so just metadata, not the actual texts or PII
your phone number is PII and everybody you ever called or texted is VERY VERY PII
AT&T says criminals stole phone records of 'nearly all' customers in data breach
741–750 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#742this breach is of course appalling. But nearly as appalling is the experience of _explaining why this matters_ to non-technical friends who stare at you with blank, distracted eyes, but only for a second; for their phone (yes, the very phone that just exposed them to uncountable future ills) has chimed. I have nearly given up; like smoking, it will be decades before the harms are understood. We have to wait for your…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#743Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#744Earlier quoted context omitted.
Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.
American businesses, especially in predatory industries like adtech, complain all the time.
Most Americans wouldn't even know what GDPR is, let alone have a reason to complain about it.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#745Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#746Earlier quoted context omitted.
The way this works in civil engineering is that the engineer refuses to sign off on an unsafe design. If costs have to increase to address the issue, then they do. If management doesn't budge, then they bleed money while twiddling their thumbs staring at an unapproved design.
Be careful what you wish for… civil engineering is a terrible awful bureaucratic profession. The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#747Earlier quoted context omitted.
It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…
Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#748Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#749AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Penalties would also incentivise businesses to hide data breaches.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#750Earlier quoted context omitted.
> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…
If one breach exposed all of their data, they don't practice the well-known security (since ancient times) technique of never having all your goodies in one location.
Snowflake's entire business model is based on selling the idea of "data lakes", "data warehouses", etc...
The basic premise of data lakes, etc, is to replicate and dump all your company data into easily queryable database instances, like Snowflake. I'm not disagreeing that this is a stupid thing to do, but just pointing out that this is something basically every Fortune 500 company is doing. Because big data is cool. (Or was cool)
Specifically since the article called out no 2fa... I'm actually very surprised how difficult 2fa is to set up with Snowflake. It's been 2-3 years since I set up a Snowflake instance, but I remember there being no obvious or easy way to enable it. (I wanted it on, but at the time enabling it was a multi-hour task, not just a setting to enable)