Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

711–720 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#711

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

They added windows to this now, but I always wondered what this windowless skyscraper was, back in the day, in Downtown NYC.

https://nymag.com/intelligencer/2016/11/new-yorks-nsa-listen...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#712

Earlier quoted context omitted.

Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

The government can't keep its own data safe, as the OPM breach showed. Apart from some resignations, nobody faced any serious consequences for that either.

Even more reason for regulatory requirements covering data security for all organisations- both private and public sector

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#713

Earlier quoted context omitted.

The AT&T app and website are so bad it takes way longer than 1 minute to log in to e.g. pay your bill. The United States needs to raise the bar for large-cap negligent operators and fine the company enough to make shareholders listen.

In approximately 100% of cases, if your intuition is to say "this company is too large should be fined/regulated more," what you should actually say is "this company is too large and should be broken into many smaller entities."

Or nationalize parts of it, as has been done for electricity, water, and the courts.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#714

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

do yourself a favor and accept that phone records have never not been recorded and the data is mostly available for purchase. the company is to blame because they are complicit or negligent in the bespoke surveillance state, probably both.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#715

Earlier quoted context omitted.

> Over in Europe this blanket saving of phone records beyond what it is necessary to operate would have been illegal in many countries, On the contrary, many European countries have mandatory data retention periods that meet or exceed the 6 months of records that were supposedly included in this breech. Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records. Saying tha…

> Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records. No they don't, because it's "suspended" by the federal network agency until courts are through with it. In fact they suspended it three days before the law would've come into force and thus it never was. The current state of affairs is this: the retention was ruled incompatible with German and European law in an…

I should add that if is not mandated, then it is illegal to do under GDPR and other privacy laws beyond what is necessary without obtaining explicit consent. Even if it was mandated, the telcos still could not do with the data as they please and forward it to another company like AT&T did.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#716
post #70

AT&T stock has already bounced back from much of the initial -2.6% drop this morning, so the market thinks AT&T is immune. Meanwhile Snowflake is -3.9% down (they have many other customers than AT&T). https://www.marketwatch.com/investing/stock/T https://www.marketwatch.com/investing/stock/SNOW

Well it’s as if you put your data in Salesforce and Salesforce got breached… maybe you’re bad at picking vendors but the real loss of trust would be on Salesforce. In this case, Snowflake was also the cause for the Ticketmaster and Lending Tree breaches according to the article so… real lack of trust in Snowflake now.

Snowflake is a platform. The lack of trust is in whoever configured Snowflake for AT&T

Credential rotation, SSO, PrivateLink or IP allowlists all should be used with PII.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#717

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect as little data as possible, and to delete it as soon as it's not strictly needed. This greatly reduces the compliance burden.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#718
This data will be a gold mine for scammers. When they know relationships and real names of people they can target people as well create specific attacks for different people. Now with what LLM's are capable of mass social engineering is possible.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#719

Earlier quoted context omitted.

I don't agree. I don't think it's reasonable to expect it, because companies show over and over that they cannot do it. And let's face it, the only reason your company hasn't fallen victim to a data breach or ransomware is that you haven't been seriously targeted yet. We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with…

This data is valuable primarily for spam mitigation and perhaps customer profiling. Expect every SMS and MMS sent or received to be part of a spam mitigation and profiling program where it's stored indefinitely. Apple not encrypting RCS is likely due to similar factors, where they have seen existing spam problems on RCS that are much harder to root out when you have end-to-end encryption.

In my not so humble opinion, the biggest problem with phone numbers in general is the general ability to spoof any number. Please correct me if I am wrong but stir/shaken is only available on the new stuff and even then there is no good way to track the origin of a phone call. This is beyond ridiculous and clearly leadership is asleep at the wheel.

There needs to be a firm timeline -- maybe a year maybe a decade, I don't know the details but something that allows customers to transition to a system where all calls can be traced through the network with 100% guarantee.

Step zero is actually having a process/protocol where any phone is tamper evident meaning we can tell 100% that this call came from this operator and the operator knows the call came from this user.

Perhaps the first phase allows individual users to opt in. So we would ask our operators to only route us calls and texts that positively identify themselves as fully traced with whatever the new protocol is that will replace SS7/sigtran so the origin of a call or text is positively identified. If this guarantee is not available, route the call to spam inbox somehow.

Then the hard part I'm guessing is fixing all the defects?

The second phase is to say after this date, no operator in the US is allowed to relay calls that are from legacy systems. This will likely take many years as I don't know how we will handle international calls and texts. But at some point we have to put our foot down and say enough is enough.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#720

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.
Post reply on HN