Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

561–570 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#561
post #549

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

No, the people whose name is attached to budget decisions and higher level company direction that leads to this are the ones who are responsible.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#562

Unbelievable that they do not enforce 2FA for a client that huge. Absolute madnesss!

What's odd is until August of last year I worked for AT&T and had to do 2FA for accessing almost every internal site I used, and that extended to most SSO integrated external sites - including the relatively small number of Snowflake instances I worked with.

I do know that not every employee designation required universal 2FA but more or less all IT/ATO staff did.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#563
post #386

"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…

It’s a cloud database, mostly olap. The ATT account was secured with a bad password and no mfa.

Its not just a bad password, it was a password that was exposed to a info stealer in some way. It might of been reused or overshared into some system that got exposed. From what I understand someone got a huge info stealer dump and started putting two and two together and noticed all these scraped passwords and tried them on snowflake

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#564
post #11

And, honestly, how is this info (which I WOULD want to know) meaningfully actionable to customers. We get our information stolen from a myriad of sources everyday. These companies do comparatively nothing to make things right and the burden falls on customers to pick up the pieces if you're in a tranch that is sold and used.

Of course it's not meaningfully actionable to customers, big time lag in not disclosing since Apr 19. (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so should it have also required SEC disclosure?) Wondering what is the significance that most of the stolen records were from the period 5/1-10/31/2022? Does i…

Because AT&T reported it to the FBI and DOJ, they in turn requested AT&T to not disclose it and there are exceptions in the SEC rules for exactly that scenario of actively working with law enforcement.

Regarding 2FA, it probably means they just enabled it in their access rules for any access to snowflake, but it's highly unlikely AT&T will walk away from Snowflake anytime soon because it had become their preferred BI/Data Analytics platform and they were actively migrating several hundred TBs of data out of Hadoop to Snowflake.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#565
post #549

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

this is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable.

Why should the software industry be any different?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#566

Earlier quoted context omitted.

> It cost money to implement security. Yes, but no amount of money will stop the data in a big database being stolen by someone sufficiently motivated to steal it. It's just bits on someone's disk. The only true solution is to not create the database. But then what would all the data scientists and their MBA masters so with their time?

in this case it’s pretty tough because the phone company does need this metadata just to bill people. so they should protect it properly.

Its a interesting issue, its kinda of like software piracy, so what if someone steals the product, we will still make money on the product with the normal sale of the data in the first place. Its just making the news because it was a breach. It's not counted as a breach if the exact same party was to buy the data outright from ATT in the first place.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#567

Earlier quoted context omitted.

Personal data cannot be secured. The only way is to not store it. That will (imaginationaly) cost companies in lost revenue for being unable to mine and sell it. Only government can make laws against a company taking your personal information and selling it. Even passwords shouldn't be stored by a company. The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 mil…

Whether or not it's disingenuous, it's our time that didn't need to be wasted in the first place by them not storing phone records

I agree with that. I just don't like big numbers being used to cause emotional responses without proper context. Probably on a spectrum, but it's my beef :)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#569
just put all information (names, addresses, ssn, DoB, etc) on a publicly visible blockchain already.

Then there is no data left to breach.

Instead develop systems to audit the usage of that blockchain and send to jail/military anyone who attempts to use that information in an unauthorized manner.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#570
post #549

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

This reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?
Post reply on HN