Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

701–710 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#701

Earlier quoted context omitted.

I am working on this with mine, but even Signal is too weaksauce in my book. Ownerless (and ideally decentralized) p2p chat is what I am after. If everyone in my group used Android then it'd be Briar or Cwtch hands down for primary text/picture msg and SimpleX or Session or Jami as voice/video call and backup. Because there's an iphone upsetting everything that scratches Briar and Cwtch, so it's SimpleX reinforced wi…

Do you make it like a fun game? Like when me and my friends in school would pass eachother coded notes and the cipher was an inside joke? I'm genuinely curious: what was the pitch that you used to get others to start using signal?

Never signal because signal is bad on requiring too much metadata (your number). It was Session for a while but since SimpleX can be hardened with Orbot (or Tor on PC) and it was way more notifications-reliable, we switched. I would much prefer Briar or even Cwtch but an iphone in the group ruins that party.

Otherwise to answer your question it is a bit of a game. I also like to remind them how, being creeped out by Aunt Matilda putting microphones and keyloggers all over, at least Aunt Matilda [most likely] has better interests for you at heart. GOOG/AAPL/MSFT have no such kinship connection yet they are surveilling in precisely the same ways. That was a decade ago, now add in the Universal Function Approximators! *Demo stable-diffusion.* *Demo lm-studio.* *Present to them a performance of Orwell's 1984.* *Show them a few documentaries on social control.* "See? Now would you like to try it?"

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#702

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

I'm no longer under this specific NDA, so, I can talk a bit about this.

It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents of the text messages themselves. Verizon was up there as well, but, I don't remember specifics.

The carrier that I worked with kept only 3 days content of the actual messages, 28 days for the text message metadata, and 28 days for the call records for their enforcement database, but, they could get calling records and sms envelope information for billing back 7 years, and at the time, we had to implement sharding at the database layer that maintained the warrant database due to the amount of traffic that we were receiving from the calling systems and the amount of queries/data that we were sending out, in near realtime, to law enforcement users who paid $10,000/month for access to that data.

AT&T wasn't storing this data out of the kindness of their heart, it was a (probably small) revenue stream for them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#703

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#704

Earlier quoted context omitted.

It's a rhetorical question that's effective because the answer is obvious.

You would think so, but one time an undergraduate IT guy in my school's computer lab essentially ran an `rm -rf` on all the students' home directories 2 weeks from the end of the semester. It turns out the lab's backups weren't working. The email from the department was pretty quick to throw that kid under the bus.

Are you trying to say that a university IT department was a toxic workplace? I'm shocked, shocked I tell you!

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#705

Earlier quoted context omitted.

> how weird it is that you're fine with the government getting a record of all your phone activity I don't like it, but accept it as the lesser evil. I'm from Europe and I believe the number of reported prevented terror attacks. The agencies need data access for that. Not good, but necessary. But are you aware that Meta, Google, Apple, MS, etc. collect every kind of information about every user of Android, iPhone or…

> I don't care if the government can get access to my WhatsApp messages when some of the most irresponsible companies, collect and use everything to their advantage. This is all voluntary. You give those companies your data. You don't have to. I use grapheneos and do not use any of those socials, for example.

The problem comes as people start shoving more and more DRM around, whether it be Google Play Protect, the new Android WebView Media Integrity API, or an eventual reboot of the Web Environment Integrity proposal.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#706
Why is it "nearly all"? Which customers didn't have their data stolen and why were they magically left aside of this? It's obvious the data theives had complete dominance in the system so what query did they run to get only "nearly all"?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#707
post #702

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

Ah, back in the day the FBI would pay our CTO $5000/hr to talk to and work with him. On top of that we would charge them a monthly colo fee for their equipment that collected data of customers.

Sometimes they had warrants, but mostly just bought the data.

A year or so after 9/11 and that relationship lasted years.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#708

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Enriching shareholders is exactly what they are required to do.

What, nobody is allowed to make money anymore?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#709

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

That’s interesting, I did not know this about the Obama govt. Do you have a good article about this? (Yes I’m lazy I could search for this)

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#710
post #654

Earlier quoted context omitted.

Sure - pretty well every corporation you purchase a service from is required to store your credit card information as well. But there are stiff penalties from the government and credit card processors for unauthorized access to that information; consequently, it's rarely stolen. Your address, cell metadata, phone number, email address, and passwords are leaked pretty well contsantly though. It's not that corporations…

> store your credit card information ... but there are stiff penalties from the government and credit card processors for unauthorized access to that information; consequently, it's rarely stolen Citation: The Onion? The Payment Card Industry Data Security Standard (PCI DSS) is the main information security standard for organizations that process credit or debit card information must abide by. The guidelines establis…

I'm not saying it doesn't happen. Credit card data is too valuable to never be stolen. I am saying that ~37 to >500 is a hell of a difference in how frequently things are stolen [0]

You pointed out how there are guidelines for holding that information, I'm saying there are consequences [1]. I'm following that up by saying that the consequences for mishandling customer information are not nearly as severe. They do not result in 6 figure fines.

I'm saying the severe consequences to mishandling CC data have led to the incredible disparity shown in the first paragraph

[0] https://haveibeenpwned.com/PwnedWebsites

[1] https://resourcehub.bakermckenzie.com/en/resources/global-da...

Post reply on HN