Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

761–770 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#761
post #702

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

They keep personal customer details like SSNs indefinitely despite no longer being a customer.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#762

Earlier quoted context omitted.

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

I was talking about the GDPR, not EU regulations in general.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#763

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

At&t is up there with defense contractors with how intertwined their businesses are with the DoD. They're basically an extension of the intelligence agencies here in the US. They don't have consequences, much like Boeing.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#764
post #621

Earlier quoted context omitted.

I agree. I think it's reasonable to expect companies to safeguard that information from malicious actors.

I don't agree. I don't think it's reasonable to expect it, because companies show over and over that they cannot do it. And let's face it, the only reason your company hasn't fallen victim to a data breach or ransomware is that you haven't been seriously targeted yet. We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with…

Finally, some sense. My first though when reading the article was why are we even allowing these companies to collect that data in the first place.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#765

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Genuinely chonky fines seems to be the answer to this problem, as it aligns incentives with rewards/penalties (if you’re lax about how your company approaches user data then you’ll be at financial risk).

Piercing the veil to prosecute those “responsible” seems like it would just incentivise the business to carry on as normal but with employees that are contractually designated (i.e. forced) to be fall guys if anything goes wrong.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#766

Earlier quoted context omitted.

I am not a historian, but I expect there would have been significant pushback as well by other types of engineers back in the day when their profession was regulated. It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do i…

Nothing stops companies or individuals from getting audits or from developing a voluntary license/certification. Consumers that want the added protection can pay the premium. But to force an entire industry into regulatory capture where its unnecessary seems foolish.

Privacy/protection of personal data is slowly being recognized as a Right across the world, as it should.

The standard legal philosophy across the world is that you can't actually predicate protection of a right on ability to pay (under reasonable limits). So, for example, nobody gets to build unsafe bridges and charge less for it, because it violates the right to life.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#767

Earlier quoted context omitted.

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

I was talking about the GDPR, not EU regulations in general.

The US also has laws that, in isolation, would suggest some sort of protection against universal corporate/government surveillance, but they’re no more effective here than in the EU.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#768

Earlier quoted context omitted.

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.

Yes, mostly blaming them for cookie banners (which aren't because of the GDPR) but also because it makes them need to think about compliance.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#769

Earlier quoted context omitted.

Do Americans complain about the GDPR? I’ve only ever seen them say they wish the US had something similar.

"but the cookie banners look so bad and ugly!" Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.

Also cookie banners are from the e-privacy directive, not the GDPR.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#770

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Imagine a world where suffering a data breach meant you could no longer collect, let alone hold or sell that class of data for a decade, and this rule preempted laws that required data gathering.

AT&T would be nearly equivalent to an E2E service overnight.

The lines wouldn’t be encrypted, so the NSA would still tap them, but at least there would be zero mutable storage in the AT&T data centers (except boot drives, SMS message queues, and a mapping between authorized sims and phone numbers).

In this day and age, why do they even maintain call records? They don’t need them for billing purposes, which was the original purpose of keeping them.

Post reply on HN