Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

691–700 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#691
post #502

Earlier quoted context omitted.

Snowflake PR, from the link above: "What makes telecom service providers unique is that they have access to consumer location data. For most other industries, a consumer can go into their phone’s privacy settings and turn off the location access in the smartphone app. But in the world of telecom, as long as the phone is connected to a network, the telecom provider can use triangulation to find the approximate locatio…

- [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]. This one is 110m customers, presumably all their current customerbase. But it's still unlikely this is "internal analytics" (for telco business-case) given the timestamps were removed but location data included. - Yes about Snowflake's cloud telco unit explicitly m…

Why would the removed timestamps make the data have no value for internal analytics?

It's possible they were operating from a privacy first principle and storing only the exact data they needed for a specific internal objective.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#692

Earlier quoted context omitted.

Do you have a source for that claim?

Here's Snowflake bragging about helping telcos sell location data: https://www.snowflake.com/blog/telecom-data-partnerships/

So if I buy a car with an advertised top speed of 200 mph, it's given that I must be violating speed limits when driving it?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#693

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

33% of all living americans? how can it be that much?

There are basically 3 carriers in the US, AT&T, T-Mobile, and Verizon; other carriers use the networks of those 3.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#694

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The breach here was not against AT&T but against a cloud computing company called Snowflake.

Cloud computing companies, so-called "tech" companies, and the people who work for them, including many HN commenters, advise the public to store data "in the cloud". They encourage the public, whether companies or individuals, to store their data on someone else's computer that is connected to the open internet 24/7 instead of their own, nevermind offline storage media.

Countless times in HN threads readers are assured by commenters that storing data on someone else's computer is a good idea because "cloud" and "_____ as a service". Silicon Valley VC marketing BS.

"Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible."

Piercing the veil refers to piercing limited liability, i.e., financial liability. Piercing the veil for crimes is relatively rare. Contract or tort claims are the most common causes of action where it is permitted.

There is generally no such thing as "criminal negligence" under US law. Negligence is generally a tort.

As for fines, if there were a statute imposing them, how high would these need to be to make Amazon, Google, Microsoft or Apple employees and shareholders face "real consequences".

Is it negligent for AT&T to decide to give data to a cloud computing company such as Snowflake? HN commenters will relentlessly claim that storing data on someone else's computers that are online 24/7 as a "service", so-called cloud computing, is a sensible choice.

Data centers are an environmental hazard in a time when the environment is becoming less habitable, they are grossly diminishing supplies of clean water when it is becoming scarce, and these so-called "tech" companies are building them anyway.

Data centers are needed so the world can have more data breaches. Enjoy.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#695

Earlier quoted context omitted.

Do you have a source for that claim?

* https://www.fcc.gov/document/fcc-fines-largest-wireless-carr... * https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte... * https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da... * https://www.vice.com/en/article/3a87bv/fcc-propose-fines-ver... * https://krebsonsecurity.com/2024/04/fcc-fines-major-u-s-wire... Joseph Cox is basically the only investigative journalist that digs into constant PII viol…

Thanks!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#697

Earlier quoted context omitted.

Its a bug. We now have Instead , we could have 1000s of smaller banks. Tons of smaller banks is the natural state of things, like restaurants. This was true before the banking cartel, TARP, ZIRP, most recently, PPP (genius backdoor to bail out wall st.). In such system, any 1 collapsing bank wont bring the entire system down. Having fewer bridges means that inevitable when they collapse, there will be far more victim…

>Having fewer bridges means that inevitable when they collapse, there will be far more victims and the event will be catastrophic. I honestly don't even know where to start with this.

It isn't safer to make building new bridges prohibitively expensive, because the result is that new bridges don't get built and then existing bridges are overused and extended beyond their design lifetime. And they're carrying several times more traffic when they ultimately fail.

It's the same for all the rest of it. You're not helping people to nominally make something better unless the better thing is actually available to them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#698

Earlier quoted context omitted.

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Money can't buy competence, at least not at organizational scale.

Fine, but they can clearly afford to pay for a lack of it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#699
post #621

Earlier quoted context omitted.

Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

I agree. I think it's reasonable to expect companies to safeguard that information from malicious actors.

I don't think it is. I assume everyone gets hacked eventually. It's really hard (I would argue impossible) to make a 100% secure computer system, and if they're operated by people, you're terribly vulnerable.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#700
post #410
post #382

Earlier quoted context omitted.

ATT could be using Snowflake for internal analytics

It's not "internal analytics", because a) 90% of the data was former customers and b) it has location data but timestamps were removed, so it's social-graph information plus location. Start asking yourself what sorts of end-users want to pay for the entire social-graph of 77m, regardless whether those customers never make a phone call again. "Alternate credit scoring, hyper-targeted marketing and more... an emerging…

One of the usecases of Snowflake is to give access to a dataset to multiple teams in your company, while filtering what each team can see : https://www.snowflake.com/en/data-cloud/workloads/collaborat...

Service A can access the dataset with the location hidden while Service B can access the dataset with the timestamp hidden while Service C can access the full dataset.

So Snowflake probably has the full dataset, and the account that was used in the breach only had access to a part of it, where the timestamp was hidden.

It's hard to come to any conclusion about what was done with the data on this account.

We can even go as far as saying that the account never used the data but had access to it because it was part of a group of accounts with access to it.

Post reply on HN