Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

581–590 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#581

Earlier quoted context omitted.

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

I actually agree with you but this is a dangerous opinion to express on this forum, where move fast and break things is seen as the one true path.

I am not a historian, but I expect there would have been significant pushback as well by other types of engineers back in the day when their profession was regulated.

It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do it themselves in a more reasonable way.

[1] Well, it has already begun. EU has the notion of the GDPR Data Protection Officer [1] https://www.gdpreu.org/the-regulation/key-concepts/data-prot...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#582
Reading the articles about this breach and the nature of the data in this Snowflake lake, I personally wouldn’t consider this breach a “leak” from the customer perspective - to me the leak is upstream of this breach.

Given the nature of the data in the database and the platform it was stored in, it seems extremely likely this data was not meant to be used internally by AT&T but was instead meant to be used externally by either a 3rd party partner (like advertisers and consumer analytics partners) or a government agency.

In other words, if it were my data in this datastore, I’d consider my data as already having been “leaked” when it went into the store - the issue here appears to be that this data was “leaked” to the wrong people from the perspective of AT&T and the FBI.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#584

Earlier quoted context omitted.

That is the worst case outcome of penalties, and it carries significant risk of whistle blowing. The default case will be compliance, because compliance is simply cost of business, something businesses understand well. Meanwhile, currently businesses are doing shit all about data breaches except handing out the absolutely useless "2 years identity monitoring", so from a consumer view it really can't get much worse. I…

Are strong whistleblower protections what’s needed to balance this? As an Australian I am absolutely horrified that we continue to put people in jail who have blown the whistle on the government here, and it makes me think that large organisations are absolutely terrified about strong whistleblowing protections. This all suggests to me that whistleblower laws would be very effective.

Whistleblower is a very revealing thing to call Mr. Assange.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#585

"still-unfolding data breach involving more than 160 customers of the cloud data provider Snowflake.' So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site: "Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential t…

> break down data silos

[x] Objective Achieved

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#586
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

This reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?

There is a whole field devoted to this called governance.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#587

Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, and is in general incompatible with the European Convention for the Protection of Human Rights and Fundamental Freedoms outside of active threats to national security and temporary measures overseen by a court.[1] There's really no reason why any service providers should save this stuf…

> Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries,

On the contrary, many European countries have mandatory data retention periods that meet or exceed the 6 months of records that were supposedly included in this breech.

Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records.

Saying that it would be illegal to collect these records in Europe is patently false, and furthermore the record collection is generally mandated for a period of time that depends on the country.

> There's really no reason why any service providers should save this stuff in the first place,

Billing. You need phone records for billing purposes. You need to keep them for a while longer because people will dispute their bills all the time.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#589

Reading the articles about this breach and the nature of the data in this Snowflake lake, I personally wouldn’t consider this breach a “leak” from the customer perspective - to me the leak is upstream of this breach. Given the nature of the data in the database and the platform it was stored in, it seems extremely likely this data was not meant to be used internally by AT&T but was instead meant to be used externally…

[dead]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#590

Earlier quoted context omitted.

For those not deeply versed in US federal regulations: Part 4a of Title 15 of the Code of Federal Regulations (CFR), which covers the "Classification, Declassification, and Public Availability of National Security Information" for the National Security Agency (NSA). https://www.ecfr.gov/current/title-15/subtitle-A/part-4a?toc... >

Not entirely sure, but I thought they were talking about the 4th amendment, which also is relevant. It prevents the government from spying on Americans without a warrant. The NSA works around it so openly by buying the spy data from third parties, and saying the 4th Amendment doesn’t apply since they didn’t collect the data themselves, so it’s fine. It’s a giant middle finger to the Constitution of the US. https://en…

Possibly. And on reflection, perhaps more plausibly.

In either regard, unambiguous comments are preferable to ambiguous ones.

The principle function of speech or writing is to accurately convey one's own state of mind to others.

Post reply on HN