Earlier quoted context omitted.
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?
AT&T says criminals stole phone records of 'nearly all' customers in data breach
621–630 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#622Earlier quoted context omitted.
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#623how can we keep such accumulations of sensitive data from arising in the first place? only countries that figure it out are likely to survive the turbulent coming decades
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#624Earlier quoted context omitted.
Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?
I agree. I think it's reasonable to expect companies to safeguard that information from malicious actors.
We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with hacking to get it.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#625Earlier quoted context omitted.
The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…
If AT&T had spent more on security, this would not have happened. I absolutely do not believe individual engineers should be held liable.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#626Earlier quoted context omitted.
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#627AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Everyone says what needs to happen. Every thread has this same exact post. We all know what needs to happen. How _would_ this ever happen? This is a board of innovators -- innovate!
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#628Earlier quoted context omitted.
The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…
You want a P.Eng (or equivalent) to sign off on anything that involves data? That won’t solve the problem but will dramatically slow down the pace of innovation. And all the while, it will funnel money further into regulated professions instead of into actually securing software. This is precisely how we end up in a world where we’re all running twenty five year old software.
Linux?
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#629wow, a spy agency acquired the entire social network graph of the usa in one intrusion. that's bad news for civil defense; it means they have a good guess at who is the favorite relative of each legislator, governor, police chief, or general. and where they can habitually be found at each hour of the week, since this leak included location data! how can we keep such accumulations of sensitive data from arising in the…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#630Earlier quoted context omitted.
I agree. I think it's reasonable to expect companies to safeguard that information from malicious actors.
I don't agree. I don't think it's reasonable to expect it, because companies show over and over that they cannot do it. And let's face it, the only reason your company hasn't fallen victim to a data breach or ransomware is that you haven't been seriously targeted yet. We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with…
Expect every SMS and MMS sent or received to be part of a spam mitigation and profiling program where it's stored indefinitely.
Apple not encrypting RCS is likely due to similar factors, where they have seen existing spam problems on RCS that are much harder to root out when you have end-to-end encryption.