AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…
AT&T says criminals stole phone records of 'nearly all' customers in data breach
561–570 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#562Unbelievable that they do not enforce 2FA for a client that huge. Absolute madnesss!
I do know that not every employee designation required universal 2FA but more or less all IT/ATO staff did.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#563"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…
It’s a cloud database, mostly olap. The ATT account was secured with a bad password and no mfa.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#564And, honestly, how is this info (which I WOULD want to know) meaningfully actionable to customers. We get our information stolen from a myriad of sources everyday. These companies do comparatively nothing to make things right and the burden falls on customers to pick up the pieces if you're in a tranch that is sold and used.
Of course it's not meaningfully actionable to customers, big time lag in not disclosing since Apr 19. (Why does this not fall under SOX violation with the obligation to report timely to affected parties? It has affected AT&T's stock price -3% in early trading, so should it have also required SEC disclosure?) Wondering what is the significance that most of the stolen records were from the period 5/1-10/31/2022? Does i…
Regarding 2FA, it probably means they just enabled it in their access rules for any access to snowflake, but it's highly unlikely AT&T will walk away from Snowflake anytime soon because it had become their preferred BI/Data Analytics platform and they were actively migrating several hundred TBs of data out of Hadoop to Snowflake.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#565AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…
Why should the software industry be any different?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#566Earlier quoted context omitted.
> It cost money to implement security. Yes, but no amount of money will stop the data in a big database being stolen by someone sufficiently motivated to steal it. It's just bits on someone's disk. The only true solution is to not create the database. But then what would all the data scientists and their MBA masters so with their time?
in this case it’s pretty tough because the phone company does need this metadata just to bill people. so they should protect it properly.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#567Earlier quoted context omitted.
Personal data cannot be secured. The only way is to not store it. That will (imaginationaly) cost companies in lost revenue for being unable to mine and sell it. Only government can make laws against a company taking your personal information and selling it. Even passwords shouldn't be stored by a company. The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 mil…
Whether or not it's disingenuous, it's our time that didn't need to be wasted in the first place by them not storing phone records
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#568Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#569Then there is no data left to breach.
Instead develop systems to audit the usage of that blockchain and send to jail/military anyone who attempts to use that information in an unauthorized manner.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#570AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…