Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

841–850 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#841

Earlier quoted context omitted.

That’s the AT&T Long Lines Building. It probably did have an NSA surveillance closet, but it wasn’t built without windows for that reason. The story I was told (by older colleagues when I worked at AT&T Labs) was that it was built during a time when riots and street violence were more common, so the fortress appearance was to ensure the city could maintain long-distance connectivity during urban unrest. I believe the…

Perhaps, but the other version would explain the "nuclear-war-proof" thing. I am sure the employees were told SOME kind of legend, because that building begs questions.

There was a lot of nuclear war planning around those from the 50s through the 80s.

There's some good sites out there that go into detail like http://coldwar-c4i.net/

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#842

Earlier quoted context omitted.

You obviously did not follow the recent drama in the EU related to Chat Control V2. The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has. You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU. It even had a da…

I was talking about the GDPR, not EU regulations in general.

At first I read this as GDR

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#843

Earlier quoted context omitted.

That’s the AT&T Long Lines Building. It probably did have an NSA surveillance closet, but it wasn’t built without windows for that reason. The story I was told (by older colleagues when I worked at AT&T Labs) was that it was built during a time when riots and street violence were more common, so the fortress appearance was to ensure the city could maintain long-distance connectivity during urban unrest. I believe the…

It’s built to withstand a nuclear blast. There’s buildings like this all over the country (though not in skyscraper format).

[deleted]

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#844

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

Americans like to complain about the GDPR, but it exists to prevent exactly this sort of thing. Data cannot be retained longer than it's actually needed or required by law, and can't be sold without explicit permission. Law enforcement can't just buy data: they need to have legal authority to get it (though in many countries the bar for that is too low). In most cases the cheapest and easiest approach is to collect a…

Let's not pretend that the GDPR fixes this in any way. There are still EU data retention laws in place which force ISPs/carriers/... to store all kinds of data for a reasonably long time.

I don't know who Europe's biggest telco is, but if they got breached, the damage would be just as bad.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#845

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Who is ultimately responsible, though when data is stolen in this fashion? The analyst who ETL'd this to Snowflake without MFA enabled? Or maybe the employee who inadvertently installed a data sniffer that captured usernames and passwords? Really want to send your coworkers to jail for falling for a phishing attack?

If you want corporate-death-sentence level fines, are you willing to work in environment with exceedingly strict regulatory oversight? Will you work from an office where the computing infrastructure is strictly controlled? Where you can't bring personal devices to work? Where you have no privileges to alter your work station without a formal security review?

Why not advocate for more resources to capture and try the actual criminals? Or, as elsewhere in this thread, simply make this kind of data collection illegal?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#846

Earlier quoted context omitted.

It surprises me that there isn't a single comment pointing out that corporations like AT&T don't collect all that data for fun. This actually costs them a lot of money, but they're legally required by the government. While everyone is blaming the company, did you not take a second and contemplate how weird it is that you're fine with the government (and now everyone else es well) getting a record of all your phone ac…

Banks are required to maintain financial transaction records. Is the argument that governments don't have a good reason to mandate record collection? Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?

Many (all?) banks keep financial transaction records for way longer than what is legally required. Thankfully, most banks are technically incompetent and are unable to easily use data that is not relatively recent. In fact, one bank I worked for had to load transactions from a CD-ROM archive which contained all the transactions in a printable text format (the same format as their printed bank statements). Multiple CDs per day, with no indexing or identification beyond the date. Trying to find a specific 10 year old transaction was very hard work indeed.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#847
post #845

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Who is ultimately responsible, though when data is stolen in this fashion? The analyst who ETL'd this to Snowflake without MFA enabled? Or maybe the employee who inadvertently installed a data sniffer that captured usernames and passwords? Really want to send your coworkers to jail for falling for a phishing attack? If you want corporate-death-sentence level fines, are you willing to work in environment with exceedin…

If the data collection becomes illegal, what's the penalty for breaking that law? We're back to figuring out an appropriate punishment.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#848
post #635
post #578

Earlier quoted context omitted.

> The people “whose negligence made this possible” are probably just rank-and-file employees. Careful what you wish for. I know I sure wouldn’t want to be legally liable if my software were vulnerable to something I didn’t know about. This isn't what's being suggested. Higher ups set the incentive structures that result in dwindling security resources. If their ass is on the line, they will actually listen to the dev…

> Higher ups set the incentive structures that result in dwindling security resources. What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time. I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect. > If their ass is on the line, they will actually listen to the developers an…

> I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect.

Because that’s what happens 90%. Of the time.

In most cases I’ve seen, there are zero people on the team who could describe themselves as having any kind of expertise in security. Developers explicitly know about at least several vulnerabilities, but management doesn’t care to allocate resources to fix them, etc. that’s what’s happening in most shops.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#849
post #651

Earlier quoted context omitted.

Yeah, security checkboxes don't necessarily result in good security. One option is to still make companies liable for security breaches, regardless of what meaningless checkboxes they may have checked, and then trust that they'll figure it out. Real liability would shift things from theater to weighing actual risks and costs. Another option is we can empower red teams (security researchers) to test the security of al…

I'm saying that's the same thing. It's probably worse, actually, because imagine yourself at the head of a company the size of AT&T. What would you do -- what could you do? -- that would ensure that some random employee would never do something that makes you vulnerable to attack? How terrified would you be? It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but wor…

> Making companies "liable" for breaches is tantamount to saying that companies will never develop software again, because the risk is simply too great.

Making humans liable for car crashes is tantamount to saying that humans will never drive again, because the risk is simply too great.

Replace with any complex activity - nuclear reactor development, aircraft, etc.

How is it that in your head data breaches are this special human activity where Boone should ever be held accountable?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#850
post #657

Earlier quoted context omitted.

If a company the size of AT&T finds themselves unable to move or do anything without creating security vulnerabilities, then it's time for the company to stagnate and go out of business, leaving fertile ground for more competent companies to replace them. It would be kind of nice if companies would say "we've grown to our level of competence, we cannot safely do more, so we will keep doing the same, no more, no less,…

Yeah, that's some nice rhetoric, but...I guarantee that, right now, some part of your personal software stack has a security vulnerability. If you write software for a living, some piece of software you maintain has a critical vulnerability. Do you want to be held personally responsible when they're breached? If your wireless access point is hacked because you waited too long to update it, and it is used to launch Do…

> If your wireless access point is hacked because you waited too long to update it, and it is used to launch DoS attacks, do you want to be liable? Do you want to be held personally responsible when you click on the just-good-enough phishing attack in your corporate inbox?

This is a strawman, corporations are suppose to have a process in place to make sure stuff is up to date. You don’t jail like a random rank and file guy for a huge breach.

Post reply on HN