications.

See:

Mail Cover (Wikipedia):

Mail cover is a law enforcement investigative technique in which the United States Postal Service, acting at the request of a law enforcement agency, records information from the outside of letters and parcels before they are delivered and then sends the information to the agency that requested it.[1] The Postal Service grants mail cover surveillance requests for about 30 days and may extend them for up to 120 days.

https://en.wikipedia.org/wiki/Mail_cover>

MICT: Mail Isolation Control and Tracking (Wikipedia):

[A]n imaging system employed by the United States Postal Service (USPS) that takes photographs of the exterior of every piece of mail that is processed in the United States.[1] The Postmaster General has stated that the system is primarily used for mail sorting,[2] though it also enables the USPS to retroactively track mail correspondence at the request of law enforcement.[2] It was created in the aftermath of the 2001 anthrax attacks that killed five people..

https://en.wikipedia.org/wiki/Mail_Isolation_Control_and_Tra...>

39 CFR § 233.3 - Mail covers. https://www.law.cornell.edu/cfr/text/39/233.3>

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#520
post #469

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

The customers are the victims, not the companies.

You picked the wrong point to counter with. The real problem is that the corporate decision-makers who bear the most responsibility will never be held accountable. They will always be able to shift blame to someone below them in the corporate hierarchy.

Post reply on HN