Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

611–620 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#611

Earlier quoted context omitted.

Are strong whistleblower protections what’s needed to balance this? As an Australian I am absolutely horrified that we continue to put people in jail who have blown the whistle on the government here, and it makes me think that large organisations are absolutely terrified about strong whistleblowing protections. This all suggests to me that whistleblower laws would be very effective.

Whistleblower is a very revealing thing to call Mr. Assange.

David McBride and Richard Boyle. Both tried the official channels then whistleblower channels. Both made some mistakes but all in the public interest. Aussie gov treated them shamefully.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#612
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

This reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?

I’m baffled that anyone is even asking the question..

Anyone reading this, if you are of the “well the employee whole typed the command is to blame!” opinion, could you please reply to this comment? I need to know what you think the purpose of a hierarchy is in the workplace.

..needless to say, responsibility for your direct reports is yours. If they fuck up, you fucked up. You have the choice to hire and fire at will. You choose who has access to take chances. You own the wins and the losses. If you’re a good leader you redistribute the wins and dissolve the losses. It’s the entire job.

It’s 2024. There are no kings or dictators in the workplace.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#613

Earlier quoted context omitted.

Whistleblower is a very revealing thing to call Mr. Assange.

I understand that Wikileaks is controversial but I don't think there is any dispute that he has acted in the role of whistleblower to some extent. But that's not really the point I'm trying to make, so I've removed the reference.

I think I'd argue for a sui generis classification, which does partake somewhat of the whistleblower, but it seems like calling Napoleon a general. He was certainly that, at times. Apologies for the nit-picking in any case.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#614

Earlier quoted context omitted.

This reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?

I’m baffled that anyone is even asking the question.. Anyone reading this, if you are of the “well the employee whole typed the command is to blame!” opinion, could you please reply to this comment? I need to know what you think the purpose of a hierarchy is in the workplace. ..needless to say, responsibility for your direct reports is yours. If they fuck up, you fucked up. You have the choice to hire and fire at wil…

It's a rhetorical question that's effective because the answer is obvious.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#615

Earlier quoted context omitted.

this is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable. Why should the software industry be any different?

because software developers aren't engineers? -- elephant in the room.

huh thats strange because I have a BSE and graduated from engineering school. Sure the history major bootcamp grads arent real engineers and we need to weed them out of the industry but there are some of us who are actually real engineers

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#616

Earlier quoted context omitted.

I was under the impression that the government wasn't allowed to create a mandate that a telco has to save all phone records like that, but it doesn't stop a telco from doing it themselves. I think that would fall more under GDPR limitations?

Historically we handled this with fiber taps at AT&T, as well as other ISPs. Some of them even knew about it.

How could they not know about it?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#617

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

Up until recently I agreed with this position because I, like you, thought that this was how licensed engineering disciplines worked. I thought that if you sign off on something you put your career on the line, making the potential penalty for signing off on bad designs worse than the one for saying no to a pushy boss.

Then the MAX crashes happened and Boeing is about to negotiate a sweetheart plea deal and there's absolutely zero talk of any of the engineering licenses that were used to sign off on the bad systems getting revoked.

If the licensing system doesn't actually include a threat of career-ending penalties for knowingly signing off on bad designs, or if the system allows executives to bypass engineer signatures, then it seems like the general consensus on here is right: it's useless overhead at best and regulatory capture at worst.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#618
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

this is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable. Why should the software industry be any different?

When I was working in a (non-software) engineering role, when I raised a technical concern it was taken seriously. As a software engineer, when I raise a technical concern it is brushed off and it I push it then my job is at risk.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#619

Earlier quoted context omitted.

This is probably a reference to US postal or mail covers. The USPS takes images of most or all postal mail as part of its delivery and postal sorting/routing processes. Those covers are retained for a limited period of time , and actually have, so far as I understand, significant privacy protections associated with them, of the sort notably absent in most electronic communications. See: Mail Cover (Wikipedia): Mail c…

You can sign up to have them email you a daily summary of your mail deliveries including the associated images they've logged under USPS Informed Delivery.

Right, more info here: https://www.usps.com/manage/informed-delivery.htm>

(I was ... vaguely aware of this.)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#620

Earlier quoted context omitted.

because software developers aren't engineers? -- elephant in the room.

huh thats strange because I have a BSE and graduated from engineering school. Sure the history major bootcamp grads arent real engineers and we need to weed them out of the industry but there are some of us who are actually real engineers

I think the issue isn't so much the programmers who aren't engineers as it is the managers who don't treat programmers like engineers.
Post reply on HN