Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

801–810 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#801
post #799

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

> There's no federal law requiring AT&T to hold onto this data. This is false? https://www.law.cornell.edu/uscode/text/18/2703 https://www.usnews.com/news/articles/2015/05/22/how-long-cel...

There's required disclosure using an administrative subpoena for records over 180 days old if they have them

CALEA requires phone (and later broadband) equipment to conform to wiretapping standards, and if a carrier gets a court order to wiretap it has to provide that data from warrant receipt til warrant expiration.

Landlines have some data retention requirements.

But there's no law on broadband or wireless data retention.

There may well and likely is a secret FISA court order under section 702 that's been served to telecoms, but an astonishingly small number of people in govt and industry know whether that actually says that they just have to hand over records in real time or whether they need to keep records for some period of time.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#802

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The breach here was not against AT&T but against a cloud computing company called Snowflake. Cloud computing companies, so-called "tech" companies, and the people who work for them, including many HN commenters, advise the public to store data "in the cloud". They encourage the public, whether companies or individuals, to store their data on someone else's computer that is connected to the open internet 24/7 instead…

If it helps to understand the comment, change the word "breach" to "unintended redistribution of data".

The comment is about the risk created by transferring data to a third party for online storage.

It is not about the specific details of how data is obtained by unauthorised recipients from the third party.

The act of storing data with third parties who keep it online 24/7 creates risk.

Obviously, the third parties will claim there is no risk as long as ["security"] is followed

If we have a historical record that shows there will always be some deficiency in following ["security"], for whatever reasons,^1 then we can conclude that using the third parties inherently creates risk.

1. HN commenters who focus on the reasons are missing the point of the comment or trying to change the subject.

If customer X gives data to party A because A needs the data to perform what customer has contracted A to do, and then party A gives the data to party B, now customer X needs to worry about both A _and_ B following ["security"]. X should only need to trust A but now X needs to trust B, too. If the data is further transferred to third parties C and D, then there is even more risk. Only A needs the data to perform its obligation to customer X. B, C and D have no obligations to X. To be sure, X may not even know that B, C and D have X's data.

A good analogy is a non-disclosure agreement. If it allows the recipient to share the information with third parties, then the disclosing party needs to be concerned about whether the recipient has a suitable NDA with each third party and will enforce it. Maybe the disclosing party prohibits such sharing or requires that the recipient obtain permission before it can disclose to other parties.^2 If the recipient allows the information to be shared with unknown third parties, then that creates more risk.

2. Would AT&T customers have consented to their call records being shared with Snowflake. The people behind so-called "tech" companies like Snowflake know that AT&T customers have no say in the matter.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#803

Earlier quoted context omitted.

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

> You obviously did not follow the recent drama in the EU related to Chat Control V2. It is strange to say they wanted it when we have proof it is voted down and widely unsupported. A part of the EU government apparatus wants it, but taking that and saying the EU wants it is not honest.

The regular Joe doesn't really care to be honest.

I have talked about it around me a bit and most people who do not work in tech or who don't have a certain interest in online privacy or privacy in general don't know about it.

Of course when you ask the citizens of the EU if they are cool about being monitored at all times by the EU LEOs then they don't want it but the commission wants it bad. All this is due from the heavy lobbying that has been happening in Brussels.

The worst part is that this is happening while the EU is saying that it wants data sovereignty, and wants to become less dependent on the software coming from the US, but it's ready to get in bed with a US company in order to deploy this mass surveillance system who supposedly is very good at finding CP.

Nevermind the fact that it means that every bit of online communication will be analyzed and dissected by a corporation that is out of reach of the EU.

But the commission is not stupid, they carved themselves a nice little clause so that they can be exempted from such mass surveillance. I guess they understand that having all telecommunications monitored by a for profit company that is not from the EU could lead to some embarrassing data leaks, just like we saw with AT&T but they don;t care if it's our data that leaks as long as it's not theirs.

That is why to me GDPR is just a facade. You can't seriously say that you are pro privacy and pro democracy if you keep trying to recreate the Stasi on a larger scale.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#804

Earlier quoted context omitted.

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

I was talking about the GDPR, not EU regulations in general.

How does it look on one hand to say that the EU cares about it's users data and wants the users to be able to choose who it is shared with, has clear guidelines related to it's storage and levy fines on companies who breach these terms and then turn around and come out with Chat Control V2?

Something does not compute. Either you are pro privacy and you act like it or you are not.

It kills me to hear that Europe is pro privacy, because it is not true. Not if you look under the veneer and start peeling back the layers.

These sorts of data breaches should be a wake up call for any state actors who are planning on collecting massive amounts of data on their citizens.

It should make them pause and say, you know maybe we should not just give away all our data to Russia or China if they manage to break in our system.

Maybe the best way to avoid such data breaches is to not store the data in the first place.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#805
post #410

Earlier quoted context omitted.

It's not "internal analytics", because a) 90% of the data was former customers and b) it has location data but timestamps were removed, so it's social-graph information plus location. Start asking yourself what sorts of end-users want to pay for the entire social-graph of 77m, regardless whether those customers never make a phone call again. "Alternate credit scoring, hyper-targeted marketing and more... an emerging…

I don't see why any of your reasons preclude analytics.

I said not "internal analytics". Not "internal". The end-customers who would be buying that aren't telcos. Like I said. They are the other (non-telco) emerging industries that Snowflake's blurb hints at.

e.g. a startup doing an Alternate credit scoring model isn't "internal analytics" wrt a telco.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#806

Earlier quoted context omitted.

I was talking about the GDPR, not EU regulations in general.

How does it look on one hand to say that the EU cares about it's users data and wants the users to be able to choose who it is shared with, has clear guidelines related to it's storage and levy fines on companies who breach these terms and then turn around and come out with Chat Control V2? Something does not compute. Either you are pro privacy and you act like it or you are not. It kills me to hear that Europe is pr…

You're arguing with a lot of things that I didn't say. My comment was entirely about the GDPR.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#807
post #328

Earlier quoted context omitted.

> Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked. In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from…

Totally agree. It feels like our banking is a decade behind - like transfer money - no direct way to do it between banks - most people use Venmo. Some banks are part of Zelle, but I’ve heard it has fraud issues (weak discovery/confirmation of correct recipient) and the banks won’t refund many fraudulent transfers (“You initiated the transfer! Not our problem you sent to the wrong person!”). So, do you get a physical…

Drawer? I would say bank lockbox but that seems like a chicken and the egg problem . It’s not entirely solved sounds like.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#808

Earlier quoted context omitted.

“Just” is a dubious adjective in this context.

some of the reports make it sound like the hackers are reading everyone's salacious texts

In a world where it's illegal in some places to help someone cross state lines for healthcare, phone records don't have to include content to be dangerous.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#809
post #62

Earlier quoted context omitted.

Snowflake is saying they knew of unusual activity "around mid-April 2024", confirmed "May 23, 2024", around which time they made MFA mandatory (although their customer AT&T say they knew of the breach "Mar 20"; these timelines keep shifting back): "Mandatory MFA option unveiled by Snowflake" - Jul 11, 2024 https://www.scmagazine.com/brief/mandatory-mfa-option-unveil... > "US cloud storage firm Snowflake has already r…

It's not mandatory, I still have Snowflake user accounts that don't use MFA.

"Mandatory MFA option unveiled by Snowflake" sounds like they made it an option for an organization to decide to make MFA mandatory within that organization. But that conflicts with TheRegister headline - Snowflake's PR machine seems to be in overdrive.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#810
post #702

Earlier quoted context omitted.

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

Retention periods seem like a moot point if the government just slurps every piece of data anyway and stores it indefinitely

Not everyone in law enforcement gets to play with the NSA's toys though. Some actually have their warrant and subpoenas glanced at by a judge before it gets rubber stamped.
Post reply on HN