[HN Gopher] AT&T says criminals stole phone records of 'nearly a...
       ___________________________________________________________________
        
       AT&T says criminals stole phone records of 'nearly all' customers
       in data breach
        
       Author : impish9208
       Score  : 480 points
       Date   : 2024-07-12 11:17 UTC (11 hours ago)
        
 (HTM) web link (techcrunch.com)
 (TXT) w3m dump (techcrunch.com)
        
       | smcin wrote:
       | This is huge; also AT&T knew on Apr 19 but only disclosed now;
       | ongoing fallout from the Snowflake compromise:
       | 
       | - Records downloaded from Snowflake cloud platform
       | 
       | - "AT&T will notify 110 million AT&T customers"
       | 
       | - Compromised data includes customer phone numbers ("for 77m
       | customers"), metadata (but not actual content or timestamp of
       | calls and messages), and location-related data. Not SSNs or DOBs.
       | Mostly during a six-month period 5/1-10/31/2022, but more recent
       | records from 1/2/2023 for a smaller but unspecified number of
       | customers. TechCrunch [1] has more details including Mandiant's
       | response, the name and suspects location of the cybercriminal
       | group
       | 
       | [1]: https://techcrunch.com/2024/07/12/att-phone-records-
       | stolen-d...
       | 
       | I wonder if Congress manages to summon TikTok-like levels of
       | anger on regulating this one.
        
       | John23832 wrote:
       | And, honestly, how is this info (which I WOULD want to know)
       | meaningfully actionable to customers. We get our information
       | stolen from a myriad of sources everyday. These companies do
       | comparatively nothing to make things right and the burden falls
       | on customers to pick up the pieces if you're in a tranch that is
       | sold and used.
        
         | smcin wrote:
         | Of course it's not meaningfully actionable to customers, big
         | time lag in not disclosing since Apr 19. (Why does this not
         | fall under SOX violation with the obligation to report timely
         | to affected parties? It has affected AT&T's stock price -3% in
         | early trading, so should it have also required SEC disclosure?)
         | 
         | Wondering what is the significance that most of the stolen
         | records were from the period 5/1-10/31/2022? Does it mean that
         | AT&T enabled 2FA on more recent records, or that more recent
         | records were on a different cloud bucket (or that they mostly
         | stopped using Snowflake since)?
        
       | lumb63 wrote:
       | This is another consequence of the surveillance state. The same
       | data that can be used to surveil us by the government can be
       | stolen by who-knows-who. We'd all (mostly) be far better off,
       | IMO, if companies didn't retain such records.
        
         | Jgrubb wrote:
         | Yes but have you ever asked a dev if they actually need the 8
         | year old logs in some bucket?
        
         | rustcleaner wrote:
         | My wet dream would be a dump of all SMS or Meta or iMessage
         | messages for a multiyear period for nearly 90% of users. Only
         | when Normie Norman's private chats to his mistress and other
         | little relationship trust disrupting secrets become
         | uncensorably hosted on the darknet and freely searchable, only
         | then will Normie Norman get a clue and install
         | SimpleX/Briar/Cwtch/any other owner-free decentralized p2p
         | chat.
        
           | dtx1 wrote:
           | While I share the sentiment, Normie Norman is not at fault.
           | Meta and other BigCorps are the perpetrators and Norman the
           | Victim.
        
             | rustcleaner wrote:
             | True, but you have to admit once you really see Normie
             | Norman you come to understand aristocracy.
             | 
             | At least I do anyway.
        
               | shrimp_emoji wrote:
               | https://dwm.suckless.org/
               | 
               | > _Because dwm is customized through editing its source
               | code, it 's pointless to make binary packages of it. This
               | keeps its userbase small and elitist._
        
               | rustcleaner wrote:
               | Not in the way of a narcissist trying to separate himself
               | from the group, but to see that Norman is very much
               | susceptible to cow-like behaviors you can leverage.
               | That's what I mean by understanding aristocracy.
               | Aristocrat : Rancher.
        
             | robcohen wrote:
             | I have to disagree. He is a fault. Ultimately, you are the
             | only person who really should care about your own security.
             | When you delegate that responsibility, you are still the
             | one who made that choice.
        
               | doublepg23 wrote:
               | I don't think it's fair to blame people for not
               | understanding the subtleties of encrypted communication.
               | 
               | Everyone only has so much attention to give.
        
               | tsujamin wrote:
               | Having a mobile phone is necessary to securing
               | employment, shelter and sustenance in many cases, yet
               | somehow it's an individuals fault for choosing to have a
               | phone account when a pair of multibillion dollar
               | companies breach that data through lax security
               | practices?
        
           | LinuxBender wrote:
           | Not unrealistic. I used to have a tail of all SMS texts
           | running 24/7 and was required to grep for specific terms for
           | certain agencies until they eventually had their own access.
           | This was only SS7 based texts and was long before RCS
           | existed. I could have saved it all to my workstation but knew
           | better than to do that. Either way SS7 and text messages are
           | very insecure.
        
       | buro9 wrote:
       | Including all location metadata associated to that?
        
         | smcin wrote:
         | The reports said celltower-level location data associated with
         | calls and texts (but not datestamps). That would allow
         | inferring their homes, job location, commute, family members,
         | social graph.
        
           | sitkack wrote:
           | You can still recover that without timestamps. It also looks
           | like if anyone interacted with an ATT customer or used an
           | MVNO your data is in there too.
        
             | dylan604 wrote:
             | It even said land lines had their numbers in the data if an
             | ATT customer contacted one.
             | 
             | Edit: I must have read that from a different article than
             | the TFA though.
        
               | sitkack wrote:
               | Yeah, all att customers, 2nd party participants and any
               | other user of their network. Not just direct customers.
        
       | akshayB wrote:
       | The real problem is that data needs to be deleted over time.
       | There is not much of a use case for customers for go back last
       | year and see who called them and obviously there are use cases
       | like criminal investigations or spying. But customer has no power
       | or ability to dictate how long their records are store and how
       | they are used. Companies should provide tools and features to
       | their customers empowering them with their data.
        
         | tantalor wrote:
         | This isn't data for serving user needs, this is data for spying
         | on users
        
         | mountainb wrote:
         | Non-murder criminal offenses typically have very short statutes
         | of limitations.
         | 
         | A lot of this could also be solved by encouraging the federal
         | government to enforce federal privacy law as written more
         | aggressively. A good incentive would be to amend the privacy
         | statutes to permit the FTC to keep the funds extracted from
         | settlements and penalties in-house. This would allow them to
         | increase staffing and create a positive feedback loop to deter
         | wrongdoing. This would have a negative effect on incumbent
         | companies and practices, but it would not take long for the
         | message to get across and for practices to change accordingly.
         | 
         | Congress tends to prefer keeping agencies on its own budgetary
         | string which paradoxically limits what the agencies are capable
         | of doing. The laws that we think protect us do not protect us
         | because many of them are within the exclusive jurisdiction of a
         | federal agency with very limited powers and funds. In the US
         | the leadership likes to create the illusion that it has made
         | "Bad Problem" illegal by writing it into the law, but it does
         | not like creating the conditions in which "Bad Problem" could
         | be solved, whether it's because the tradeoffs involved are
         | tough to contemplate or because keeping "Bad Problem" around as
         | a visible enemy is clever politics.
        
           | _heimdall wrote:
           | > Non-murder criminal offenses typically have very short
           | statutes of limitations.
           | 
           | There's a hidden assumption here. The expectation is that
           | data retention and potential privacy violations are a
           | necessary evil because anyone may later be under
           | investigation for a crime. The data could go uncollected, it
           | isn't AT&Ts job to retain private information on all of us
           | just in case an investigator wants it.
           | 
           | Take telecoms out of it and consider a convenience store.
           | Police would like to have video recordings of whatever moment
           | in time they are investigating, but that doesn't mean the
           | video has to be recorded and retained. A shop owner can
           | choose to record videos and only retain them for a week if
           | they want, or they can have cameras installed but not even
           | recording if they're okay with just the effect of deterrence.
        
             | mountainb wrote:
             | Many civil claims have short statutes of limitation as
             | well. It's not really that good for these companies to
             | maintain regular business records going back to infinity
             | that are subject to discovery in disputes that are not even
             | related to anything the telecom company did. Complying with
             | the discovery requests and subpoenas is expensive. The
             | fetish for the somewhat imagined benefits of big data
             | creates open-ended liabilities for these companies. But the
             | pressure that law enforcement and the spy agencies put on
             | the telecom companies to facilitate this has been an open
             | secret for a long time now.
             | 
             | A lot of this is on the federal government and Congress for
             | leaving an area in which it has power dormant and within
             | its relatively exclusive control. Thanks for the
             | conversation.
        
           | willmadden wrote:
           | That's another bandaid. The root cause is customer data
           | collection mandated by outdated regulation. People should be
           | able to digitally sign or provide a public key for their
           | personal information without providing the raw text to 3rd
           | parties. Various 1970's style government tax and regulatory
           | rules need to be updated as well.
        
         | softfalcon wrote:
         | They have a financial incentive to never delete your data.
         | Storing old data forever creates a perfect paper trail to sell
         | to advertisers and perfect the shadow profile they keep on all
         | of us.
         | 
         | I agree that deleting all your data after a year makes sense
         | practically, but they'll never do it because it makes them too
         | much money to keep it around.
        
       | smcin wrote:
       | Ongoing fallout from the Snowflake compromise; AT&T knew on Apr
       | 19 but only disclosed now (Why does this not fall under SOX
       | violation with the obligation to report timely to affected
       | parties? It has affected AT&T's stock price -3% in early trading,
       | so shouldn't it have also required SEC disclosure?)
       | 
       | - Records downloaded from Snowflake cloud platform
       | 
       | - AT&T will notify 110 million AT&T customers
       | 
       | - Compromised data includes customer phone numbers, metadata (but
       | not actual content or timestamp of calls and messages), and
       | location-related data. Not SSNs or DOBs. Mostly during a six-
       | month period 5/1-10/31/2022, but more recent records from
       | 1/2/2023 for a smaller but unspecified number of customers.
       | TechCrunch report has more details including Mandiant's response,
       | the name and suspects location of the cybercriminal group
       | 
       | I wonder if Congress manages to summon TikTok-like levels of
       | anger on regulating this one.
        
         | softwaredoug wrote:
         | > Snowflake blamed the data thefts on its customers for not
         | using multi-factor authentication to secure their Snowflake
         | accounts, a security feature that the cloud data giant did not
         | enforce or require its customers to use.
         | 
         | So AT&T put all our call information somewhere and hid it
         | probably behind a weak password with no additional factors. IMO
         | that's actionable negligence and I hope they get sued to
         | oblivion.
        
           | smcin wrote:
           | I'm more stunned that AT&T knew back on Apr 19 [UPDATE: Mar
           | 20] yet feels it had neither an SOX violation or SEC
           | obligation (share price effect) to notify timely. Like, by
           | Apr 22. Not three months later [UPDATE: 4 months later].
           | 
           | Remember the massive Yahoo 2014 hack which Yahoo management
           | failed to notify its own users for 2 years?
           | 
           | If SOX violation only literally covers users' own passwords
           | getting breached, but not 2FA or other passwords to access
           | the same data, will Congress amend it urgently?
           | 
           | EDIT: apparently they're hiding behind the 3/20 disclosure
           | [0] which is all they disclosed until [1],[2] today.
           | 
           | [0]: March 30, 2024 - "AT&T Addresses Recent Data Set
           | Released on the Dark Web"
           | https://about.att.com/story/2024/addressing-data-set-
           | release...
           | 
           | > _" AT&T has determined that AT&T data-specific fields were
           | contained in a data set released on the dark web; source is
           | still being assessed...
           | 
           | > "AT&T has launched a robust investigation supported by
           | internal and external cybersecurity experts. Based on our
           | preliminary analysis, the data set appears to be from 2019 or
           | earlier [incorrect], impacting... approx 7.6m current and
           | 65.4m former AT&T account holders"*
           | 
           | > _"Currently, AT&T does not have evidence of unauthorized
           | access to its systems resulting in exfiltration of the data
           | set.... As of today, this incident has not had a material
           | impact on AT&T's operations."* [but did it have a material
           | impact on the customers/ex-customers?!]
           | 
           | [1]: Jul 12, 2024 - "AT&T Addresses Recent Incidents
           | Regarding Access to Data" https://about.att.com/pages/data-
           | incident.html
           | 
           | [2]: Jul 12, 2024 - "AT&T Addresses Illegal Download of
           | Customer Data" https://about.att.com/story/2024/addressing-
           | illegal-download...
           | 
           | > _" Based on our investigation, the compromised data
           | includes files containing AT&T records of calls and texts of
           | nearly all of customers of [AT&T's cellular and (MVNOs) using
           | AT&T's wireless network], as well as AT&T's landline
           | customers who interacted with those cellular numbers between
           | May 1, 2022 - October 31, 2022. The compromised data also
           | includes records from January 2, 2023, for a very small
           | number of customers. The records identify the telephone
           | numbers an AT&T or MVNO cellular number interacted with
           | during these periods. For a subset of records, one or more
           | cell site identification number(s) associated with the
           | interactions are also included."_
        
             | smcin wrote:
             | Subsequent reporting reveals that the DOJ ordered two
             | ~month-long "delay periods" in disclosure:
             | 
             | > _The Justice Department determined on May 9 and again on
             | June 5 that a delay in providing public disclosure was
             | warranted, so the company is now timely filing the report.
             | 
             | > The company [AT&T] is working with law enforcement and
             | believes at least one person has been apprehended,
             | according to the filing. It does not expect the event to
             | have a material impact on its financials._
             | 
             | MarketWatch: [https://www.marketwatch.com/story/at-ts-
             | stock-slides-2-9-aft...]
        
         | amanaplanacanal wrote:
         | According to CNN:
         | 
         | "The company said the US Department of Justice Department
         | determined in May and in June that a delay in public disclosure
         | was warranted. It's not clear why that the US government
         | requested that data be delayed. CNN has reached out to the
         | Justice Department for comment."
        
           | nimbius wrote:
           | May 16 Dow Jones Industrial Average surpasses 40,000 points
           | for the first time, before closing at 39,869.
           | 
           | public disclosure of a cataclysmic security breach in a
           | darling of the stock market could have significant
           | repercussions.
        
         | adamtaylor_13 wrote:
         | It definitely included SSNs for some of them.
         | 
         | Source: me. My data was included in the leak and it included my
         | SSN. It's been a cluster fuck of a cleanup.
        
           | wredue wrote:
           | My SIN number has been leaked no less than 4 times tied to
           | basically every standard identifying question about me now,
           | if that helps ease your worry.
           | 
           | I guess the new methodology is that a company cannot be sued
           | if they just all leak data, that way nobody knows which one
           | is responsible for your identity theft.
        
       | John23832 wrote:
       | How has Snowflake felt ANY recourse for being the source of all
       | of these hacks?
        
         | beardedwizard wrote:
         | The dark web and info stealing malware are the source of the
         | hacks.
         | 
         | My worry is not only that consumers get numb to breaches, but
         | they consume rampant misinformation and have no idea how to
         | hold appropriate parties accountable.
         | 
         | How many times have you held AWS accountable for stolen access
         | keys?
         | 
         | Was it AWS fault when rabbit leaked their own keys?
         | 
         | Is it snowflakes fault when you lose your creds to infostealing
         | malware?
         | 
         | How should snowflake enforce mfa on machine service account
         | credentials?
         | 
         | The answers are no, no, and they can not possibly. Not even
         | hyperscalers have this magic.
        
           | edm0nd wrote:
           | Eh, iirc the source of the hack was just regular stealers
           | like Redline, not "the dark web".
           | 
           | It was actually Snowflakes fault.
           | 
           | The threat actors were able to find a test/demo account they
           | could log into and from there they were able to access prod
           | things they shouldnt have.
        
             | beardedwizard wrote:
             | This is exactly the kind of comment I'm talking about. You
             | have not read anything from snowflake, mandiant or
             | crowdstrike on this, and you haven't even read the cnn
             | article that has snowflakes response on this. The snowflake
             | demo account has nothing to do with it.
        
         | taspeotis wrote:
         | > Snowflake blamed the data thefts on its customers for not
         | using multi-factor authentication to secure their Snowflake
         | accounts
        
         | Aaronstotle wrote:
         | its not Snowflake's fault their customers used weak passwords
         | and no MFA. Not enforcing MFA does merit some blame on
         | Snowflake, however, I still think its on the customer to secure
         | your own environment.
        
           | smcin wrote:
           | Snowflake is saying they knew of unusual activity "around
           | mid-April 2024", confirmed "May 23, 2024", around which time
           | they made MFA mandatory (although their customer AT&T say
           | they knew of the breach "Mar 20"; these timelines keep
           | shifting back):
           | 
           | "Mandatory MFA option unveiled by Snowflake" - Jul 11, 2024
           | https://www.scmagazine.com/brief/mandatory-mfa-option-
           | unveil...
           | 
           | > _" US cloud storage firm Snowflake has already required the
           | implementation of multi-factor authentication across all user
           | accounts a month following the widespread breach of customer
           | accounts, including those of Ticketmaster and Santander Bank,
           | reports The Register."_
        
             | iaabtpbtpnn wrote:
             | It's not mandatory, I still have Snowflake user accounts
             | that don't use MFA.
        
           | mewpmewp2 wrote:
           | It's industry standard to enforce MFA for customers of such
           | sensitive data though. There's always going to be weak links.
        
           | chefandy wrote:
           | Right. Snowflake facilitated AT&T'S abject negligence, but
           | ultimately the buck stops with AT&T, here.
        
           | dghlsakjg wrote:
           | Totally, way too many people are trying to blame snowflake.
           | 
           | ATT is a technology infrastructure company. Secure
           | transmission of data is one of their core business
           | competencies (theoretically). They are a corporation that we
           | trust to handle incredibly sensitive info. Call records are,
           | in fact, incredibly sensitive data.
           | 
           | They should be telling Snowflake what best practices to be
           | using, not the other way around!
        
             | yyyfb wrote:
             | AT&T and phone carriers in general are not technology
             | companies. They are infrastructure companies that purchase
             | off-the-shelf communication technology, slap a billing
             | system on top, and then spend most of their time on
             | operations (finding places to put towers, keeping the gear
             | up and running) and marketing. The security component of
             | communications isn't built by them, but by the equipment
             | manufacturers that they purchase from. There are no strong
             | penalties for involuntary data leaks - why would they do
             | more?
        
               | dghlsakjg wrote:
               | ATT has a rich history of being a technology company.
               | They invented UNIX! That's in the past, fair enough.
               | 
               | So they used to develop cutting edge technology, they
               | sell technology, they buy technology, they operate
               | technology, they work with manufacturers to develop new
               | technology, they operate the infrastructure underpinning
               | the modern technology economy, but they aren't a
               | technology company?
               | 
               | Even if you want to argue that they aren't a technology
               | company, they sure spend enough time doing everything a
               | technology company does to hold them accountable for
               | their technology failures.
        
               | dahart wrote:
               | > They invented UNIX!
               | 
               | They also invented the transistor, C, the photovoltaic
               | cell, radio astronomy, and ... the telephone. ;)
               | 
               | Yes that's the past, but AT&T labs still employs almost
               | two thousand people. It's very funny to try to claim AT&T
               | isn't a technology company and only peddles services on
               | top of equipment made by others.
        
               | metabagel wrote:
               | It's unclear what you're arguing. That AT&T isn't capable
               | of securing customer data, and we shouldn't expect that
               | of them? That they shouldn't be held liable?
               | 
               | If they don't have the core competency, they need to
               | obtain it as a requirement of doing business.
        
               | dahart wrote:
               | > The security component of communications isn't built by
               | them
               | 
               | Are you claiming AT&T outsourced security and have
               | contracts to back that up? Buying security equipment
               | surely doesn't amount to having security, that would be
               | hilariously naive. Equipment manufactures are not
               | responsible for AT&T's data security, AT&T is. There are
               | laws around security that can hold AT&T liable, in the US
               | and Europe and elsewhere. Whether they will hold the
               | company liable is another question, but these laws will
               | not accept an excuse that AT&T purchased security
               | equipment from another company.
        
             | disgruntledphd2 wrote:
             | > Totally, way too many people are trying to blame
             | snowflake.
             | 
             | Well the _actual_ compromise started from one of their
             | employees, so it's pretty unsurprising that they're getting
             | (some of) the blame.
        
               | dghlsakjg wrote:
               | Ahh. The linked article didn't have that detail.
               | 
               | They attributed it to a lack of 2FA
        
             | throwway120385 wrote:
             | AT&T is a real-estate company that coincidentally sells
             | telecommunications services. My wife used to work for them
             | and given what she's told me I would never in a million
             | years do any business with them intentionally.
        
           | John23832 wrote:
           | I feel like this would be true if ONE customer was hacked. At
           | this point it's more than a handful. AND snowflake knew about
           | it.
           | 
           | If all the lockboxes in a bank get broken into, is it
           | respectable to say "ah all of the customers should have used
           | better locks"? The bank is the party who is supposed to be
           | giving the insight into secure storage. They're not just
           | renting space.
        
         | sickofparadox wrote:
         | The Mandiant report said that some Snowflake customers declined
         | to use MFA AND had passwords in place for 4+ years[1]. Maybe
         | Snowflake should have pushed for MFA harder but at the end of
         | the day, this is AT&T's fault.
         | 
         | [1] https://cloud.google.com/blog/topics/threat-
         | intelligence/unc...
        
           | Ragnarork wrote:
           | I'd say the blame lies halfway between AT&T and Snowflake. If
           | you let your customers have poor security practices, and you
           | have the power to ensure a heightened security level, you're
           | also partly to blame...
        
             | theluketaylor wrote:
             | Snowflake also made it hard to have good practices, giving
             | them further culpability. There was no setting for
             | customers to force their entire tenant to enforce MFA.
             | Customers had to depend on each person with access to do
             | the right thing, something that is unlikely to be
             | universally true.
        
           | wredue wrote:
           | Non-expiring passwords is probably no more or less secure,
           | unless you are a rampantly terrible employer known for
           | setting ablaze every bridge ever to the point of atomic
           | annihilation.
        
             | dylan604 wrote:
             | Are you suggesting a disgruntled former employee could use
             | the password and do things? At that point, I have
             | questions. How is the former employee accessing the cloud
             | service? If your cloud is allowing public access without a
             | VPN, then you've done something wrong there. If the former
             | employee is still accessing your VPN, again, you've done
             | something wrong. Many other things still come to mind but
             | point back to you well before password rotation rules.
        
       | softwaredoug wrote:
       | > AT&T blamed an "illegal download" on a third-party cloud
       | platform
       | 
       | WTF does this even mean?
       | 
       | The cloud employees downloaded it? If its so sensitive, why
       | wouldn't this be heavily e2e encrypted?
        
         | JohnMakin wrote:
         | This is related to the snowflake breach. Snowflake is blaming
         | customers for not enabling MFA.
        
           | tpurves wrote:
           | Looks like more than enough blame to go around. Not enabling
           | MFA is pretty egregious by ATT. Snowflake creating a platform
           | where such a high consequence mistake is apparently easy to
           | make, and obviously without sufficient compensating controls
           | to detect or limit impact of such a single point of failure.
           | That's egregious too.
        
       | rybosworld wrote:
       | Consumers are so numb to data breaches that these events now
       | bring very little outrage. I think without that anger from the
       | consumer, there's little incentive for companies to do more to
       | stop data breaches from happening.
        
         | chefandy wrote:
         | Well it's starting to feel like data privacy just doesn't exist
         | anymore. I don't know why administrators for big customer
         | databases even bother setting passwords these days.
        
           | pavel_lishin wrote:
           | My mother was concerned that some of her information, and
           | mine, leaked because she signed up for another bank account
           | from a place she decided she didn't trust. She said she
           | wasn't worried about the money being stolen, but she was
           | worried about our identities being stolen.
           | 
           | My concern was the complete opposite - I assume that my
           | social security number and address are already for sale for a
           | fraction of a cent somewhere, bundled with 10,000 other
           | identities. But if money gets stolen, that's a whole
           | rigamarole, with banks wringing their hands and saying
           | "identity theft" as if that clears them from any
           | responsibility.
        
             | 0cf8612b2e1e wrote:
             | As a nobody, I keep wanting a financial product that is a
             | black hole. Money can go in, but cannot come out without
             | significant pain. Seven+ day waiting period, in person
             | visit, physical mail verification, something, anything that
             | means if I do get hacked my accounts are not drained in
             | milliseconds.
             | 
             | When I need a legitimate large withdrawal, I can go through
             | the required effort.
        
               | chefandy wrote:
               | You can have a financial manager control your accounts
               | for you and just keep a small checking account, (plus
               | they'll help you grow your balances) but they're not
               | free. Well, they're not free if you want them to be
               | unbiased. Given, what's going to keep them from getting
               | scammed? Maybe what you're looking for is several safe
               | deposit boxes.
        
               | 0cf8612b2e1e wrote:
               | I still want my money invested into the economy. I just
               | want Chase/Fidelity/etc to have an understanding that I
               | am never going to withdraw money from these accounts
               | without planning for it. So, "I" should never be
               | authorized to drain the account at a moments notice
               | without extensive approval. Anything to cause friction
               | for would be scammers and only once-a-year (?) pain from
               | me to triply confirm the money can move.
        
               | chefandy wrote:
               | I don't have direct access to my long-term savings and
               | retirement accounts-- I have to go through my financial
               | manager who'll works in a small, local firm, and so would
               | anyone trying to impersonate me. He would probably
               | recognize my voice, knows where I live and what's going
               | on in my life, to whom I'm married, etc. because we have
               | bi-annual check in meetings. He'd definitely contact me
               | through his existing contact info if there was anything
               | weird going on with one of my requests, especially if it
               | involved a different address or account than he's used to
               | dealing with. As anyone in that compliance-and-accuracy-
               | focused line of work should be, he's very intent on
               | making sure all of the Ts are crossed and Is are dotted.
               | He charges a flat percentage of my modest retirement
               | savings annually (I'm far behind most white collar
               | workers my age, coming from a working class early
               | adulthood) so he has a financial interest in my
               | investments, and does a really solid job managing them.
               | The accounts are in a large investment-focused bank which
               | I believe only he can access. I think it's about as safe
               | as you could get while still keeping your money active in
               | the economy and not having a rich person's resources.
        
               | xyst wrote:
               | This already exists. Withdraw from account to physical
               | cash. Proceed to stash cash in "secret" location.
               | 
               | Most businesses don't even accept cash anymore. Can't get
               | "hacked" although it's prone to many other issues --
               | space, humidity, physical theft.
        
               | pavel_lishin wrote:
               | That sounds like the opposite of what OP wants, because
               | that money can very easily come out, without any pain,
               | and without you even being notified that it's been moved
               | - unless you're re-implementing your own bank-level
               | security, I guess.
               | 
               | For example, let's say you have $100k in savings. I think
               | you would be absolutely bonkers to store that in some
               | secret part of your (flammable! break-in-able!) house.
               | 
               | I guess you could put it in a safety deposit box, and if
               | you needed to spend it in a non-cash way, you could walk
               | it directly to the teller and deposit it and make it
               | available? The equivalent of a cold wallet, I suppose.
        
             | chefandy wrote:
             | If you have at least a fraud watch on your credit which
             | means creditors are supposed to call you on the number they
             | have listed before they open new accounts, then the money
             | is arguably worth protecting more. But if you think it's
             | tough to convince the bank with which you have an existing
             | relationship that you didn't make some withdrawals, imagine
             | trying to convince a bank you've never heard of that you
             | didn't actually approve a loan for 3 Cadillac Escalade
             | Platinums which neither you nor the bank realize are
             | currently in a shipping container on their way to Abu Dabi.
             | 
             | (Nothing against Abu Dabi-- I just picked a random place
             | not under US jurisdiction where plenty of people have
             | Escalade Platinum money.)
        
               | pavel_lishin wrote:
               | I often choose Abu Dhabi as an "example destination",
               | because that's where Garfield kept mailing Nermal in the
               | comics.
        
             | reaperman wrote:
             | Classic Mitchell and Webb skit[0]:
             | 
             | Bank: "No, you see it was your identity that they stole!"
             | 
             | Customer: "Well I don't know because I seem to have my
             | identity whereas you seem to have lost several thousands of
             | dollars. I'm not clear why you think it's _my_ identity
             | that was stolen rather than _your_ money. "
             | 
             | 0: https://www.youtube.com/watch?v=CS9ptA3Ya9E
        
         | strangecharm2 wrote:
         | And why didn't they do anything when we WERE angry?
        
         | TeaBrain wrote:
         | I think many companies think they can solve this issue by
         | throwing money at their cyber security teams. It just happens
         | that cyber security teams are often ineffective.
        
           | marcosdumay wrote:
           | How could they? Everything related to computers is designed
           | to exfiltrate data nowadays.
        
           | softfalcon wrote:
           | Maybe this is how it is at some places, but in my experience,
           | it is not the case. I have friends who have worked in cyber-
           | security for Fortune 500 companies and almost all of those
           | companies would short-change (or outright ignore) the
           | recommended spend and suggestions of their cyber-security
           | employees, contractors, and advisors.
           | 
           | Where are you getting your information from? The levels of
           | security negligence I hear about aren't even a big ask. Huge
           | companies neglect to do basic things like "don't store your
           | passwords in plain text" or "make sure you salt and hash your
           | passwords".
           | 
           | I don't think it's fair to say cyber security teams are
           | failing if companies are blatantly doing the worst and most
           | obviously wrong things on the daily at the highest levels.
        
           | mrguyorama wrote:
           | It's hard for a CyberSecurity team to be effective when the
           | Execs keep failing the phishing tests and IT does not have
           | the authority to fire them for it.
        
         | kredd wrote:
         | After Equifax debacle, I don't think anyone cares. It'll only
         | be a big deal if there's a huge B2B leak and business-critical
         | data gets exposed, other than the usual name, address and phone
         | number.
        
           | al_borland wrote:
           | I'm still upset the government hasn't started work on a new
           | national ID program after the Equifax breach. The SSN is not
           | a suitable ID number in this day and age. We need something
           | better that can withstand these kind of things without
           | screwing people for life. My credit will be frozen for the
           | rest of my life, and everyone else should do the same.
        
           | chankstein38 wrote:
           | This is it for me tbh. Yeah I don't want my identity stolen
           | and I'm still careful but after Equifax I just assume
           | everyone already has my data so all of these data breaches
           | are meaningless to me at this point. It sucks and it makes me
           | mad but all I can do is shake my fist and wish these
           | companies would be better anyway, so what else can I do but
           | just be ok with it?
        
         | xyst wrote:
         | AT&T is a public company. Public company needs to get fined
         | appropriately.
         | 
         | Start issuing multi billion dollar fines for these breaches and
         | suddenly companies are invested in security.
         | 
         | Unfortunately with government agencies getting defanged as part
         | of recent SCOTUS ruling, it's likely not possible.
         | 
         | Have to rely on civil court to issue fines now (ie, class
         | action lawsuits).
        
       | hughesjj wrote:
       | And this is yet another reason why I use signal
        
         | jacobwilliamroy wrote:
         | Do you exclusively use signal? Do your friends also use signal?
         | Do you have friends who only use signal to communucate with
         | you?
        
           | llm_trw wrote:
           | Yes.
        
             | ghaff wrote:
             | Aside from a couple non-US friends, I know no one in the US
             | who uses anything other than straight SMS (and Apple
             | iMessage). I'm sure they exist but certainly not in the
             | circle of people I communicate with.
        
               | BenjiWiebe wrote:
               | There's definitely different circles in the US. My circle
               | of friends and family is on Whatsapp. More than 99% of my
               | communications would be through WhatsApp.
        
               | lotsofpulp wrote:
               | Everyone I know in the US uses either iMessage or
               | Whatsapp. No one I know uses MMS.
        
               | ectospheno wrote:
               | Everyone I know uses signal. Different people really are
               | different.
        
               | ghaff wrote:
               | For whatever reason, chat seems to definitely encourage
               | tribalism. The last company I worked for eventually
               | bought into Slack because so many people WOULD NOT use
               | anything else while a lot of us were like "ANOTHER chat
               | app??" because we were perfectly happy with Gchat which
               | we had as part of Google Workplace.
               | 
               | I know there are some historical reasons for non-SMS
               | because of text pricing outside the US but everyone I
               | know in the US would look at you funny if you wanted to
               | use some special app for texting.
        
             | postexitus wrote:
             | do you have friends in plural?
        
               | llm_trw wrote:
               | I've gotten everyone from my in laws to my co workers on
               | signal.
               | 
               | >I can share baby pictures without them being stored in
               | google forever.
               | 
               | >We can organize whose bringing the coke without leaving
               | a paper trail that lasts forever.
        
               | jacobwilliamroy wrote:
               | I DO
               | 
               | I HAVE 3
               | 
               | 3 IS MORE THAN 1
        
             | jacobwilliamroy wrote:
             | Do you make it like a fun game? Like when me and my friends
             | in school would pass eachother coded notes and the cipher
             | was an inside joke?
             | 
             | I'm genuinely curious: what was the pitch that you used to
             | get others to start using signal?
        
           | rustcleaner wrote:
           | I am working on this with mine, but even Signal is too
           | weaksauce in my book. Ownerless (and ideally decentralized)
           | p2p chat is what I am after. If everyone in my group used
           | Android then it'd be Briar or Cwtch hands down for primary
           | text/picture msg and SimpleX or Session or Jami as
           | voice/video call and backup. Because there's an iphone
           | upsetting everything that scratches Briar and Cwtch, so it's
           | SimpleX reinforced with Orbot on my group's menu currently
           | and it seems to work reliably. Session has terrible
           | notification delays when in the background, they use the
           | [IMO] boneheaded send-on-select abstraction within the
           | selection gallery when attaching an image on their Android
           | app (oh and your unsent typed text is wiped). Very
           | unprofessional, needs a bottom-up redesign for its interface.
           | Really has that everyone quit feel to it.
        
             | jacobwilliamroy wrote:
             | Do you make it like a fun game? Like when me and my friends
             | in school would pass eachother coded notes and the cipher
             | was an inside joke?
             | 
             | I'm genuinely curious: what was the pitch that you used to
             | get others to start using signal?
        
         | abixb wrote:
         | I hope you didn't sign-up for Signal with an AT&T-tied phone
         | number. Else this breach would've probably exposed your PII
         | either way.
        
       | jen20 wrote:
       | This is the kind of breach that really should be company-ending,
       | but will sadly instead likely result in a slap on the wrist.
       | 
       | It is high time for the US to have a privacy law with real teeth,
       | and to enforce it with vigour.
        
         | Ekaros wrote:
         | Class-action suit sounds reasonable, but sadly those never give
         | penalties in right ballpark. Here it should be hundreds to
         | thousands at least per affected customer.
         | 
         | But my guess it is few tens of cents, if that... While lawyer
         | will get nice couple million pop...
        
         | criddell wrote:
         | Or maybe it's time to turn software engineering into an actual
         | engineering profession. If the people responsible for designing
         | and maintaining the AT&T system were "real" engineers, they
         | could be sued for malpractice or even lose their license to
         | practice.
        
           | ghaff wrote:
           | Do you really think that requiring 4-year degrees and passing
           | a licensing exam would make a big difference? The fact is
           | that, outside of civil engineering which involves a lot of
           | dealing with regulatory agencies, most engineers in the US
           | don't have PEs. I started on the path to get one because, had
           | I stayed on my initial career path, I'd have been sending
           | blueprints etc. to regulatory agencies but I ended up
           | changing careers.
        
             | acuozzo wrote:
             | No, what will make the difference is being personally
             | liable for the vulnerabilities you introduce.
             | 
             | Not the company. You.
        
               | ghaff wrote:
               | How many individual engineers do you suppose get
               | prosecuted for making errors--even careless ones? I'm
               | guessing very few in the West. And I'm not even sure
               | lopping off a head here and there to encourage the others
               | is even a good idea.
        
               | criddell wrote:
               | > How many individual engineers do you suppose get
               | prosecuted for making errors--even careless ones?
               | 
               | Not many but is that because they don't get sued or
               | because professionals who face consequences for
               | negligence make fewer stupid decisions?
        
               | ghaff wrote:
               | I would assume that engineers, at least in the US, are
               | far more concerned about getting fired/eased out than
               | prosecuted if they do stupid things given that companies
               | can do so pretty easily.
        
               | criddell wrote:
               | Would you say the same is true for a lawyer? Are they
               | more worried about being fired from a law firm than being
               | sued for malpractice and being disbarred? If not, why
               | would engineers be different?
        
               | ghaff wrote:
               | I would assume that being disbarred has a pretty high
               | standard of misconduct as opposed to simply not making
               | partner or whatever level of action makes maintaining
               | employment at a large law firm practical.
        
               | jen20 wrote:
               | Look at Sarbanes-Oxley for precedent. Management has to
               | be made liable for sufficient cultural shift to occur.
        
           | lesuorac wrote:
           | Snowflake still works though. What civil engineer has been
           | sued because somebody jumped off their bridge? You get sued
           | when the bridge collapses not when somebody uses it for an
           | unintended action.
        
           | jen20 wrote:
           | The root cause is not whether engineers are licensed (I'm
           | fine with that idea, but it's not going to resolve this
           | specific problem). Instead, it is a culture of not caring
           | about security because the fines are a cost of doing business
           | is, and which comes from management, and treating personal
           | information as an asset instead of a liability.
           | 
           | A Sarbanes-Oxley style law that makes the CEO personally
           | criminally responsible for breaches will be vastly more
           | effective than pursuing individual engineers - many of whom
           | will be on the types of visa where they have no effective
           | route of pushback on orders anyway.
        
             | criddell wrote:
             | When a doctor is negligent, their employer is often also
             | sued if it can be shown that it knew shenanigans were
             | underway and did nothing.
             | 
             | We shouldn't choose between holding engineers or executives
             | responsible. Each should be held responsible for their
             | part.
        
               | jen20 wrote:
               | Indeed - but we should start at the place likely to
               | actually make a difference: the executives.
        
       | JohnMakin wrote:
       | So where/what is my compensation? (I know there is no recourse).
       | 
       | When no one is on the hook for secure practices, like enabling
       | MFA on your effin data stores that contain massive amounts of
       | customer PII, this is the result. Not even an apology, just
       | report it and move on. woops! those gosh darned cyber criminals.
        
         | criddell wrote:
         | If you go to court and ask for compensation you would likely be
         | asked to show harm. Could you?
        
           | JohnMakin wrote:
           | It really doesn't matter. Compensation has been dispensed to
           | customers in data breaches such as credit/ssn info, no harm
           | proof needed. Potential for harm is enough. Breach of
           | contract, as a customer do I have a reasonable expectation
           | that this data is not exposed? of course I do. No one could
           | very seriously argue it's a zero sum.
        
           | EarthLaunch wrote:
           | Is there no harm, or is there harm that is hard to show in
           | court?
        
             | lesuorac wrote:
             | A bit of both.
             | 
             | Most people aren't going to have their identity stolen (or
             | insert w/e crime). Those that do will have trouble proving
             | it was from this leak.
        
         | latchkey wrote:
         | I've received checks over the years for various things like
         | this. You end up having to fill out a claim form and then wait
         | about 5 years and one day, you get this check in the mail for
         | some tiny amount of money.
        
       | floatrock wrote:
       | > In a statement, AT&T said that the stolen data contains phone
       | numbers of both cellular and landline customers, as well as AT&T
       | records of calls and text messages -- such as who contacted who
       | by phone or text -- during a six-month period between May 1, 2022
       | and October 31, 2022.
       | 
       | AT&T customer? Prepare for phone calls / text messages from your
       | most frequent contacts saying "I got stranded / I'm Officer
       | Blahblahman helping your friend get home... please send gift card
       | / venmo"
       | 
       | It's only metadata...
        
         | morkalork wrote:
         | I guess everyone is going to learn what Snowden was worried
         | about the hard way now. I imagine there's going to be extortion
         | attempts over calls to abortion clinics etc.
        
           | smcin wrote:
           | Among other things. The data's mostly from May-Oct 2022.
        
         | rustcleaner wrote:
         | I just realized this is going to fvck my call blocking strategy
         | up: now creditors will have a bank of known good numbers to
         | spoof into my whitelist with! :^O
        
       | josefritzishere wrote:
       | damn
        
       | ungreased0675 wrote:
       | So, AT&T wasn't using MFA?
       | 
       | A lot of information can be derived from analysis of call
       | records. If this information becomes public, it could be
       | disastrous.
        
         | ffsm8 wrote:
         | > _If this information becomes public, it could be disastrous._
         | 
         | Isn't it even worse if it doesn't become public? It's been
         | downloaded by an unauthorized party after all, so if they're
         | not publishing the data, I'd wager they've found another way to
         | profit from it. I.e. blackmail or similar.
         | 
         | I guess it depends on your viewpoint wherever that's better or
         | worse.
        
       | xyzzy4747 wrote:
       | It's interesting when you have these old, large, sprawling
       | bureaucratic organizations and the employees hardly give a sh!t
       | anymore and allow for these large vulnerabilities. It's not a
       | money issue, it's a caring issue I think.
        
         | hypeatei wrote:
         | Our economic system is at odds with security because we're
         | trying to "get by" as cheap as possible. That doesn't bode well
         | for protection of users' data.
        
           | lotsofpulp wrote:
           | During the last decade, ATT's leaders decided to burn tens of
           | billions of dollars by overpaying for obviated businesses
           | like DirecTV and Time Warner.
           | 
           | I can only imagine the quality of mobile and fiber networking
           | we could have had if that money was spent on
           | telecommunications. And maybe they would have spent a few
           | million on having proper security.
        
             | dopylitty wrote:
             | Not only that they blew $8 billion/year on dividends that
             | could've gone into the business or to employees instead of
             | being extracted and given to people who have nothing to do
             | with the business.
        
               | lotsofpulp wrote:
               | When people invest in a business, whether it be your
               | sibling's business, or a local business, or a publicly
               | traded business, they do it because they expect a return
               | on investment.
               | 
               | An infrastructure utility such as ATT typically has to
               | offer dividends because it is not going to experience the
               | type of growth that would result in a return via share
               | price increase.
               | 
               | Of course, ATT's prices are not regulated like a proper
               | utility, even though they should be, but it is still
               | subject to the same market forces that prevent it from
               | growing like a tech company would, who would have the
               | option of foregoing dividends (or share buybacks).
        
         | aitchnyu wrote:
         | Tangential, why did you/anybody spell "shit" like they are
         | evading Tiktok language filters?
        
       | swarnie wrote:
       | Why would AT&T even need to keep this data?
       | 
       | All i can think of is billing for a fraction of plans from the
       | early 2000s who still pay per min/per text. Or maybe for capacity
       | metrics but even then you only need the overall data point not
       | the actual records once collaborated.
       | 
       | What's the US law for keeping data as long as its relevant and
       | needed?
        
       | ilteris wrote:
       | I am an ATT user and on a pixel which generally good at filtering
       | spam messages. I have noticed I was getting so much spam messages
       | recently ("wanna make money working remotely for x hours a day
       | only") I was surprised and thought my number somehow made it to
       | one of those spam networks. This confirms my suspicions.
        
       | bobo_legos wrote:
       | Snowflake might want to take this page down in light of today's
       | news.
       | 
       | https://www.snowflake.com/en/customers/all-customers/case-st...
        
       | cddotdotslash wrote:
       | Another article[1] cites AT&T's Snowflake deployment as the
       | source of the breach:
       | 
       | > It's not clear for what reason AT&T was storing customer data
       | in Snowflake, and the spokesperson would not say.
       | 
       | [1] https://techcrunch.com/2024/07/12/att-phone-records-
       | stolen-d...
        
       | smcin wrote:
       | AT&T stock has already bounced back from much of the initial
       | -2.6% drop this morning, so the market thinks AT&T is immune.
       | Meanwhile Snowflake is -3.9% down (they have many other customers
       | than AT&T).
       | 
       | https://www.marketwatch.com/investing/stock/T
       | 
       | https://www.marketwatch.com/investing/stock/SNOW
        
         | jader201 wrote:
         | I never got the impression that the market ever cares about
         | data breaches. It seems most companies are rarely held
         | financially responsible for data breaches anyway.
         | 
         | I would bet any effects you're seeing in stocks is unrelated to
         | this news.
        
           | smcin wrote:
           | They are very much related to the news, that's precisely why
           | I linked to the stock charts: AT&T was flat overnight but
           | opened (9am ET) with a -2.6% spike down, but has been
           | recovering since. Their press release appears to have been
           | Friday 7am ET shortly before market open
           | [https://about.att.com/story/2024/addressing-illegal-
           | download...].
           | 
           | Also as corroboration here's MarketWatch: "AT&T's stock
           | slides 3% after company discloses hack of calls and texts"
           | [https://www.marketwatch.com/story/at-ts-stock-
           | slides-2-9-aft...]
        
             | soulofmischief wrote:
             | I'm not saying there's no way the stock pullback wasn't
             | caused by the hack, but it's also important to note that
             | MarketWatch article only establishes correlation, not
             | causation.
        
               | seadan83 wrote:
               | Most linked financial news is auto-generated and auto-
               | correlated. Lots of "why did.." when nobody knows, and
               | frankly there often is no why. Perhaps that was the day a
               | retirement fund shifted money, who knows.
               | 
               | While this price movement is very well correlated,
               | perhaps causal even, but marketwatch (and all similar
               | bottom feeders that are just trying to make ad revenue),
               | it's a case of a broken clock being right. Those
               | financial news sites which link recent news to stocks, eg
               | Yahoo, benzings, - those recent news headlines are just
               | the same as ad tech now. It is noise.
        
           | graybeardhacker wrote:
           | I agree.
           | 
           | This is precisely why breaches keep happening and will keep
           | happening. It cost money to implement security. There's no
           | cost benefit to spending that time and money since there are
           | no consequences.
           | 
           | Businesses do not spend money unless it will make them money
           | or save them money.
           | 
           | There needs to be a hefty federal fine on a per-affected-user
           | basis for data breaches. Also a federal fine for each day a
           | breach is unreported.
           | 
           | That money should go into a pool which can be accessed by
           | people who have their identity stolen.
        
             | ThunderSizzle wrote:
             | Or a lawsuit go through where someone can win quite a bit
             | from from data leaks. If each person affected sued and won
             | 100k or so, or even 1k, AT&T would definitely be spending
             | money on security.
             | 
             | But it appears $5 or credit monitoring from an agency that
             | also gets hacked is sufficient for class action lawsuits.
        
               | malcolmgreaves wrote:
               | That requires people to be rich enough to sue. It takes a
               | lot of money and time to sue. Almost no one has enough
               | resources to do this. The courts are not an effective way
               | to implement this policy. Unless you only want rich
               | people to be able to get justice.
        
               | CityOfThrowaway wrote:
               | 110M people impacted = class action
               | 
               | The lawyers work on contingency
        
               | unixhero wrote:
               | Imagine the GDPR fine
        
               | pas wrote:
               | showing damages is hard
        
               | mrguyorama wrote:
               | Class action suits regularly end up getting you "$5"
               | worth of credit monitoring from the exact company who
               | lost your data. It's a joke. Class action suits as they
               | exist today in the US are an abject failure of justice.
        
               | fn-mote wrote:
               | If they end up with the company having to pay anything,
               | it is greater than fines imposed by regulatory
               | agencies... who should be doing this job.
        
               | Borg3 wrote:
               | And rich people usually do deals off-court. You will pay
               | me this and we are ok. Because its faster and both sides
               | know they capabilities usually.
        
               | financypants wrote:
               | "12 months free credit monitoring with auto-renewal".
        
               | blackeyeblitzar wrote:
               | Most companies now include clauses that force arbitration
               | and prevent you from using a class action lawsuit. This
               | type of sidestepping of the public justice system should
               | be outlawed, retroactively, with retroactive lawsuits (by
               | extending the statute of limitations), retroactive fines,
               | and retroactive jail time.
        
             | cm2187 wrote:
             | Most breaches are because of developper incompetence.
             | Throwing money at it won't really help. You need better
             | basic security skills.
        
               | slg wrote:
               | No two people are incompetent in exactly the same way.
               | Hiring two developers to review each other's code leads
               | to better code because they will often find problems that
               | the other one didn't see. In a well managed organization
               | (admittedly not a trivial caveat these days), more people
               | working on security leads to better security.
        
               | cm2187 wrote:
               | Certainly, but for instance no sane developer should
               | concatenate a string in a sql query unless there is
               | absolutely certainty the string is safe. This should be
               | reflex, not a matter of money or time.
        
               | slg wrote:
               | People are alway going to make bad decisions. Sometimes
               | that is out of a lack of experience or knowledge which
               | can be fixed by better training (which also requires
               | money). Other times it is out of apathy, laziness, or
               | something else that can't be easily fixed. Either way,
               | time and money can provide extra sets of eyes to find and
               | fix those mistakes before they lead to a breach.
        
             | dboreham wrote:
             | > It cost money to implement security.
             | 
             | Yes, but no amount of money will stop the data in a big
             | database being stolen by someone sufficiently motivated to
             | steal it. It's just bits on someone's disk.
             | 
             | The only true solution is to not create the database. But
             | then what would all the data scientists and their MBA
             | masters so with their time?
        
               | currymj wrote:
               | in this case it's pretty tough because the phone company
               | does need this metadata just to bill people. so they
               | should protect it properly.
        
               | compootr wrote:
               | I don't see a reason as to recording who contacted who.
               | If it's for billing, just record duration, if they're not
               | an 'unlimited' customer and flags on whether it'd incur
               | extra charges (i.e roaming, international call)
        
           | chung8123 wrote:
           | I think they will care a lot more when it directly impacts
           | them. If all their text conversations were publicly available
           | that would cause some outrage.
        
           | rybosworld wrote:
           | There is some evidence that it does hurt stock prices:
           | 
           | https://www.comparitech.com/blog/information-
           | security/data-b...
           | 
           | "Stocks of breached companies on average underperformed the
           | NASDAQ by -3.2% in the six months after a breach disclosure"
           | 
           | That said, it's not clear what the long term impact is on
           | stock price (if there is any).
        
             | teraflop wrote:
             | Unfortunately, that analysis seems to have made absolutely
             | no attempt to check whether the results are statistically
             | significant.
             | 
             | Pick 118 random companies at 118 random points in time.
             | It's vanishingly unlikely that the average returns of that
             | group will _exactly_ track the NASDAQ returns over the
             | following 60 days. It might underperform, or it might
             | overperform. An underperformance of 3.2% could easily just
             | be the result of random chance, and have nothing to do with
             | data breaches.
        
               | jkaptur wrote:
               | My hypothesis would be that companies with poor
               | operational practices are more likely to underperform the
               | index _and_ have data breaches - in other words, that the
               | study confuses cause and effect.
               | 
               | This wouldn't be that hard to test. I suspect that the
               | breached companies underperformed in the six months
               | before the breach as well as the six months after.
        
               | Terr_ wrote:
               | Also, events which are not "just" data-leaks but also
               | interruptions or degradation in regular operations. I
               | suspect investors may be more sensitive to those events
               | and their fallout, and such events more likely to either
               | be caused by bad-practice or to be somehow connected to
               | data-leaks.
        
           | weezin wrote:
           | Really should be up to the government to fine these companies
           | and pay out to those effected to disincentivize lax security
           | standards.
        
             | kcmastrpc wrote:
             | How would such damages be assessed or proven?
        
               | Eisenstein wrote:
               | They would be assessed according to rules written by
               | people who are skilled at writing such rules. The rules
               | would be evaluated by looking at data over time and
               | revised as needed by experts in the industry who are as
               | neutral as possible, maybe with some feedback from the
               | public. The courts exist for any contention regarding
               | responsibility.
        
             | hodgesrm wrote:
             | Well, I guess we devs should also be looking at ourselves,
             | then. A lot of the lax security comes from us collectively
             | choosing to build applications using cloud services that
             | talk to each other over the public internet. That pretty
             | much describes the so-called "modern data stack."
        
           | nashashmi wrote:
           | Insurance takes up a lot of the fallout from data breaches.
        
           | darby_nine wrote:
           | I'm certainly not going to defend negligence of data
           | protection but it's extremely difficult to cost as a
           | liability (naively, you might even consider it not a
           | liability at all) without government oversight.
        
           | hodgesrm wrote:
           | > I never got the impression that the market ever cares about
           | data breaches. It seems most companies are rarely held
           | financially responsible for data breaches anyway.
           | 
           | This might also explain why there's little visible effect on
           | other cloud database services either. After all, the attack
           | is pretty simple and potentially affects any cloud database
           | that allows access from the Internet.
        
           | omoikane wrote:
           | My reading is that the market thinks Snowflake takes the
           | majority of the blame, and the content of the linked article
           | seemed to suggest as much despite having only AT&T in the
           | headline.
        
           | lp0_on_fire wrote:
           | The market doesn't care precisely because there is never any
           | accountability.
        
           | Vicinity9635 wrote:
           | It's actually a great way to tell that it is known that the
           | punishment is insufficient.
        
           | blackeyeblitzar wrote:
           | The market correctly does not care because there is no
           | consequence for the current or prior executives and no
           | financial consequence for the company. All they will do is
           | send out some obligatory notices, mention it in their
           | investor relation materials, maybe offer a year of credit
           | score monitoring, and move on.
           | 
           | We need regulations with massive fines, class action lawsuits
           | (a ban on arbitration clauses), and maybe automatic minimum
           | level compensation to those customers.
        
         | xyst wrote:
         | It's priced in.
        
         | treflop wrote:
         | Well it's as if you put your data in Salesforce and Salesforce
         | got breached... maybe you're bad at picking vendors but the
         | real loss of trust would be on Salesforce.
         | 
         | In this case, Snowflake was also the cause for the Ticketmaster
         | and Lending Tree breaches according to the article so...
         | 
         | real lack of trust in Snowflake now.
        
       | pylua wrote:
       | And earlier this year my ssn was on the dark web due to their
       | leak (or vendor). One year of monitoring? No, I'm going to need
       | it for life.
       | 
       | Security is not a concern. There is no real incentive to change
       | the status quo. Make them pay for monitoring indefinitely .
        
         | ajsnigrutin wrote:
         | I never understood the american secrecy about SSN... it should
         | be a "username" not a "password"...
         | 
         | In my country you can calculate our own national id (mix of
         | date of birth, autoincreasing number by each birth that day + 1
         | checksum number), and if you do/have any kind of personal
         | business, your personal tax number has to be written
         | everywhere, on every receipt you hand out or anything you buy
         | as a business.
         | 
         | Somehow knowing that first boy born today will have an ID
         | number of 120702450001X (too lazy to calculate the checksum,
         | but the algorithm is public), doesn't help anyone with anyting
         | bad.
        
           | ThunderSizzle wrote:
           | SSN is too public for it to be private or secret. Multiple
           | employers, schools, medical institutions, financial
           | institutions all ask for it, so it's not private.
           | 
           | It's also treated as evidence of who you are, but it isn't
           | tied to identification like an ID is. These institutions use
           | it without ever truly validating it.
           | 
           | It's similar to how records fraud can occur - people can
           | record anything to the local registrar office, including
           | fraudulent documents, without any checks. Once it's
           | registered, it becomes evidence against the real owner. It's
           | really messed up.
        
           | strangecharm2 wrote:
           | This comment pops up every time someone talks about social
           | security numbers. Yes, they were never supposed to be
           | private, but now they are. So either Congress can do
           | something about it, or big companies can stop leaking them.
           | Clever "well, actually"s didn't stop my identity from being
           | stolen recently after a breach, and they never will.
        
             | dboreham wrote:
             | They're not really private+, and nobody should design a
             | system with the assumption that they are. afaik nobody does
             | these days. There are extra authentication checks done in
             | addition to simply "I have the SSN".
             | 
             | + e.g. until very recently there were US states that used
             | your SSN as your driver license number.
        
           | browningstreet wrote:
           | A lot of financial things in the US are "secured" or anchored
           | by SSN, that's the only reason why. That and mother's maiden
           | name and first vacation and other security questions. It'd be
           | less important with MFA now but SSN is also needed when
           | opening new credit, so having it allows you to pretty easily
           | fake someone else's identity for credit. KYC hasn't removed
           | it from the equation.
        
             | madcaptenor wrote:
             | "Mother's maiden name" won't work for my kids - my wife
             | kept her name and the kids' last name is hyphenated, so you
             | just have to guess whose name we put first.
        
               | AuryGlenz wrote:
               | It's also probably increasing easy to look up.
               | 
               | We need a national (preferably RFID-ish) password system.
        
             | athenot wrote:
             | One mitigation is to make your mother's maiden name the
             | output of:                   head -c 20 /dev/random |
             | base64
             | 
             | And keep track of the result in your favorite password
             | manager.
             | 
             | Fortunately, fewer and fewer orgs are using security
             | questions, but there are still some important ones that
             | only use that and no MFA.
        
               | theluketaylor wrote:
               | The problem with that plan is social engineering attacks.
               | CSRs are often careless and will accept 'a bunch of
               | random letters and numbers' as the answer rather than
               | validating each character.
               | 
               | Better to randomly select a long dictionary word or
               | hypenate a few together. Equally unguessable but easily
               | verified, so it won't be weakened during a phone
               | conversation.
        
           | dylan604 wrote:
           | Even the US gov't gave up on the notion the SSN was not to be
           | used as an identifier. My dad's SS card had a phrase printed
           | on it saying so. My SS card did not have that text.
        
             | hermitdev wrote:
             | My SS card has that text. I got into an argument at the DMV
             | when they asked for it. I relented because I needed my
             | drivers license.
             | 
             | Congress could solve this by enacting a simple law.
             | Something to the effect of SSNs shall not be used as a
             | means of identification by any party, governmental or
             | otherwise other than the Social Security Administration.
             | Use of an SSN as identification shall be subject to a $100
             | fine per each SSN used as identification, per day.
        
           | alistairSH wrote:
           | _I never understood the american secrecy about SSN... it
           | should be a "username" not a "password"..._
           | 
           | The problem is banks/financial services do a piss-poor job
           | validating identity when issuing credit/opening accounts.
           | "Oh, you provided an address, a SSN, and [non-random, easily
           | discoverable personal fact]! Sure, here's a CC with a $150k
           | limit!"
           | 
           | It's not the leak that's the problem; it's the ease with
           | which that leaked data is used to either obtain fraudulent
           | credit or access accounts.
           | 
           | I don't have a good answer, because at some point, a
           | financial institution needs to trust people to do business.
           | Customer loses their phone, so MFA doesn't work, ok, now
           | what? I guess the customer needs to have one-time use
           | recovery tokens saved somewhere that can't be lost? How many
           | people do that (not nearly enough)? How many banks even issue
           | those tokens? And what if the token store gets hacked? Now
           | you're really fucked.
        
             | piva00 wrote:
             | > Customer loses their phone, so MFA doesn't work, ok, now
             | what? I guess the customer needs to have one-time use
             | recovery tokens saved somewhere that can't be lost? How
             | many people do that (not nearly enough)? How many banks
             | even issue those tokens? And what if the token store gets
             | hacked? Now you're really fucked.
             | 
             | In my experience with banking in Brazil and Sweden this is
             | easily solved with a OTP device you get from your bank.
             | 
             | Brazilian banks before that used to provide a card of
             | 50-100 tokens you'd use for authenticating, which is
             | obviously dangerous as people would carry them in their
             | wallets with their cards (and associated banking details).
             | Since the early 2010s banks have instead provided a
             | physical OTP generator that you associate with your
             | account.
             | 
             | In Sweden if I lose access to my phone with my digital
             | identification app (BankID) I can fall back to my hardware
             | OTP generator to login into my account, and authorise a new
             | BankID installation in case I need a new phone.
             | 
             | It's a solved problem, even though the US developed a lot
             | of the tech industry it feels like digital infrastructure
             | is still in the late 90s for a lot of stuff; banking is a
             | clear case, and government systems are another good
             | example, e.g.: the DHS website for visa application is
             | atrocious, we are in 2024 and applying for a visa feels
             | like an experience from when I navigated the web on
             | Netscape in the early 2000s.
        
               | alistairSH wrote:
               | Totally agree. It feels like our banking is a decade
               | behind - like transfer money - no direct way to do it
               | between banks - most people use Venmo. Some banks are
               | part of Zelle, but I've heard it has fraud issues (weak
               | discovery/confirmation of correct recipient) and the
               | banks won't refund many fraudulent transfers ("You
               | initiated the transfer! Not our problem you sent to the
               | wrong person!").
               | 
               | So, do you get a physical OTP generator for every
               | financial institution? I guess that works, but that would
               | mean I'd have a drawer full (2x bank, 1x work, current
               | 401k, past IRA, and a brokerage account - x2 because my
               | wife has about the same).
               | 
               | I was thrilled last year when I discovered I could renew
               | my passport online! In 2023! That should have been
               | available eons ago.
        
           | galdosdi wrote:
           | It's because it happened gradually / naturally / semi un
           | intentionally, because:
           | 
           | 1) SSN was not intended as a national ID, but it so happened
           | to fit the shape of one, in that almost everyone has one and
           | they're unique.
           | 
           | 2) It has never been possible to institute an intentional
           | national ID system in the US for political reasons
           | 
           | That is the recipe for the problem we have now. Strong demand
           | for a national ID from many business purposes, the existence
           | of something that looks a lot like, but is an imperfect form
           | of, national ID, and the refusal to create a proper national
           | ID, has naturally led to a de facto system of abusing the SSN
           | as a national ID and just kind of everyone being a little
           | annoyed and sketched out about it but putting up with it
           | anyway for lack of alternatives.
           | 
           | Incidentally, did you know anyone can generate a valid new
           | EIN (which is a lot like an SSN, and can be used where an SSN
           | can be used for some but not all purposes, specifically
           | filing taxes and ) at this page
           | https://www.irs.gov/businesses/small-businesses-self-
           | employe... ? This isn't legal advice and I'm not a lawyer and
           | I don't know in what situations you personally would be
           | legally permitted to use this (it's meant for businesses,
           | absolutely not some kind of personal alias) -- but
           | technologically, it's just honor system, and anyone can
           | certify they need and are entitled to a new EIN and the IRS
           | web site will provide you with a new unique one. I don't
           | think you even need a legal entity, since you don't need a
           | legal entity to run a business in the US.
        
             | james_marks wrote:
             | Also NAL, but watch out for how this is reported to states.
             | California is currently $800/year min, even if the entity
             | has no activity.
        
           | galdosdi wrote:
           | > Somehow knowing that first boy born today will have an ID
           | number of 120702450001X
           | 
           | It's even worse. Only post-2011 IIRC births have an
           | algoirthmic SSN. So everyone over the age of 13 still has old
           | fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by
           | 
           | 1) XXX is the code for the office that issues your card. Can
           | be guessed precisely and accurately by knowing birth
           | location. For example, I can guess what region of the US you
           | were born in (or lived in when you immigrated) by the first
           | digit. 0 or 1 is probably northeast. 4 or 5 is probably near
           | Texas. 7 might be near Arkansas. Etc.
           | 
           | 2) YY-ZZZZ is sequential by date! So by knowing just birth
           | day, can be guessed to within a range. In practice, this
           | means it's easy to guess YY alone, but harder to get all 4
           | digits of ZZZZ
           | 
           | 3) For some stupid reason it got popular to print SSNs with
           | all but the last four digits masked. This is horribly bad
           | because those four are ACTUALLY THE MOST SECRET PART! It's
           | the only part that might not be guessable. But since it's
           | common to be more lax with securing them..... it is super
           | easy to recover the full SSN if you find a piece of paper
           | that says something like
           | 
           | JOHN SMITH
           | 
           | 123 Main St
           | 
           | Alabama City, AL 76543
           | 
           | In ref acct: XXX-XX-1234 (2001-03-14)
           | 
           | Dear Mr Smith,
           | 
           | Your account is overdrawn. Have a nice day.
           | 
           | Thinking of you,
           | 
           | The Bank
           | 
           | It also means if someone is personally known to me, even
           | vaguely, I may be able to reconstruct their social seeing
           | nothing but a scrap of paper that has just the last four, if
           | I can guess approximately where and when they were born or
           | first entered the US. If I'm in a situation where I can try
           | several guesses, it's even easier.
        
             | 5555624 wrote:
             | > 1) XXX is the code for the office that issues your card.
             | Can be guessed precisely and accurately by knowing birth
             | location.
             | 
             | While the first sentence is true, the second is only true
             | if you were born after the mid-1980s, when a Reagan-era tax
             | reform was enacted. (It required a SSN when claiming
             | dependents.) Prior to that, most people did not get a SSN
             | until they got a job.
        
               | nostrademons wrote:
               | I looked this up and while your first sentence is true,
               | the second (non-parenthetical) sentence is only true if
               | you did not require any of the other services that
               | required a SSN. There's a list of those under "Exhibit 2"
               | (about 2/3 of the way down the page) on the SSA's
               | website:
               | 
               | https://www.ssa.gov/policy/docs/ssb/v69n2/v69n2p55.html
               | 
               | tl;dr: If you had a bank account, applied for a federal
               | benefit, were on food stamps, applied for school lunch,
               | or did any number of other financial or government
               | transactions, you needed a SSN starting in the 1970s.
               | That's enough of an incentive that many parents might've
               | just applied at birth, figuring that their kid will
               | eventually need it. Also everyone born 1968-1981 would've
               | likely gotten one in 1986, when the change you mentioned
               | about dependents was enacted, and then after 1988 they
               | started being required for issuance of a birth
               | certificate.
        
               | 5555624 wrote:
               | I stand corrected. Thanks. I didn't bother to look it up,
               | since I'm old and got mine when I started working.
               | Although people born 1968-1981 were getting SSNs where
               | they currently lived, which is not necessarily where they
               | were born; which was the original point.
        
             | chankstein38 wrote:
             | When I was in school (almost 20 years ago) this came up
             | because someone mentioned the first 6 digits of their SSN
             | and they matched mine. Since then it's similarly bothered
             | the hell out of me that the practice is to mask all but the
             | last 4 of the SSN and that a lot of places require you to
             | enter your last 4 of your SSN.
             | 
             | I didn't know the reasons for the matches but them being my
             | age and likely born in the same place as me made me realize
             | those were identifiers and the last 4 were the unique bit.
        
         | demondemidi wrote:
         | When I went to college in the late 80s my ssn was automatically
         | used as my student id. When I got my first bank account in
         | 1990, they used my ssn as the account number.
        
           | buildsjets wrote:
           | Our class grades with names snd SSNs were posted on the wall
           | after exams in a list of hundreds of students.
           | 
           | Go Jackets.
        
             | galdosdi wrote:
             | Ah it was a different time. Societal trust was greater.
             | Without global internetification, the only people who could
             | ever have any opportunity to exploit this information were
             | your fellow campus denizens (students, professors, etc).
             | 
             | Without global internetification, there was not as much an
             | average person could really do or would know to do with an
             | SSN alone to exploit it.
             | 
             | This story is a good parable for so much of what has
             | changed in the world the last couple decades -- we had a
             | world built for less globalization, then we globalized, and
             | we've been gradually adapting to / dealing with the
             | unintended consequences since then.
             | 
             | A real life door can only be picked by your neighbors or
             | anyone else nearby -- attack surface is limited by the
             | nature of physical distance.
             | 
             | A virtual door can be picked at by 7 billion people.
        
             | xyst wrote:
             | I wonder if the schools actually verified the SSN.
             | 
             | Would have been dank to see 666-66-6666 next to your name
        
           | mdavidn wrote:
           | My first big employer in the aughts had my SSN encoded in a
           | bar code on the back of my company ID, which they expected us
           | to display at the office.
        
         | uticus wrote:
         | It's okay, will no longer be problem after Social Security
         | Admin itself fails in next decade for being unsustainable
        
           | vundercind wrote:
           | Why would that happen?
           | 
           | (Payouts are expected to drop in about ten years if no action
           | is taken, but that doesn't render the SSA irrelevant or cause
           | it to suddenly collapse and shut down, so I assume you mean
           | something else)
        
         | pixelesque wrote:
         | SSN might be the least of the problems in some cases in terms
         | of the info leaked...
         | 
         | What about people who have called suicide helplines, abortion
         | clinics, loan servicing, etc...
         | 
         | With the numbers available, that will be possible to find
         | out...
        
       | cwillu wrote:
       | "Brad Jones, chief information security officer at Snowflake,
       | told CNN in a separate statement that the company has not found
       | evidence this activity was "caused by a vulnerability,
       | misconfiguration or breach of Snowflake's platform." Jones said
       | this has been verified by investigations by third-party
       | cybersecurity experts at Mandiant and CrowdStroke.
       | 
       | AT&T said it launched an investigation, hired cybersecurity
       | experts and took steps to close the "illegal access point.""
       | 
       | That's pretty rich: "it wasn't misconfigured, it was just
       | illegally open, and now we're closing it".
        
       | zomg wrote:
       | when will governments hold these companies, but more importantly
       | their executives, criminally liable for their lack of protecting
       | customers' information?
        
         | hulitu wrote:
         | When they will not buy data from them. /s
        
       | mdale wrote:
       | Interesting that they use the word criminals instead of hackers..
       | makes it sound like it was a physical heist rather than poor
       | security practices on their part :)
        
         | demondemidi wrote:
         | They are criminals.
        
       | BenFranklin100 wrote:
       | This is a political problem. Until we pass laws that companies
       | can be find liable for significant damages in the event of data
       | breaches, we will see little progress on data security. This is
       | an area where Congress needs to act. Current law does not
       | adequately protect the public due to the difficulties in
       | establishing standing, tying specific breaches to specific
       | personal damages, other reasons.
       | 
       | Such a law would seriously impact current practices of the
       | majority of IT firms, including small app developers, which is
       | why we see little push from silicon valley for such changes.
        
       | abduhl wrote:
       | >> AT&T said it learned of the data breach on April 19, and that
       | it was unrelated to its earlier security incident in March.
       | 
       | Why was this not disclosed on AT&T's earnings call on April 24?
       | At least someone will get compensated for the breach, although
       | it'll be the lawyers for the class action lawsuit that's about to
       | hit instead of the customers that got their information stolen.
        
       | graybeardhacker wrote:
       | Freeze your credit people! It's super easy. It's not a perfect
       | fix but it's so trivial to do and it will help.
       | 
       | https://www.usa.gov/credit-freeze
       | 
       | You can unfreeze through an app whenever you want/need to.
        
         | pavel_lishin wrote:
         | Is there any reason not to keep credit frozen _permanently_ ,
         | only unfreezing it when you're making a large purchase that
         | requires it?
        
           | noodlesUK wrote:
           | Unfortunately it isn't an option in every country. In the
           | U.S., you can freeze your credit for free, but in the UK, you
           | can't. I think we should get rid of the CRAs entirely, but
           | that's a conversation for another day.
        
           | troyvit wrote:
           | That's what I do. It also slows my roll. It's an extra step I
           | have to take before making that large purchase or applying
           | for anything that requires a credit check.
        
             | yelling_cat wrote:
             | It's an extra step, but a surprisingly simple one. When I
             | opened a checking account recently the bank told me which
             | credit agency they'd use, and I unfroze that account and
             | ChexSystems (another credit agency you should freeze with
             | that is used specifically for new bank accounts) in five
             | minutes using their automated systems. You can supply a re-
             | freeze date when unfreezing as well so you don't need to
             | remember to do that manually once you're approved.
        
           | k4j8 wrote:
           | Keeping your credit frozen permanently is a great idea. Some
           | of the credit agencies even encourage this with features such
           | as a temporary unfreeze of your credit for a few days/weeks
           | and then back to the permanently frozen state.
        
           | tnel77 wrote:
           | It's a great idea! I only unfreeze my credit for big
           | purchases like buying a house or car.
        
           | david422 wrote:
           | Yep. This is what I did after the first Experian data breach,
           | for peace of mind. I am probably financially lucky enough
           | that I don't need to constantly be checking or using my
           | credit... but honestly it seems like this is what everyone
           | needs to be doing.
        
           | lotsofpulp wrote:
           | I open credit cards for the bonuses frequently enough that
           | freezing my credit would be more inconvenience than it's
           | worth.
           | 
           | Also, all the big bank websites seem to offer real time
           | credit history monitoring for free, so I am betting I'll just
           | deal with any problem if/when they happen.
        
           | rqtwteye wrote:
           | That's what I do. But it's a little bit of pain to unfreeze
           | your credit with three bureaus when you want a new credit
           | card. Wish there was a way to do this in one place.
        
             | r3trohack3r wrote:
             | After the first time unfreezing, I put the website URL,
             | unlock pins, and concise instructions for all 3 as a single
             | note in my password vault.
             | 
             | Doing all 3 takes ~5minutes now - which can usually happen
             | in parallel with whatever paperwork the vendor needs to get
             | in order.
        
           | al_borland wrote:
           | This is how I have operated ever since the Equifax breach.
           | Once that happened, none of the others seemed to matter,
           | everything important for identity theft is out there.
           | 
           | I've had no problems. Someone will try to run my credit, it
           | will fail, then I ask which one they're trying to use, and I
           | unfreeze it for a day. Some of them have the option to
           | unfreeze for a single pull with a 1 time code (if I remember
           | correctly), but when I tried to use that the person trying to
           | pull the report seemed clueless, so I had to do the 1 day
           | unfreeze.
        
             | bee_rider wrote:
             | Credit is a weird ad-how system.
             | 
             | At some point, I wonder if folks will realize that having
             | an unfrozen credit report is a sign of imprudence.
        
           | kodt wrote:
           | One interesting thing I ran into with frozen credit, is that
           | you cannot sign up for USPS informed delivery without them
           | running your credit as a method of address verification IIRC.
           | If it is frozen the process gets stuck in limbo (at least it
           | did many years ago when I ran into this situation)
        
             | golf1052 wrote:
             | This is no longer the case. I signed up for Informed
             | Delivery last year with frozen credit with no issues.
        
           | nijave wrote:
           | As someone else mentioned, some authentication schemes
           | require your credit to be unfrozen. This can include
           | insurance companies (really any company that needs to verify
           | your identity)
        
         | xyst wrote:
         | I typically don't "freeze" my credit but do have a handful of
         | services actively monitoring my credit for free (have been
         | involved with many data breaches) and it's included with my
         | credit cards.
         | 
         | > A credit freeze restricts access to your credit report
         | 
         | So if I freeze my credit, this will also deny access to the
         | monitoring services AND financial institutions, right?
         | 
         | Side note: financial institutions often do "soft" credit pulls
         | on active account holders to determine if they are eligible for
         | credit limit increases. Have been growing my existing credit
         | line for some time now without having to obtain additional
         | credit cards. So far, close to $500K in unsecured credit.
         | 
         | Seems more like a nuclear option.
        
         | psadauskas wrote:
         | Fuck that. I'm gonna open a bunch of credit cards, buy a bunch
         | of cool shit, and when they ask me to pay my bill, just say my
         | identity was stolen.
         | 
         | If I have to fight the credit bureaus anyway, I might as well
         | get something out of it. Stealing my own identity seems pretty
         | straightforward.
        
         | zzyzxd wrote:
         | I keep my credit frozen all the time, but still keep getting
         | alerts about new "no credit check" bank accounts from companies
         | like chime.com. Then I give them my PII again just to verify
         | and close those accounts, even though I don't have any business
         | with them.
        
         | lfmunoz4 wrote:
         | what app or website do you use? Seems like you have to sign up
         | for all three websites? Equifax Experian TransUnion?
        
         | therealmocker wrote:
         | I couldn't find a reference to an app on the linked page, could
         | you share more details on the app you use?
        
         | 93po wrote:
         | I was unable to get any of the three to verify my identity last
         | I did this, and one of the three has never once in my 15 years
         | of trying to get my free credit report let me actually get it.
        
           | nijave wrote:
           | I think you can go the paper route and mail something in to
           | freeze
        
         | neogodless wrote:
         | You can also freeze your non-credit banking:
         | 
         | https://www.chexsystems.com/security-freeze/place-freeze
         | 
         | It was recommended that I do this after a checking account was
         | opened using my identity.
         | 
         | As others have stated, my default is "frozen." I put temporary
         | thaws on when applying for credit, though in some cases, you'll
         | be informed exactly which agency/agencies will be queried, and
         | may not need to unfreeze all of them.
        
           | awad wrote:
           | This is a great tip as most people only know of the big 3,
           | thanks for sharing
        
         | currymj wrote:
         | i don't think credit freezing matters too much in this case
         | because the leak wasn't tied to SSN, name, etc. that would be
         | used for identity theft. it was phone call and location data.
         | much worse for privacy but less useful for financial fraud.
        
           | monetus wrote:
           | It sadly does matter for anyone who applied to work at
           | advance autoparts , though. Their SSNs and the like are out
           | there; the company's main database was hit.
        
       | zsdfgyn wrote:
       | Key point of the article:
       | 
       | "Snowflake allows its corporate customers, like tech companies
       | and telcos, to analyze huge amounts of customer data in the
       | cloud. It's not clear for what reason AT&T was storing customer
       | data in Snowflake, and the spokesperson would not say."
       | 
       | Finally journalists are asking the question why customer data
       | must be stored with third party cloud providers. AT&T is a long
       | way from Bell Labs, shame on them.
        
         | orochimaaru wrote:
         | All companies use third party cloud providers. A lot of legacy
         | companies have been shutting down data centers to move to the
         | cloud. So there isn't a question of whether why your data is in
         | the cloud. It's going to be in the cloud.
        
           | sbarre wrote:
           | And honestly, I think I'd rather trust cloud providers with
           | the data than the remnants of a decimated IT team in a large
           | enterprise that's struggling to maintain their own on-prem
           | infrastructure that's super old and probably not up to date
           | on patches.
        
             | Andrex wrote:
             | The problem is then you have even fewer technically-
             | competent people internally to actually manage the cloud,
             | and combined with AWS's many documented footguns it's not
             | clear to me the "new normal" is actually any better for
             | security.
             | 
             | You go from being a potentially-small-fry target to getting
             | your data collated in massive breaches. There's risks to
             | both.
        
               | orochimaaru wrote:
               | That's the thing though - this was a snowflake breach.
               | It's not an AT&T miss because of their decimated sw
               | engineering teams. Snowflake has much better sw
               | engineering than AT&T.
        
               | nicce wrote:
               | > this was a snowflake breach
               | 
               | AT&T was not using MFA, while it was possible. Someone
               | leaked credentials and this is the result. Only thing
               | Snowflake could have done was to force MFA for everyone.
        
               | lokar wrote:
               | They added a feature recently to make it easy to force
               | mfa
        
       | ChrisArchitect wrote:
       | Official support page: https://www.att.com/support/article/my-
       | account/000102979/
        
       | jonplackett wrote:
       | Unbelievable that they do not enforce 2FA for a client that huge.
       | Absolute madnesss!
        
       | MOARDONGZPLZ wrote:
       | Is this leak why the spam next messages have gone from "Hi how is
       | your day ?" or "Hi [not my name] please do thing X. Of you're not
       | [not my name] I'm so sorry perhaps we can be friends." to "Hi is
       | this [my full name]?" or "Hello [my first name] how is your day
       | ?"
        
         | jeffwilcox wrote:
         | Any leak with your mobile and name pair could have done that.
         | As a non-AT&T customer, I get the my-speecific-name pig
         | butchering texts, too.
        
           | MOARDONGZPLZ wrote:
           | True. They're brand new to me though. I've been getting the
           | former for years, the latter for only weeks.
        
       | bediger4000 wrote:
       | That's an enormous amount of data. How do you not notice a huge,
       | network-hogging data flow?
        
       | the8472 wrote:
       | The headline could equally say "AT&T kept data for criminals to
       | steal".
       | 
       | If wiretapping laws didn't exist then most of this data would not
       | be justified to exist. Flat-rate billing doesn't need to keep
       | track of this information. Even usage-based plans could keep
       | cumulative records rather than individual ones, or at least
       | delete them at the end of a billing period.
       | 
       | Where there is a trough, pigs gather.
        
       | throwaway120724 wrote:
       | There's no way to make the software perfectly safe from hackers
       | and from social engineering. So, yes, companies should be more
       | careful with the data and, yes, the data shouldn't be kept
       | forever. I agree companies should be doing more to protect the
       | data.
       | 
       | I see lots of outrage at the companies and why isn't the
       | government doing more to punish them and how do I get compensated
       | ...
       | 
       | But, I feel like everyone is blaming the victim. Is it the home
       | owners fault when someone breaks in and steals stuff?
       | 
       | Where's the outrage at the hackers breaking into these accounts?
       | Where's the "why aren't the governments tracking these people
       | down?" Why is no one demanding that the hackers be brought to
       | justice?
        
         | rightbyte wrote:
         | > But, I feel like everyone is blaming the victim. Is it the
         | home owners fault when someone breaks in and steals stuff?
         | 
         | > Where's the outrage at the hackers breaking into these
         | accounts?
         | 
         | The internet is essentially every hooligan in the world about
         | to kick in your dooor. So yes, I blame the home owner.
         | 
         | It seems silly to me to condemn anonymous users of the
         | internet.
         | 
         | Back in the days when nothing of importance was done on the
         | internet the view was way more healty.
         | 
         | If you have sensitive data, don't expose it to the hooligans.
         | Easy as that.
        
         | metabagel wrote:
         | > There's no way to make the software perfectly safe from
         | hackers and from social engineering.
         | 
         | This is a straw man argument. Companies should use best
         | practices in order to prevent most intrusions. When they do
         | not, as in this case, criticism is warranted.
        
         | throwway120385 wrote:
         | The problem with analogies is that they're a leaky abstraction.
         | You're comparing a single person with maybe a handful of
         | employees to a giant, multinational corporation with corporate
         | offices, hundreds of thousands of employees, enough real-estate
         | to create a small country, and billions of dollars per year in
         | revenue. It's a false equivalence to compare this to door
         | kicking like it was some kind of petty theft.
         | 
         | They literally kept everyone's information in a machine that
         | was connected to the internet and then didn't make any effort
         | to treat that with the gravitas it deserves. They are not the
         | victim here, we are. It's a little shameful that you don't see
         | that.
        
       | squeegee_scream wrote:
       | It's ok everyone! Protecting our data is one of AT&T's top
       | priorities.
       | 
       | > Protecting your data is one of our top priorities. We have
       | confirmed the affected access point has been secured.
       | 
       | > We hold ourselves to a high standard and commit to delivering
       | the experience that you deserve. We constantly evaluate and
       | enhance our security to address changing cybersecurity threats
       | and work to create a secure environment for you. We invest in our
       | network's security using a broad array of resources including
       | people, capital, and innovative technology advancements.
       | 
       | I hope there's an enormous fine for this kind of negligence
        
         | nashashmi wrote:
         | Not their fault. Snowflake was breached. And the data was with
         | Snowflake.
        
           | jeff_tyrrill wrote:
           | Your contractor being breached means you were breached.
        
           | hobs wrote:
           | Snowflake was "breached" by AT&T users using the same
           | password in Snowflake and another system that was breached.
           | 
           | This is just trivial pivoting done with some guesswork done
           | fairly well.
        
           | nijave wrote:
           | Snowflake wasn't breached. A Snowflake database belonging to
           | AT&T was breached.
        
             | nashashmi wrote:
             | You are right apparently.
             | 
             | > hundreds of Snowflake customer credentials ... of
             | staffers who have access to their employer's Snowflake
             | environment ... credentials available online linked to
             | Snowflake environments suggests an ongoing risk to
             | customers who have not yet changed their passwords or
             | enabled MFA.
        
           | jdgoesmarching wrote:
           | That's not how any shared responsibility model works
        
         | xyst wrote:
         | The "fine" will consist of a class action lawsuit that will
         | eventually (3-4 years later) be bargained down to 1/2 the
         | original claim. Lawyers take their 25% (or whatever cut was
         | negotiated) fee. Then the impacted customers (assuming they
         | submitted all of the claim paperwork) get paid out a few
         | dollars.
        
         | panarky wrote:
         | There may be no "good" telcos or big tech firms, but some are
         | absolutely worse than others. AT&T is actively hostile in a way
         | others aren't.
        
       | OutOfHere wrote:
       | Unfortunate as it is, nobody genuinely cares about:
       | 
       | 1. Preventing data breaches
       | 
       | 2. Properly anonymizing aggregated personally identifiable data
       | 
       | 3. Having and using a secure ID and verification system
        
         | gmd63 wrote:
         | They don't care because they don't know how the systems they
         | use daily work, much less the costs and risks involved.
         | 
         | If they knew, they would care, and that's why representatives
         | care on their behalf.
         | 
         | You could say the same about health and nutrition, but people
         | very much do care when a medical issue tangibly affects them
         | negatively.
        
         | mv4 wrote:
         | I am seeing this mentality as well, and it's disheartening. My
         | company manufactures and sells a privacy-first, fully
         | autonomous, on-prem, video security system for home and SMB.
         | Yet, some people choose a cloud based service (convenient) and
         | are surprised when their private data is either a) hacked, or
         | b) abused by the provider's own employees (see the latest
         | Amazon Ring settlement).
         | 
         | With the latest scandals and breaches though, I feel it's
         | gradually starting to change.
        
       | stevetron wrote:
       | AT&T bought into a significant amount of DirecTV - so much so
       | that everything that had the DirecTV logo on it was changed to
       | the AT&T logo, such as the invoicing. So the AT&T customer base
       | has included, for several years, the Directv customer base. The
       | article doesn't attempt to clarify who the 'nearly all' customers
       | are, and some people will jump to the conclusion that it is the
       | cell phone customers. But it could include the DirecTV customer
       | base whose data is also at risk.
        
         | vel0city wrote:
         | AT&T didn't just buy into a significant amount of DirecTV, they
         | _owned_ DirecTV. As in, 100% ownership. So yes, all DirecTV
         | customers were AT &T customers, because AT&T and DirecTV were
         | not separate entities. It wasn't until 2021 that DirecTV was
         | spun off into a separate company again, but still with 70%
         | ownership by AT&T.
        
         | hermitdev wrote:
         | AT&T does a lot more than just cell phones. Probably also the
         | largest US ISP behind Comcast, I'd expect. I had AT&T fiber to
         | the home at a previous residence, and that was a great product.
         | Far superior to Comcast.
        
       | skybrian wrote:
       | > Snowflake blamed the data thefts on its customers for not using
       | multi-factor authentication to secure their Snowflake accounts, a
       | security feature that the cloud data giant did not enforce or
       | require its customers to use.
       | 
       | And is that going to change?
        
         | dboreham wrote:
         | This is a diversion. Why did they build a system that permitted
         | a bulk database dump of hundreds of millions of rows even with
         | 2FA?
        
           | skybrian wrote:
           | Because that's what a data warehouse is? You'd think they'd
           | guard them more, though.
        
           | vel0city wrote:
           | > Why did they build a system that permitted a bulk database
           | dump of hundreds of millions of rows
           | 
           | Should all databases be capped at a few million rows total or
           | something? I don't quite understand where you're going with
           | this.
        
       | MisterBastahrd wrote:
       | Be nice to have a new federal law: you get breached, you pay $5K
       | plus lifetime credit monitoring to each person involved. Non-
       | dischargeable by bankruptcy. No arbitration, no lawsuit. You pay.
        
         | joemi wrote:
         | Interesting idea, though I think that having it be $5K (or any
         | fixed amount) no matter the size of the company favors large
         | companies, since large companies can probably spend more to
         | reduce the risk of getting hacked. Hell, it might even
         | incentivize large companies to fund hackers to breach their
         | smaller rivals, in order to wipe out their competition.
        
       | kjellsbells wrote:
       | I find it interesting that in your typical BigCo breach, they are
       | at pains to point out that credit card details were not stolen. I
       | infer from this that something about credit cards, and how they
       | are secured, has real teeth and BigCo's lawyers are trying to
       | stop them biting. Is this PCI-DSS? Maybe someone can comment.
       | 
       | As far as this breach goes, I think it just confirms my gut feel
       | that Snowflake are heading to the wood chipper.
        
         | jeff_tyrrill wrote:
         | I think it's a desperate attempt to downplay the severity in
         | any way plausible, taking advantage of the fact that credit
         | card numbers and social security numbers have been mythologized
         | in the American consciousness as nearly-mystical totems of
         | identity and security, as part of the "identity theft" meme,
         | even though they play little role in actual information
         | security or privacy.
        
       | mensetmanusman wrote:
       | Nice way to rule out who is a spy or not. Nice.
        
       | autoexec wrote:
       | > The company said the hack wouldn't be material to its
       | operations or negatively impact its financial results.
       | 
       | And this is why consumers will continue to see their information
       | compromised by companies who collect and retain more data than
       | they need and then fail to invest the time and resources to
       | protect it.
        
       | JoshTriplett wrote:
       | "AT&T reveals it has records of cellular customers calls and
       | texts"
       | 
       | These records should have been deleted at the _latest_ at the
       | point where they 're no longer relevant for billing. (Which also
       | means that for customers with unlimited calling/texting, there
       | shouldn't be any records in the first place.)
        
         | gumby wrote:
         | I believe this practice was followed only in postwar France,
         | and I think even there has long been jettisoned. It's been a
         | while since I got a French phone bill though.
        
         | xyst wrote:
         | AT&T is well known for working with NSA -- 33 Thomas St [1]
         | 
         | [1] https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-
         | new-...
        
           | rockskon wrote:
           | That doesn't excuse this. If these records only existed so
           | they could give them to the NSA at a later time, that further
           | illustrates the dangers of accommodating the agency's desire
           | for access to data generated from the U.S. Telecom backbone.
        
             | SoftTalker wrote:
             | If they are obligated to give the data to the NSA, they
             | should give it to them in real time and then delete their
             | own logs as soon as they no longer need them.
        
             | spencerflem wrote:
             | It does explain it though. By coincidence they also get
             | billions of dollars in federal subsidies
        
               | rockskon wrote:
               | So do other ISPs. Yet AT&T is by far the worst of all of
               | them with regards to customer privacy.
               | 
               | Did you know that AT&T has a commercial product where
               | they sell Metadata of websites visited (unclear if it's
               | only Netflow or if it includes DNS lookups too) to law
               | enforcement and private investigators?
               | 
               | AT&T is a blight on the privacy of U.S. citizens.
        
               | hulitu wrote:
               | > Did you know that AT&T has a commercial product where
               | they sell Metadata of websites visited (unclear if it's
               | only Netflow or if it includes DNS lookups too) to law
               | enforcement
               | 
               | Do you think that only AT&T does it ? Welcome to
               | democracy, my friend. /s
        
               | rockskon wrote:
               | For their landline customers? I'm not aware of any other
               | ISP that's so shamelessly brazen about the practice.
        
         | Cheer2171 wrote:
         | They keep all records for 7 years because the US Federal
         | Government asked them to, not because they legally have to, but
         | same with T-Mobile and Verizon:
         | https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...
        
           | pixl97 wrote:
           | Wasn't there some telco executive that was tossed in jail not
           | long after 9/11 because he didn't want to play along with the
           | government and keep data around forever?
        
             | Lammy wrote:
             | https://en.wikipedia.org/wiki/Joseph_Nacchio
             | 
             | > Joseph P. Nacchio was the only head of a communications
             | company to demand a court order, or approval under the
             | Foreign Intelligence Surveillance Act, in order to turn
             | over communications records to the NSA.[11]
        
         | clwg wrote:
         | I wish that were the world we live in.
         | 
         | This is from the Snowflake breach, meaning this database was an
         | "AI Powered Unified Data Platform." It almost feels like the
         | erosion of our privacy is fueling the growth of allot
         | companies.
         | 
         | I really hope that the boogeyman is real and all this was worth
         | it.
        
       | gumby wrote:
       | The data can be used for traffic analysis (number->number call
       | data); "no PII" except it's pretty easy to match a number to a
       | likely user.
       | 
       | I'm an AT&T customer, and in my case I don't have a risk, but I
       | can imagine this info could be very handy for divorce, custody,
       | and corporate IP lawsuits. So worse than it might look to
       | ordinary folks.
        
       | spacephysics wrote:
       | Text _meta_ data is an important distinction
       | 
       | Still not good, but headline feels clickbait if I think my text
       | messages leaked
        
         | ethbr1 wrote:
         | That's still pretty gnarly in terms of social graphing though.
        
       | SoftTalker wrote:
       | "While the data does not include customer names, there are often
       | ways, using publicly available online tools, to find the name
       | associated with a specific telephone number"
       | 
       | In other words, your phone number and name is likely in a public
       | record somewhere. It's not that private.
       | 
       | The info leak should not have happened but in the grand scheme of
       | things it's not that big a deal. "The content of the calls and
       | messages was not compromised." The worst it does is reveal who
       | has been sending messages to or calling each other.
        
         | BobAliceInATree wrote:
         | That metadata was can be terrible for many people like
         | politicians, those having affairs, drug dealers or buyers,
         | those with sensitive healthcare providers, and so on.
        
           | mass_and_energy wrote:
           | This. If you're in an abusive relationship and your abuser
           | sees that you're calling a lawyer, a helpline, a family
           | member etc, bad things can happen quite quickly. This
           | information is non-public for a reason, and you don't have to
           | be a drug dealer to be protected by it either.
        
             | SoftTalker wrote:
             | Yeah it's not good. But would be worse if the actual
             | contents of the messages had been leaked.
             | 
             | That said the few abusive people I know are not smart
             | enough to find data dumps of AT&T call records on the dark
             | web. Nor could they pay for them. Nor could they likely
             | make sense of them. But I'm sure some could.
        
       | CuriouslyC wrote:
       | Big breaches like this are gonna be wild with advanced GenAI.
       | Combing through the shit for the diamonds provided some degree of
       | limitation on the impact of big breaches in the past but all
       | those calls are going to be accurately transcribed and mined by
       | AI and the attackers are going to have a buffet of products and
       | targets laid at their feet.
        
         | mass_and_energy wrote:
         | It's just metadata, no transcription of calls can take place.
         | In the future, please read the article before engaging in the
         | discussion of its content.
        
           | nunez wrote:
           | Metadata can be identifying enough. For example, given
           | someone has this data and some local LLaMa variant on their
           | machine, they could theoretically run a query like: "Give me
           | all of the people that $NAME have called to, sorted by the
           | number of times they called each other"
        
           | hulitu wrote:
           | > It's just metadata
           | 
           | That's what they always say, honey, before calling the
           | police. /s
        
       | II2II wrote:
       | My first question is: why was the data being stored by a third
       | party in the first place?
       | 
       | Shouldn't data like this be stored completely independently of
       | the Internet? Yes, I realize that does not guarantee it is secure
       | since there has to be some point of access. On the other hand, it
       | would reduce opportunities for people to breech the databases.
        
         | Cheer2171 wrote:
         | Because they don't care about actual information security, they
         | care about "national security." They optimize for giving all
         | branches of US law enforcement, from the federal to state to
         | local level, access to 7 years of historical data whenever they
         | claim they need it.
        
           | II2II wrote:
           | I don't buy into that theory, at lrast in this case. There
           | are other ways to hand-off data when it is legally requested.
           | On the other hand, such data would be valuable to foreign
           | actors who do not have a legal means of accessing such data.
           | It would require a high degree of incompetence to sacrifice
           | national security in the name of convenience.
        
       | chasenjohnson wrote:
       | You would effectively be able to cross reference this meta data
       | with 2 factor authentication services. It's probably time to
       | start removing this option entirely.
        
         | sedatk wrote:
         | How would cross-referencing be useful? You'd just find out what
         | services people use?
        
           | rboyd wrote:
           | I guess after mapping the services used you would find the
           | accounts worth going for and those become SIM swap targets
        
             | mikeocool wrote:
             | Seems like there's a lot of cross referencing well beyond
             | MFA that this'll likely be used for.
             | 
             | Way easier to target phish people's bank logins, if you
             | know what banks they are regularly communicating with.
        
           | chasenjohnson wrote:
           | If GitHub always uses the same number(s) for 2fa and there
           | are outgoing texts to your number then the connection is
           | obvious. I've read that sim jacking is somewhat common and
           | this would be a good data point.
        
             | sedatk wrote:
             | So, just for discovering what services people use?
        
       | throwaway81523 wrote:
       | This happened in 2022 and they're just disclosing it now? Or did
       | they just find out about it, which is maybe even worse?
        
         | JohnMakin wrote:
         | The data was from 2022. The breach was from april of this year.
        
           | tardy_one wrote:
           | Who was the data being kept for?
        
             | JohnMakin wrote:
             | ATT did not answer this question. I would expect them to
             | keep phone records going back a ways, but 2022 seems pretty
             | far. I'd guess for law enforcement.
        
               | throwaway81523 wrote:
               | I think there is a requirement to keep them 18 months.
               | Any reasons to keep them in bulk for longer than that are
               | probably bad.
        
             | weberer wrote:
             | Likely the NSA
             | 
             | https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-
             | new-...
        
         | molave wrote:
         | The authorities requested the delay of the disclosure:
         | https://cbs58.com/news/nearly-all-at-t-cell-customers-call-a...
        
       | mjevans wrote:
       | These are all security nightmares aren't they? It smells as if
       | all the resources went into delivering billing, then barely
       | enough for technically working service, and then is there even
       | anything leftover for security (instead of this being part of the
       | foundation of a service)?
        
         | hateful wrote:
         | Something happens when you tune your business only to the
         | things you can measure.
         | 
         | I still (or at least try to still) have this naive opinion that
         | if you make a good product, the money will come.
         | 
         | We sometimes spend too much time counting the beans and not
         | enough time growing them. Not saying you don't need to count
         | the beans, you do, but when your whole team is counting, they
         | may forget to water them.
         | 
         | Also - to be on topic - don't forget to protect the beans!
        
       | blessedwhiskers wrote:
       | The TechCrunch article indicates cell site identifiers were
       | included, which means approximate location as well.
       | 
       | https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...
        
       | dapearce wrote:
       | No dates or timestamps included meaning they were using the data
       | to build a social graph.
        
       | yiamvino wrote:
       | I might be lone wolf here but I kind feel pity for ATT I dont
       | know why they are solely getting all the loathe here . actual
       | incident occurred on public cloud provider who had not provided
       | secure tools practice to their customer. so in this customer
       | getting blamed for buying service cloud provider lack of best
       | practices.
        
       | smcin wrote:
       | Some new news in the article and comment:
       | 
       | - [security expert] "This [logs without timestamps] isn't one of
       | their main databases; it is metadata on who is contacting who.
       | Its only real use is to know who is contacting whom and how many
       | times."
       | 
       | - [commenter] "I have a theory that this call log was being used
       | for a national security investigation. Otherwise why would this
       | rise to the level of public safety/national security exemption?"
       | [with two DOJ-approved 1-month delays for disclosure]
       | 
       | So, someone set up a separate Snowflake instance with mostly May-
       | Oct 2022 AT&T data (90% former customers) apparently for that
       | purpose. And left it up. Will anyone in Congress (e.g. Sen Ron
       | Wyden) ask who did and why? (Another commenter on HN pointed out
       | that Roe v Wade was overturned 6/2022, presumably that was not
       | the intent of the original national-security investigation, but
       | there's a potential for privacy abuse by the hackers' customers
       | beyond everyday spam)
       | 
       | - In early 2023, Snowflake set up a unit especially for Telco
       | data. But when you read the blurb (below), this product is not
       | aimed at the telco's use-case; coincidentally this was also
       | around the time Snowflake was touting integration with GenAI.
       | 
       | "Unlocking the Value of Telecom Data: Why It's Time to Act"
       | https://www.snowflake.com/blog/telecom-data-partnerships/
       | 
       |  _" Telecoms are the connecting tissue of the modern economy.
       | They run everything... growing importance... hyperconnectivity.
       | 
       | What makes telecom service providers unique is that they have
       | access to consumer location data. For most other industries, a
       | consumer can go into their phone's privacy settings and turn off
       | the location access in the smartphone app. But in the world of
       | telecom, as long as the phone is connected to a network, the
       | telecom provider can use triangulation to find the approximate
       | location of a consumer. This is why there is an emerging trend of
       | companies [which ones?] building partnerships with telecoms to
       | power use cases across multiple industries from competitor
       | intelligence, alternate credit scoring, hyper-targeted marketing
       | and more.
       | 
       | ... Yet, despite the importance of telecommunications for society
       | and in connecting industries, network operators are not yet fully
       | embracing the value of the data they have at their fingertips"_
       | 
       | But the value of this data (90% former customers) was clearly not
       | to the telco itself... so who is the unnamed partnership and who
       | is the end-customer? And was one of Snowflake's AI partners
       | involved?
        
         | koolba wrote:
         | > Its only real use is to know who is contacting whom and how
         | many times.
         | 
         | Which is exactly the type of info that would be used to find
         | evidence of an affair.
         | 
         | Though this is specific to SMS so it would not include iMessage
         | or other messaging apps.
        
           | nerdponx wrote:
           | Do organizations like Planned Parenthood offer SMS support?
        
         | axus wrote:
         | Didn't Congress already rubber-stamp AT&T sending the NSA this
         | data?
        
       | riffic wrote:
       | did they just enumerate an open web endpoint for it or something?
        
         | nerdponx wrote:
         | The data was stored in a cloud data warehouse called Snowflake,
         | which had a major breach recently.
        
         | itscrush wrote:
         | API based credentials are just username + password in this
         | context, nothing else seems to be restricting access to data.
         | So if your Snowflake tenant isn't enforcing IP restriction to
         | limit source auth attempts, those creds can be used to pull the
         | data from any source IP.
         | 
         | Even then, you'll still have an HTTP 403 response layer
         | filtering those auth attempts based on IP... where we can
         | assume these failed to implement it.
         | 
         | So far between TechCrunch, Wired, and other reporting it seems
         | most claim creds get owned, sold, then used against under-
         | restrictive Snowflake tenants which are exposed by default.
         | 
         | i.e; https://epa06486.snowflakecomputing.com/console/login#/
         | here's someone's tenant, if you were able to go buy some creds
         | for it, should walk right in.
         | 
         | [edit] I have a more detailed Snowflake comment with references
         | that might fill in better gaps here;
         | https://news.ycombinator.com/item?id=40554753
        
           | lokar wrote:
           | You can use oath or rsa keypair for service account auth
        
       | gz5 wrote:
       | The root cause (1) is the data store should not have been
       | available on the underlay network. Anything connected to an
       | underlay network is a ticking time bomb.
       | 
       | Any servers or admins which need to talk to the data store should
       | instead use a private overlay (2) network.
       | 
       | Any users (likely just remote admins) should do the same.
       | 
       | (1) Same root cause as 99% of breaches and yet it is too often
       | swept under the rug while we focus on the infinite # of proximate
       | causes
       | 
       | (2) Software, not private circuits.
        
         | jodrellblank wrote:
         | It seems from the article that AT&T uploaded data to a cloud
         | service, protected by username and password, and someone
         | obtained credentials or breached the cloud service.
         | 
         | What does that have to do with 'underlay networks' and wow is
         | that "the root cause of 99% of breaches"?
        
           | gz5 wrote:
           | An attacker who gets username/pw still can't get on the
           | overlay network (the overlay requires credentials which can't
           | easily be stolen or compromised, e.g. a private key signed
           | X.509 certificate).
           | 
           | Yes, because 99% of attacks use the underlay network to
           | access the target and exfiltrate the data. Said the other
           | way, an attacker didn't physically walk into a Snowflake data
           | center, console into the right server, and walk out with all
           | the data.
        
             | Aloisius wrote:
             | That sounds more like the lack of certificate-based
             | authentication (or some other stronger authentication
             | method) was the problem, not the lack of a private overlay
             | network.
             | 
             | After all, plenty of private overlay networks use simple
             | username/password auth or no auth at all.
        
               | gz5 wrote:
               | Agree, good point, the overlay needs to do strong
               | identity, authN, authZ.
               | 
               | The critical part the overlay adds to traditional auth is
               | making the server unreachable from the underlay networks,
               | reducing attack surface by billions. Meaning:
               | 
               | + Let's say the server did have good auth, but there was
               | a bug, misconfig, zero day, etc. (one of the myriads of
               | proximate causes).
               | 
               | + Since the server is available on the underlay network,
               | that vulnerability can be exploited by anyone on the
               | underlay (billions Internet nodes).
               | 
               | + In contrast, making the server only available on the
               | overlay, reduces the attack surface from billions of
               | Internet nodes to the nodes which can ID, authN and authZ
               | (for that particular server) on the overlay.
        
           | jvanderbot wrote:
           | I doubt they "breeched the cloud service" _provider_. They
           | almost certainly exploited no 2fa controls _on the clients
           | access_ via _the clients network_ , which is what GP was
           | saying. If you're on a businesses network it's too easy to
           | get at their cloud storage or dbs because they should be on a
           | secure overlay network.
        
           | wmf wrote:
           | OP is using weird terminology. It would probably be clearer
           | to say "Anything connected to the Internet is a ticking time
           | bomb. Any servers or admins which need to talk to the
           | database should instead use a VPN." which indeed was best
           | practice until recently.
        
             | mbreese wrote:
             | _> indeed was best practice until recently_
             | 
             | But we should remember why it's not always considered best
             | practices... you shouldn't assume that your private network
             | is any more secure than the public network. When you have
             | too many devices attached to that private (overlay?)
             | network, it can be at just as much risk as if it was on the
             | public internet. So, the zero-trust model is that you don't
             | trust anything... public... private... it should all be
             | untrusted.
             | 
             | Given that this was a "third-party cloud provider", I'm
             | assuming that it was a credential leak and they only have
             | username/password protections. Moreover, I doubt you'd have
             | been able to add the provider's DB to an ATT based private
             | VPN/network.
        
               | gz5 wrote:
               | yep was trying to avoid word which carry varying
               | connotations, e.g. vpn or zero trust.
               | 
               | zero implicit trust is likely the best term? you have to
               | trust something, but enforce (and therefore trust) strong
               | (not network based) identity, authN and authZ. this can
               | be done anywhere via a software-only overlay.
               | 
               | a litmus test is server iptables (to use an example)
               | looks like: iptables -P INPUT DROP iptables -P FORWARD
               | DROP
               | 
               | and the only route outbound from the server is to the
               | private overlay on one port, and that server still can't
               | make those connections unless it is strongly identified
               | and authenticated, and the overlay will not connect the
               | client and server unless they are both authorized to
               | communicate for that particular service(1)
               | 
               | (1)so for example if there is a zero day causing the
               | 'server' to try to communicate with some_IP then the
               | private overlay will not accept the connection, even
               | though it is coming from the server
        
               | mbreese wrote:
               | For highly secured services, I completely see the
               | rationale for a private overlayed network. Tailscale, et
               | al are great for this, where you're only exposing
               | services to members of the private network. The problems
               | start when people make the assumption that the private
               | network is a secured network.
               | 
               | I don't think any of this would have mattered to ATT, as
               | the breach was from a third party that wouldn't have been
               | on a private network anyway.
               | 
               | But, that would be a great service bonus -- only being
               | able to connect to a service via a user-configurable
               | private overlay network. It would be nice, but highly
               | impractical... I can't even begin thinking about how
               | customer support would be able to handle a scheme like
               | this.
        
         | biggc wrote:
         | What? Has anyone published an RCA that confirms this? Is this
         | how the data was ex filtrated from Snowflake? Or did ATT's
         | Snowflake credentials leak?
        
         | reaperducer wrote:
         | _Software, not private circuits_
         | 
         | If only AT&T had some kind of way for its computers to talk to
         | one another without going over the public internet...
        
       | nequo wrote:
       | @dang Could I ask why this topic gets systematically penalized in
       | the HN ranking? There have been 15 submissions so far, I assume
       | partly because previous submissions are not shown on the main
       | page so HN users keep re-submitting it. This topic is both
       | newsworthy and high interest.
       | 
       | (I was going to link to the 14 other submissions but the list is
       | too long and it'd just come across as obnoxious.)
        
         | behnamoh wrote:
         | The new HN voting mechanism is broken imo. Useless posts and
         | articles of low value make it to the frontpage but valuable
         | ones get shadowed.
        
           | arrowsmith wrote:
           | There's a new voting mechanism?
        
             | robxorb wrote:
             | And where do we go to find out about these things? Is there
             | a discussion space or something?
        
               | nvr219 wrote:
               | Nah
        
         | nanidin wrote:
         | At the moment this is #1 on the frontpage.
        
         | bloopernova wrote:
         | The threads have probably tripped the flamewar detector.
         | Certain amount of comments plus some other metrics will hide
         | the thread from the front page.
        
       | DarkmSparks wrote:
       | Isnt this just a legally mandated api for all phone operators in
       | the US?
       | 
       | Edward Snowden published several slide decks about it a few years
       | ago, before he defected to Russia.
        
         | lfmunoz4 wrote:
         | think you don't know the definition of defected
        
           | booleandilemma wrote:
           | What do you think would have happened to him if he had stayed
           | here?
           | 
           | The last whistleblower the US government got to was
           | imprisoned for seven years and identifies as a woman now.
           | 
           | Snowden would be crazy to come anywhere near the US.
        
             | 1d22a wrote:
             | I'm not sure why gender identity is relevant. I agree that
             | the punishments he would have gotten for whistleblowing
             | justify him not staying in the US.
        
             | nolok wrote:
             | He didn't disagree with the need to leave for Snowden, he
             | said it wasn't a defection.
             | 
             | Snowden hasn't defected the US anymore than the Dalai Lama
             | has been deflected Tibet.
             | 
             | I guess "went into exile" would be the proper naming.
        
             | blueblob wrote:
             | The parent wasn't arguing he should come back but saying
             | that "defected" is not the correct word. The correct phrase
             | is probably "took asylum."
        
           | hn92726819 wrote:
           | Why are you booing him? He's right!
           | 
           | > to forsake one cause, party, or nation for another often
           | because of a change in ideology
           | 
           | I don't think he left because of a change in ideology.
        
             | slim wrote:
             | he was not heading to russia. he's just trapped there
        
               | DarkmSparks wrote:
               | Of course. He accidentally tripped, fell, and landed in
               | Sheremetyevo International Airport with a nice cushy job
               | in the Russian government, with Russian citizenship and a
               | nice estate worth 10s of millions of dollars, and clearly
               | just accidentally mispoke when he swore allegiance to
               | Russia. All the nsa secrets he took with him were
               | irrelevant to that story, typical of any asylum seeker
               | arriving anywhere.
               | 
               | lol, oops, I forgot how triggered some people get for
               | calling it defecting.
        
         | not2b wrote:
         | It doesn't appear to be, though it was speculated that it might
         | be. Companies keep all that data in the hope of making money by
         | mining it.
        
       | wly_cdgr wrote:
       | Why did it take them over a year and a half to disclose this?
        
         | u32480932048 wrote:
         | Something, something, national security?
        
           | smcin wrote:
           | The DOJ approved two 1-month "delay periods", first in May,
           | then in June, as part of the criminal investigation. We found
           | that out earlier this morning, see earlier discussion.
        
         | JohnMakin wrote:
         | It didn't. The breach happened in april of this year. The data
         | is from 2022.
        
       | advael wrote:
       | It's disgusting that we still write headlines as "hackers steal"
       | rather than "enormous company fumbles security for data they
       | should never have retained"
        
         | SJMG wrote:
         | That is a good reframe.
        
         | mrbluecoat wrote:
         | How can I upvote this a million times?!
        
       | not2b wrote:
       | "It remains unclear why so many major corporations persist in the
       | belief that it is somehow acceptable to store so much sensitive
       | customer data with so few security protections."
       | 
       | It's because there are almost no consequences to them if they
       | lose the customer data, beyond a day or two of bad press. If they
       | faced significant fines, fines that get worse the more sensitive
       | the data is, then they'd have an incentive to do better.
        
         | Jaygles wrote:
         | No consequences, the cost can be great, and it can negatively
         | impact productivity by introducing hurdles to legitimate uses.
         | Those are immense pressures a soulless company will need to
         | overcome to do the right thing.
        
       | fnord77 wrote:
       | so just metadata, not the actual texts or PII
        
         | macintux wrote:
         | "Just" is a dubious adjective in this context.
        
         | wordpad25 wrote:
         | your phone number is PII and everybody you ever called or
         | texted is VERY VERY PII
        
       | RyanAdamas wrote:
       | Criminal charges need to be filed and class action lawsuit for
       | fraudulent services for all the customers duped into renewing
       | monthly services ignorant of the fact the service is not secure
       | as plainly stated it must be in federal law.
        
       | advael wrote:
       | At the scale of this kind of incompetent failure, no human being
       | should be on board with the narrative that we should be blaming
       | "criminals" for this
       | 
       | If we don't hold companies accountable for keeping far more
       | access and retention than should be legal, and securing their
       | systems poorly, this situation will never get better
        
         | balls187 wrote:
         | Who is the "we" here? And how should companies be held
         | accountable?
         | 
         | It's very rare for someone at the highest level to be held to
         | any kind of liability, and paying fines rarely, if ever, causes
         | these too-big-to-fail corporations to materially impact them.
         | 
         | Strictly speaking about the US here.
        
           | advael wrote:
           | Needs to be at the level of enforcement by regulatory
           | agencies, large scale lawsuits backed by state governments,
           | and maybe even congressional action
           | 
           | These companies have scale as their moat and that's called a
           | monopoly. We need to be aggressively pursuing corporate
           | malfeasance, closing loopholes, and breaking up companies. In
           | my ideal world the entire doctrine of the "corporate veil"
           | would be overturned, but that seems unlikely to happen
           | without drastic upheaval. Antitrust action and large-scale
           | suits can happen and to some degree those wheels are already
           | in motion, but it would help a lot to stop buying this
           | bullshit about how we should think of this as a "crime" for
           | which we should uniquely blame hackers. These megacorps want
           | to pretend that they and their customers are in solidarity as
           | victims of the hackers. In reality, these companies get hit
           | with essentially none of the consequences, and their
           | practices are most of the relevant causal factors. A better
           | model would be that the customers (and often non-customers on
           | whom they collect data without even the figleaf of
           | manufactured consent) are victims of the companies and the
           | hackers
        
             | balls187 wrote:
             | These companies are so massively large that they price in
             | the risk of databreaches as a cost of doing business.
             | 
             | Insurance Underwriters pour through corpo infosec
             | documents, and require only the most basic level of
             | protections.
             | 
             | I think instead, a stricter certification standard needs to
             | be created, and all these large companies must pass ANNUAL
             | audits, or simply lose access to government leased
             | spectrum.
        
               | advael wrote:
               | It seems that we agree that regulatory enforcement is a
               | great framework through which to make this happen. I
               | think we should regulate both security and data retention
               | far more aggressively, and be willing to destroy
               | companies if they fail to comply. The lack of an
               | existential risk makes it easier for them to maneuver
               | around other solutions
        
               | tuxone wrote:
               | > These companies are so massively large that they price
               | in the risk of databreaches as a cost of doing business.
               | 
               | Just make the fine a % of the annual revenue and that
               | will change.
        
           | slg wrote:
           | > paying fines rarely, if ever, causes these too-big-to-fail
           | corporations to materially impact them.
           | 
           | That means the fines aren't big enough. They should probably
           | be scaled according to the business' revenue.
        
             | waterhouse wrote:
             | From a justice perspective, it should be scaled according
             | to the number of customers impacted (and how bad the impact
             | was). Which is likely to be about the same as scaling with
             | revenue.
        
       | Animats wrote:
       | _" still-unfolding data breach involving more than 160 customers
       | of the cloud data provider Snowflake.'_
       | 
       | So what is Snowflake normally doing with all that AT&T data?
       | Redistributing it to "marketing partners"? Apparently.
       | Snowflake's mission statement, from their web site:
       | 
       |  _" Our mission is to break down data silos, overcome complexity
       | and enable secure data collaboration between publishers,
       | advertisers and the essential technologies that support them."_
       | 
       | So this was not, apparently, a break-in to the operational side
       | of AT&T. Someone unauthorized got hold of data they were already
       | selling to marketers. Is that correct?
        
         | biggc wrote:
         | ATT could be using Snowflake for internal analytics
        
           | smcin wrote:
           | It's not "internal analytics", because a) 90% of the data was
           | former customers and b) it has location data but timestamps
           | were removed, so it's social-graph information plus location.
           | Start asking yourself what sorts of end-users want to pay for
           | the entire social-graph of 77m, regardless whether those
           | customers never make a phone call again.
           | 
           |  _" Alternate credit scoring, hyper-targeted marketing and
           | more... an emerging trend of companies building partnerships
           | with telecoms to power use cases across multiple
           | industries."_ was the blurb for the unit Snowflake specially
           | set up for Telco data in early 2023 touting "location data",
           | but this product is not aimed at the telco's use-case;
           | coincidentally this was also around the time Snowflake was
           | touting integration with GenAI.
           | 
           | (It's not "competitor analysis" either, because if it was
           | they would have obscured the 68m former phone numbers to
           | prevent abuse by direct-marketing.)
           | 
           | [0]: "Unlocking the Value of Telecom Data: Why It's Time to
           | Act" https://www.snowflake.com/blog/telecom-data-
           | partnerships/
        
             | Animats wrote:
             | Snowflake PR, from the link above: _" What makes telecom
             | service providers unique is that they have access to
             | consumer location data. For most other industries, a
             | consumer can go into their phone's privacy settings and
             | turn off the location access in the smartphone app. But in
             | the world of telecom, as long as the phone is connected to
             | a network, the telecom provider can use triangulation to
             | find the approximate location of a consumer. This is why
             | there is an emerging trend of companies building
             | partnerships with telecoms to power use cases across
             | multiple industries from competitor intelligence, alternate
             | credit scoring, hyper-targeted marketing and more."_
             | 
             | That pretty much says it.
             | 
             | It's disappointing that TechCrunch didn't point this out.
             | Nor did the New York Times.[1] Yet it's right there on
             | Snowflake's site.
             | 
             | [1] https://www.nytimes.com/2024/07/12/business/att-data-
             | breach....
        
               | smcin wrote:
               | - [EDIT: I confused the details of this AT&T breach with
               | the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO
               | customers, 90% of them former customers]. This one is
               | 110m customers, presumably all their current
               | customerbase.
               | 
               | - Yes about the Snowflake's cloud telco unit explicitly
               | marketing the fact that telco data contains location. See
               | my updated post:
               | https://news.ycombinator.com/item?id=40949640
        
         | lokar wrote:
         | It's a cloud database, mostly olap. The ATT account was secured
         | with a bad password and no mfa.
        
         | jmspring wrote:
         | This would probably be no different if someone like Salesforce
         | had a breach and a large customer of theirs being impacted.
         | There are large companies using SaaS services for a chunks of
         | their back office stuff.
        
         | Root_Denied wrote:
         | If that's the case then they're probably more upset that
         | they're not getting paid for this data than anything else.
        
       | declan_roberts wrote:
       | I would like to sue AT&T in small claims for this and for leaking
       | my Social Security number. But it's difficult to prove damages in
       | these situations.
       | 
       | Does anybody have any advice? Proving damages means showing
       | actual monetary harm.
        
         | josh-sematic wrote:
         | IANAL but this would seem like a "class action" situation.
        
           | vdqtp3 wrote:
           | I also ANAL but if I recall correctly, you can decline to be
           | represented in the class, and file your own lawsuit
        
           | whalesalad wrote:
           | can't wait to get that check in the mail for $1.32
        
             | reaperducer wrote:
             | I got a check in the mail last week for 12C/ from Google
             | hoovering up my data. Yes, that's _twelve cents!_
             | 
             | Google certainly made more off of my data than that.
        
               | whalesalad wrote:
               | costs more to mail a letter
        
             | josh-sematic wrote:
             | True but personally I also wouldn't want to go through the
             | time and expense to sue them solo. At least in a class
             | action the company faces _some_ penalty that's possibly
             | meaningful to them (even if it's not meaningful to most of
             | the claimants).
        
           | voxic11 wrote:
           | At&t customers are bound to individual arbitration so there
           | will be no class action lawsuit for this.
           | 
           | > Please read this Agreement carefully. It requires you and
           | AT&T to resolve disputes through arbitration on an individual
           | basis rather than jury trials or class actions.
           | 
           | https://www.att.com/legal/terms.consumerServiceAgreement.htm.
           | ..
        
           | arcimpulse wrote:
           | Very difficult to run these days. Since 2018, federal courts
           | have ground away many of the legal routes needed to run a
           | successful class action suit against a national or
           | multinational corporation.
        
         | djbusby wrote:
         | And look for Arbitration clause in your contract. Might limit
         | your options.
        
         | voxic11 wrote:
         | You likely cannot file in small claims and would need to pursue
         | arbitration instead.
         | 
         | > Please read this Agreement carefully. It requires you and
         | AT&T to resolve disputes through arbitration on an individual
         | basis rather than jury trials or class actions.
         | 
         | https://www.att.com/legal/terms.consumerServiceAgreement.htm...
        
           | quercusa wrote:
           | _- AT &T will usually pay all of the arbitration fees (with
           | some exceptions). _
           | 
           | That could get pretty expensive for them quickly.
        
       | 1attice wrote:
       | this breach is of course appalling. But nearly as appalling is
       | the experience of _explaining why this matters_ to non-technical
       | friends who stare at you with blank, distracted eyes, but only
       | for a second; for their phone (yes, the very phone that just
       | exposed them to uncountable future ills) has chimed.
       | 
       | I have nearly given up; like smoking, it will be decades before
       | the harms are understood. We have to wait for your neighbour's
       | brother to have died in a targetted political killing, because
       | someone didn't like his Substack and borrowed the number and
       | likeness of a friend; for his daughter's credit score to have
       | been crushed by an anti-abortioneer who borrowed her face and
       | likeness and number knew her first-grade teacher; for his son to
       | die a death of despair, after making the wrong friends, and
       | getting doxxed along with the rest of them.
       | 
       | This should be a five-foot headline moment. But no; CNN will lead
       | with Biden-mumbles or Trump-grumbles.
       | 
       | How is it that the things that are killing us --- inequality,
       | climate change, privacy collapse -- all have this same shape?
       | Hamlets, all of us.
        
       | whyenot wrote:
       | AT&T has 110 million customers. Let's be optimistic and assume
       | that each customer only has to spend one minute of extra time
       | managing their account due to the break-in. That is more than 209
       | years of lost time.
       | 
       | Laws related to data breaches need to have much sharper teeth.
       | Companies are going to do the bare minimum when it comes to
       | securing data as long as breaches have almost no real
       | consequences. Maybe pierce the corporate veil and criminally
       | prosecute those whose negligence made this possible. Maybe have
       | fines that are so massive that company leadership and
       | stockholders face real consequences.
        
         | pcblues wrote:
         | Personal data cannot be secured. The only way is to not store
         | it. That will (imaginationaly) cost companies in lost revenue
         | for being unable to mine and sell it. Only government can make
         | laws against a company taking your personal information and
         | selling it. Even passwords shouldn't be stored by a company.
         | 
         | The years of lost time argument is disingenuous. Over that
         | number of people, 209 years of lost time from 700 million years
         | of lives is nothing.
        
           | compootr wrote:
           | Whether or not it's disingenuous, it's our time that didn't
           | need to be wasted in the first place by them not storing
           | phone records
        
           | dopylitty wrote:
           | I'd take it a step further. If a technology is impossible to
           | secure it shouldn't be used. Maybe it's time to rethink all
           | the parts of our lives we've handed over to software.
        
           | tomComb wrote:
           | There are lots of companies that take security seriously and
           | don't lose their customers data. Which is good, because there
           | are companies that need to hold customer data.
           | 
           | Companies that don't take security seriously and lose peoples
           | data should be punished accordingly.
           | 
           | Companies that sell customers data should be identified.
           | 
           | But if we treat them all the same, then we let the bad
           | companies off the hook, and punish the responsible companies
           | unfairly.
        
         | voisin wrote:
         | But hey, in 5-7 years there will be a settlement to the
         | inevitable class action lawsuit and each of these customers
         | (that fills in a form, ensuring only a small fraction actually
         | do) gets a $3.75 credit on their next bill. The lawyers will
         | get 30% of the settlement and each walk away with several
         | million dollars. Justice! _chef's kiss_
        
         | wkcheng wrote:
         | Yeah, you're right. Data breaches are essentially just slaps on
         | the wrist to companies like AT&T. Maybe it's possible to fine
         | them based on the proportion of the userbase that was affected
         | and the profits they generated for a certain time period.
         | 
         | I wonder if this will push companies to stop using external
         | vendors to store and process data. If companies stored all of
         | their info in house, it would prevent the case where
         | compromising one vendor compromises everyone's data. But it
         | would also mean that each individual company needs to do a good
         | job securing their data, which seems like a tall ask.
        
           | hnlmorg wrote:
           | The reason some companies use external vendors is to
           | outsource the risk.
        
         | choppaface wrote:
         | The AT&T app and website are so bad it takes way longer than 1
         | minute to log in to e.g. pay your bill. The United States needs
         | to raise the bar for large-cap negligent operators and fine the
         | company enough to make shareholders listen.
        
           | AnthonyMouse wrote:
           | In approximately 100% of cases, if your intuition is to say
           | "this company is too large should be fined/regulated more,"
           | what you should actually say is "this company is too large
           | and should be broken into many smaller entities."
        
             | physhster wrote:
             | We should break down AT&T. Oh wait. We tried already and
             | re-consolidated? Ow.
        
               | AnthonyMouse wrote:
               | Part of breaking them up is supposed to be not letting
               | them re-consolidate. Mergers involving any entity that
               | already has 15% market share should just be flatly
               | disallowed.
        
         | edanm wrote:
         | > Laws related to data breaches need to have much sharper
         | teeth. Companies are going to do the bare minimum when it comes
         | to securing data as long as breaches have almost no real
         | consequences. Maybe pierce the corporate veil and criminally
         | prosecute those whose negligence made this possible. Maybe have
         | fines that are so massive that company leadership and
         | stockholders face real consequences.
         | 
         | I really dislike this attitude.
         | 
         | AT&T were attacked, by criminals. The criminals are the ones
         | who did something wrong, but here you are immediately blaming
         | the victim. You're assuming negligence on the part of AT&T, and
         | to the extent you're right, then I agree that they should be
         | fined in a bigger manner.
         | 
         | But the truth is, given the size and international nature of
         | the internet, there are effectively armies of criminals,
         | sometimes actually linked to governments, that have incredible
         | incentives to breach organizations. It doesn't require
         | negligence for a data breach to occur - with enough resources,
         | almost any organization can be breached.
         | 
         | Put another way - you trust a classical bank, with a money, to
         | secure your money from criminals. But you don't expect it to
         | protect your money in the case of an army attacking it. But
         | that's exactly the situation these organizations are in -
         | anyone on Earth can attack them, very much including basically
         | armies. We _cannot_ expect organizations to be able to defend
         | themselves forever, it is an impossible ask in the long run.
         | This _has_ to be solved by the equivalent of a standing army
         | protecting a country, and by going after the criminals who do
         | these breaches.
        
           | dwattttt wrote:
           | In this analysis, the effort the bank puts towards defending
           | themselves is relevant. We wouldn't blame the bank for an
           | army attacking them, but if they left the door unlocked and
           | the neighbours kids made off with your money you very rightly
           | would feel differently.
        
             | Kailhus wrote:
             | Which does make me wonder why we never really hear of banks
             | being attacked and robbed in such a way? One would think
             | they would be the most obvious targets to throw an army of
             | criminals at.
        
               | edanm wrote:
               | Banks don't really physically store much money any more.
               | 
               | And more importantly - the police exist. If someone were
               | to actually physically rob a bank, enormous resources
               | would be spent trying to find and capture them, then
               | they'd be thrown in jail.
               | 
               | If they could do the same thing, but also be physically
               | located in another country while doing it, with no chance
               | at all of going to jail... more banks _would_ be robbed!
        
               | cellis wrote:
               | Crypto Exchange has entered the chat.
        
               | ufmace wrote:
               | It's pretty much the definition of a functional state
               | that the police can gather more resources faster than any
               | group of criminals. By the time you gather enough
               | criminals to hold off the police for even a few minutes,
               | most of the time, combined with the sibling's point of
               | not that much physical money being stored at banks,
               | there's not much money to go around to that many people.
        
           | mikeweiss wrote:
           | Companies could also stop storing customer information for
           | purposes unrelated to the core product that you are
           | using..... But that's not going to happen because it's still
           | far more profitable to mine customers data even with the risk
           | of theft or breach.
        
           | hansvm wrote:
           | I think the implicit assumption is that the vast majority of
           | these breaches are obviously preventable (basic incompetence
           | like leaving a non-password-protected database connected to
           | the public internet is common).
           | 
           | A better analogy is not a bank defending against an army, but
           | a bank forgetting to install doors, locks, cameras, or
           | guards. _Yes_, the criminals are the root cause, but human
           | nature being what it is it's negligent to leave a giant pile
           | of money and data completely unprotected.
        
             | edanm wrote:
             | > I think the implicit assumption is that the vast majority
             | of these breaches are obviously preventable (basic
             | incompetence like leaving a non-password-protected database
             | connected to the public internet is common).
             | 
             | Some breaches are certainly preventable. But is that the
             | case here? I didn't see the technical details, I think they
             | aren't released yet, but this is the conclusion everyone
             | seems to jump to automatically, without necessarily good
             | reason.
             | 
             | More importantly - these companies employ thousand of
             | employees, all of whom could be doing something wrong that
             | is causing a security threat. And there are thousands,
             | maybe tens of thousands of people trying to find their way
             | in. my point is that even without any negligence, if you
             | have thousands of people trying to hack your company every
             | day for years, it's easy to slip up, even if it's
             | preventable-in-hindsight.
             | 
             | One of the first things you learn in working in security is
             | that there is no perfect security, and you have to
             | understand the nature of the threat you are facing. For
             | these companies, the threat might very well be "North Korea
             | decides to dedicate state-level resources to breaking into
             | your company, plus thousands of criminals are doing the
             | same every day". How is any company supposed to protect
             | against that?
        
               | hmottestad wrote:
               | Would assume someone would notice all the data that is
               | being transferred.
               | 
               | And if this turns out to be a sophisticated attack then
               | who's to say they didn't backdoor a bunch of systems? I
               | heard a talk from a big Norwegian company that got
               | attacked. Every single server, every single switch, every
               | single laptop, all had to be reformatted and reinstalled.
               | I assume that AT&T would have to end up doing the same.
        
           | usea wrote:
           | If a breach is so inevitable like you say, then it's
           | negligent to store the information in the first place.
           | They're accumulating and organizing data with the inescapable
           | conclusion of handing it out to criminal organizations.
        
           | A4ET8a8uTh0 wrote:
           | << AT&T were attacked, by criminals. The criminals are the
           | ones who did something wrong, but here you are immediately
           | blaming the victim. You're assuming negligence on the part of
           | AT&T,
           | 
           | I am sure LEOs will do what they are paid to do and catch
           | criminals. In the meantime, I would like to focus on service
           | provider not being able to provide a reasonable level of
           | privacy.
           | 
           | I am blaming a corporation, because for most of us here it is
           | an ongoing, recurring pattern that we have recognized and
           | corporations effectively codified into simple deflection
           | strategy.
           | 
           | Do I assume the corporation messed up? Yes. But even if I
           | didn't, there is a fair amount of historical evidence
           | suggesting that security was not a priority.
           | 
           | << Put another way - you trust a classical bank, with a
           | money, to secure your money from criminals.
           | 
           | Honestly, if average person saw how some of those decisions
           | are made, I don't think a sane person would.
           | 
           | << But the truth is, given the size and international nature
           | of the internet, there are effectively armies of criminals,
           | sometimes actually linked to governments, that have
           | incredible incentives to breach organizations. It doesn't
           | require negligence for a data breach to occur - with enough
           | resources, almost any organization can be breached.
           | 
           | Ahh, yes. Poor corporation has become too big of a target.
           | Can you guess my solution to that? Yes, smaller corporation
           | with MUCH smaller customer base and footprint so that even if
           | the criminal element manages to squeeze through those
           | defenses that the corporation made such a high priority ( so
           | high ), the impact will be sufficiently minimal.
           | 
           | I have argued for this before. We need to make hoarding data
           | a liability. This is the only way to make this insanity stop.
        
         | abdullahkhalids wrote:
         | The correct way is to follow what all other engineering and
         | trade (medicine/law) already follow.
         | 
         | Some software engineers are licensed. A company must hire these
         | software engineers, and any changes to what data is saved or
         | how is saved must be signed by these engineers. If a breach
         | occurs, an investigation occurs and if these licensed software
         | engineers are found to be negligent, they lose their license.
         | If they are found to be at fault, they get criminal penalties.
         | 
         | This, of course, must be coupled with penalties for management
         | personals as well.
        
           | AnthonyMouse wrote:
           | This kind of system has consistent led to regulatory capture
           | by the licensed industry. Even the mechanism of operation de
           | facto assumes a significant gatekeeping barrier to getting a
           | license, since otherwise companies would just pick one most
           | willing to cut corners to save costs, or pay the license fee
           | to get greenhorns certified because that costs less than
           | adding two years to the development schedule to do it well.
           | Making everything cost quadratically more than it already
           | does is not a good solution.
           | 
           | What you want here is for them not to be holding the data to
           | begin with. The solution to which is to just let customers
           | sue them. Not for $0.30 and "free credit monitoring" but for
           | actual money. Then companies can choose whether they want to
           | mitigate their risk by doing actual security or by not
           | storing the data to begin with, but most likely the second
           | one is their better option.
        
       | zombiwoof wrote:
       | User: admin Password: password
        
       | chmod775 wrote:
       | Over in Europe this blanket saving of phone records beyond what
       | it is necessary to operate would have been illegal in many
       | countries, and is in general incompatible with the European
       | Convention for the Protection of Human Rights and Fundamental
       | Freedoms outside of active threats to national security and
       | temporary measures overseen by a court.[1]
       | 
       | There's really no reason why any service providers should save
       | this stuff in the first place, and it isn't hard to fix with
       | legislation. Just make it illegal to even keep.
       | 
       | [1]
       | https://curia.europa.eu/juris/document/document.jsf?text=&do...
        
         | Aerroon wrote:
         | I was under the impression that the government wasn't allowed
         | to create a mandate that a telco has to save all phone records
         | like that, but it doesn't stop a telco from doing it
         | themselves. I think that would fall more under GDPR
         | limitations?
        
           | chmod775 wrote:
           | I believe you are correct. That's what I was referring to
           | with "illegal in many countries". Most judgements on this
           | issue predate GDPR, but before GDPR, many countries already
           | had similar laws and attitudes. For example article 2* and 10
           | of the German constitution protect personal data and
           | communication, not just from others, but also from the
           | government. Not unlike the GDPR.
           | 
           | Some service providers in Europe don't even want to save any
           | data. The linked judgement above was the German state suing
           | Telekom, which didn't want to save that data, and losing.
           | Given the state of affairs, the question of "illegal or not"
           | doesn't really come up as much. At least I'm not aware of any
           | high profile judgements.
           | 
           | Besides Telekom, which always tried to minimize they data
           | they keep to the point of fighting it all the way to Europe's
           | highest courts, most other telcos don't really care and pick
           | whichever middle-ground is available between "must" and "must
           | not". Whatever is least-likely to get them into trouble.
           | Right now that just happens to mean "save little".
           | 
           | * It's not stated explicitly in article 2, but the German
           | constitutional court decided that it follows from those
           | personal rights:
           | https://en.wikipedia.org/wiki/Informational_self-
           | determinati...
        
           | bobmcnamara wrote:
           | Historically we handled this with fiber taps at AT&T, as well
           | as other ISPs. Some of them even knew about it.
        
         | kevin_thibedeau wrote:
         | What the NSA wants, the NSA gets. No legislation is needed when
         | the system is working as intended.
        
           | ldoughty wrote:
           | According to the article, the data was being made available
           | to other businesses... From the detail level involved, I
           | imagine the NSA has some sweeter deal with telcos... And they
           | have much richer data.
        
             | VonGuard wrote:
             | New lines of business. Another way for them to sell your
             | data. The NSA is quaint. The Valley knows everything about
             | everyone already, and even has their current GPS
             | coordinates.
        
             | kevin_thibedeau wrote:
             | The NSA buys _all_ of the data available from data brokers.
             | 4A? What 4A? With telcos they have the extra advantage of
             | ordering them around with an NSL.
        
               | dredmorbius wrote:
               | For those not deeply versed in US federal regulations:
               | Part 4a of Title 15 of the Code of Federal Regulations
               | (CFR), which covers the "Classification,
               | Declassification, and Public Availability of National
               | Security Information" for the National Security Agency
               | (NSA).
               | 
               | <https://www.ecfr.gov/current/title-15/subtitle-A/part-4a
               | ?toc...>
        
           | arcticbull wrote:
           | The NSA shouldn't need the telcos to retain these records,
           | just hand them over to the NSA to retain right?
        
             | ASalazarMX wrote:
             | It's a good business decision to make others do your work.
        
               | arcticbull wrote:
               | Government is not a business!
        
             | erikig wrote:
             | Which leads me to wonder - were any of the NSA's own
             | employee, call and SMS records at AT&T part of the
             | comprised data?
             | 
             | (edited for grammar)
        
               | stainforth wrote:
               | Right, if phone records for Congressmen and known (or
               | deduced) DOD were made public would that sway any changes
        
             | AnthonyMouse wrote:
             | It's not so much the NSA as various other government
             | agencies. The NSA is hoovering everything up, but if the
             | local cops call them and want access to it, the NSA is
             | going to tell them that they're not even authorized to know
             | whether or not the NSA has that information. Also,
             | something something due process something something
             | American citizens.
             | 
             | Whereas if they can get the telcos to keep it then the cops
             | can get it using the third party doctrine. This is
             | basically an end run around the constitution, which is why
             | they like it.
        
           | JumpCrisscross wrote:
           | > _What the NSA wants, the NSA gets_
           | 
           | The NSA's power is in being boring and unnoticed. This could
           | be a revenue rider.
        
           | ChumpGPT wrote:
           | Every txt and phone call, every email and letter sent to your
           | address along with every utility bill (list goes on) has been
           | saved since at least 1999/2000 to present day. People like
           | Bernie went to jail because they pushed back and it was all
           | because of this....
           | 
           | Just saying.
        
             | tomrod wrote:
             | ... letter?
        
               | ChumpGPT wrote:
               | Anything you receive via post office. Sender/Receiver
               | address is scanned. Post office uses OCR's for sortation
               | and that information is captured.
        
               | tomrod wrote:
               | Ah. The metadata. Inconsequential, then, to a degree.
        
             | fsagx wrote:
             | who's Bernie?
        
         | kolbe wrote:
         | You live in a place where the government is for the people, not
         | for themselves.
        
           | chmod775 wrote:
           | If it wasn't for the courts and a decent de-facto
           | "constitution" (collection of treaties really), governments
           | would absolutely love to expand the amount of data _they_
           | (police, spy apparatus, etc.) have access to. That they also
           | try to reduce the amount of data _companies_ are allowed to
           | save for themselves is tangential.
           | 
           | The court case I linked is evidence of that. The German state
           | wanted Telekom to save more data, but the telco refused and
           | won in court.
        
       | nxobject wrote:
       | I look forward to receiving my 30 cents in settlement money in
       | five years.
        
       | exabrial wrote:
       | The only "criminals" is AT&T for leaving the doors wide open.
        
       | TriangleEdge wrote:
       | When are we going to see the technical report of what happened?
       | Since this data has a specific time frame, it makes sense to me
       | that a backup was stolen. But, we'll see.
       | 
       | My guess is that the tech leaders a AT&T are going to have sore
       | wrists for a few minutes because of this.
        
       | smcin wrote:
       | Joining the dots on the facts so far, people don't seem to have
       | grasped the apparent huge significance:
       | 
       | - guessing it was some GenAI startup looking into consumer
       | tracking, alternate credit scoring, surveillance or other
       | national-security use-case.
       | 
       | - Very unusually, the DOJ ordered two ~month-long "delay periods"
       | in disclosure: _( "The Justice Department determined on May 9 and
       | again on June 5 that a delay in providing public disclosure was
       | warranted")_. Yet this didn't happen for Ticketmaster or MOVEit
       | breaches revealed around the same time. "Cybersecurity delay
       | period requests" is a new power quietly authorized by the
       | DOJ+SEC+FBI, 18 Dec 2023 [0]. Note that [1] emphasizes this as
       | "Corporate Alert - guidance for delay requests [on SEC 8-K]".
       | Might Congress already have known/suspected, when it authorized
       | the cybersecurity delay request powers, of the Snowflake/AT&T
       | breach? Either way, whoever is involved seems to have very
       | powerful friends. Also, the big FISA renewal vote was Apr 19 2024
       | [2].
       | 
       | - Seems the cloud instance was set up the same time GPT-4 was
       | released (March 2023), also when Snowflake set up a Telco
       | business unit [3] _( "Location data... Alternate credit scoring,
       | hyper-targeted marketing and more... an emerging trend of
       | companies building partnerships with telecoms to power use cases
       | across multiple industries")_. This product is not aimed at the
       | telcos' use-cases, but at new revenue streams. (Who might the
       | unnamed Snowflake AI partner(s) be?)
       | 
       | - They set up the Snowflake instance with AT&T/MVNO customers
       | with timestamps removed, but with location data, yet the phone
       | numbers not obscured or removed. Doesn't sound like "internal
       | analytics" or "competitor analysis". What sorts of end-users want
       | to pay for the entire social-graph of 110m, regardless whether
       | those customers never make a phone call again? [EDIT: I confused
       | the details of this AT&T breach with the other (2019) one
       | disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former
       | customers]
       | 
       | [0]: "FBI Guidance to Victims of Cyber Incidents on SEC Reporting
       | Requirements: FBI Policy Notice Summary"
       | https://www.fbi.gov/investigate/cyber/fbi-guidance-to-victim...
       | 
       | [1]: "US Corporate Alert - DOJ, FBI, and SEC provide guidance for
       | delay requests relating to disclosure of cybersecurity incidents
       | under form 8-K" https://www.klgates.com/DOJ-FBI-and-SEC-Provide-
       | Guidance-for...
       | 
       | [2]: US House approves FISA renewal - warrantless surveillance
       | and all https://news.ycombinator.com/item?id=40041784
       | 
       | [3]: Snowflake cloud Telco unit, 4/2023: "Unlocking the Value of
       | Telecom Data: Why It's Time to Act"
       | https://www.snowflake.com/blog/telecom-data-partnerships/
        
       | jdlyga wrote:
       | It's one more reason to use an end to end encrypted messaging app
       | like iMessage or Telegram. Even WhatsApp is end to end encrypted.
       | Don't use SMS/RCS.
        
         | menacingly wrote:
         | unless I'm misunderstanding, the same data could be pulled from
         | those services.
         | 
         | the message content wasn't leaked here
        
       | purpleblue wrote:
       | WHY IS THIS DATA EVEN AVAILABLE TO BE DOWNLOADED??? Why do we not
       | have protection in place so that hackers can't even download this
       | data even if they wanted to?? What purpose does 2 year old data
       | serve AT&T except to monitor us and to create social networks of
       | people and associations?
        
       | demondemidi wrote:
       | Would be great if some of the smart people here could help
       | explain why this is such a big deal to my less tech savvy
       | friends. I know that I _don't know_ how the data broker to dark
       | web hacker pipeline works, I just know security is important. But
       | my family is like "big deal".
        
       | benreesman wrote:
       | The old-timers remember a term: "dark fiber".
       | 
       | There's going to be a lot of "dark compute" once we throw these
       | lazy assholes out.
       | 
       | Speaking for myself, I'm thinking of what the economics look like
       | when HBM is abundant.
        
       ___________________________________________________________________
       (page generated 2024-07-12 23:00 UTC)