Earlier quoted context omitted.
There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity
I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…
AT&T says criminals stole phone records of 'nearly all' customers in data breach
761–770 of 874 posts
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#762Earlier quoted context omitted.
Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…
You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#763AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#764Earlier quoted context omitted.
I agree. I think it's reasonable to expect companies to safeguard that information from malicious actors.
I don't agree. I don't think it's reasonable to expect it, because companies show over and over that they cannot do it. And let's face it, the only reason your company hasn't fallen victim to a data breach or ransomware is that you haven't been seriously targeted yet. We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with…
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#765AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
Piercing the veil to prosecute those “responsible” seems like it would just incentivise the business to carry on as normal but with employees that are contractually designated (i.e. forced) to be fall guys if anything goes wrong.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#766Earlier quoted context omitted.
I am not a historian, but I expect there would have been significant pushback as well by other types of engineers back in the day when their profession was regulated. It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do i…
Nothing stops companies or individuals from getting audits or from developing a voluntary license/certification. Consumers that want the added protection can pay the premium. But to force an entire industry into regulatory capture where its unnecessary seems foolish.
The standard legal philosophy across the world is that you can't actually predicate protection of a right on ability to pay (under reasonable limits). So, for example, nobody gets to build unsafe bridges and charge less for it, because it violates the right to life.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#767Earlier quoted context omitted.
You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…
I was talking about the GDPR, not EU regulations in general.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#768Earlier quoted context omitted.
Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…
Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#769Earlier quoted context omitted.
Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.
"but the cookie banners look so bad and ugly!" Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.
Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach
#770AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…
AT&T would be nearly equivalent to an E2E service overnight.
The lines wouldn’t be encrypted, so the NSA would still tap them, but at least there would be zero mutable storage in the AT&T data centers (except boot drives, SMS message queues, and a mapping between authorized sims and phone numbers).
In this day and age, why do they even maintain call records? They don’t need them for billing purposes, which was the original purpose of keeping them.