Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

821–830 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#821
post #549

Earlier quoted context omitted.

The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing.…

This reminds me of the story where someone accidentally deletes the database and there are no backups. Who's at fault? The individual IT employee who made a mistake, or the entire organization (especially leaders) who created a situation where one person could delete the database and there are no backups?

You can safely assume that every company or org which fell to ransomware campaigns didn't have proper backups. Because such a restore wouldn't be in the news as serious outage.

The percentage of no backups seem to be crazy. I only read about the Central bank of Sambia being able to restore from backups, everyone else was down. All these responsible should be fired.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#822

Earlier quoted context omitted.

this is already an established principle in other engineering fields. If a civil engineer screws up and a building collapses, both that engineer and the engineering firm are liable. Why should the software industry be any different?

because software developers aren't engineers? -- elephant in the room.

Some call themselves Hackers, they love to bypass processes.

And some call themselves code monkeys, they know how to follow orders, but have no incentives at all to think by themselves for proper security.

Only a tiny fraction call themselves engineers.

I favor non-licensed free professions, but if you're free you should be able to follow best practices and be able to think for yourself.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#823
post #708

Earlier quoted context omitted.

Enriching shareholders is exactly what they are required to do. What, nobody is allowed to make money anymore?

No, they shouldn't be allowed to fuck over their customers at ever turn so they can be greedy. The suggestion that we should be more worried about how much money the AT&T execs and shareholders make over their needs of their 100 million customers is bizarre.

Those are not mutually exclusive.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#824
post #667

Earlier quoted context omitted.

The government isn’t distributing my data to everyone else (so far). For profit companies have a pretty massive list of breaches so far.

You are forced to give your personal data to government. You don't have to give your data to any company. That's huge difference.

Only if you cut all ties with civil society and live solitary.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#825

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

You are more likely striken by lightning than coming in contact with terrorism whatsoever

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#826

Earlier quoted context omitted.

That’s the AT&T Long Lines Building. It probably did have an NSA surveillance closet, but it wasn’t built without windows for that reason. The story I was told (by older colleagues when I worked at AT&T Labs) was that it was built during a time when riots and street violence were more common, so the fortress appearance was to ensure the city could maintain long-distance connectivity during urban unrest. I believe the…

Perhaps, but the other version would explain the "nuclear-war-proof" thing. I am sure the employees were told SOME kind of legend, because that building begs questions.

A tall above-ground building with no windows doesn’t seem like a good candidate to survive a nuclear blast.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#827

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

That’s was Bush not Obama

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#829

Earlier quoted context omitted.

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

> You obviously did not follow the recent drama in the EU related to Chat Control V2. It is strange to say they wanted it when we have proof it is voted down and widely unsupported. A part of the EU government apparatus wants it, but taking that and saying the EU wants it is not honest.

The fact that it had to be voted in the first place, and then represented again within six months is the problem.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#830

Earlier quoted context omitted.

Perhaps, but the other version would explain the "nuclear-war-proof" thing. I am sure the employees were told SOME kind of legend, because that building begs questions.

A tall above-ground building with no windows doesn’t seem like a good candidate to survive a nuclear blast.

Yup, an underground structure would normally be a better design. But that would quickly get flooded with water in Manhattan in the event of a nuclear blast followed by loss of power.
Post reply on HN