Live data from Hacker News

AT&T says criminals stole phone records of 'nearly all' customers in data breach

techcrunch.com

861–870 of 874 posts

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#861

Earlier quoted context omitted.

"but the cookie banners look so bad and ugly!" Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.

> way too many website owners rather torture their users including official EU websites

Which usually have an

[ACCEPT] [REJECT]

without any dark patterns whatsoever.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#862
Why don't organizations hide their servers behind data diodes? Store everything in an air gapped network with strictly defined interfaces.

I've been wondering this since the Office of Personnel breach[1] back in 2015.

[1] https://en.m.wikipedia.org/wiki/Office_of_Personnel_Manageme...

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#863
post #707
post #702

Earlier quoted context omitted.

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

Ah, back in the day the FBI would pay our CTO $5000/hr to talk to and work with him. On top of that we would charge them a monthly colo fee for their equipment that collected data of customers. Sometimes they had warrants, but mostly just bought the data. A year or so after 9/11 and that relationship lasted years.

Welcome to the US - claimed "praiser" of freedom, but with no respect for privacy. Even the EU is better at maintaining privacy than the US.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#864

Earlier quoted context omitted.

Retention periods seem like a moot point if the government just slurps every piece of data anyway and stores it indefinitely

Not everyone in law enforcement gets to play with the NSA's toys though. Some actually have their warrant and subpoenas glanced at by a judge before it gets rubber stamped.

While being briefly "glanced at" by a judge is certainly better than nothing (or just already having the data like NSA), practically it just means law enforcement needs to adapt some generic boilerplate justification text to each request.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#865
post #222

Earlier quoted context omitted.

This already exists. Withdraw from account to physical cash. Proceed to stash cash in “secret” location. Most businesses don’t even accept cash anymore. Can’t get “hacked” although it’s prone to many other issues — space, humidity, physical theft.

> Most businesses don’t even accept cash anymore. Really? I've been using cash almost exclusively for the past several months and haven't had any real problems. Sure, the overpriced hipster vegan Thai place in the McMall district may not take cash, but the family-owned ramen restaurant a couple miles down the road is more than happy to do so. Personally I find the "won't take cash" attribute to be a strong indicator…

I've encountered nearly no businesses that don't accept cash and I pay with cash all the time. The lower-income end of the working class makes up a huge percentage of our economy, and it's an extremely cash-centric demographic. But even then, I've got a friend who sells fine handmade jewelry and some folks came in and bought like a 30k piece from her in cash because they owned a cash-only business. I can't imagine anyone existing outside of a ultra-gentrified corporate enclave that would encounter nearly any businesses that don't accept cash, let alone most. Maybe they just never see anyone use cash because they're not in a socioeconomic segment where it's still the standard?

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#866
post #76

Earlier quoted context omitted.

Eh, iirc the source of the hack was just regular stealers like Redline, not "the dark web". It was actually Snowflakes fault. The threat actors were able to find a test/demo account they could log into and from there they were able to access prod things they shouldnt have.

This is exactly the kind of comment I'm talking about. You have not read anything from snowflake, mandiant or crowdstrike on this, and you haven't even read the cnn article that has snowflakes response on this. The snowflake demo account has nothing to do with it.

No, its what happened 100%. Funnily enough, its YOU who hasnt read anything.

https://cloud.google.com/blog/topics/threat-intelligence/unc...

"In April 2024, Mandiant received threat intelligence on database records that were subsequently determined to have originated from a victim’s Snowflake instance. Mandiant notified the victim, who then engaged Mandiant to investigate suspected data theft involving their Snowflake instance. During this investigation, Mandiant determined that the organization’s Snowflake instance had been compromised by a threat actor using credentials previously stolen via infostealer malware. The threat actor used these stolen credentials to access the customer’s Snowflake instance and ultimately exfiltrate valuable data. At the time of the compromise, the account did not have multi-factor authentication (MFA) enabled."

https://www.symmetry-systems.com/blog/what-we-know-so-far-ab...

"Snowflake has confirmed that a threat actor obtained credentials of a single former employee and accessed demo accounts they had access to. Snowflake asserts these accounts contained no “sensitive” data and were isolated from production and corporate systems. However, unlike Snowflake’s core systems, which are protected by Okta and Multi-Factor Authentication (MFA), these dormant demo accounts lacked such safeguards. "

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#867
post #702

Earlier quoted context omitted.

There's no federal law requiring AT&T to hold onto this data. There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity

I'm no longer under this specific NDA, so, I can talk a bit about this. It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents o…

Thank you for sharing this, it is helpful context when discussing data security and privacy with regulators and federal Congressional reps.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#868
post #707

Earlier quoted context omitted.

Ah, back in the day the FBI would pay our CTO $5000/hr to talk to and work with him. On top of that we would charge them a monthly colo fee for their equipment that collected data of customers. Sometimes they had warrants, but mostly just bought the data. A year or so after 9/11 and that relationship lasted years.

Welcome to the US - claimed "praiser" of freedom, but with no respect for privacy. Even the EU is better at maintaining privacy than the US.

the EU is much more aggressive at banning and censoring websites though. I can't recall the last time I ran into a website in the US that's blocked at the provider level (private moderation like e.g. Youtube is a different story). Maybe Tiktok is the most famous, but it's still around and available afaik. But in the EU, ran into "the government has decided this information is bad for you" all the time, with a nice notice from the internet provider. My hunch is that under various pretexts both societies will continue to drift towards more censorship and less privacy, perhaps with some temporary local differences.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#869

Earlier quoted context omitted.

Welcome to the US - claimed "praiser" of freedom, but with no respect for privacy. Even the EU is better at maintaining privacy than the US.

the EU is much more aggressive at banning and censoring websites though. I can't recall the last time I ran into a website in the US that's blocked at the provider level (private moderation like e.g. Youtube is a different story). Maybe Tiktok is the most famous, but it's still around and available afaik. But in the EU, ran into "the government has decided this information is bad for you" all the time, with a nice no…

I've never encountered anything like that while over here.

Re: AT&T says criminals stole phone records of 'nearly all' customers in data breach

#870

Earlier quoted context omitted.

It was snowflake’s lack of security that did this not ATT. Not saying ATT is a paragon of security or anything but snowflake was where the hack took place.

What do you know about Snowflake's role in this? According to the article, Snowflake says that they offered 2FA and AT&T didn't use it. Perhaps that's not the whole story, but if true then blame certainly lies with AT&T to a significant degree.

It’s mostly AT&Ts fault but it’s sort of a side effect of Snowflake making their product easy to use and most of the industry overlooking credential reuse risks.

Databases are not historically internet facing so data compromise also meant getting network access. But Snowflake provided web access to your database so they were “easy to use” database as a service (“cloud data warehouse”). Snowflake did not offer you a way to host data within your network or within your dedicated subnets within a cloud provider, so companies could not solely rely on those networking barriers to limit malicious counterparties.

Snowflake has apparently begun requiring MFA for new accounts since this incident I’ve heard. If shutting the gate after the horses have left implies culpability, Snowflake has some.

Post reply on HN