Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

781–790 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#782

Earlier quoted context omitted.

They added windows to this now, but I always wondered what this windowless skyscraper was, back in the day, in Downtown NYC. https://nymag.com/intelligencer/2016/11/new-yorks-nsa-listen...

That’s the AT&T Long Lines Building. It probably did have an NSA surveillance closet, but it wasn’t built without windows for that reason. The story I was told (by older colleagues when I worked at AT&T Labs) was that it was built during a time when riots and street violence were more common, so the fortress appearance was to ensure the city could maintain long-distance connectivity during urban unrest. I believe the…

It’s built to withstand a nuclear blast. There’s buildings like this all over the country (though not in skyscraper format).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#783

In EU, this would have been a huge scandal. This would involve huge fines and the company would really try their best not to be so sloppy with data protection. But they are not in EU.

It would be interesting if any ex-customers, living in the eu are affected - they may be covered by gdpr (though unlikely).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#784
post #637

Earlier quoted context omitted.

How do you know it was a spy agency? Sounded like just a hacker group. I assume 5 eyes are the only ones who have this already anyway as a matter of course. All they have to do is buy it from AT&T, no hacking necessary.

it seems unlikely that it was just for the lulz. if the intruders are auctioning off the data, do you think the russian fsb, the ministry of state security, hizbullah, mossad, or the usdoj will bid highest? (the last, hypothetically, to destroy the data rather than use it for leverage in investigations—if not, it's in effect just another spy agency)

Would they destroy only the hacked stuff? All the good info is still with the company..they can be hacked again.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#785

WHY IS THIS DATA EVEN AVAILABLE TO BE DOWNLOADED??? Why do we not have protection in place so that hackers can't even download this data even if they wanted to?? What purpose does 2 year old data serve AT&T except to monitor us and to create social networks of people and associations?

Er....exactly.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#786

Earlier quoted context omitted.

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

> You obviously did not follow the recent drama in the EU related to Chat Control V2.

It is strange to say they wanted it when we have proof it is voted down and widely unsupported. A part of the EU government apparatus wants it, but taking that and saying the EU wants it is not honest.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#787

Earlier quoted context omitted.

American businesses, especially in predatory industries like adtech, complain all the time.

I would hardly roll that up to all Americans though. Of course companies who's business model is seriously hurt by GDPR would complain. Most Americans wouldn't even know what GDPR is, let alone have a reason to complain about it.

They are talking about Americans on this site, who very often work at companies that GDPR is made to stop predating on users. Many European users here also works at such companies, so you often see it from them as well, but not as often since those companies are mostly American.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#788

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

That's quite a CPNI incident. Wonder what their fine will be. [0]

[0] https://www.tlp.law/2023/08/01/fcc-proposes-20-million-fine-....

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#789

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

And whom is a large percentage of shareholders?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#790

Earlier quoted context omitted.

Money can't buy competence, at least not at organizational scale.

Fine, but they can clearly afford to pay for a lack of it.

Fine is cheaper than solving compliance issues. Many such cases unfortunately.
Post reply on HN