AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Yeah, you're right. Data breaches are essentially just slaps on the wrist to companies like AT&T. Maybe it's possible to fine them based on the proportion of the userbase that was affected and the profits they generated for a certain time period. I wonder if this will push companies to stop using external vendors to store and process data. If companies stored all of their info in house, it would prevent the case wher…
AT&T says criminals stole phone records of 'nearly all' customers in data breach
751–760 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#752Earlier quoted context omitted.
I actually agree with you but this is a dangerous opinion to express on this forum, where move fast and break things is seen as the one true path.
I am not a historian, but I expect there would have been significant pushback as well by other types of engineers back in the day when their profession was regulated. It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do i…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#753Earlier quoted context omitted.
>Having fewer bridges means that inevitable when they collapse, there will be far more victims and the event will be catastrophic. I honestly don't even know where to start with this.
It isn't safer to make building new bridges prohibitively expensive, because the result is that new bridges don't get built and then existing bridges are overused and extended beyond their design lifetime. And they're carrying several times more traffic when they ultimately fail. It's the same for all the rest of it. You're not helping people to nominally make something better unless the better thing is actually avai…
You are only succeeding at keeping 1 engineering firm alive, who can afford to bid and build mega-expensive projects.
Eventually, the megafirm will adopt poor practices. And now, those practices will literally spread out across every single bridge built in the world. You now have a mono-culture of engineering that includes cancer as part of its DNA. Congratulations - you have granted a monopoly to a firm that sells ticking time bombs to your own citizens
This is, in essence, NASA, banking, Fannie/Freddie.
Errors are a part of nature. They must happen. We are humans and fallible. The question, when errors do happen, how big and hurtful will they be? Small or big ?
You can't buy your way out of human error and hubris. This is the fatal conceit.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#754Earlier quoted context omitted.
There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity
Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…
The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has.
You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU.
It even had a data retention law that forced providers to keep up to 8 years of data related to their customers so that it could be handed over to LEOs.
The EU's stance on privacy is just lipstick on a pig. When you pick under the curtain of the privacy laws in the EU, you'll see that it's not better here than in the US.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#755Earlier quoted context omitted.
I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…
Retention periods seem like a moot point if the government just slurps every piece of data anyway and stores it indefinitely
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#756AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Penalties would also incentivise businesses to hide data breaches.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#757AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Prison time being on the table for officers of the corporation is the only thing that will change this behavior.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#758Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#759Earlier quoted context omitted.
Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.
It was snowflake’s lack of security that did this not ATT. Not saying ATT is a paragon of security or anything but snowflake was where the hack took place.