Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

741–750 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#742

this breach is of course appalling. But nearly as appalling is the experience of _explaining why this matters_ to non-technical friends who stare at you with blank, distracted eyes, but only for a second; for their phone (yes, the very phone that just exposed them to uncountable future ills) has chimed. I have nearly given up; like smoking, it will be decades before the harms are understood. We have to wait for your…

I think humans are like corrupted, selfish and evil LLMs that like to think Utopia is possible if you think about it that way it’s super easy to understand

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#743

Earlier quoted context omitted.

33% of all living americans? how can it be that much?

There are basically 3 carriers in the US, AT&T, T-Mobile, and Verizon; other carriers use the networks of those 3.

Recount

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#744

Earlier quoted context omitted.

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.

American businesses, especially in predatory industries like adtech, complain all the time.

I would hardly roll that up to all Americans though. Of course companies who's business model is seriously hurt by GDPR would complain.

Most Americans wouldn't even know what GDPR is, let alone have a reason to complain about it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#746

Earlier quoted context omitted.

The way this works in civil engineering is that the engineer refuses to sign off on an unsafe design. If costs have to increase to address the issue, then they do. If management doesn't budge, then they bleed money while twiddling their thumbs staring at an unapproved design.

Be careful what you wish for… civil engineering is a terrible awful bureaucratic profession. The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.

To be fair, AT&T, Equifax, United Health, and Peraton are probably as far away from startup culture as it gets.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#747

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

It was snowflake’s lack of security that did this not ATT. Not saying ATT is a paragon of security or anything but snowflake was where the hack took place.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#748

so just metadata, not the actual texts or PII

“Just” is a dubious adjective in this context.

some of the reports make it sound like the hackers are reading everyone's salacious texts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#749

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Penalties would also incentivise businesses to hide data breaches.

GDPR has fines for data breaches

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#750
post #635

Earlier quoted context omitted.

> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…

If one breach exposed all of their data, they don't practice the well-known security (since ancient times) technique of never having all your goodies in one location.

The attack vector was an exposed Snowflake instance.

Snowflake's entire business model is based on selling the idea of "data lakes", "data warehouses", etc...

The basic premise of data lakes, etc, is to replicate and dump all your company data into easily queryable database instances, like Snowflake. I'm not disagreeing that this is a stupid thing to do, but just pointing out that this is something basically every Fortune 500 company is doing. Because big data is cool. (Or was cool)

Specifically since the article called out no 2fa... I'm actually very surprised how difficult 2fa is to set up with Snowflake. It's been 2-3 years since I set up a Snowflake instance, but I remember there being no obvious or easy way to enable it. (I wanted it on, but at the time enabling it was a multi-hour task, not just a setting to enable)

Post reply on HN