Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

71–80 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#72
post #7

The real problem is that data needs to be deleted over time. There is not much of a use case for customers for go back last year and see who called them and obviously there are use cases like criminal investigations or spying. But customer has no power or ability to dictate how long their records are store and how they are used. Companies should provide tools and features to their customers empowering them with their…

This isn't data for serving user needs, this is data for spying on users

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#73

How has Snowflake felt ANY recourse for being the source of all of these hacks?

its not Snowflake's fault their customers used weak passwords and no MFA. Not enforcing MFA does merit some blame on Snowflake, however, I still think its on the customer to secure your own environment.

It's industry standard to enforce MFA for customers of such sensitive data though. There's always going to be weak links.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#74

Consumers are so numb to data breaches that these events now bring very little outrage. I think without that anger from the consumer, there's little incentive for companies to do more to stop data breaches from happening.

Well it's starting to feel like data privacy just doesn't exist anymore. I don't know why administrators for big customer databases even bother setting passwords these days.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#75
And earlier this year my ssn was on the dark web due to their leak (or vendor). One year of monitoring? No, I’m going to need it for life.

Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#76

How has Snowflake felt ANY recourse for being the source of all of these hacks?

The dark web and info stealing malware are the source of the hacks. My worry is not only that consumers get numb to breaches, but they consume rampant misinformation and have no idea how to hold appropriate parties accountable. How many times have you held AWS accountable for stolen access keys? Was it AWS fault when rabbit leaked their own keys? Is it snowflakes fault when you lose your creds to infostealing malware…

Eh, iirc the source of the hack was just regular stealers like Redline, not "the dark web".

It was actually Snowflakes fault.

The threat actors were able to find a test/demo account they could log into and from there they were able to access prod things they shouldnt have.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#77

How has Snowflake felt ANY recourse for being the source of all of these hacks?

The Mandiant report said that some Snowflake customers declined to use MFA AND had passwords in place for 4+ years[1]. Maybe Snowflake should have pushed for MFA harder but at the end of the day, this is AT&T's fault. [1] https://cloud.google.com/blog/topics/threat-intelligence/unc...

I'd say the blame lies halfway between AT&T and Snowflake. If you let your customers have poor security practices, and you have the power to ensure a heightened security level, you're also partly to blame...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#78

So where/what is my compensation? (I know there is no recourse). When no one is on the hook for secure practices, like enabling MFA on your effin data stores that contain massive amounts of customer PII, this is the result. Not even an apology, just report it and move on. woops! those gosh darned cyber criminals.

If you go to court and ask for compensation you would likely be asked to show harm. Could you?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#79
“Brad Jones, chief information security officer at Snowflake, told CNN in a separate statement that the company has not found evidence this activity was “caused by a vulnerability, misconfiguration or breach of Snowflake’s platform.” Jones said this has been verified by investigations by third-party cybersecurity experts at Mandiant and CrowdStroke.

AT&T said it launched an investigation, hired cybersecurity experts and took steps to close the “illegal access point.””

That's pretty rich: “it wasn't misconfigured, it was just illegally open, and now we're closing it”.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#80
post #7

The real problem is that data needs to be deleted over time. There is not much of a use case for customers for go back last year and see who called them and obviously there are use cases like criminal investigations or spying. But customer has no power or ability to dictate how long their records are store and how they are used. Companies should provide tools and features to their customers empowering them with their…

Non-murder criminal offenses typically have very short statutes of limitations.

A lot of this could also be solved by encouraging the federal government to enforce federal privacy law as written more aggressively. A good incentive would be to amend the privacy statutes to permit the FTC to keep the funds extracted from settlements and penalties in-house. This would allow them to increase staffing and create a positive feedback loop to deter wrongdoing. This would have a negative effect on incumbent companies and practices, but it would not take long for the message to get across and for practices to change accordingly.

Congress tends to prefer keeping agencies on its own budgetary string which paradoxically limits what the agencies are capable of doing. The laws that we think protect us do not protect us because many of them are within the exclusive jurisdiction of a federal agency with very limited powers and funds. In the US the leadership likes to create the illusion that it has made "Bad Problem" illegal by writing it into the law, but it does not like creating the conditions in which "Bad Problem" could be solved, whether it's because the tradeoffs involved are tough to contemplate or because keeping "Bad Problem" around as a visible enemy is clever politics.

Post reply on HN