Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

591–600 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#591

Earlier quoted context omitted.

> This kind of system has consistent led to regulatory capture by the licensed industry. That is indeed the intention. To counteract the financial incentives of shareholders (which result in bridges collapsing or data breaches) with the financial and legal incentives of a special class of employees - licensed engineers. The reasons this works better than letting people sue after the accident has already happened [1]…

> To counteract the financial incentives of shareholders (which result in bridges collapsing or data breaches) with the financial and legal incentives of a special class of employees - licensed engineers. But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by de…

>But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much.

This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which is what's happening with data leaks now.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#592
post #527

Earlier quoted context omitted.

For highly secured services, I completely see the rationale for a private overlayed network. Tailscale, et al are great for this, where you're only exposing services to members of the private network. The problems start when people make the assumption that the private network is a secured network. I don't think any of this would have mattered to ATT, as the breach was from a third party that wouldn't have been on a p…

Companies worked that way for decades. Everything was on the corporate network which was only accessible in an office or via VPN.

Sorry, I was trying to refer to creating overly VPN networks with vendors. So in the ATT case, it would mean their DB vendor (I’m assuming) creating separate VPN networks for each of their customers to connect through (in addition to username/pass credentials). The logistics of managing separate VPNs for each customer, for each user account, etc seems overwhelming.

For more traditional single-entity networks, you’re right. But with more and more BYOD, those networks are at a higher risk than they used to be. That’s the reason for the shift… VPN tech is still sound, but it requires that you trust the devices that are connected to it.

If you’re now also trying to trust devices from your company and your customers, that’s harder to work my head around.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#593

Earlier quoted context omitted.

> To counteract the financial incentives of shareholders (which result in bridges collapsing or data breaches) with the financial and legal incentives of a special class of employees - licensed engineers. But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by de…

>But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much. This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which…

It's a bug. You can't make everything cost more without bound or ordinary people can no longer afford to make rent. There has to be balance.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#594

Earlier quoted context omitted.

>But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much. This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which…

It's a bug. You can't make everything cost more without bound or ordinary people can no longer afford to make rent. There has to be balance.

You can't make houses cheap without bound either, you turn them into death traps quite quickly.

Everything related to personal data is currently at the slum without firecodes level. But it also has a few unregulated nuclear reactors in the mix.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#595
post #549

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

Direct liability to the front line / middle management which is cleared in exchange for defined levels of cooperation with criminal, regulatory, and civil investigations aimed at landing higher-ups would be a useful development.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#596

Earlier quoted context omitted.

If AT&T had spent more on security, this would not have happened. I absolutely do not believe individual engineers should be held liable.

The way this works in civil engineering is that the engineer refuses to sign off on an unsafe design. If costs have to increase to address the issue, then they do. If management doesn't budge, then they bleed money while twiddling their thumbs staring at an unapproved design.

Be careful what you wish for… civil engineering is a terrible awful bureaucratic profession.

The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#597

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Banks are required to maintain financial transaction records.

Is the argument that governments don't have a good reason to mandate record collection?

Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#598

Earlier quoted context omitted.

Are strong whistleblower protections what’s needed to balance this? As an Australian I am absolutely horrified that we continue to put people in jail who have blown the whistle on the government here, and it makes me think that large organisations are absolutely terrified about strong whistleblowing protections. This all suggests to me that whistleblower laws would be very effective.

Whistleblower is a very revealing thing to call Mr. Assange.

Another example would be David McBride who was in the Australian military and blew the whistle on war crimes. He recently got sentenced to jail while actual exposed war criminals are free.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#599

Earlier quoted context omitted.

It's a bug. You can't make everything cost more without bound or ordinary people can no longer afford to make rent. There has to be balance.

You can't make houses cheap without bound either, you turn them into death traps quite quickly. Everything related to personal data is currently at the slum without firecodes level. But it also has a few unregulated nuclear reactors in the mix.

This is the excuse used to justify the regulatory capture. There is a mile of difference between simply having fire exits vs. minimum parking requirements, de jure or de facto minimum unit sizes and density constraints. You need something that can distinguish these things, not something that provides the trash choice between none of them or all of them together.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#600

Earlier quoted context omitted.

> To counteract the financial incentives of shareholders (which result in bridges collapsing or data breaches) with the financial and legal incentives of a special class of employees - licensed engineers. But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by de…

>But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much. This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which…

Its a bug.

We now have Instead , we could have 1000s of smaller banks. Tons of smaller banks is the natural state of things, like restaurants. This was true before the banking cartel, TARP, ZIRP, most recently, PPP (genius backdoor to bail out wall st.). In such system, any 1 collapsing bank wont bring the entire system down.

Having fewer bridges means that inevitable when they collapse, there will be far more victims and the event will be catastrophic.

Tech is one of the few bright spots in our moribund economy. Don't introduce a cartel that will blow up eventually.

Post reply on HN