Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

811–820 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#811

Earlier quoted context omitted.

I would hardly roll that up to all Americans though. Of course companies who's business model is seriously hurt by GDPR would complain. Most Americans wouldn't even know what GDPR is, let alone have a reason to complain about it.

They are talking about Americans on this site, who very often work at companies that GDPR is made to stop predating on users. Many European users here also works at such companies, so you often see it from them as well, but not as often since those companies are mostly American.

Ah got it, I totally missed that context here somehow. I hadn't noticed a habit of Americans here complaining about GDPR, but that's interesting given another common pattern here of libertarian ideas. An American complaining about a different countries internal policies doesn't seem particularly libertarian.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#812
post #750

Earlier quoted context omitted.

If one breach exposed all of their data, they don't practice the well-known security (since ancient times) technique of never having all your goodies in one location.

The attack vector was an exposed Snowflake instance. Snowflake's entire business model is based on selling the idea of "data lakes", "data warehouses", etc... The basic premise of data lakes, etc, is to replicate and dump all your company data into easily queryable database instances, like Snowflake. I'm not disagreeing that this is a stupid thing to do, but just pointing out that this is something basically every Fo…

One password fail should never expose everything.

2fa is not the answer. The answer is compartmentalization. Just like a battleship is divided into many watertight compartments, because someone will poke a hole in it.

The Titanic needed 6 compartments to be breached before it was in danger of sinking.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#813

Earlier quoted context omitted.

Historically we handled this with fiber taps at AT&T, as well as other ISPs. Some of them even knew about it.

How could they not know about it?

Easy, we installed them between their sites, before they were lit up.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#814
post #637

Earlier quoted context omitted.

it seems unlikely that it was just for the lulz. if the intruders are auctioning off the data, do you think the russian fsb, the ministry of state security, hizbullah, mossad, or the usdoj will bid highest? (the last, hypothetically, to destroy the data rather than use it for leverage in investigations—if not, it's in effect just another spy agency)

Would they destroy only the hacked stuff? All the good info is still with the company..they can be hacked again.

sadly, they will

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#815

Earlier quoted context omitted.

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

Money can't buy competence, at least not at organizational scale.

Maybe not for execs, but if not for money you literally couldn't hire competent security folks

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#816
Events like these will only become more prevalent as more personal, corporate and other information is digitized and stored by organizations too busy with other things to 100% button down their data (possibly an impossible thing anyhow), or simply too inept (a very common thing). There is a possible good side to it though, that it makes everyone, not just a few lone souls, much more conscious about privacy and rampant personal data collection, perhaps enough for a sea change in habits in the corporate and consumer worlds.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#818
post #131

Earlier quoted context omitted.

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they pur…

ATT has a rich history of being a technology company. They invented UNIX! That's in the past, fair enough. So they used to develop cutting edge technology, they sell technology, they buy technology, they operate technology, they work with manufacturers to develop new technology, they operate the infrastructure underpinning the modern technology economy, but they aren't a technology company? Even if you want to argue…

The company called AT&T now and the company called AT&T that invented Unix have really nothing in common but a thin stretch of history by now. The technology development units of AT&T were split off into Lucent a long time ago.

Calling AT&T a tech company because they operate technological infrastructure is like calling Spirit Airlines an aerospace technology company because they operate jet airplanes.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#819
post #215
post #131

Earlier quoted context omitted.

AT&T and phone carriers in general are not technology companies. They are infrastructure companies that purchase off-the-shelf communication technology, slap a billing system on top, and then spend most of their time on operations (finding places to put towers, keeping the gear up and running) and marketing. The security component of communications isn't built by them, but by the equipment manufacturers that they pur…

> The security component of communications isn’t built by them Are you claiming AT&T outsourced security and have contracts to back that up? Buying security equipment surely doesn’t amount to having security, that would be hilariously naïve. Equipment manufactures are not responsible for AT&T’s data security, AT&T is. There are laws around security that can hold AT&T liable, in the US and Europe and elsewhere. Whethe…

I claim that these companies do not have a particularly high amount of in-house infosec know-how and outsource a lot of it, not necessarily just in terms of buying equipment, but also the service component of how to set up business practices in a secure way. It doesn't absolve them of their failures but I'm no less surprised in AT&T failing to protect data than I would be McDonald's.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#820
post #736
post #578

Earlier quoted context omitted.

> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the dev…

I understand that isn’t what’s being suggested. What I’m suggesting is that there is perhaps a distortion of the common idea of who is “responsible” for something. I think the idea that fault bubbles up to the highest level in the chain of command is silly. Fault is distributed across the entire chain, and if we want to address this issue, we can’t ignore that. To draw an analogy, if someone’s 16-year-old child is te…

I agree with your view completely. There is nuance, and there should often be blame at multiple levels. At the same time, there is a basis for the common view, which is that higher ups create the incentive structures from which most things flow. If it turns out the incentives here were well made by the brass, I'd retract my jumped-to conclusion. But it rarely turns out that way, which is why I jumped to it.
Post reply on HN