Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

661–670 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#661
post #657

Earlier quoted context omitted.

If a company the size of AT&T finds themselves unable to move or do anything without creating security vulnerabilities, then it's time for the company to stagnate and go out of business, leaving fertile ground for more competent companies to replace them. It would be kind of nice if companies would say "we've grown to our level of competence, we cannot safely do more, so we will keep doing the same, no more, no less,…

Yeah, that's some nice rhetoric, but...I guarantee that, right now, some part of your personal software stack has a security vulnerability. If you write software for a living, some piece of software you maintain has a critical vulnerability. Do you want to be held personally responsible when they're breached? If your wireless access point is hacked because you waited too long to update it, and it is used to launch Do…

> Do you want to be held personally responsible?

No, I don't. I don't want anyone to be held personally responsible.

> consider why you'd ask the same thing from a corporation

I'm not asking the same from companies. I don't consider putting liability on a company the same as putting liability on an individual, and neither do our laws. Companies may pay liabilities out of profits, companies may have to sell assets, companies may go out of business and people lose their jobs. None of that is the same as someone being personally liable.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#662
post #611

Earlier quoted context omitted.

Whistleblower is a very revealing thing to call Mr. Assange.

David McBride and Richard Boyle. Both tried the official channels then whistleblower channels. Both made some mistakes but all in the public interest. Aussie gov treated them shamefully.

Witness K and Bernard Collaery came to mind when I was writing it. They blew the whistle on illegal espionage used to pillage the resources of our tiny neighbour, and the government threw the book at them. Absolutely shameful.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#665

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Money can't buy competence, at least not at organizational scale.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#666

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

I've never heard of this, and cursory web searches don't seem to be turning up anything relevant (although that's admittedly not saying much with the state of search lately). Can you explain how the law requires this level of data retention?

Apparently they'd uploaded their customer data into something called Snowflake to do some kind of analysis on it, but it wasn't particularly well secured. They haven't said why they were analysing the data, but there's no indication that it had anything to do with government demands.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#667

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

The government isn’t distributing my data to everyone else (so far). For profit companies have a pretty massive list of breaches so far.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#668

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

"legally required by the government" to keep securely. If you can't keep to the rules don't play the game. I'm sure any other telecom would be glad to get the market share.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#669

That's an enormous amount of data. How do you not notice a huge, network-hogging data flow?

> That's an enormous amount of data. How do you not notice a huge, network-hogging data flow?

No it isn't. Not even close to some of the larger data sets that Snowflake most likely manages.

We're talking about the public cloud. You don't "hog" AWS's network with a one-time download in numbers like what we're seeing from the article.

Let's be generous and estimate that there are 1k records for each customer. That's almost certainly an overestimation for the time period that TFA specified, but for the sake of argument let's run with it. There are about 100M customers. So that's only 100B records. Assuming each record is on the order of 1kB in size, again likely a huge overestimation, then that would be just 100TB. AWS would charge $7k to egress 100TB, which would be a rounding error in AT&T's cloud spend.

The real amount is most likely less than half of that, if not a quarter.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#670

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Hurting the shareholder is the only option to actually fix anything. Until the C-suite and board are forced to face the music caused by rich people being parted from their money, they'll just continue patting themselves on the back and giving themselves bonuses.

I agree.

Shareholders can vote and decide the direction of a company. They should also be held liable for any problems the company causes.

If the company is fined it should come out of company and then shareholder pockets. I might even add courts should be able to award damages by directly fining share holders.

If a company does something severely illegal then very large shareholders should risk jail time.

It’s your company after all as a shareholder. You own it.

It’s no different if your dog bites someone or child breaks the law. You have to pay the fines.

Post reply on HN