Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

831–840 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#831

Earlier quoted context omitted.

> You obviously did not follow the recent drama in the EU related to Chat Control V2. It is strange to say they wanted it when we have proof it is voted down and widely unsupported. A part of the EU government apparatus wants it, but taking that and saying the EU wants it is not honest.

The regular Joe doesn't really care to be honest. I have talked about it around me a bit and most people who do not work in tech or who don't have a certain interest in online privacy or privacy in general don't know about it. Of course when you ask the citizens of the EU if they are cool about being monitored at all times by the EU LEOs then they don't want it but the commission wants it bad. All this is due from th…

CP is just a pretext to keep records on everyone. Good thing everyone over 40 in Eastern Europe still remembers the Stasi and its sister secret police agencies that collected data on everyone and tortured political prisoners. I suspect that climate activists are the next likely candidates for an eventual repression apparatus, so better beware.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#832

Earlier quoted context omitted.

"but the cookie banners look so bad and ugly!" Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.

Also cookie banners are from the e-privacy directive, not the GDPR.

I'm positive informed consent doesn't require cookie banners, but the advertisers opted to make it as annoying as possible so that everyone would click "accept" just to be left alone. It could be a browser mechanism that only asks once for all sites and have a whitelist.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#833
post #523
post #469

Earlier quoted context omitted.

> Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences. I really dislike this att…

No, the root-cause is not AT&T were "attacked, by criminals"; there's a much wider issue involving Snowflake and multiple customers. The full facts are not in yet. AT&T's data was compromised as one of Snowflake's many customer breaches (Ticketmaster/LiveNation, LendingTree, Advance Auto Parts, Santander Bank, AT&T, probably others [0][1]), which occurred and were notified in 4/2024 (EDIT: some reports says as far ba…

> Supposedly these happened because Snowflake made it impossible to mandate MFA

What's crazy is that Snowflake made MFA enforcement available only 5 days ago.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#834

Reading the articles about this breach and the nature of the data in this Snowflake lake, I personally wouldn’t consider this breach a “leak” from the customer perspective - to me the leak is upstream of this breach. Given the nature of the data in the database and the platform it was stored in, it seems extremely likely this data was not meant to be used internally by AT&T but was instead meant to be used externally…

I wonder how many times Snowflake has openly transmitted CP from ATT customers because they are too hungry to ingest and sell data rather than verify it.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#835

Earlier quoted context omitted.

Being required to do something doesn't justify doing it poorly. AT&T brought in over $3 billion with a B of profit with a P in Q1 2024. They have more than enough money to secure their systems. They're not struggling. In March of this year they bought back 157M of their stock. They could have instead put that money towards security, but they didn't: they put it towards enriching shareholders.

It was snowflake’s lack of security that did this not ATT. Not saying ATT is a paragon of security or anything but snowflake was where the hack took place.

Part of the job of the contractor is taking responsibility with who they take security from. To take it to the logical extreme if 'some rando they met in a bar' offered to store AT&T's credit card information for cheap and it turns out said rando was stealing credit card information? Totally AT&Ts fault for not properly vetting them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#836
post #678

Earlier quoted context omitted.

Government has no right to track that either, they themselves launder trillions, start wars and massacre millions, even a drug lord is a petty criminal compared to them, and it's clear their tracking of any and all records of any type is more about control than safety, thus it should be disregarded as an argument and be done away with entirely.

> they themselves launder trillions, start wars and massacre millions, even a drug lord is a petty criminal compared to them And then people wonder why privacy has a difficult time getting public support.

No, we already know it is because people are complete idiots who not only fall for 'tiger repelling rocks' but actively demand them.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#837

Earlier quoted context omitted.

Perhaps, but the other version would explain the "nuclear-war-proof" thing. I am sure the employees were told SOME kind of legend, because that building begs questions.

A tall above-ground building with no windows doesn’t seem like a good candidate to survive a nuclear blast.

Long lines buildings were not going to take a direct nuclear hit, but were very robust to handle shockwaves and EMP.

I came very close to buying a long lines microwave relay site, and got to tour it a few times. It had a hardened tower, as well as copper grounding that went deep into the ground. Mining the copper would have paid for the site, but alas.

These buildings were built based on the 1950s threat of Soviet bombers attacking the United States. The New York City metro area was protected by air defense missile sites and interceptors. The air defense systems would air burst small nukes in wartime to destroy bomber formations.

Once the threat shifted to ICBMs in the 1970s hardening was moot.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#838

Earlier quoted context omitted.

Hurting the shareholder is the only option to actually fix anything. Until the C-suite and board are forced to face the music caused by rich people being parted from their money, they'll just continue patting themselves on the back and giving themselves bonuses.

If bankruptcy can clear liabilities then your suggestion won't help. The shareholders are usually gone by the time the bill comes due: it's often cheaper to go bankrupt. And there's a whole private equity industry revolving around taking dirty liabilities and slowly bankrupting a company to squeeze the last dollar out before shutting down. Look at the same problem with environmental disasters that were created by cor…

You don't need to try to seek value from the shareholders in a bankruptcy to hurt them. (Doing so would be going against rule of law and as for changing the law, well do you hear that giant sucking sound of funds fleeing your economy?) Just having their holding's value go to zero is sufficient.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#839

Earlier quoted context omitted.

Hurting the shareholder is the only option to actually fix anything. Until the C-suite and board are forced to face the music caused by rich people being parted from their money, they'll just continue patting themselves on the back and giving themselves bonuses.

I agree. Shareholders can vote and decide the direction of a company. They should also be held liable for any problems the company causes. If the company is fined it should come out of company and then shareholder pockets. I might even add courts should be able to award damages by directly fining share holders. If a company does something severely illegal then very large shareholders should risk jail time. It’s your…

Under that twisted logic Israel would be perfectly justified with nuking Palestine. They voted for terrorists, therefore they should be liable for everything their country caused.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#840
post #756

Earlier quoted context omitted.

Penalties would also incentivise businesses to hide data breaches.

So you make it a crime to hide the existence of a data breach for more than X amount of time for the purpose of figuring out exactly what happened. I don't know off the top of my head how long X should be. 30 days? 60?

Sounds like a recipe for willful ignorance. Why put any effort into checking for data breaches if it would only hurt you?
Post reply on HN