AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
AT&T says criminals stole phone records of 'nearly all' customers in data breach
601–610 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#602Earlier quoted context omitted.
Are strong whistleblower protections what’s needed to balance this? As an Australian I am absolutely horrified that we continue to put people in jail who have blown the whistle on the government here, and it makes me think that large organisations are absolutely terrified about strong whistleblowing protections. This all suggests to me that whistleblower laws would be very effective.
Whistleblower is a very revealing thing to call Mr. Assange.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#603Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#604AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Hurting the shareholder is the only option to actually fix anything. Until the C-suite and board are forced to face the music caused by rich people being parted from their money, they'll just continue patting themselves on the back and giving themselves bonuses.
Look at the same problem with environmental disasters that were created by corporations. The problem with security liabilities is similar? Externalities are hard to get shareholders to pay for.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#605Earlier quoted context omitted.
You can't make houses cheap without bound either, you turn them into death traps quite quickly. Everything related to personal data is currently at the slum without firecodes level. But it also has a few unregulated nuclear reactors in the mix.
This is the excuse used to justify the regulatory capture. There is a mile of difference between simply having fire exits vs. minimum parking requirements, de jure or de facto minimum unit sizes and density constraints. You need something that can distinguish these things, not something that provides the trash choice between none of them or all of them together.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#606AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…
2. Nothing to no consequence to the executives.
3. Lawlessness of such events. Very poor consumer protection laws in this country.
4. Cybersecurity illiterate leadership making cybersecurity decisions.
5. Investing absolute little in Cybersecurity to meet bare-minimum standards.
6. Or all of the above?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#607Earlier quoted context omitted.
The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…
this is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable. Why should the software industry be any different?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#608Earlier quoted context omitted.
... letter?
This is probably a reference to US postal or mail covers. The USPS takes images of most or all postal mail as part of its delivery and postal sorting/routing processes. Those covers are retained for a limited period of time , and actually have, so far as I understand, significant privacy protections associated with them, of the sort notably absent in most electronic communications. See: Mail Cover (Wikipedia): Mail c…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#609AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#610AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…
This is precisely how we end up in a world where we’re all running twenty five year old software.