Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

671–680 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#671
post #34

And this is yet another reason why I use signal

I hope you didn't sign-up for Signal with an AT&T-tied phone number. Else this breach would've probably exposed your PII either way.

I did not, and even then, none of my call logs or texts via signal would have been included, regardless of carrier.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#672

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

> how weird it is that you're fine with the government getting a record of all your phone activity I don't like it, but accept it as the lesser evil. I'm from Europe and I believe the number of reported prevented terror attacks. The agencies need data access for that. Not good, but necessary. But are you aware that Meta, Google, Apple, MS, etc. collect every kind of information about every user of Android, iPhone or…

> I don't care if the government can get access to my WhatsApp messages when some of the most irresponsible companies, collect and use everything to their advantage.

This is all voluntary. You give those companies your data. You don't have to. I use grapheneos and do not use any of those socials, for example.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#673

And this is yet another reason why I use signal

Do you exclusively use signal? Do your friends also use signal? Do you have friends who only use signal to communucate with you?

Unironically yes. I'm in a bunch of different group chats with little overlap in signal. There was a huge push amongst my friend group to get people on it back in like 2015. I have some family not on it but we just talk in person.

Not everyone switched, but a surprising amount did, and only more have switched over time.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#674
post #24

Earlier quoted context omitted.

Yes.

Do you make it like a fun game? Like when me and my friends in school would pass eachother coded notes and the cipher was an inside joke? I'm genuinely curious: what was the pitch that you used to get others to start using signal?

Not all my friends switched, I had one good friend who decided not to because she already had a bunch of apps and didn't just want to talk to me on yet another app.

It's much easier when it's a group. I got some of my family to get on it too and they pretty much exclusively use it to talk to me.

In the mid 2010s it wasn't that hard of a call because the various Google apps kept getting deprecated (we were all in hangouts before), iPhone users wanted something rcs like and they couldn't for android users with mms, in general the app scene was taking off with Snapchat wechat etc. so people were easier to convince to dl it.

My pitch was 'you know how randomly Facebook or YouTube will serve you some adds about something you were talking about about, even though you didn't search with them? You're much less likely to have that happen with signal'

Then if they pressed I'd share a link from the net neutrality fight days about DNS hijacking etc and having them remember when all their failed urls would go to an ISP run search domain

I definitely used some FUD but it worked.

Actually I think some of the FUD was 'what if the carrier gets hacked?'.... Which, I mean for all carriers and all systems is just a matter of time. As t-> inf the probability of a breach converges to 1.

Also if any of your friends do drugs, of any sort, that was a great motivator for them to switch lol. Weed has only been legal for recreational since 2013 in any state.

Oh, and pretty much every techie friend I had went 'yo that's awesome' and changed over, even if they don't have a tech job.

Finally, back in the day/for many years, signal could default to normal MMS messaging, so the pitch was 'if they don't have signal, you can just text like normal'

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#675

Earlier quoted context omitted.

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Money can't buy competence, at least not at organizational scale.

Sure, but “incentivise a business to do something, and they’re more likely to do it” is still true.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#676
post #31
post #24

Earlier quoted context omitted.

Yes.

Aside from a couple non-US friends, I know no one in the US who uses anything other than straight SMS (and Apple iMessage). I'm sure they exist but certainly not in the circle of people I communicate with.

iMessage is very much a US thing. Most of the Non US people or people with international connection exclusively use messaging App ( whatsapp, Telegram, Signal)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#677
post #328

Earlier quoted context omitted.

I never understood the american secrecy about SSN... it should be a "username" not a "password"... The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!" It's not the leak that's the problem; it's the ease with which that leaked…

> Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked. In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from…

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#678

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

Government has no right to track that either, they themselves launder trillions, start wars and massacre millions, even a drug lord is a petty criminal compared to them, and it's clear their tracking of any and all records of any type is more about control than safety, thus it should be disregarded as an argument and be done away with entirely.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#679

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

Where do you draw the line? Does that mean you need a license to write Excel formulas?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#680

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The law that would have prevented this breach would be to make it illegal for telcos to sell customer data. The reason AT&T was feeding ALL the data to Snowflake was to sell their customer's location and social graph to marketers. It is unconscionable to me that this in not currently the law.
Post reply on HN