Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

651–660 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#651
post #635

Earlier quoted context omitted.

> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…

Yeah, security checkboxes don't necessarily result in good security. One option is to still make companies liable for security breaches, regardless of what meaningless checkboxes they may have checked, and then trust that they'll figure it out. Real liability would shift things from theater to weighing actual risks and costs. Another option is we can empower red teams (security researchers) to test the security of al…

I'm saying that's the same thing. It's probably worse, actually, because imagine yourself at the head of a company the size of AT&T. What would you do -- what could you do? -- that would ensure that some random employee would never do something that makes you vulnerable to attack? How terrified would you be?

It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but worse, because at least something like SOC2 is providing a safe haven if you do the right things. Making companies "liable" for breaches is tantamount to saying that companies will never develop software again, because the risk is simply too great. Certainly, if I were in that kind of a situation, I'd rarely use a third-party service, and never use a startup, or a smaller company. I can't be responsible for the risks of AT&T, and every software company AT&T uses. That's crazy!

We're going to have to come to terms with the fact that "security" is a verb, not a noun, and that data leaks are going to happen, even in the best secured institutions. Punitive rules might improve security in the marginal case, but only at huge costs industry wide.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#653
post #635
post #578

Earlier quoted context omitted.

> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the dev…

> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…

If one breach exposed all of their data, they don't practice the well-known security (since ancient times) technique of never having all your goodies in one location.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#654

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Sure - pretty well every corporation you purchase a service from is required to store your credit card information as well. But there are stiff penalties from the government and credit card processors for unauthorized access to that information; consequently, it's rarely stolen.

Your address, cell metadata, phone number, email address, and passwords are leaked pretty well contsantly though.

It's not that corporations are incompetent. The laws and regulations mean it's not worth the cost to treat your personal information with any real respect.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#655
post #651

Earlier quoted context omitted.

Yeah, security checkboxes don't necessarily result in good security. One option is to still make companies liable for security breaches, regardless of what meaningless checkboxes they may have checked, and then trust that they'll figure it out. Real liability would shift things from theater to weighing actual risks and costs. Another option is we can empower red teams (security researchers) to test the security of al…

I'm saying that's the same thing. It's probably worse, actually, because imagine yourself at the head of a company the size of AT&T. What would you do -- what could you do? -- that would ensure that some random employee would never do something that makes you vulnerable to attack? How terrified would you be? It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but wor…

If a company the size of AT&T finds themselves unable to move or do anything without creating security vulnerabilities, then it's time for the company to stagnate and go out of business, leaving fertile ground for more competent companies to replace them.

It would be kind of nice if companies would say "we've grown to our level of competence, we cannot safely do more, so we will keep doing the same, no more, no less, and make sure we do it well, and we will allow innovation to come from other companies". Instead, they say "let's recklessly chase every fad and who cares about poor security, it's not our liability".

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#656
post #654

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Sure - pretty well every corporation you purchase a service from is required to store your credit card information as well. But there are stiff penalties from the government and credit card processors for unauthorized access to that information; consequently, it's rarely stolen. Your address, cell metadata, phone number, email address, and passwords are leaked pretty well contsantly though. It's not that corporations…

> store your credit card information ... but there are stiff penalties from the government and credit card processors for unauthorized access to that information; consequently, it's rarely stolen

Citation: The Onion?

The Payment Card Industry Data Security Standard (PCI DSS) is the main information security standard for organizations that process credit or debit card information must abide by. The guidelines established in PCI DSS cover how to secure data handling processes.

So here are the top 5 info breaches:

https://www.goanywhere.com/blog/the-5-biggest-pci-compliance...

To be fair, if what happened to Heartland happened more often, PCI compliance would be taken more seriously, and breached less often.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#657
post #651

Earlier quoted context omitted.

I'm saying that's the same thing. It's probably worse, actually, because imagine yourself at the head of a company the size of AT&T. What would you do -- what could you do? -- that would ensure that some random employee would never do something that makes you vulnerable to attack? How terrified would you be? It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but wor…

If a company the size of AT&T finds themselves unable to move or do anything without creating security vulnerabilities, then it's time for the company to stagnate and go out of business, leaving fertile ground for more competent companies to replace them. It would be kind of nice if companies would say "we've grown to our level of competence, we cannot safely do more, so we will keep doing the same, no more, no less,…

Yeah, that's some nice rhetoric, but...I guarantee that, right now, some part of your personal software stack has a security vulnerability. If you write software for a living, some piece of software you maintain has a critical vulnerability.

Do you want to be held personally responsible when they're breached? If your wireless access point is hacked because you waited too long to update it, and it is used to launch DoS attacks, do you want to be liable? Do you want to be held personally responsible when you click on the just-good-enough phishing attack in your corporate inbox?

If not, then consider why you'd ask the same thing from a corporation of tens of thousands of people.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#660

Earlier quoted context omitted.

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

Up until recently I agreed with this position because I, like you, thought that this was how licensed engineering disciplines worked. I thought that if you sign off on something you put your career on the line, making the potential penalty for signing off on bad designs worse than the one for saying no to a pushy boss. Then the MAX crashes happened and Boeing is about to negotiate a sweetheart plea deal and there's a…

Wait, your saying the software engineers behind MAX8 debacle were licensed? What licenses?
Post reply on HN