Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

731–740 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#731

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

They added windows to this now, but I always wondered what this windowless skyscraper was, back in the day, in Downtown NYC. https://nymag.com/intelligencer/2016/11/new-yorks-nsa-listen...

That’s the AT&T Long Lines Building. It probably did have an NSA surveillance closet, but it wasn’t built without windows for that reason. The story I was told (by older colleagues when I worked at AT&T Labs) was that it was built during a time when riots and street violence were more common, so the fortress appearance was to ensure the city could maintain long-distance connectivity during urban unrest.

I believe there was another similar nexus downtown near the World Trade Center, which was destroyed on 9/11. For at least a couple of weeks we had very limited communications and credit cards were hard to use as a result.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#732
post #708

Earlier quoted context omitted.

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Enriching shareholders is exactly what they are required to do. What, nobody is allowed to make money anymore?

No, they shouldn't be allowed to fuck over their customers at ever turn so they can be greedy. The suggestion that we should be more worried about how much money the AT&T execs and shareholders make over their needs of their 100 million customers is bizarre.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#733
post #502

Earlier quoted context omitted.

- [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]. This one is 110m customers, presumably all their current customerbase. But it's still unlikely this is "internal analytics" (for telco business-case) given the timestamps were removed but location data included. - Yes about Snowflake's cloud telco unit explicitly m…

Why would the removed timestamps make the data have no value for internal analytics? It's possible they were operating from a privacy first principle and storing only the exact data they needed for a specific internal objective.

More corroboration from another commenter on TechCrunch: https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...

> [Eric Scott] AT&T was using the data to build a social graph. They didn't record the date and time because they didn't need it.

That isn't "internal analytics". The end-customers who would be buying that aren't telcos. Like I said.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#734

Earlier quoted context omitted.

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.

"but the cookie banners look so bad and ugly!"

Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#735
post #702

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

Retention periods seem like a moot point if the government just slurps every piece of data anyway and stores it indefinitely

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#736
post #578
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the dev…

I understand that isn’t what’s being suggested. What I’m suggesting is that there is perhaps a distortion of the common idea of who is “responsible” for something. I think the idea that fault bubbles up to the highest level in the chain of command is silly. Fault is distributed across the entire chain, and if we want to address this issue, we can’t ignore that.

To draw an analogy, if someone’s 16-year-old child is texting while driving and gets in a car accident, is their parent to blame? Most people could see that there is some fault on the part of both the parent (for perhaps not emphasizing enough the importance of safety while driving), and the child (for doing something they know is unsafe). And this fault exists in a continuum; maybe the parent told their child every day to not text while driving, and the child did it anyway. Maybe the parent never told them anything about safe driving habits, so the child had never considered that texting while driving was unsafe.

My point is that pretending that the highest C-suite executive is wholly responsible for everything that goes on in the company is extreme. Everyone along the entire chain of command has to do their part to ensure secure products are shipped - the executive needs to prioritize it, hire the right people to develop a plan, ensure people are enforcing the plan, etc., all the way down to the software engineers, the cleaning staff, etc. If one link in that chain breaks, the entire system fails, and it could be because of a weakness anywhere along the chain.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#737

Earlier quoted context omitted.

In approximately 100% of cases, if your intuition is to say "this company is too large should be fined/regulated more," what you should actually say is "this company is too large and should be broken into many smaller entities."

Or nationalize parts of it, as has been done for electricity, water, and the courts.

I understand the desire to push for this but I also know first hand it would make things worse specifically around competency. I've had countless calls and meetings with state and federal agencies that could not grasp even the simplest of technical issues and this was with the very people charged with the responsibility for their systems. On the state level, explaining to the California DMV repeatedly that they may not use RC1918 address space in public MX records and expect emails and faxes to get through. That was an actual battle. Or arguing and escalating with 3 letter federal agencies that we will not "install their server certs" on our tens of thousands of servers and they must install the intermediate certs correctly. I wish I could share who that was because nobody would believe me... There are countless battles I've had with these agencies. I do not want more of these people running critical and sensitive systems. It's bad enough that leaders in companies like AT&T bend over backwards to just hand over data to them. I've had to hand over the data, looking the other way, giving unfettered unlimited unmonitored access to mainframes without warrants. This was at a company that was gobbled up by AT&T. Or being told to let a scammer with access to an SS7 link scam infinite people because they are paying for the link. Governments running these systems would be the wolves running the hen-house.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#738

Earlier quoted context omitted.

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.

"but the cookie banners look so bad and ugly!" Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.

> way too many website owners rather torture their users

including official EU websites

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#740
post #462

Joining the dots on the facts so far, people don't seem to have grasped the apparent huge significance: - guessing it was some GenAI startup looking into consumer tracking, alternate credit scoring, surveillance or other national-security use-case. - Very unusually, the DOJ ordered two ~month-long "delay periods" in disclosure: ("The Justice Department determined on May 9 and again on June 5 that a delay in providing…

Dats cuz swifties don’t like Ticketmaster boo Ticketmaster (& hov)
Post reply on HN