Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

531–540 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#531

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

What the NSA wants, the NSA gets. No legislation is needed when the system is working as intended.

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#532

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#533

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

> There's really no reason why any service providers should save this stuff

There are many reasons! Most of them are simply contrary to how folks think business should operate. Unfortunately the US seems to value "disruption" over "customer protection", so legally protecting data is unpopular on the hill.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#534

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Everyone says what needs to happen. Every thread has this same exact post. We all know what needs to happen. How _would_ this ever happen? This is a board of innovators -- innovate!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#535
And corporations like AT&T are themselves immune to having their own identities stolen (my notes: https://win-vector.com/2024/07/12/yet-another-way-corporatio... ). Corporate EINs (the US corporation equivalent to US social security numbers) and public. Knowing one doesn't let you commit identity theft and credit card against a corporation (unlike the case for people).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#536
post #469

Earlier quoted context omitted.

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

The customers are the victims, not the companies. You picked the wrong point to counter with. The real problem is that the corporate decision-makers who bear the most responsibility will never be held accountable. They will always be able to shift blame to someone below them in the corporate hierarchy.

Your point needs more emphasis. The idea that the victim is anyone other than the customer is so wrong.

The other points are dubious too.

> But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.

So given that this is known, why was the data stored such that it could be taken? Why was it kept at all? Oh.. to sell.

> Put another way - you trust a classical bank, with a money, to secure your money from criminals. But you don't expect it to protect your money in the case of an army attacking it.

Yes I do expect that. And it’s protected and insured by my government.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#537

Earlier quoted context omitted.

We should break down AT&T. Oh wait. We tried already and re-consolidated? Ow.

Part of breaking them up is supposed to be not letting them re-consolidate. Mergers involving any entity that already has 15% market share should just be flatly disallowed.

This is not the AT&T Judge Harry Greene broke up. This AT&T is a roll up of most of the RBOCs the breakup created.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#538
post #94

Earlier quoted context omitted.

Non-expiring passwords is probably no more or less secure, unless you are a rampantly terrible employer known for setting ablaze every bridge ever to the point of atomic annihilation.

Are you suggesting a disgruntled former employee could use the password and do things? At that point, I have questions. How is the former employee accessing the cloud service? If your cloud is allowing public access without a VPN, then you've done something wrong there. If the former employee is still accessing your VPN, again, you've done something wrong. Many other things still come to mind but point back to you we…

Yeah. I agree. We have a strong offboarding process as well. But other employers? I mean. I’ve seen some shit in my day.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#539

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Penalties would also incentivise businesses to hide data breaches.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#540
post #169

Earlier quoted context omitted.

After Equifax debacle, I don’t think anyone cares. It’ll only be a big deal if there’s a huge B2B leak and business-critical data gets exposed, other than the usual name, address and phone number.

This is it for me tbh. Yeah I don't want my identity stolen and I'm still careful but after Equifax I just assume everyone already has my data so all of these data breaches are meaningless to me at this point. It sucks and it makes me mad but all I can do is shake my fist and wish these companies would be better anyway, so what else can I do but just be ok with it?

It's not that simple. This time, phone records and location data are stolen. These are more sensitive than the stolen data from typical data breaches.
Post reply on HN