Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

791–800 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#791
post #719

Earlier quoted context omitted.

In my not so humble opinion, the biggest problem with phone numbers in general is the general ability to spoof any number. Please correct me if I am wrong but stir/shaken is only available on the new stuff and even then there is no good way to track the origin of a phone call. This is beyond ridiculous and clearly leadership is asleep at the wheel. There needs to be a firm timeline -- maybe a year maybe a decade, I d…

> Step zero is actually having a process/protocol where any phone is tamper evident meaning we can tell 100% that this call came from this operator and the operator knows the call came from this user. This basically doesn't work because the mapping between phone numbers, users and operators isn't exactly 1:1:1. Some businesses have a single number that they use as Caller ID on all their calls , despite having one cor…

Amazing article about why phone spam is so much harder to fight than email spam.

Thank you for sharing it!

Now I need to lean SS7 signaling.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#792

Earlier quoted context omitted.

I don't agree. I don't think it's reasonable to expect it, because companies show over and over that they cannot do it. And let's face it, the only reason your company hasn't fallen victim to a data breach or ransomware is that you haven't been seriously targeted yet. We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with…

Finally, some sense. My first though when reading the article was why are we even allowing these companies to collect that data in the first place.

How would they bill customers and other providers for usage if they didn't keep call/text metadata?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#793
post #719

Earlier quoted context omitted.

In my not so humble opinion, the biggest problem with phone numbers in general is the general ability to spoof any number. Please correct me if I am wrong but stir/shaken is only available on the new stuff and even then there is no good way to track the origin of a phone call. This is beyond ridiculous and clearly leadership is asleep at the wheel. There needs to be a firm timeline -- maybe a year maybe a decade, I d…

> Step zero is actually having a process/protocol where any phone is tamper evident meaning we can tell 100% that this call came from this operator and the operator knows the call came from this user. This basically doesn't work because the mapping between phone numbers, users and operators isn't exactly 1:1:1. Some businesses have a single number that they use as Caller ID on all their calls , despite having one cor…

> ...yet they're all legally authorized to use that number.

But why? I get that they want a unifed appearance, but as a phone subscriber I want to know if it's BigCo calling from New Delhi vs. BigCo calling from Chicago.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#794

Earlier quoted context omitted.

The way this works in civil engineering is that the engineer refuses to sign off on an unsafe design. If costs have to increase to address the issue, then they do. If management doesn't budge, then they bleed money while twiddling their thumbs staring at an unapproved design.

Be careful what you wish for… civil engineering is a terrible awful bureaucratic profession. The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.

"Move fast and break things" isn't an appropriate philosophy for critical public infrastructure

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#795

Earlier quoted context omitted.

IANAL but this would seem like a “class action” situation.

At&t customers are bound to individual arbitration so there will be no class action lawsuit for this. > Please read this Agreement carefully. It requires you and AT&T to resolve disputes through arbitration on an individual basis rather than jury trials or class actions. https://www.att.com/legal/terms.consumerServiceAgreement.htm...

I was not a customer of AT&T when the leak happened.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#797

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

welcome to a post 9/11 world. privacy has been dying for a long time. the general population doesn't care anymore. they freely give up everything to big tech anyways.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#798
post #443

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

But hey, in 5-7 years there will be a settlement to the inevitable class action lawsuit and each of these customers (that fills in a form, ensuring only a small fraction actually do) gets a $3.75 credit on their next bill. The lawyers will get 30% of the settlement and each walk away with several million dollars. Justice! chef’s kiss

This is from an email I got yesterday from PayPal:

"Google Referrer Header Privacy Settlement has sent you $0.11 USD."

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#799

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

> There's no federal law requiring AT&T to hold onto this data.

This is false? https://www.law.cornell.edu/uscode/text/18/2703 https://www.usnews.com/news/articles/2015/05/22/how-long-cel...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#800

Earlier quoted context omitted.

Finally, some sense. My first though when reading the article was why are we even allowing these companies to collect that data in the first place.

How would they bill customers and other providers for usage if they didn't keep call/text metadata?

These are records from 2022. The hack wasn't carried out the second the calls were made. You really need to keep the records that long to do your billing? That's absurd.
Post reply on HN