Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

851–860 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#851
post #845

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Who is ultimately responsible, though when data is stolen in this fashion? The analyst who ETL'd this to Snowflake without MFA enabled? Or maybe the employee who inadvertently installed a data sniffer that captured usernames and passwords? Really want to send your coworkers to jail for falling for a phishing attack? If you want corporate-death-sentence level fines, are you willing to work in environment with exceedin…

> If you want corporate-death-sentence level fines, are you willing to work in environment with exceedingly strict regulatory oversight? Will you work from an office where the computing infrastructure is strictly controlled? Where you can't bring personal devices to work? Where you have no privileges to alter your work station without a formal security review?

If it means that privacy and safety is actually respected then yes. Working in an environment with "exceedingly strict" regulatory oversight would be a reassurance that observed violations will be dealt with in a timely fashion instead of put in the backlog and never addressed.

> Why not advocate for more resources to capture and try the actual criminals?

Yes, why not? While we're at it, let's try and capture the easily-spotted criminals who perform the most trivial of attacks to servers. Just open up your SSH server logs and start going after and preventing the fecktons of log spam that hide real attacks.

> Or, as elsewhere in this thread, simply make this kind of data collection illegal?

Making something illegal is great! Unfortunately it doesn't really do anything to help people after it's been stolen a second time (first time was by AT&T if it were illegal).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#853

Earlier quoted context omitted.

110M people impacted = class action The lawyers work on contingency

Imagine the GDPR fine

Up to 4% of income. This is not the end of the world either.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#854

Earlier quoted context omitted.

in this case it’s pretty tough because the phone company does need this metadata just to bill people. so they should protect it properly.

I don't see a reason as to recording who contacted who. If it's for billing, just record duration, if they're not an 'unlimited' customer and flags on whether it'd incur extra charges (i.e roaming, international call)

This is the kind of information that the end user may want.

OTOH this could be an opt in decision with a warning on the consequences

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#855

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

The correct way is to follow what all other engineering and trade (medicine/law) already follow. Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are f…

If you're going to do that, you're going to need to get universities to treat computers as an actual applied discipline. Physical engineers at least get some practice working with numbers around real materials.

I've met too many recent university graduates that don't even know you need to sanitize database inputs. Which, not their fault, but the university system as it currently exists in relation to software is not set up do do the thing you're asking.

The alternative is to have a really long exam (or a series of them like actuaries do?). Here are 10 random architectures. Describe the security flaws of each and what you would change to mitigate them.

The other change that needs to be made, is that engineers need to be able to describe the bounds of their software. This happens in the other engineering disciplines. A civil engineer can design a bridge with weight capacity X, maybe a pedestrian bridge. If someone builds it and drives semi-trucks over it, that's kinda their problem (and liability).

We would need some sort of way to say "this code is rated for use on an internal network or local only" and, given that rating, hooking it up to the open internet would be legally hazardous.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#856
post #689

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

Nothing happened to Experian, and those clowns have beaches every year. The USA has so far proved that we don't care about privacy and don't believe data is real.

> don't believe data is real.

Oh but they do, try taking some data that belongs to a corporation and see how quickly law enforcement responds. Aaron Swartz found out the hard way

It’s only when you steal personal data that nobody cares.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#857

AT&T has 110 million customers. Let's be optimistic and assume that each customer only has to spend one minute of extra time managing their account due to the break-in. That is more than 209 years of lost time. Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the c…

If you're going to start holding companies accountable for wasting people's time then AT&T has a lot more to answer for than this one little event.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#858
post #831

Earlier quoted context omitted.

The regular Joe doesn't really care to be honest. I have talked about it around me a bit and most people who do not work in tech or who don't have a certain interest in online privacy or privacy in general don't know about it. Of course when you ask the citizens of the EU if they are cool about being monitored at all times by the EU LEOs then they don't want it but the commission wants it bad. All this is due from th…

CP is just a pretext to keep records on everyone. Good thing everyone over 40 in Eastern Europe still remembers the Stasi and its sister secret police agencies that collected data on everyone and tortured political prisoners. I suspect that climate activists are the next likely candidates for an eventual repression apparatus, so better beware.

Portugal and Spain also aren't found of their politicians from 50 years ago (their regimes fell in 1974, and 1975, respectively). To add to your point.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#859

Earlier quoted context omitted.

If bankruptcy can clear liabilities then your suggestion won't help. The shareholders are usually gone by the time the bill comes due: it's often cheaper to go bankrupt. And there's a whole private equity industry revolving around taking dirty liabilities and slowly bankrupting a company to squeeze the last dollar out before shutting down. Look at the same problem with environmental disasters that were created by cor…

You don't need to try to seek value from the shareholders in a bankruptcy to hurt them. (Doing so would be going against rule of law and as for changing the law, well do you hear that giant sucking sound of funds fleeing your economy?) Just having their holding's value go to zero is sufficient.

Maybe irrelevant for security flaws, but the point is that externalities can easily exceed market capitalisation. Trading while insolvent is illegal, but that is hard to judge with liabilities. Examples are Johnson&Johnson (public) and Purdue Pharma (private).

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#860
post #610

Earlier quoted context omitted.

You want a P.Eng (or equivalent) to sign off on anything that involves data? That won’t solve the problem but will dramatically slow down the pace of innovation. And all the while, it will funnel money further into regulated professions instead of into actually securing software. This is precisely how we end up in a world where we’re all running twenty five year old software.

> This is precisely how we end up in a world where we’re all running twenty five year old software. Linux?

Are you claiming that Linus Torvalds is a P.Eng (or equivalent)? He doesn’t so that’s a very poor comment. As for Linux, it has changed constantly over those 25 years so that’s not a coherent argument either.
Post reply on HN