[HN Gopher] AT&T says criminals stole phone records of 'nearly a...
___________________________________________________________________
AT&T says criminals stole phone records of 'nearly all' customers
in data breach
Author : impish9208
Score : 480 points
Date : 2024-07-12 11:17 UTC (11 hours ago)
(HTM) web link (techcrunch.com)
(TXT) w3m dump (techcrunch.com)
| smcin wrote:
| This is huge; also AT&T knew on Apr 19 but only disclosed now;
| ongoing fallout from the Snowflake compromise:
|
| - Records downloaded from Snowflake cloud platform
|
| - "AT&T will notify 110 million AT&T customers"
|
| - Compromised data includes customer phone numbers ("for 77m
| customers"), metadata (but not actual content or timestamp of
| calls and messages), and location-related data. Not SSNs or DOBs.
| Mostly during a six-month period 5/1-10/31/2022, but more recent
| records from 1/2/2023 for a smaller but unspecified number of
| customers. TechCrunch [1] has more details including Mandiant's
| response, the name and suspects location of the cybercriminal
| group
|
| [1]: https://techcrunch.com/2024/07/12/att-phone-records-
| stolen-d...
|
| I wonder if Congress manages to summon TikTok-like levels of
| anger on regulating this one.
| John23832 wrote:
| And, honestly, how is this info (which I WOULD want to know)
| meaningfully actionable to customers. We get our information
| stolen from a myriad of sources everyday. These companies do
| comparatively nothing to make things right and the burden falls
| on customers to pick up the pieces if you're in a tranch that is
| sold and used.
| smcin wrote:
| Of course it's not meaningfully actionable to customers, big
| time lag in not disclosing since Apr 19. (Why does this not
| fall under SOX violation with the obligation to report timely
| to affected parties? It has affected AT&T's stock price -3% in
| early trading, so should it have also required SEC disclosure?)
|
| Wondering what is the significance that most of the stolen
| records were from the period 5/1-10/31/2022? Does it mean that
| AT&T enabled 2FA on more recent records, or that more recent
| records were on a different cloud bucket (or that they mostly
| stopped using Snowflake since)?
| lumb63 wrote:
| This is another consequence of the surveillance state. The same
| data that can be used to surveil us by the government can be
| stolen by who-knows-who. We'd all (mostly) be far better off,
| IMO, if companies didn't retain such records.
| Jgrubb wrote:
| Yes but have you ever asked a dev if they actually need the 8
| year old logs in some bucket?
| rustcleaner wrote:
| My wet dream would be a dump of all SMS or Meta or iMessage
| messages for a multiyear period for nearly 90% of users. Only
| when Normie Norman's private chats to his mistress and other
| little relationship trust disrupting secrets become
| uncensorably hosted on the darknet and freely searchable, only
| then will Normie Norman get a clue and install
| SimpleX/Briar/Cwtch/any other owner-free decentralized p2p
| chat.
| dtx1 wrote:
| While I share the sentiment, Normie Norman is not at fault.
| Meta and other BigCorps are the perpetrators and Norman the
| Victim.
| rustcleaner wrote:
| True, but you have to admit once you really see Normie
| Norman you come to understand aristocracy.
|
| At least I do anyway.
| shrimp_emoji wrote:
| https://dwm.suckless.org/
|
| > _Because dwm is customized through editing its source
| code, it 's pointless to make binary packages of it. This
| keeps its userbase small and elitist._
| rustcleaner wrote:
| Not in the way of a narcissist trying to separate himself
| from the group, but to see that Norman is very much
| susceptible to cow-like behaviors you can leverage.
| That's what I mean by understanding aristocracy.
| Aristocrat : Rancher.
| robcohen wrote:
| I have to disagree. He is a fault. Ultimately, you are the
| only person who really should care about your own security.
| When you delegate that responsibility, you are still the
| one who made that choice.
| doublepg23 wrote:
| I don't think it's fair to blame people for not
| understanding the subtleties of encrypted communication.
|
| Everyone only has so much attention to give.
| tsujamin wrote:
| Having a mobile phone is necessary to securing
| employment, shelter and sustenance in many cases, yet
| somehow it's an individuals fault for choosing to have a
| phone account when a pair of multibillion dollar
| companies breach that data through lax security
| practices?
| LinuxBender wrote:
| Not unrealistic. I used to have a tail of all SMS texts
| running 24/7 and was required to grep for specific terms for
| certain agencies until they eventually had their own access.
| This was only SS7 based texts and was long before RCS
| existed. I could have saved it all to my workstation but knew
| better than to do that. Either way SS7 and text messages are
| very insecure.
| buro9 wrote:
| Including all location metadata associated to that?
| smcin wrote:
| The reports said celltower-level location data associated with
| calls and texts (but not datestamps). That would allow
| inferring their homes, job location, commute, family members,
| social graph.
| sitkack wrote:
| You can still recover that without timestamps. It also looks
| like if anyone interacted with an ATT customer or used an
| MVNO your data is in there too.
| dylan604 wrote:
| It even said land lines had their numbers in the data if an
| ATT customer contacted one.
|
| Edit: I must have read that from a different article than
| the TFA though.
| sitkack wrote:
| Yeah, all att customers, 2nd party participants and any
| other user of their network. Not just direct customers.
| akshayB wrote:
| The real problem is that data needs to be deleted over time.
| There is not much of a use case for customers for go back last
| year and see who called them and obviously there are use cases
| like criminal investigations or spying. But customer has no power
| or ability to dictate how long their records are store and how
| they are used. Companies should provide tools and features to
| their customers empowering them with their data.
| tantalor wrote:
| This isn't data for serving user needs, this is data for spying
| on users
| mountainb wrote:
| Non-murder criminal offenses typically have very short statutes
| of limitations.
|
| A lot of this could also be solved by encouraging the federal
| government to enforce federal privacy law as written more
| aggressively. A good incentive would be to amend the privacy
| statutes to permit the FTC to keep the funds extracted from
| settlements and penalties in-house. This would allow them to
| increase staffing and create a positive feedback loop to deter
| wrongdoing. This would have a negative effect on incumbent
| companies and practices, but it would not take long for the
| message to get across and for practices to change accordingly.
|
| Congress tends to prefer keeping agencies on its own budgetary
| string which paradoxically limits what the agencies are capable
| of doing. The laws that we think protect us do not protect us
| because many of them are within the exclusive jurisdiction of a
| federal agency with very limited powers and funds. In the US
| the leadership likes to create the illusion that it has made
| "Bad Problem" illegal by writing it into the law, but it does
| not like creating the conditions in which "Bad Problem" could
| be solved, whether it's because the tradeoffs involved are
| tough to contemplate or because keeping "Bad Problem" around as
| a visible enemy is clever politics.
| _heimdall wrote:
| > Non-murder criminal offenses typically have very short
| statutes of limitations.
|
| There's a hidden assumption here. The expectation is that
| data retention and potential privacy violations are a
| necessary evil because anyone may later be under
| investigation for a crime. The data could go uncollected, it
| isn't AT&Ts job to retain private information on all of us
| just in case an investigator wants it.
|
| Take telecoms out of it and consider a convenience store.
| Police would like to have video recordings of whatever moment
| in time they are investigating, but that doesn't mean the
| video has to be recorded and retained. A shop owner can
| choose to record videos and only retain them for a week if
| they want, or they can have cameras installed but not even
| recording if they're okay with just the effect of deterrence.
| mountainb wrote:
| Many civil claims have short statutes of limitation as
| well. It's not really that good for these companies to
| maintain regular business records going back to infinity
| that are subject to discovery in disputes that are not even
| related to anything the telecom company did. Complying with
| the discovery requests and subpoenas is expensive. The
| fetish for the somewhat imagined benefits of big data
| creates open-ended liabilities for these companies. But the
| pressure that law enforcement and the spy agencies put on
| the telecom companies to facilitate this has been an open
| secret for a long time now.
|
| A lot of this is on the federal government and Congress for
| leaving an area in which it has power dormant and within
| its relatively exclusive control. Thanks for the
| conversation.
| willmadden wrote:
| That's another bandaid. The root cause is customer data
| collection mandated by outdated regulation. People should be
| able to digitally sign or provide a public key for their
| personal information without providing the raw text to 3rd
| parties. Various 1970's style government tax and regulatory
| rules need to be updated as well.
| softfalcon wrote:
| They have a financial incentive to never delete your data.
| Storing old data forever creates a perfect paper trail to sell
| to advertisers and perfect the shadow profile they keep on all
| of us.
|
| I agree that deleting all your data after a year makes sense
| practically, but they'll never do it because it makes them too
| much money to keep it around.
| smcin wrote:
| Ongoing fallout from the Snowflake compromise; AT&T knew on Apr
| 19 but only disclosed now (Why does this not fall under SOX
| violation with the obligation to report timely to affected
| parties? It has affected AT&T's stock price -3% in early trading,
| so shouldn't it have also required SEC disclosure?)
|
| - Records downloaded from Snowflake cloud platform
|
| - AT&T will notify 110 million AT&T customers
|
| - Compromised data includes customer phone numbers, metadata (but
| not actual content or timestamp of calls and messages), and
| location-related data. Not SSNs or DOBs. Mostly during a six-
| month period 5/1-10/31/2022, but more recent records from
| 1/2/2023 for a smaller but unspecified number of customers.
| TechCrunch report has more details including Mandiant's response,
| the name and suspects location of the cybercriminal group
|
| I wonder if Congress manages to summon TikTok-like levels of
| anger on regulating this one.
| softwaredoug wrote:
| > Snowflake blamed the data thefts on its customers for not
| using multi-factor authentication to secure their Snowflake
| accounts, a security feature that the cloud data giant did not
| enforce or require its customers to use.
|
| So AT&T put all our call information somewhere and hid it
| probably behind a weak password with no additional factors. IMO
| that's actionable negligence and I hope they get sued to
| oblivion.
| smcin wrote:
| I'm more stunned that AT&T knew back on Apr 19 [UPDATE: Mar
| 20] yet feels it had neither an SOX violation or SEC
| obligation (share price effect) to notify timely. Like, by
| Apr 22. Not three months later [UPDATE: 4 months later].
|
| Remember the massive Yahoo 2014 hack which Yahoo management
| failed to notify its own users for 2 years?
|
| If SOX violation only literally covers users' own passwords
| getting breached, but not 2FA or other passwords to access
| the same data, will Congress amend it urgently?
|
| EDIT: apparently they're hiding behind the 3/20 disclosure
| [0] which is all they disclosed until [1],[2] today.
|
| [0]: March 30, 2024 - "AT&T Addresses Recent Data Set
| Released on the Dark Web"
| https://about.att.com/story/2024/addressing-data-set-
| release...
|
| > _" AT&T has determined that AT&T data-specific fields were
| contained in a data set released on the dark web; source is
| still being assessed...
|
| > "AT&T has launched a robust investigation supported by
| internal and external cybersecurity experts. Based on our
| preliminary analysis, the data set appears to be from 2019 or
| earlier [incorrect], impacting... approx 7.6m current and
| 65.4m former AT&T account holders"*
|
| > _"Currently, AT&T does not have evidence of unauthorized
| access to its systems resulting in exfiltration of the data
| set.... As of today, this incident has not had a material
| impact on AT&T's operations."* [but did it have a material
| impact on the customers/ex-customers?!]
|
| [1]: Jul 12, 2024 - "AT&T Addresses Recent Incidents
| Regarding Access to Data" https://about.att.com/pages/data-
| incident.html
|
| [2]: Jul 12, 2024 - "AT&T Addresses Illegal Download of
| Customer Data" https://about.att.com/story/2024/addressing-
| illegal-download...
|
| > _" Based on our investigation, the compromised data
| includes files containing AT&T records of calls and texts of
| nearly all of customers of [AT&T's cellular and (MVNOs) using
| AT&T's wireless network], as well as AT&T's landline
| customers who interacted with those cellular numbers between
| May 1, 2022 - October 31, 2022. The compromised data also
| includes records from January 2, 2023, for a very small
| number of customers. The records identify the telephone
| numbers an AT&T or MVNO cellular number interacted with
| during these periods. For a subset of records, one or more
| cell site identification number(s) associated with the
| interactions are also included."_
| smcin wrote:
| Subsequent reporting reveals that the DOJ ordered two
| ~month-long "delay periods" in disclosure:
|
| > _The Justice Department determined on May 9 and again on
| June 5 that a delay in providing public disclosure was
| warranted, so the company is now timely filing the report.
|
| > The company [AT&T] is working with law enforcement and
| believes at least one person has been apprehended,
| according to the filing. It does not expect the event to
| have a material impact on its financials._
|
| MarketWatch: [https://www.marketwatch.com/story/at-ts-
| stock-slides-2-9-aft...]
| amanaplanacanal wrote:
| According to CNN:
|
| "The company said the US Department of Justice Department
| determined in May and in June that a delay in public disclosure
| was warranted. It's not clear why that the US government
| requested that data be delayed. CNN has reached out to the
| Justice Department for comment."
| nimbius wrote:
| May 16 Dow Jones Industrial Average surpasses 40,000 points
| for the first time, before closing at 39,869.
|
| public disclosure of a cataclysmic security breach in a
| darling of the stock market could have significant
| repercussions.
| adamtaylor_13 wrote:
| It definitely included SSNs for some of them.
|
| Source: me. My data was included in the leak and it included my
| SSN. It's been a cluster fuck of a cleanup.
| wredue wrote:
| My SIN number has been leaked no less than 4 times tied to
| basically every standard identifying question about me now,
| if that helps ease your worry.
|
| I guess the new methodology is that a company cannot be sued
| if they just all leak data, that way nobody knows which one
| is responsible for your identity theft.
| John23832 wrote:
| How has Snowflake felt ANY recourse for being the source of all
| of these hacks?
| beardedwizard wrote:
| The dark web and info stealing malware are the source of the
| hacks.
|
| My worry is not only that consumers get numb to breaches, but
| they consume rampant misinformation and have no idea how to
| hold appropriate parties accountable.
|
| How many times have you held AWS accountable for stolen access
| keys?
|
| Was it AWS fault when rabbit leaked their own keys?
|
| Is it snowflakes fault when you lose your creds to infostealing
| malware?
|
| How should snowflake enforce mfa on machine service account
| credentials?
|
| The answers are no, no, and they can not possibly. Not even
| hyperscalers have this magic.
| edm0nd wrote:
| Eh, iirc the source of the hack was just regular stealers
| like Redline, not "the dark web".
|
| It was actually Snowflakes fault.
|
| The threat actors were able to find a test/demo account they
| could log into and from there they were able to access prod
| things they shouldnt have.
| beardedwizard wrote:
| This is exactly the kind of comment I'm talking about. You
| have not read anything from snowflake, mandiant or
| crowdstrike on this, and you haven't even read the cnn
| article that has snowflakes response on this. The snowflake
| demo account has nothing to do with it.
| taspeotis wrote:
| > Snowflake blamed the data thefts on its customers for not
| using multi-factor authentication to secure their Snowflake
| accounts
| Aaronstotle wrote:
| its not Snowflake's fault their customers used weak passwords
| and no MFA. Not enforcing MFA does merit some blame on
| Snowflake, however, I still think its on the customer to secure
| your own environment.
| smcin wrote:
| Snowflake is saying they knew of unusual activity "around
| mid-April 2024", confirmed "May 23, 2024", around which time
| they made MFA mandatory (although their customer AT&T say
| they knew of the breach "Mar 20"; these timelines keep
| shifting back):
|
| "Mandatory MFA option unveiled by Snowflake" - Jul 11, 2024
| https://www.scmagazine.com/brief/mandatory-mfa-option-
| unveil...
|
| > _" US cloud storage firm Snowflake has already required the
| implementation of multi-factor authentication across all user
| accounts a month following the widespread breach of customer
| accounts, including those of Ticketmaster and Santander Bank,
| reports The Register."_
| iaabtpbtpnn wrote:
| It's not mandatory, I still have Snowflake user accounts
| that don't use MFA.
| mewpmewp2 wrote:
| It's industry standard to enforce MFA for customers of such
| sensitive data though. There's always going to be weak links.
| chefandy wrote:
| Right. Snowflake facilitated AT&T'S abject negligence, but
| ultimately the buck stops with AT&T, here.
| dghlsakjg wrote:
| Totally, way too many people are trying to blame snowflake.
|
| ATT is a technology infrastructure company. Secure
| transmission of data is one of their core business
| competencies (theoretically). They are a corporation that we
| trust to handle incredibly sensitive info. Call records are,
| in fact, incredibly sensitive data.
|
| They should be telling Snowflake what best practices to be
| using, not the other way around!
| yyyfb wrote:
| AT&T and phone carriers in general are not technology
| companies. They are infrastructure companies that purchase
| off-the-shelf communication technology, slap a billing
| system on top, and then spend most of their time on
| operations (finding places to put towers, keeping the gear
| up and running) and marketing. The security component of
| communications isn't built by them, but by the equipment
| manufacturers that they purchase from. There are no strong
| penalties for involuntary data leaks - why would they do
| more?
| dghlsakjg wrote:
| ATT has a rich history of being a technology company.
| They invented UNIX! That's in the past, fair enough.
|
| So they used to develop cutting edge technology, they
| sell technology, they buy technology, they operate
| technology, they work with manufacturers to develop new
| technology, they operate the infrastructure underpinning
| the modern technology economy, but they aren't a
| technology company?
|
| Even if you want to argue that they aren't a technology
| company, they sure spend enough time doing everything a
| technology company does to hold them accountable for
| their technology failures.
| dahart wrote:
| > They invented UNIX!
|
| They also invented the transistor, C, the photovoltaic
| cell, radio astronomy, and ... the telephone. ;)
|
| Yes that's the past, but AT&T labs still employs almost
| two thousand people. It's very funny to try to claim AT&T
| isn't a technology company and only peddles services on
| top of equipment made by others.
| metabagel wrote:
| It's unclear what you're arguing. That AT&T isn't capable
| of securing customer data, and we shouldn't expect that
| of them? That they shouldn't be held liable?
|
| If they don't have the core competency, they need to
| obtain it as a requirement of doing business.
| dahart wrote:
| > The security component of communications isn't built by
| them
|
| Are you claiming AT&T outsourced security and have
| contracts to back that up? Buying security equipment
| surely doesn't amount to having security, that would be
| hilariously naive. Equipment manufactures are not
| responsible for AT&T's data security, AT&T is. There are
| laws around security that can hold AT&T liable, in the US
| and Europe and elsewhere. Whether they will hold the
| company liable is another question, but these laws will
| not accept an excuse that AT&T purchased security
| equipment from another company.
| disgruntledphd2 wrote:
| > Totally, way too many people are trying to blame
| snowflake.
|
| Well the _actual_ compromise started from one of their
| employees, so it's pretty unsurprising that they're getting
| (some of) the blame.
| dghlsakjg wrote:
| Ahh. The linked article didn't have that detail.
|
| They attributed it to a lack of 2FA
| throwway120385 wrote:
| AT&T is a real-estate company that coincidentally sells
| telecommunications services. My wife used to work for them
| and given what she's told me I would never in a million
| years do any business with them intentionally.
| John23832 wrote:
| I feel like this would be true if ONE customer was hacked. At
| this point it's more than a handful. AND snowflake knew about
| it.
|
| If all the lockboxes in a bank get broken into, is it
| respectable to say "ah all of the customers should have used
| better locks"? The bank is the party who is supposed to be
| giving the insight into secure storage. They're not just
| renting space.
| sickofparadox wrote:
| The Mandiant report said that some Snowflake customers declined
| to use MFA AND had passwords in place for 4+ years[1]. Maybe
| Snowflake should have pushed for MFA harder but at the end of
| the day, this is AT&T's fault.
|
| [1] https://cloud.google.com/blog/topics/threat-
| intelligence/unc...
| Ragnarork wrote:
| I'd say the blame lies halfway between AT&T and Snowflake. If
| you let your customers have poor security practices, and you
| have the power to ensure a heightened security level, you're
| also partly to blame...
| theluketaylor wrote:
| Snowflake also made it hard to have good practices, giving
| them further culpability. There was no setting for
| customers to force their entire tenant to enforce MFA.
| Customers had to depend on each person with access to do
| the right thing, something that is unlikely to be
| universally true.
| wredue wrote:
| Non-expiring passwords is probably no more or less secure,
| unless you are a rampantly terrible employer known for
| setting ablaze every bridge ever to the point of atomic
| annihilation.
| dylan604 wrote:
| Are you suggesting a disgruntled former employee could use
| the password and do things? At that point, I have
| questions. How is the former employee accessing the cloud
| service? If your cloud is allowing public access without a
| VPN, then you've done something wrong there. If the former
| employee is still accessing your VPN, again, you've done
| something wrong. Many other things still come to mind but
| point back to you well before password rotation rules.
| softwaredoug wrote:
| > AT&T blamed an "illegal download" on a third-party cloud
| platform
|
| WTF does this even mean?
|
| The cloud employees downloaded it? If its so sensitive, why
| wouldn't this be heavily e2e encrypted?
| JohnMakin wrote:
| This is related to the snowflake breach. Snowflake is blaming
| customers for not enabling MFA.
| tpurves wrote:
| Looks like more than enough blame to go around. Not enabling
| MFA is pretty egregious by ATT. Snowflake creating a platform
| where such a high consequence mistake is apparently easy to
| make, and obviously without sufficient compensating controls
| to detect or limit impact of such a single point of failure.
| That's egregious too.
| rybosworld wrote:
| Consumers are so numb to data breaches that these events now
| bring very little outrage. I think without that anger from the
| consumer, there's little incentive for companies to do more to
| stop data breaches from happening.
| chefandy wrote:
| Well it's starting to feel like data privacy just doesn't exist
| anymore. I don't know why administrators for big customer
| databases even bother setting passwords these days.
| pavel_lishin wrote:
| My mother was concerned that some of her information, and
| mine, leaked because she signed up for another bank account
| from a place she decided she didn't trust. She said she
| wasn't worried about the money being stolen, but she was
| worried about our identities being stolen.
|
| My concern was the complete opposite - I assume that my
| social security number and address are already for sale for a
| fraction of a cent somewhere, bundled with 10,000 other
| identities. But if money gets stolen, that's a whole
| rigamarole, with banks wringing their hands and saying
| "identity theft" as if that clears them from any
| responsibility.
| 0cf8612b2e1e wrote:
| As a nobody, I keep wanting a financial product that is a
| black hole. Money can go in, but cannot come out without
| significant pain. Seven+ day waiting period, in person
| visit, physical mail verification, something, anything that
| means if I do get hacked my accounts are not drained in
| milliseconds.
|
| When I need a legitimate large withdrawal, I can go through
| the required effort.
| chefandy wrote:
| You can have a financial manager control your accounts
| for you and just keep a small checking account, (plus
| they'll help you grow your balances) but they're not
| free. Well, they're not free if you want them to be
| unbiased. Given, what's going to keep them from getting
| scammed? Maybe what you're looking for is several safe
| deposit boxes.
| 0cf8612b2e1e wrote:
| I still want my money invested into the economy. I just
| want Chase/Fidelity/etc to have an understanding that I
| am never going to withdraw money from these accounts
| without planning for it. So, "I" should never be
| authorized to drain the account at a moments notice
| without extensive approval. Anything to cause friction
| for would be scammers and only once-a-year (?) pain from
| me to triply confirm the money can move.
| chefandy wrote:
| I don't have direct access to my long-term savings and
| retirement accounts-- I have to go through my financial
| manager who'll works in a small, local firm, and so would
| anyone trying to impersonate me. He would probably
| recognize my voice, knows where I live and what's going
| on in my life, to whom I'm married, etc. because we have
| bi-annual check in meetings. He'd definitely contact me
| through his existing contact info if there was anything
| weird going on with one of my requests, especially if it
| involved a different address or account than he's used to
| dealing with. As anyone in that compliance-and-accuracy-
| focused line of work should be, he's very intent on
| making sure all of the Ts are crossed and Is are dotted.
| He charges a flat percentage of my modest retirement
| savings annually (I'm far behind most white collar
| workers my age, coming from a working class early
| adulthood) so he has a financial interest in my
| investments, and does a really solid job managing them.
| The accounts are in a large investment-focused bank which
| I believe only he can access. I think it's about as safe
| as you could get while still keeping your money active in
| the economy and not having a rich person's resources.
| xyst wrote:
| This already exists. Withdraw from account to physical
| cash. Proceed to stash cash in "secret" location.
|
| Most businesses don't even accept cash anymore. Can't get
| "hacked" although it's prone to many other issues --
| space, humidity, physical theft.
| pavel_lishin wrote:
| That sounds like the opposite of what OP wants, because
| that money can very easily come out, without any pain,
| and without you even being notified that it's been moved
| - unless you're re-implementing your own bank-level
| security, I guess.
|
| For example, let's say you have $100k in savings. I think
| you would be absolutely bonkers to store that in some
| secret part of your (flammable! break-in-able!) house.
|
| I guess you could put it in a safety deposit box, and if
| you needed to spend it in a non-cash way, you could walk
| it directly to the teller and deposit it and make it
| available? The equivalent of a cold wallet, I suppose.
| chefandy wrote:
| If you have at least a fraud watch on your credit which
| means creditors are supposed to call you on the number they
| have listed before they open new accounts, then the money
| is arguably worth protecting more. But if you think it's
| tough to convince the bank with which you have an existing
| relationship that you didn't make some withdrawals, imagine
| trying to convince a bank you've never heard of that you
| didn't actually approve a loan for 3 Cadillac Escalade
| Platinums which neither you nor the bank realize are
| currently in a shipping container on their way to Abu Dabi.
|
| (Nothing against Abu Dabi-- I just picked a random place
| not under US jurisdiction where plenty of people have
| Escalade Platinum money.)
| pavel_lishin wrote:
| I often choose Abu Dhabi as an "example destination",
| because that's where Garfield kept mailing Nermal in the
| comics.
| reaperman wrote:
| Classic Mitchell and Webb skit[0]:
|
| Bank: "No, you see it was your identity that they stole!"
|
| Customer: "Well I don't know because I seem to have my
| identity whereas you seem to have lost several thousands of
| dollars. I'm not clear why you think it's _my_ identity
| that was stolen rather than _your_ money. "
|
| 0: https://www.youtube.com/watch?v=CS9ptA3Ya9E
| strangecharm2 wrote:
| And why didn't they do anything when we WERE angry?
| TeaBrain wrote:
| I think many companies think they can solve this issue by
| throwing money at their cyber security teams. It just happens
| that cyber security teams are often ineffective.
| marcosdumay wrote:
| How could they? Everything related to computers is designed
| to exfiltrate data nowadays.
| softfalcon wrote:
| Maybe this is how it is at some places, but in my experience,
| it is not the case. I have friends who have worked in cyber-
| security for Fortune 500 companies and almost all of those
| companies would short-change (or outright ignore) the
| recommended spend and suggestions of their cyber-security
| employees, contractors, and advisors.
|
| Where are you getting your information from? The levels of
| security negligence I hear about aren't even a big ask. Huge
| companies neglect to do basic things like "don't store your
| passwords in plain text" or "make sure you salt and hash your
| passwords".
|
| I don't think it's fair to say cyber security teams are
| failing if companies are blatantly doing the worst and most
| obviously wrong things on the daily at the highest levels.
| mrguyorama wrote:
| It's hard for a CyberSecurity team to be effective when the
| Execs keep failing the phishing tests and IT does not have
| the authority to fire them for it.
| kredd wrote:
| After Equifax debacle, I don't think anyone cares. It'll only
| be a big deal if there's a huge B2B leak and business-critical
| data gets exposed, other than the usual name, address and phone
| number.
| al_borland wrote:
| I'm still upset the government hasn't started work on a new
| national ID program after the Equifax breach. The SSN is not
| a suitable ID number in this day and age. We need something
| better that can withstand these kind of things without
| screwing people for life. My credit will be frozen for the
| rest of my life, and everyone else should do the same.
| chankstein38 wrote:
| This is it for me tbh. Yeah I don't want my identity stolen
| and I'm still careful but after Equifax I just assume
| everyone already has my data so all of these data breaches
| are meaningless to me at this point. It sucks and it makes me
| mad but all I can do is shake my fist and wish these
| companies would be better anyway, so what else can I do but
| just be ok with it?
| xyst wrote:
| AT&T is a public company. Public company needs to get fined
| appropriately.
|
| Start issuing multi billion dollar fines for these breaches and
| suddenly companies are invested in security.
|
| Unfortunately with government agencies getting defanged as part
| of recent SCOTUS ruling, it's likely not possible.
|
| Have to rely on civil court to issue fines now (ie, class
| action lawsuits).
| hughesjj wrote:
| And this is yet another reason why I use signal
| jacobwilliamroy wrote:
| Do you exclusively use signal? Do your friends also use signal?
| Do you have friends who only use signal to communucate with
| you?
| llm_trw wrote:
| Yes.
| ghaff wrote:
| Aside from a couple non-US friends, I know no one in the US
| who uses anything other than straight SMS (and Apple
| iMessage). I'm sure they exist but certainly not in the
| circle of people I communicate with.
| BenjiWiebe wrote:
| There's definitely different circles in the US. My circle
| of friends and family is on Whatsapp. More than 99% of my
| communications would be through WhatsApp.
| lotsofpulp wrote:
| Everyone I know in the US uses either iMessage or
| Whatsapp. No one I know uses MMS.
| ectospheno wrote:
| Everyone I know uses signal. Different people really are
| different.
| ghaff wrote:
| For whatever reason, chat seems to definitely encourage
| tribalism. The last company I worked for eventually
| bought into Slack because so many people WOULD NOT use
| anything else while a lot of us were like "ANOTHER chat
| app??" because we were perfectly happy with Gchat which
| we had as part of Google Workplace.
|
| I know there are some historical reasons for non-SMS
| because of text pricing outside the US but everyone I
| know in the US would look at you funny if you wanted to
| use some special app for texting.
| postexitus wrote:
| do you have friends in plural?
| llm_trw wrote:
| I've gotten everyone from my in laws to my co workers on
| signal.
|
| >I can share baby pictures without them being stored in
| google forever.
|
| >We can organize whose bringing the coke without leaving
| a paper trail that lasts forever.
| jacobwilliamroy wrote:
| I DO
|
| I HAVE 3
|
| 3 IS MORE THAN 1
| jacobwilliamroy wrote:
| Do you make it like a fun game? Like when me and my friends
| in school would pass eachother coded notes and the cipher
| was an inside joke?
|
| I'm genuinely curious: what was the pitch that you used to
| get others to start using signal?
| rustcleaner wrote:
| I am working on this with mine, but even Signal is too
| weaksauce in my book. Ownerless (and ideally decentralized)
| p2p chat is what I am after. If everyone in my group used
| Android then it'd be Briar or Cwtch hands down for primary
| text/picture msg and SimpleX or Session or Jami as
| voice/video call and backup. Because there's an iphone
| upsetting everything that scratches Briar and Cwtch, so it's
| SimpleX reinforced with Orbot on my group's menu currently
| and it seems to work reliably. Session has terrible
| notification delays when in the background, they use the
| [IMO] boneheaded send-on-select abstraction within the
| selection gallery when attaching an image on their Android
| app (oh and your unsent typed text is wiped). Very
| unprofessional, needs a bottom-up redesign for its interface.
| Really has that everyone quit feel to it.
| jacobwilliamroy wrote:
| Do you make it like a fun game? Like when me and my friends
| in school would pass eachother coded notes and the cipher
| was an inside joke?
|
| I'm genuinely curious: what was the pitch that you used to
| get others to start using signal?
| abixb wrote:
| I hope you didn't sign-up for Signal with an AT&T-tied phone
| number. Else this breach would've probably exposed your PII
| either way.
| jen20 wrote:
| This is the kind of breach that really should be company-ending,
| but will sadly instead likely result in a slap on the wrist.
|
| It is high time for the US to have a privacy law with real teeth,
| and to enforce it with vigour.
| Ekaros wrote:
| Class-action suit sounds reasonable, but sadly those never give
| penalties in right ballpark. Here it should be hundreds to
| thousands at least per affected customer.
|
| But my guess it is few tens of cents, if that... While lawyer
| will get nice couple million pop...
| criddell wrote:
| Or maybe it's time to turn software engineering into an actual
| engineering profession. If the people responsible for designing
| and maintaining the AT&T system were "real" engineers, they
| could be sued for malpractice or even lose their license to
| practice.
| ghaff wrote:
| Do you really think that requiring 4-year degrees and passing
| a licensing exam would make a big difference? The fact is
| that, outside of civil engineering which involves a lot of
| dealing with regulatory agencies, most engineers in the US
| don't have PEs. I started on the path to get one because, had
| I stayed on my initial career path, I'd have been sending
| blueprints etc. to regulatory agencies but I ended up
| changing careers.
| acuozzo wrote:
| No, what will make the difference is being personally
| liable for the vulnerabilities you introduce.
|
| Not the company. You.
| ghaff wrote:
| How many individual engineers do you suppose get
| prosecuted for making errors--even careless ones? I'm
| guessing very few in the West. And I'm not even sure
| lopping off a head here and there to encourage the others
| is even a good idea.
| criddell wrote:
| > How many individual engineers do you suppose get
| prosecuted for making errors--even careless ones?
|
| Not many but is that because they don't get sued or
| because professionals who face consequences for
| negligence make fewer stupid decisions?
| ghaff wrote:
| I would assume that engineers, at least in the US, are
| far more concerned about getting fired/eased out than
| prosecuted if they do stupid things given that companies
| can do so pretty easily.
| criddell wrote:
| Would you say the same is true for a lawyer? Are they
| more worried about being fired from a law firm than being
| sued for malpractice and being disbarred? If not, why
| would engineers be different?
| ghaff wrote:
| I would assume that being disbarred has a pretty high
| standard of misconduct as opposed to simply not making
| partner or whatever level of action makes maintaining
| employment at a large law firm practical.
| jen20 wrote:
| Look at Sarbanes-Oxley for precedent. Management has to
| be made liable for sufficient cultural shift to occur.
| lesuorac wrote:
| Snowflake still works though. What civil engineer has been
| sued because somebody jumped off their bridge? You get sued
| when the bridge collapses not when somebody uses it for an
| unintended action.
| jen20 wrote:
| The root cause is not whether engineers are licensed (I'm
| fine with that idea, but it's not going to resolve this
| specific problem). Instead, it is a culture of not caring
| about security because the fines are a cost of doing business
| is, and which comes from management, and treating personal
| information as an asset instead of a liability.
|
| A Sarbanes-Oxley style law that makes the CEO personally
| criminally responsible for breaches will be vastly more
| effective than pursuing individual engineers - many of whom
| will be on the types of visa where they have no effective
| route of pushback on orders anyway.
| criddell wrote:
| When a doctor is negligent, their employer is often also
| sued if it can be shown that it knew shenanigans were
| underway and did nothing.
|
| We shouldn't choose between holding engineers or executives
| responsible. Each should be held responsible for their
| part.
| jen20 wrote:
| Indeed - but we should start at the place likely to
| actually make a difference: the executives.
| JohnMakin wrote:
| So where/what is my compensation? (I know there is no recourse).
|
| When no one is on the hook for secure practices, like enabling
| MFA on your effin data stores that contain massive amounts of
| customer PII, this is the result. Not even an apology, just
| report it and move on. woops! those gosh darned cyber criminals.
| criddell wrote:
| If you go to court and ask for compensation you would likely be
| asked to show harm. Could you?
| JohnMakin wrote:
| It really doesn't matter. Compensation has been dispensed to
| customers in data breaches such as credit/ssn info, no harm
| proof needed. Potential for harm is enough. Breach of
| contract, as a customer do I have a reasonable expectation
| that this data is not exposed? of course I do. No one could
| very seriously argue it's a zero sum.
| EarthLaunch wrote:
| Is there no harm, or is there harm that is hard to show in
| court?
| lesuorac wrote:
| A bit of both.
|
| Most people aren't going to have their identity stolen (or
| insert w/e crime). Those that do will have trouble proving
| it was from this leak.
| latchkey wrote:
| I've received checks over the years for various things like
| this. You end up having to fill out a claim form and then wait
| about 5 years and one day, you get this check in the mail for
| some tiny amount of money.
| floatrock wrote:
| > In a statement, AT&T said that the stolen data contains phone
| numbers of both cellular and landline customers, as well as AT&T
| records of calls and text messages -- such as who contacted who
| by phone or text -- during a six-month period between May 1, 2022
| and October 31, 2022.
|
| AT&T customer? Prepare for phone calls / text messages from your
| most frequent contacts saying "I got stranded / I'm Officer
| Blahblahman helping your friend get home... please send gift card
| / venmo"
|
| It's only metadata...
| morkalork wrote:
| I guess everyone is going to learn what Snowden was worried
| about the hard way now. I imagine there's going to be extortion
| attempts over calls to abortion clinics etc.
| smcin wrote:
| Among other things. The data's mostly from May-Oct 2022.
| rustcleaner wrote:
| I just realized this is going to fvck my call blocking strategy
| up: now creditors will have a bank of known good numbers to
| spoof into my whitelist with! :^O
| josefritzishere wrote:
| damn
| ungreased0675 wrote:
| So, AT&T wasn't using MFA?
|
| A lot of information can be derived from analysis of call
| records. If this information becomes public, it could be
| disastrous.
| ffsm8 wrote:
| > _If this information becomes public, it could be disastrous._
|
| Isn't it even worse if it doesn't become public? It's been
| downloaded by an unauthorized party after all, so if they're
| not publishing the data, I'd wager they've found another way to
| profit from it. I.e. blackmail or similar.
|
| I guess it depends on your viewpoint wherever that's better or
| worse.
| xyzzy4747 wrote:
| It's interesting when you have these old, large, sprawling
| bureaucratic organizations and the employees hardly give a sh!t
| anymore and allow for these large vulnerabilities. It's not a
| money issue, it's a caring issue I think.
| hypeatei wrote:
| Our economic system is at odds with security because we're
| trying to "get by" as cheap as possible. That doesn't bode well
| for protection of users' data.
| lotsofpulp wrote:
| During the last decade, ATT's leaders decided to burn tens of
| billions of dollars by overpaying for obviated businesses
| like DirecTV and Time Warner.
|
| I can only imagine the quality of mobile and fiber networking
| we could have had if that money was spent on
| telecommunications. And maybe they would have spent a few
| million on having proper security.
| dopylitty wrote:
| Not only that they blew $8 billion/year on dividends that
| could've gone into the business or to employees instead of
| being extracted and given to people who have nothing to do
| with the business.
| lotsofpulp wrote:
| When people invest in a business, whether it be your
| sibling's business, or a local business, or a publicly
| traded business, they do it because they expect a return
| on investment.
|
| An infrastructure utility such as ATT typically has to
| offer dividends because it is not going to experience the
| type of growth that would result in a return via share
| price increase.
|
| Of course, ATT's prices are not regulated like a proper
| utility, even though they should be, but it is still
| subject to the same market forces that prevent it from
| growing like a tech company would, who would have the
| option of foregoing dividends (or share buybacks).
| aitchnyu wrote:
| Tangential, why did you/anybody spell "shit" like they are
| evading Tiktok language filters?
| swarnie wrote:
| Why would AT&T even need to keep this data?
|
| All i can think of is billing for a fraction of plans from the
| early 2000s who still pay per min/per text. Or maybe for capacity
| metrics but even then you only need the overall data point not
| the actual records once collaborated.
|
| What's the US law for keeping data as long as its relevant and
| needed?
| ilteris wrote:
| I am an ATT user and on a pixel which generally good at filtering
| spam messages. I have noticed I was getting so much spam messages
| recently ("wanna make money working remotely for x hours a day
| only") I was surprised and thought my number somehow made it to
| one of those spam networks. This confirms my suspicions.
| bobo_legos wrote:
| Snowflake might want to take this page down in light of today's
| news.
|
| https://www.snowflake.com/en/customers/all-customers/case-st...
| cddotdotslash wrote:
| Another article[1] cites AT&T's Snowflake deployment as the
| source of the breach:
|
| > It's not clear for what reason AT&T was storing customer data
| in Snowflake, and the spokesperson would not say.
|
| [1] https://techcrunch.com/2024/07/12/att-phone-records-
| stolen-d...
| smcin wrote:
| AT&T stock has already bounced back from much of the initial
| -2.6% drop this morning, so the market thinks AT&T is immune.
| Meanwhile Snowflake is -3.9% down (they have many other customers
| than AT&T).
|
| https://www.marketwatch.com/investing/stock/T
|
| https://www.marketwatch.com/investing/stock/SNOW
| jader201 wrote:
| I never got the impression that the market ever cares about
| data breaches. It seems most companies are rarely held
| financially responsible for data breaches anyway.
|
| I would bet any effects you're seeing in stocks is unrelated to
| this news.
| smcin wrote:
| They are very much related to the news, that's precisely why
| I linked to the stock charts: AT&T was flat overnight but
| opened (9am ET) with a -2.6% spike down, but has been
| recovering since. Their press release appears to have been
| Friday 7am ET shortly before market open
| [https://about.att.com/story/2024/addressing-illegal-
| download...].
|
| Also as corroboration here's MarketWatch: "AT&T's stock
| slides 3% after company discloses hack of calls and texts"
| [https://www.marketwatch.com/story/at-ts-stock-
| slides-2-9-aft...]
| soulofmischief wrote:
| I'm not saying there's no way the stock pullback wasn't
| caused by the hack, but it's also important to note that
| MarketWatch article only establishes correlation, not
| causation.
| seadan83 wrote:
| Most linked financial news is auto-generated and auto-
| correlated. Lots of "why did.." when nobody knows, and
| frankly there often is no why. Perhaps that was the day a
| retirement fund shifted money, who knows.
|
| While this price movement is very well correlated,
| perhaps causal even, but marketwatch (and all similar
| bottom feeders that are just trying to make ad revenue),
| it's a case of a broken clock being right. Those
| financial news sites which link recent news to stocks, eg
| Yahoo, benzings, - those recent news headlines are just
| the same as ad tech now. It is noise.
| graybeardhacker wrote:
| I agree.
|
| This is precisely why breaches keep happening and will keep
| happening. It cost money to implement security. There's no
| cost benefit to spending that time and money since there are
| no consequences.
|
| Businesses do not spend money unless it will make them money
| or save them money.
|
| There needs to be a hefty federal fine on a per-affected-user
| basis for data breaches. Also a federal fine for each day a
| breach is unreported.
|
| That money should go into a pool which can be accessed by
| people who have their identity stolen.
| ThunderSizzle wrote:
| Or a lawsuit go through where someone can win quite a bit
| from from data leaks. If each person affected sued and won
| 100k or so, or even 1k, AT&T would definitely be spending
| money on security.
|
| But it appears $5 or credit monitoring from an agency that
| also gets hacked is sufficient for class action lawsuits.
| malcolmgreaves wrote:
| That requires people to be rich enough to sue. It takes a
| lot of money and time to sue. Almost no one has enough
| resources to do this. The courts are not an effective way
| to implement this policy. Unless you only want rich
| people to be able to get justice.
| CityOfThrowaway wrote:
| 110M people impacted = class action
|
| The lawyers work on contingency
| unixhero wrote:
| Imagine the GDPR fine
| pas wrote:
| showing damages is hard
| mrguyorama wrote:
| Class action suits regularly end up getting you "$5"
| worth of credit monitoring from the exact company who
| lost your data. It's a joke. Class action suits as they
| exist today in the US are an abject failure of justice.
| fn-mote wrote:
| If they end up with the company having to pay anything,
| it is greater than fines imposed by regulatory
| agencies... who should be doing this job.
| Borg3 wrote:
| And rich people usually do deals off-court. You will pay
| me this and we are ok. Because its faster and both sides
| know they capabilities usually.
| financypants wrote:
| "12 months free credit monitoring with auto-renewal".
| blackeyeblitzar wrote:
| Most companies now include clauses that force arbitration
| and prevent you from using a class action lawsuit. This
| type of sidestepping of the public justice system should
| be outlawed, retroactively, with retroactive lawsuits (by
| extending the statute of limitations), retroactive fines,
| and retroactive jail time.
| cm2187 wrote:
| Most breaches are because of developper incompetence.
| Throwing money at it won't really help. You need better
| basic security skills.
| slg wrote:
| No two people are incompetent in exactly the same way.
| Hiring two developers to review each other's code leads
| to better code because they will often find problems that
| the other one didn't see. In a well managed organization
| (admittedly not a trivial caveat these days), more people
| working on security leads to better security.
| cm2187 wrote:
| Certainly, but for instance no sane developer should
| concatenate a string in a sql query unless there is
| absolutely certainty the string is safe. This should be
| reflex, not a matter of money or time.
| slg wrote:
| People are alway going to make bad decisions. Sometimes
| that is out of a lack of experience or knowledge which
| can be fixed by better training (which also requires
| money). Other times it is out of apathy, laziness, or
| something else that can't be easily fixed. Either way,
| time and money can provide extra sets of eyes to find and
| fix those mistakes before they lead to a breach.
| dboreham wrote:
| > It cost money to implement security.
|
| Yes, but no amount of money will stop the data in a big
| database being stolen by someone sufficiently motivated to
| steal it. It's just bits on someone's disk.
|
| The only true solution is to not create the database. But
| then what would all the data scientists and their MBA
| masters so with their time?
| currymj wrote:
| in this case it's pretty tough because the phone company
| does need this metadata just to bill people. so they
| should protect it properly.
| compootr wrote:
| I don't see a reason as to recording who contacted who.
| If it's for billing, just record duration, if they're not
| an 'unlimited' customer and flags on whether it'd incur
| extra charges (i.e roaming, international call)
| chung8123 wrote:
| I think they will care a lot more when it directly impacts
| them. If all their text conversations were publicly available
| that would cause some outrage.
| rybosworld wrote:
| There is some evidence that it does hurt stock prices:
|
| https://www.comparitech.com/blog/information-
| security/data-b...
|
| "Stocks of breached companies on average underperformed the
| NASDAQ by -3.2% in the six months after a breach disclosure"
|
| That said, it's not clear what the long term impact is on
| stock price (if there is any).
| teraflop wrote:
| Unfortunately, that analysis seems to have made absolutely
| no attempt to check whether the results are statistically
| significant.
|
| Pick 118 random companies at 118 random points in time.
| It's vanishingly unlikely that the average returns of that
| group will _exactly_ track the NASDAQ returns over the
| following 60 days. It might underperform, or it might
| overperform. An underperformance of 3.2% could easily just
| be the result of random chance, and have nothing to do with
| data breaches.
| jkaptur wrote:
| My hypothesis would be that companies with poor
| operational practices are more likely to underperform the
| index _and_ have data breaches - in other words, that the
| study confuses cause and effect.
|
| This wouldn't be that hard to test. I suspect that the
| breached companies underperformed in the six months
| before the breach as well as the six months after.
| Terr_ wrote:
| Also, events which are not "just" data-leaks but also
| interruptions or degradation in regular operations. I
| suspect investors may be more sensitive to those events
| and their fallout, and such events more likely to either
| be caused by bad-practice or to be somehow connected to
| data-leaks.
| weezin wrote:
| Really should be up to the government to fine these companies
| and pay out to those effected to disincentivize lax security
| standards.
| kcmastrpc wrote:
| How would such damages be assessed or proven?
| Eisenstein wrote:
| They would be assessed according to rules written by
| people who are skilled at writing such rules. The rules
| would be evaluated by looking at data over time and
| revised as needed by experts in the industry who are as
| neutral as possible, maybe with some feedback from the
| public. The courts exist for any contention regarding
| responsibility.
| hodgesrm wrote:
| Well, I guess we devs should also be looking at ourselves,
| then. A lot of the lax security comes from us collectively
| choosing to build applications using cloud services that
| talk to each other over the public internet. That pretty
| much describes the so-called "modern data stack."
| nashashmi wrote:
| Insurance takes up a lot of the fallout from data breaches.
| darby_nine wrote:
| I'm certainly not going to defend negligence of data
| protection but it's extremely difficult to cost as a
| liability (naively, you might even consider it not a
| liability at all) without government oversight.
| hodgesrm wrote:
| > I never got the impression that the market ever cares about
| data breaches. It seems most companies are rarely held
| financially responsible for data breaches anyway.
|
| This might also explain why there's little visible effect on
| other cloud database services either. After all, the attack
| is pretty simple and potentially affects any cloud database
| that allows access from the Internet.
| omoikane wrote:
| My reading is that the market thinks Snowflake takes the
| majority of the blame, and the content of the linked article
| seemed to suggest as much despite having only AT&T in the
| headline.
| lp0_on_fire wrote:
| The market doesn't care precisely because there is never any
| accountability.
| Vicinity9635 wrote:
| It's actually a great way to tell that it is known that the
| punishment is insufficient.
| blackeyeblitzar wrote:
| The market correctly does not care because there is no
| consequence for the current or prior executives and no
| financial consequence for the company. All they will do is
| send out some obligatory notices, mention it in their
| investor relation materials, maybe offer a year of credit
| score monitoring, and move on.
|
| We need regulations with massive fines, class action lawsuits
| (a ban on arbitration clauses), and maybe automatic minimum
| level compensation to those customers.
| xyst wrote:
| It's priced in.
| treflop wrote:
| Well it's as if you put your data in Salesforce and Salesforce
| got breached... maybe you're bad at picking vendors but the
| real loss of trust would be on Salesforce.
|
| In this case, Snowflake was also the cause for the Ticketmaster
| and Lending Tree breaches according to the article so...
|
| real lack of trust in Snowflake now.
| pylua wrote:
| And earlier this year my ssn was on the dark web due to their
| leak (or vendor). One year of monitoring? No, I'm going to need
| it for life.
|
| Security is not a concern. There is no real incentive to change
| the status quo. Make them pay for monitoring indefinitely .
| ajsnigrutin wrote:
| I never understood the american secrecy about SSN... it should
| be a "username" not a "password"...
|
| In my country you can calculate our own national id (mix of
| date of birth, autoincreasing number by each birth that day + 1
| checksum number), and if you do/have any kind of personal
| business, your personal tax number has to be written
| everywhere, on every receipt you hand out or anything you buy
| as a business.
|
| Somehow knowing that first boy born today will have an ID
| number of 120702450001X (too lazy to calculate the checksum,
| but the algorithm is public), doesn't help anyone with anyting
| bad.
| ThunderSizzle wrote:
| SSN is too public for it to be private or secret. Multiple
| employers, schools, medical institutions, financial
| institutions all ask for it, so it's not private.
|
| It's also treated as evidence of who you are, but it isn't
| tied to identification like an ID is. These institutions use
| it without ever truly validating it.
|
| It's similar to how records fraud can occur - people can
| record anything to the local registrar office, including
| fraudulent documents, without any checks. Once it's
| registered, it becomes evidence against the real owner. It's
| really messed up.
| strangecharm2 wrote:
| This comment pops up every time someone talks about social
| security numbers. Yes, they were never supposed to be
| private, but now they are. So either Congress can do
| something about it, or big companies can stop leaking them.
| Clever "well, actually"s didn't stop my identity from being
| stolen recently after a breach, and they never will.
| dboreham wrote:
| They're not really private+, and nobody should design a
| system with the assumption that they are. afaik nobody does
| these days. There are extra authentication checks done in
| addition to simply "I have the SSN".
|
| + e.g. until very recently there were US states that used
| your SSN as your driver license number.
| browningstreet wrote:
| A lot of financial things in the US are "secured" or anchored
| by SSN, that's the only reason why. That and mother's maiden
| name and first vacation and other security questions. It'd be
| less important with MFA now but SSN is also needed when
| opening new credit, so having it allows you to pretty easily
| fake someone else's identity for credit. KYC hasn't removed
| it from the equation.
| madcaptenor wrote:
| "Mother's maiden name" won't work for my kids - my wife
| kept her name and the kids' last name is hyphenated, so you
| just have to guess whose name we put first.
| AuryGlenz wrote:
| It's also probably increasing easy to look up.
|
| We need a national (preferably RFID-ish) password system.
| athenot wrote:
| One mitigation is to make your mother's maiden name the
| output of: head -c 20 /dev/random |
| base64
|
| And keep track of the result in your favorite password
| manager.
|
| Fortunately, fewer and fewer orgs are using security
| questions, but there are still some important ones that
| only use that and no MFA.
| theluketaylor wrote:
| The problem with that plan is social engineering attacks.
| CSRs are often careless and will accept 'a bunch of
| random letters and numbers' as the answer rather than
| validating each character.
|
| Better to randomly select a long dictionary word or
| hypenate a few together. Equally unguessable but easily
| verified, so it won't be weakened during a phone
| conversation.
| dylan604 wrote:
| Even the US gov't gave up on the notion the SSN was not to be
| used as an identifier. My dad's SS card had a phrase printed
| on it saying so. My SS card did not have that text.
| hermitdev wrote:
| My SS card has that text. I got into an argument at the DMV
| when they asked for it. I relented because I needed my
| drivers license.
|
| Congress could solve this by enacting a simple law.
| Something to the effect of SSNs shall not be used as a
| means of identification by any party, governmental or
| otherwise other than the Social Security Administration.
| Use of an SSN as identification shall be subject to a $100
| fine per each SSN used as identification, per day.
| alistairSH wrote:
| _I never understood the american secrecy about SSN... it
| should be a "username" not a "password"..._
|
| The problem is banks/financial services do a piss-poor job
| validating identity when issuing credit/opening accounts.
| "Oh, you provided an address, a SSN, and [non-random, easily
| discoverable personal fact]! Sure, here's a CC with a $150k
| limit!"
|
| It's not the leak that's the problem; it's the ease with
| which that leaked data is used to either obtain fraudulent
| credit or access accounts.
|
| I don't have a good answer, because at some point, a
| financial institution needs to trust people to do business.
| Customer loses their phone, so MFA doesn't work, ok, now
| what? I guess the customer needs to have one-time use
| recovery tokens saved somewhere that can't be lost? How many
| people do that (not nearly enough)? How many banks even issue
| those tokens? And what if the token store gets hacked? Now
| you're really fucked.
| piva00 wrote:
| > Customer loses their phone, so MFA doesn't work, ok, now
| what? I guess the customer needs to have one-time use
| recovery tokens saved somewhere that can't be lost? How
| many people do that (not nearly enough)? How many banks
| even issue those tokens? And what if the token store gets
| hacked? Now you're really fucked.
|
| In my experience with banking in Brazil and Sweden this is
| easily solved with a OTP device you get from your bank.
|
| Brazilian banks before that used to provide a card of
| 50-100 tokens you'd use for authenticating, which is
| obviously dangerous as people would carry them in their
| wallets with their cards (and associated banking details).
| Since the early 2010s banks have instead provided a
| physical OTP generator that you associate with your
| account.
|
| In Sweden if I lose access to my phone with my digital
| identification app (BankID) I can fall back to my hardware
| OTP generator to login into my account, and authorise a new
| BankID installation in case I need a new phone.
|
| It's a solved problem, even though the US developed a lot
| of the tech industry it feels like digital infrastructure
| is still in the late 90s for a lot of stuff; banking is a
| clear case, and government systems are another good
| example, e.g.: the DHS website for visa application is
| atrocious, we are in 2024 and applying for a visa feels
| like an experience from when I navigated the web on
| Netscape in the early 2000s.
| alistairSH wrote:
| Totally agree. It feels like our banking is a decade
| behind - like transfer money - no direct way to do it
| between banks - most people use Venmo. Some banks are
| part of Zelle, but I've heard it has fraud issues (weak
| discovery/confirmation of correct recipient) and the
| banks won't refund many fraudulent transfers ("You
| initiated the transfer! Not our problem you sent to the
| wrong person!").
|
| So, do you get a physical OTP generator for every
| financial institution? I guess that works, but that would
| mean I'd have a drawer full (2x bank, 1x work, current
| 401k, past IRA, and a brokerage account - x2 because my
| wife has about the same).
|
| I was thrilled last year when I discovered I could renew
| my passport online! In 2023! That should have been
| available eons ago.
| galdosdi wrote:
| It's because it happened gradually / naturally / semi un
| intentionally, because:
|
| 1) SSN was not intended as a national ID, but it so happened
| to fit the shape of one, in that almost everyone has one and
| they're unique.
|
| 2) It has never been possible to institute an intentional
| national ID system in the US for political reasons
|
| That is the recipe for the problem we have now. Strong demand
| for a national ID from many business purposes, the existence
| of something that looks a lot like, but is an imperfect form
| of, national ID, and the refusal to create a proper national
| ID, has naturally led to a de facto system of abusing the SSN
| as a national ID and just kind of everyone being a little
| annoyed and sketched out about it but putting up with it
| anyway for lack of alternatives.
|
| Incidentally, did you know anyone can generate a valid new
| EIN (which is a lot like an SSN, and can be used where an SSN
| can be used for some but not all purposes, specifically
| filing taxes and ) at this page
| https://www.irs.gov/businesses/small-businesses-self-
| employe... ? This isn't legal advice and I'm not a lawyer and
| I don't know in what situations you personally would be
| legally permitted to use this (it's meant for businesses,
| absolutely not some kind of personal alias) -- but
| technologically, it's just honor system, and anyone can
| certify they need and are entitled to a new EIN and the IRS
| web site will provide you with a new unique one. I don't
| think you even need a legal entity, since you don't need a
| legal entity to run a business in the US.
| james_marks wrote:
| Also NAL, but watch out for how this is reported to states.
| California is currently $800/year min, even if the entity
| has no activity.
| galdosdi wrote:
| > Somehow knowing that first boy born today will have an ID
| number of 120702450001X
|
| It's even worse. Only post-2011 IIRC births have an
| algoirthmic SSN. So everyone over the age of 13 still has old
| fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by
|
| 1) XXX is the code for the office that issues your card. Can
| be guessed precisely and accurately by knowing birth
| location. For example, I can guess what region of the US you
| were born in (or lived in when you immigrated) by the first
| digit. 0 or 1 is probably northeast. 4 or 5 is probably near
| Texas. 7 might be near Arkansas. Etc.
|
| 2) YY-ZZZZ is sequential by date! So by knowing just birth
| day, can be guessed to within a range. In practice, this
| means it's easy to guess YY alone, but harder to get all 4
| digits of ZZZZ
|
| 3) For some stupid reason it got popular to print SSNs with
| all but the last four digits masked. This is horribly bad
| because those four are ACTUALLY THE MOST SECRET PART! It's
| the only part that might not be guessable. But since it's
| common to be more lax with securing them..... it is super
| easy to recover the full SSN if you find a piece of paper
| that says something like
|
| JOHN SMITH
|
| 123 Main St
|
| Alabama City, AL 76543
|
| In ref acct: XXX-XX-1234 (2001-03-14)
|
| Dear Mr Smith,
|
| Your account is overdrawn. Have a nice day.
|
| Thinking of you,
|
| The Bank
|
| It also means if someone is personally known to me, even
| vaguely, I may be able to reconstruct their social seeing
| nothing but a scrap of paper that has just the last four, if
| I can guess approximately where and when they were born or
| first entered the US. If I'm in a situation where I can try
| several guesses, it's even easier.
| 5555624 wrote:
| > 1) XXX is the code for the office that issues your card.
| Can be guessed precisely and accurately by knowing birth
| location.
|
| While the first sentence is true, the second is only true
| if you were born after the mid-1980s, when a Reagan-era tax
| reform was enacted. (It required a SSN when claiming
| dependents.) Prior to that, most people did not get a SSN
| until they got a job.
| nostrademons wrote:
| I looked this up and while your first sentence is true,
| the second (non-parenthetical) sentence is only true if
| you did not require any of the other services that
| required a SSN. There's a list of those under "Exhibit 2"
| (about 2/3 of the way down the page) on the SSA's
| website:
|
| https://www.ssa.gov/policy/docs/ssb/v69n2/v69n2p55.html
|
| tl;dr: If you had a bank account, applied for a federal
| benefit, were on food stamps, applied for school lunch,
| or did any number of other financial or government
| transactions, you needed a SSN starting in the 1970s.
| That's enough of an incentive that many parents might've
| just applied at birth, figuring that their kid will
| eventually need it. Also everyone born 1968-1981 would've
| likely gotten one in 1986, when the change you mentioned
| about dependents was enacted, and then after 1988 they
| started being required for issuance of a birth
| certificate.
| 5555624 wrote:
| I stand corrected. Thanks. I didn't bother to look it up,
| since I'm old and got mine when I started working.
| Although people born 1968-1981 were getting SSNs where
| they currently lived, which is not necessarily where they
| were born; which was the original point.
| chankstein38 wrote:
| When I was in school (almost 20 years ago) this came up
| because someone mentioned the first 6 digits of their SSN
| and they matched mine. Since then it's similarly bothered
| the hell out of me that the practice is to mask all but the
| last 4 of the SSN and that a lot of places require you to
| enter your last 4 of your SSN.
|
| I didn't know the reasons for the matches but them being my
| age and likely born in the same place as me made me realize
| those were identifiers and the last 4 were the unique bit.
| demondemidi wrote:
| When I went to college in the late 80s my ssn was automatically
| used as my student id. When I got my first bank account in
| 1990, they used my ssn as the account number.
| buildsjets wrote:
| Our class grades with names snd SSNs were posted on the wall
| after exams in a list of hundreds of students.
|
| Go Jackets.
| galdosdi wrote:
| Ah it was a different time. Societal trust was greater.
| Without global internetification, the only people who could
| ever have any opportunity to exploit this information were
| your fellow campus denizens (students, professors, etc).
|
| Without global internetification, there was not as much an
| average person could really do or would know to do with an
| SSN alone to exploit it.
|
| This story is a good parable for so much of what has
| changed in the world the last couple decades -- we had a
| world built for less globalization, then we globalized, and
| we've been gradually adapting to / dealing with the
| unintended consequences since then.
|
| A real life door can only be picked by your neighbors or
| anyone else nearby -- attack surface is limited by the
| nature of physical distance.
|
| A virtual door can be picked at by 7 billion people.
| xyst wrote:
| I wonder if the schools actually verified the SSN.
|
| Would have been dank to see 666-66-6666 next to your name
| mdavidn wrote:
| My first big employer in the aughts had my SSN encoded in a
| bar code on the back of my company ID, which they expected us
| to display at the office.
| uticus wrote:
| It's okay, will no longer be problem after Social Security
| Admin itself fails in next decade for being unsustainable
| vundercind wrote:
| Why would that happen?
|
| (Payouts are expected to drop in about ten years if no action
| is taken, but that doesn't render the SSA irrelevant or cause
| it to suddenly collapse and shut down, so I assume you mean
| something else)
| pixelesque wrote:
| SSN might be the least of the problems in some cases in terms
| of the info leaked...
|
| What about people who have called suicide helplines, abortion
| clinics, loan servicing, etc...
|
| With the numbers available, that will be possible to find
| out...
| cwillu wrote:
| "Brad Jones, chief information security officer at Snowflake,
| told CNN in a separate statement that the company has not found
| evidence this activity was "caused by a vulnerability,
| misconfiguration or breach of Snowflake's platform." Jones said
| this has been verified by investigations by third-party
| cybersecurity experts at Mandiant and CrowdStroke.
|
| AT&T said it launched an investigation, hired cybersecurity
| experts and took steps to close the "illegal access point.""
|
| That's pretty rich: "it wasn't misconfigured, it was just
| illegally open, and now we're closing it".
| zomg wrote:
| when will governments hold these companies, but more importantly
| their executives, criminally liable for their lack of protecting
| customers' information?
| hulitu wrote:
| When they will not buy data from them. /s
| mdale wrote:
| Interesting that they use the word criminals instead of hackers..
| makes it sound like it was a physical heist rather than poor
| security practices on their part :)
| demondemidi wrote:
| They are criminals.
| BenFranklin100 wrote:
| This is a political problem. Until we pass laws that companies
| can be find liable for significant damages in the event of data
| breaches, we will see little progress on data security. This is
| an area where Congress needs to act. Current law does not
| adequately protect the public due to the difficulties in
| establishing standing, tying specific breaches to specific
| personal damages, other reasons.
|
| Such a law would seriously impact current practices of the
| majority of IT firms, including small app developers, which is
| why we see little push from silicon valley for such changes.
| abduhl wrote:
| >> AT&T said it learned of the data breach on April 19, and that
| it was unrelated to its earlier security incident in March.
|
| Why was this not disclosed on AT&T's earnings call on April 24?
| At least someone will get compensated for the breach, although
| it'll be the lawyers for the class action lawsuit that's about to
| hit instead of the customers that got their information stolen.
| graybeardhacker wrote:
| Freeze your credit people! It's super easy. It's not a perfect
| fix but it's so trivial to do and it will help.
|
| https://www.usa.gov/credit-freeze
|
| You can unfreeze through an app whenever you want/need to.
| pavel_lishin wrote:
| Is there any reason not to keep credit frozen _permanently_ ,
| only unfreezing it when you're making a large purchase that
| requires it?
| noodlesUK wrote:
| Unfortunately it isn't an option in every country. In the
| U.S., you can freeze your credit for free, but in the UK, you
| can't. I think we should get rid of the CRAs entirely, but
| that's a conversation for another day.
| troyvit wrote:
| That's what I do. It also slows my roll. It's an extra step I
| have to take before making that large purchase or applying
| for anything that requires a credit check.
| yelling_cat wrote:
| It's an extra step, but a surprisingly simple one. When I
| opened a checking account recently the bank told me which
| credit agency they'd use, and I unfroze that account and
| ChexSystems (another credit agency you should freeze with
| that is used specifically for new bank accounts) in five
| minutes using their automated systems. You can supply a re-
| freeze date when unfreezing as well so you don't need to
| remember to do that manually once you're approved.
| k4j8 wrote:
| Keeping your credit frozen permanently is a great idea. Some
| of the credit agencies even encourage this with features such
| as a temporary unfreeze of your credit for a few days/weeks
| and then back to the permanently frozen state.
| tnel77 wrote:
| It's a great idea! I only unfreeze my credit for big
| purchases like buying a house or car.
| david422 wrote:
| Yep. This is what I did after the first Experian data breach,
| for peace of mind. I am probably financially lucky enough
| that I don't need to constantly be checking or using my
| credit... but honestly it seems like this is what everyone
| needs to be doing.
| lotsofpulp wrote:
| I open credit cards for the bonuses frequently enough that
| freezing my credit would be more inconvenience than it's
| worth.
|
| Also, all the big bank websites seem to offer real time
| credit history monitoring for free, so I am betting I'll just
| deal with any problem if/when they happen.
| rqtwteye wrote:
| That's what I do. But it's a little bit of pain to unfreeze
| your credit with three bureaus when you want a new credit
| card. Wish there was a way to do this in one place.
| r3trohack3r wrote:
| After the first time unfreezing, I put the website URL,
| unlock pins, and concise instructions for all 3 as a single
| note in my password vault.
|
| Doing all 3 takes ~5minutes now - which can usually happen
| in parallel with whatever paperwork the vendor needs to get
| in order.
| al_borland wrote:
| This is how I have operated ever since the Equifax breach.
| Once that happened, none of the others seemed to matter,
| everything important for identity theft is out there.
|
| I've had no problems. Someone will try to run my credit, it
| will fail, then I ask which one they're trying to use, and I
| unfreeze it for a day. Some of them have the option to
| unfreeze for a single pull with a 1 time code (if I remember
| correctly), but when I tried to use that the person trying to
| pull the report seemed clueless, so I had to do the 1 day
| unfreeze.
| bee_rider wrote:
| Credit is a weird ad-how system.
|
| At some point, I wonder if folks will realize that having
| an unfrozen credit report is a sign of imprudence.
| kodt wrote:
| One interesting thing I ran into with frozen credit, is that
| you cannot sign up for USPS informed delivery without them
| running your credit as a method of address verification IIRC.
| If it is frozen the process gets stuck in limbo (at least it
| did many years ago when I ran into this situation)
| golf1052 wrote:
| This is no longer the case. I signed up for Informed
| Delivery last year with frozen credit with no issues.
| nijave wrote:
| As someone else mentioned, some authentication schemes
| require your credit to be unfrozen. This can include
| insurance companies (really any company that needs to verify
| your identity)
| xyst wrote:
| I typically don't "freeze" my credit but do have a handful of
| services actively monitoring my credit for free (have been
| involved with many data breaches) and it's included with my
| credit cards.
|
| > A credit freeze restricts access to your credit report
|
| So if I freeze my credit, this will also deny access to the
| monitoring services AND financial institutions, right?
|
| Side note: financial institutions often do "soft" credit pulls
| on active account holders to determine if they are eligible for
| credit limit increases. Have been growing my existing credit
| line for some time now without having to obtain additional
| credit cards. So far, close to $500K in unsecured credit.
|
| Seems more like a nuclear option.
| psadauskas wrote:
| Fuck that. I'm gonna open a bunch of credit cards, buy a bunch
| of cool shit, and when they ask me to pay my bill, just say my
| identity was stolen.
|
| If I have to fight the credit bureaus anyway, I might as well
| get something out of it. Stealing my own identity seems pretty
| straightforward.
| zzyzxd wrote:
| I keep my credit frozen all the time, but still keep getting
| alerts about new "no credit check" bank accounts from companies
| like chime.com. Then I give them my PII again just to verify
| and close those accounts, even though I don't have any business
| with them.
| lfmunoz4 wrote:
| what app or website do you use? Seems like you have to sign up
| for all three websites? Equifax Experian TransUnion?
| therealmocker wrote:
| I couldn't find a reference to an app on the linked page, could
| you share more details on the app you use?
| 93po wrote:
| I was unable to get any of the three to verify my identity last
| I did this, and one of the three has never once in my 15 years
| of trying to get my free credit report let me actually get it.
| nijave wrote:
| I think you can go the paper route and mail something in to
| freeze
| neogodless wrote:
| You can also freeze your non-credit banking:
|
| https://www.chexsystems.com/security-freeze/place-freeze
|
| It was recommended that I do this after a checking account was
| opened using my identity.
|
| As others have stated, my default is "frozen." I put temporary
| thaws on when applying for credit, though in some cases, you'll
| be informed exactly which agency/agencies will be queried, and
| may not need to unfreeze all of them.
| awad wrote:
| This is a great tip as most people only know of the big 3,
| thanks for sharing
| currymj wrote:
| i don't think credit freezing matters too much in this case
| because the leak wasn't tied to SSN, name, etc. that would be
| used for identity theft. it was phone call and location data.
| much worse for privacy but less useful for financial fraud.
| monetus wrote:
| It sadly does matter for anyone who applied to work at
| advance autoparts , though. Their SSNs and the like are out
| there; the company's main database was hit.
| zsdfgyn wrote:
| Key point of the article:
|
| "Snowflake allows its corporate customers, like tech companies
| and telcos, to analyze huge amounts of customer data in the
| cloud. It's not clear for what reason AT&T was storing customer
| data in Snowflake, and the spokesperson would not say."
|
| Finally journalists are asking the question why customer data
| must be stored with third party cloud providers. AT&T is a long
| way from Bell Labs, shame on them.
| orochimaaru wrote:
| All companies use third party cloud providers. A lot of legacy
| companies have been shutting down data centers to move to the
| cloud. So there isn't a question of whether why your data is in
| the cloud. It's going to be in the cloud.
| sbarre wrote:
| And honestly, I think I'd rather trust cloud providers with
| the data than the remnants of a decimated IT team in a large
| enterprise that's struggling to maintain their own on-prem
| infrastructure that's super old and probably not up to date
| on patches.
| Andrex wrote:
| The problem is then you have even fewer technically-
| competent people internally to actually manage the cloud,
| and combined with AWS's many documented footguns it's not
| clear to me the "new normal" is actually any better for
| security.
|
| You go from being a potentially-small-fry target to getting
| your data collated in massive breaches. There's risks to
| both.
| orochimaaru wrote:
| That's the thing though - this was a snowflake breach.
| It's not an AT&T miss because of their decimated sw
| engineering teams. Snowflake has much better sw
| engineering than AT&T.
| nicce wrote:
| > this was a snowflake breach
|
| AT&T was not using MFA, while it was possible. Someone
| leaked credentials and this is the result. Only thing
| Snowflake could have done was to force MFA for everyone.
| lokar wrote:
| They added a feature recently to make it easy to force
| mfa
| ChrisArchitect wrote:
| Official support page: https://www.att.com/support/article/my-
| account/000102979/
| jonplackett wrote:
| Unbelievable that they do not enforce 2FA for a client that huge.
| Absolute madnesss!
| MOARDONGZPLZ wrote:
| Is this leak why the spam next messages have gone from "Hi how is
| your day ?" or "Hi [not my name] please do thing X. Of you're not
| [not my name] I'm so sorry perhaps we can be friends." to "Hi is
| this [my full name]?" or "Hello [my first name] how is your day
| ?"
| jeffwilcox wrote:
| Any leak with your mobile and name pair could have done that.
| As a non-AT&T customer, I get the my-speecific-name pig
| butchering texts, too.
| MOARDONGZPLZ wrote:
| True. They're brand new to me though. I've been getting the
| former for years, the latter for only weeks.
| bediger4000 wrote:
| That's an enormous amount of data. How do you not notice a huge,
| network-hogging data flow?
| the8472 wrote:
| The headline could equally say "AT&T kept data for criminals to
| steal".
|
| If wiretapping laws didn't exist then most of this data would not
| be justified to exist. Flat-rate billing doesn't need to keep
| track of this information. Even usage-based plans could keep
| cumulative records rather than individual ones, or at least
| delete them at the end of a billing period.
|
| Where there is a trough, pigs gather.
| throwaway120724 wrote:
| There's no way to make the software perfectly safe from hackers
| and from social engineering. So, yes, companies should be more
| careful with the data and, yes, the data shouldn't be kept
| forever. I agree companies should be doing more to protect the
| data.
|
| I see lots of outrage at the companies and why isn't the
| government doing more to punish them and how do I get compensated
| ...
|
| But, I feel like everyone is blaming the victim. Is it the home
| owners fault when someone breaks in and steals stuff?
|
| Where's the outrage at the hackers breaking into these accounts?
| Where's the "why aren't the governments tracking these people
| down?" Why is no one demanding that the hackers be brought to
| justice?
| rightbyte wrote:
| > But, I feel like everyone is blaming the victim. Is it the
| home owners fault when someone breaks in and steals stuff?
|
| > Where's the outrage at the hackers breaking into these
| accounts?
|
| The internet is essentially every hooligan in the world about
| to kick in your dooor. So yes, I blame the home owner.
|
| It seems silly to me to condemn anonymous users of the
| internet.
|
| Back in the days when nothing of importance was done on the
| internet the view was way more healty.
|
| If you have sensitive data, don't expose it to the hooligans.
| Easy as that.
| metabagel wrote:
| > There's no way to make the software perfectly safe from
| hackers and from social engineering.
|
| This is a straw man argument. Companies should use best
| practices in order to prevent most intrusions. When they do
| not, as in this case, criticism is warranted.
| throwway120385 wrote:
| The problem with analogies is that they're a leaky abstraction.
| You're comparing a single person with maybe a handful of
| employees to a giant, multinational corporation with corporate
| offices, hundreds of thousands of employees, enough real-estate
| to create a small country, and billions of dollars per year in
| revenue. It's a false equivalence to compare this to door
| kicking like it was some kind of petty theft.
|
| They literally kept everyone's information in a machine that
| was connected to the internet and then didn't make any effort
| to treat that with the gravitas it deserves. They are not the
| victim here, we are. It's a little shameful that you don't see
| that.
| squeegee_scream wrote:
| It's ok everyone! Protecting our data is one of AT&T's top
| priorities.
|
| > Protecting your data is one of our top priorities. We have
| confirmed the affected access point has been secured.
|
| > We hold ourselves to a high standard and commit to delivering
| the experience that you deserve. We constantly evaluate and
| enhance our security to address changing cybersecurity threats
| and work to create a secure environment for you. We invest in our
| network's security using a broad array of resources including
| people, capital, and innovative technology advancements.
|
| I hope there's an enormous fine for this kind of negligence
| nashashmi wrote:
| Not their fault. Snowflake was breached. And the data was with
| Snowflake.
| jeff_tyrrill wrote:
| Your contractor being breached means you were breached.
| hobs wrote:
| Snowflake was "breached" by AT&T users using the same
| password in Snowflake and another system that was breached.
|
| This is just trivial pivoting done with some guesswork done
| fairly well.
| nijave wrote:
| Snowflake wasn't breached. A Snowflake database belonging to
| AT&T was breached.
| nashashmi wrote:
| You are right apparently.
|
| > hundreds of Snowflake customer credentials ... of
| staffers who have access to their employer's Snowflake
| environment ... credentials available online linked to
| Snowflake environments suggests an ongoing risk to
| customers who have not yet changed their passwords or
| enabled MFA.
| jdgoesmarching wrote:
| That's not how any shared responsibility model works
| xyst wrote:
| The "fine" will consist of a class action lawsuit that will
| eventually (3-4 years later) be bargained down to 1/2 the
| original claim. Lawyers take their 25% (or whatever cut was
| negotiated) fee. Then the impacted customers (assuming they
| submitted all of the claim paperwork) get paid out a few
| dollars.
| panarky wrote:
| There may be no "good" telcos or big tech firms, but some are
| absolutely worse than others. AT&T is actively hostile in a way
| others aren't.
| OutOfHere wrote:
| Unfortunate as it is, nobody genuinely cares about:
|
| 1. Preventing data breaches
|
| 2. Properly anonymizing aggregated personally identifiable data
|
| 3. Having and using a secure ID and verification system
| gmd63 wrote:
| They don't care because they don't know how the systems they
| use daily work, much less the costs and risks involved.
|
| If they knew, they would care, and that's why representatives
| care on their behalf.
|
| You could say the same about health and nutrition, but people
| very much do care when a medical issue tangibly affects them
| negatively.
| mv4 wrote:
| I am seeing this mentality as well, and it's disheartening. My
| company manufactures and sells a privacy-first, fully
| autonomous, on-prem, video security system for home and SMB.
| Yet, some people choose a cloud based service (convenient) and
| are surprised when their private data is either a) hacked, or
| b) abused by the provider's own employees (see the latest
| Amazon Ring settlement).
|
| With the latest scandals and breaches though, I feel it's
| gradually starting to change.
| stevetron wrote:
| AT&T bought into a significant amount of DirecTV - so much so
| that everything that had the DirecTV logo on it was changed to
| the AT&T logo, such as the invoicing. So the AT&T customer base
| has included, for several years, the Directv customer base. The
| article doesn't attempt to clarify who the 'nearly all' customers
| are, and some people will jump to the conclusion that it is the
| cell phone customers. But it could include the DirecTV customer
| base whose data is also at risk.
| vel0city wrote:
| AT&T didn't just buy into a significant amount of DirecTV, they
| _owned_ DirecTV. As in, 100% ownership. So yes, all DirecTV
| customers were AT &T customers, because AT&T and DirecTV were
| not separate entities. It wasn't until 2021 that DirecTV was
| spun off into a separate company again, but still with 70%
| ownership by AT&T.
| hermitdev wrote:
| AT&T does a lot more than just cell phones. Probably also the
| largest US ISP behind Comcast, I'd expect. I had AT&T fiber to
| the home at a previous residence, and that was a great product.
| Far superior to Comcast.
| skybrian wrote:
| > Snowflake blamed the data thefts on its customers for not using
| multi-factor authentication to secure their Snowflake accounts, a
| security feature that the cloud data giant did not enforce or
| require its customers to use.
|
| And is that going to change?
| dboreham wrote:
| This is a diversion. Why did they build a system that permitted
| a bulk database dump of hundreds of millions of rows even with
| 2FA?
| skybrian wrote:
| Because that's what a data warehouse is? You'd think they'd
| guard them more, though.
| vel0city wrote:
| > Why did they build a system that permitted a bulk database
| dump of hundreds of millions of rows
|
| Should all databases be capped at a few million rows total or
| something? I don't quite understand where you're going with
| this.
| MisterBastahrd wrote:
| Be nice to have a new federal law: you get breached, you pay $5K
| plus lifetime credit monitoring to each person involved. Non-
| dischargeable by bankruptcy. No arbitration, no lawsuit. You pay.
| joemi wrote:
| Interesting idea, though I think that having it be $5K (or any
| fixed amount) no matter the size of the company favors large
| companies, since large companies can probably spend more to
| reduce the risk of getting hacked. Hell, it might even
| incentivize large companies to fund hackers to breach their
| smaller rivals, in order to wipe out their competition.
| kjellsbells wrote:
| I find it interesting that in your typical BigCo breach, they are
| at pains to point out that credit card details were not stolen. I
| infer from this that something about credit cards, and how they
| are secured, has real teeth and BigCo's lawyers are trying to
| stop them biting. Is this PCI-DSS? Maybe someone can comment.
|
| As far as this breach goes, I think it just confirms my gut feel
| that Snowflake are heading to the wood chipper.
| jeff_tyrrill wrote:
| I think it's a desperate attempt to downplay the severity in
| any way plausible, taking advantage of the fact that credit
| card numbers and social security numbers have been mythologized
| in the American consciousness as nearly-mystical totems of
| identity and security, as part of the "identity theft" meme,
| even though they play little role in actual information
| security or privacy.
| mensetmanusman wrote:
| Nice way to rule out who is a spy or not. Nice.
| autoexec wrote:
| > The company said the hack wouldn't be material to its
| operations or negatively impact its financial results.
|
| And this is why consumers will continue to see their information
| compromised by companies who collect and retain more data than
| they need and then fail to invest the time and resources to
| protect it.
| JoshTriplett wrote:
| "AT&T reveals it has records of cellular customers calls and
| texts"
|
| These records should have been deleted at the _latest_ at the
| point where they 're no longer relevant for billing. (Which also
| means that for customers with unlimited calling/texting, there
| shouldn't be any records in the first place.)
| gumby wrote:
| I believe this practice was followed only in postwar France,
| and I think even there has long been jettisoned. It's been a
| while since I got a French phone bill though.
| xyst wrote:
| AT&T is well known for working with NSA -- 33 Thomas St [1]
|
| [1] https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-
| new-...
| rockskon wrote:
| That doesn't excuse this. If these records only existed so
| they could give them to the NSA at a later time, that further
| illustrates the dangers of accommodating the agency's desire
| for access to data generated from the U.S. Telecom backbone.
| SoftTalker wrote:
| If they are obligated to give the data to the NSA, they
| should give it to them in real time and then delete their
| own logs as soon as they no longer need them.
| spencerflem wrote:
| It does explain it though. By coincidence they also get
| billions of dollars in federal subsidies
| rockskon wrote:
| So do other ISPs. Yet AT&T is by far the worst of all of
| them with regards to customer privacy.
|
| Did you know that AT&T has a commercial product where
| they sell Metadata of websites visited (unclear if it's
| only Netflow or if it includes DNS lookups too) to law
| enforcement and private investigators?
|
| AT&T is a blight on the privacy of U.S. citizens.
| hulitu wrote:
| > Did you know that AT&T has a commercial product where
| they sell Metadata of websites visited (unclear if it's
| only Netflow or if it includes DNS lookups too) to law
| enforcement
|
| Do you think that only AT&T does it ? Welcome to
| democracy, my friend. /s
| rockskon wrote:
| For their landline customers? I'm not aware of any other
| ISP that's so shamelessly brazen about the practice.
| Cheer2171 wrote:
| They keep all records for 7 years because the US Federal
| Government asked them to, not because they legally have to, but
| same with T-Mobile and Verizon:
| https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...
| pixl97 wrote:
| Wasn't there some telco executive that was tossed in jail not
| long after 9/11 because he didn't want to play along with the
| government and keep data around forever?
| Lammy wrote:
| https://en.wikipedia.org/wiki/Joseph_Nacchio
|
| > Joseph P. Nacchio was the only head of a communications
| company to demand a court order, or approval under the
| Foreign Intelligence Surveillance Act, in order to turn
| over communications records to the NSA.[11]
| clwg wrote:
| I wish that were the world we live in.
|
| This is from the Snowflake breach, meaning this database was an
| "AI Powered Unified Data Platform." It almost feels like the
| erosion of our privacy is fueling the growth of allot
| companies.
|
| I really hope that the boogeyman is real and all this was worth
| it.
| gumby wrote:
| The data can be used for traffic analysis (number->number call
| data); "no PII" except it's pretty easy to match a number to a
| likely user.
|
| I'm an AT&T customer, and in my case I don't have a risk, but I
| can imagine this info could be very handy for divorce, custody,
| and corporate IP lawsuits. So worse than it might look to
| ordinary folks.
| spacephysics wrote:
| Text _meta_ data is an important distinction
|
| Still not good, but headline feels clickbait if I think my text
| messages leaked
| ethbr1 wrote:
| That's still pretty gnarly in terms of social graphing though.
| SoftTalker wrote:
| "While the data does not include customer names, there are often
| ways, using publicly available online tools, to find the name
| associated with a specific telephone number"
|
| In other words, your phone number and name is likely in a public
| record somewhere. It's not that private.
|
| The info leak should not have happened but in the grand scheme of
| things it's not that big a deal. "The content of the calls and
| messages was not compromised." The worst it does is reveal who
| has been sending messages to or calling each other.
| BobAliceInATree wrote:
| That metadata was can be terrible for many people like
| politicians, those having affairs, drug dealers or buyers,
| those with sensitive healthcare providers, and so on.
| mass_and_energy wrote:
| This. If you're in an abusive relationship and your abuser
| sees that you're calling a lawyer, a helpline, a family
| member etc, bad things can happen quite quickly. This
| information is non-public for a reason, and you don't have to
| be a drug dealer to be protected by it either.
| SoftTalker wrote:
| Yeah it's not good. But would be worse if the actual
| contents of the messages had been leaked.
|
| That said the few abusive people I know are not smart
| enough to find data dumps of AT&T call records on the dark
| web. Nor could they pay for them. Nor could they likely
| make sense of them. But I'm sure some could.
| CuriouslyC wrote:
| Big breaches like this are gonna be wild with advanced GenAI.
| Combing through the shit for the diamonds provided some degree of
| limitation on the impact of big breaches in the past but all
| those calls are going to be accurately transcribed and mined by
| AI and the attackers are going to have a buffet of products and
| targets laid at their feet.
| mass_and_energy wrote:
| It's just metadata, no transcription of calls can take place.
| In the future, please read the article before engaging in the
| discussion of its content.
| nunez wrote:
| Metadata can be identifying enough. For example, given
| someone has this data and some local LLaMa variant on their
| machine, they could theoretically run a query like: "Give me
| all of the people that $NAME have called to, sorted by the
| number of times they called each other"
| hulitu wrote:
| > It's just metadata
|
| That's what they always say, honey, before calling the
| police. /s
| II2II wrote:
| My first question is: why was the data being stored by a third
| party in the first place?
|
| Shouldn't data like this be stored completely independently of
| the Internet? Yes, I realize that does not guarantee it is secure
| since there has to be some point of access. On the other hand, it
| would reduce opportunities for people to breech the databases.
| Cheer2171 wrote:
| Because they don't care about actual information security, they
| care about "national security." They optimize for giving all
| branches of US law enforcement, from the federal to state to
| local level, access to 7 years of historical data whenever they
| claim they need it.
| II2II wrote:
| I don't buy into that theory, at lrast in this case. There
| are other ways to hand-off data when it is legally requested.
| On the other hand, such data would be valuable to foreign
| actors who do not have a legal means of accessing such data.
| It would require a high degree of incompetence to sacrifice
| national security in the name of convenience.
| chasenjohnson wrote:
| You would effectively be able to cross reference this meta data
| with 2 factor authentication services. It's probably time to
| start removing this option entirely.
| sedatk wrote:
| How would cross-referencing be useful? You'd just find out what
| services people use?
| rboyd wrote:
| I guess after mapping the services used you would find the
| accounts worth going for and those become SIM swap targets
| mikeocool wrote:
| Seems like there's a lot of cross referencing well beyond
| MFA that this'll likely be used for.
|
| Way easier to target phish people's bank logins, if you
| know what banks they are regularly communicating with.
| chasenjohnson wrote:
| If GitHub always uses the same number(s) for 2fa and there
| are outgoing texts to your number then the connection is
| obvious. I've read that sim jacking is somewhat common and
| this would be a good data point.
| sedatk wrote:
| So, just for discovering what services people use?
| throwaway81523 wrote:
| This happened in 2022 and they're just disclosing it now? Or did
| they just find out about it, which is maybe even worse?
| JohnMakin wrote:
| The data was from 2022. The breach was from april of this year.
| tardy_one wrote:
| Who was the data being kept for?
| JohnMakin wrote:
| ATT did not answer this question. I would expect them to
| keep phone records going back a ways, but 2022 seems pretty
| far. I'd guess for law enforcement.
| throwaway81523 wrote:
| I think there is a requirement to keep them 18 months.
| Any reasons to keep them in bulk for longer than that are
| probably bad.
| weberer wrote:
| Likely the NSA
|
| https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-
| new-...
| molave wrote:
| The authorities requested the delay of the disclosure:
| https://cbs58.com/news/nearly-all-at-t-cell-customers-call-a...
| mjevans wrote:
| These are all security nightmares aren't they? It smells as if
| all the resources went into delivering billing, then barely
| enough for technically working service, and then is there even
| anything leftover for security (instead of this being part of the
| foundation of a service)?
| hateful wrote:
| Something happens when you tune your business only to the
| things you can measure.
|
| I still (or at least try to still) have this naive opinion that
| if you make a good product, the money will come.
|
| We sometimes spend too much time counting the beans and not
| enough time growing them. Not saying you don't need to count
| the beans, you do, but when your whole team is counting, they
| may forget to water them.
|
| Also - to be on topic - don't forget to protect the beans!
| blessedwhiskers wrote:
| The TechCrunch article indicates cell site identifiers were
| included, which means approximate location as well.
|
| https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...
| dapearce wrote:
| No dates or timestamps included meaning they were using the data
| to build a social graph.
| yiamvino wrote:
| I might be lone wolf here but I kind feel pity for ATT I dont
| know why they are solely getting all the loathe here . actual
| incident occurred on public cloud provider who had not provided
| secure tools practice to their customer. so in this customer
| getting blamed for buying service cloud provider lack of best
| practices.
| smcin wrote:
| Some new news in the article and comment:
|
| - [security expert] "This [logs without timestamps] isn't one of
| their main databases; it is metadata on who is contacting who.
| Its only real use is to know who is contacting whom and how many
| times."
|
| - [commenter] "I have a theory that this call log was being used
| for a national security investigation. Otherwise why would this
| rise to the level of public safety/national security exemption?"
| [with two DOJ-approved 1-month delays for disclosure]
|
| So, someone set up a separate Snowflake instance with mostly May-
| Oct 2022 AT&T data (90% former customers) apparently for that
| purpose. And left it up. Will anyone in Congress (e.g. Sen Ron
| Wyden) ask who did and why? (Another commenter on HN pointed out
| that Roe v Wade was overturned 6/2022, presumably that was not
| the intent of the original national-security investigation, but
| there's a potential for privacy abuse by the hackers' customers
| beyond everyday spam)
|
| - In early 2023, Snowflake set up a unit especially for Telco
| data. But when you read the blurb (below), this product is not
| aimed at the telco's use-case; coincidentally this was also
| around the time Snowflake was touting integration with GenAI.
|
| "Unlocking the Value of Telecom Data: Why It's Time to Act"
| https://www.snowflake.com/blog/telecom-data-partnerships/
|
| _" Telecoms are the connecting tissue of the modern economy.
| They run everything... growing importance... hyperconnectivity.
|
| What makes telecom service providers unique is that they have
| access to consumer location data. For most other industries, a
| consumer can go into their phone's privacy settings and turn off
| the location access in the smartphone app. But in the world of
| telecom, as long as the phone is connected to a network, the
| telecom provider can use triangulation to find the approximate
| location of a consumer. This is why there is an emerging trend of
| companies [which ones?] building partnerships with telecoms to
| power use cases across multiple industries from competitor
| intelligence, alternate credit scoring, hyper-targeted marketing
| and more.
|
| ... Yet, despite the importance of telecommunications for society
| and in connecting industries, network operators are not yet fully
| embracing the value of the data they have at their fingertips"_
|
| But the value of this data (90% former customers) was clearly not
| to the telco itself... so who is the unnamed partnership and who
| is the end-customer? And was one of Snowflake's AI partners
| involved?
| koolba wrote:
| > Its only real use is to know who is contacting whom and how
| many times.
|
| Which is exactly the type of info that would be used to find
| evidence of an affair.
|
| Though this is specific to SMS so it would not include iMessage
| or other messaging apps.
| nerdponx wrote:
| Do organizations like Planned Parenthood offer SMS support?
| axus wrote:
| Didn't Congress already rubber-stamp AT&T sending the NSA this
| data?
| riffic wrote:
| did they just enumerate an open web endpoint for it or something?
| nerdponx wrote:
| The data was stored in a cloud data warehouse called Snowflake,
| which had a major breach recently.
| itscrush wrote:
| API based credentials are just username + password in this
| context, nothing else seems to be restricting access to data.
| So if your Snowflake tenant isn't enforcing IP restriction to
| limit source auth attempts, those creds can be used to pull the
| data from any source IP.
|
| Even then, you'll still have an HTTP 403 response layer
| filtering those auth attempts based on IP... where we can
| assume these failed to implement it.
|
| So far between TechCrunch, Wired, and other reporting it seems
| most claim creds get owned, sold, then used against under-
| restrictive Snowflake tenants which are exposed by default.
|
| i.e; https://epa06486.snowflakecomputing.com/console/login#/
| here's someone's tenant, if you were able to go buy some creds
| for it, should walk right in.
|
| [edit] I have a more detailed Snowflake comment with references
| that might fill in better gaps here;
| https://news.ycombinator.com/item?id=40554753
| lokar wrote:
| You can use oath or rsa keypair for service account auth
| gz5 wrote:
| The root cause (1) is the data store should not have been
| available on the underlay network. Anything connected to an
| underlay network is a ticking time bomb.
|
| Any servers or admins which need to talk to the data store should
| instead use a private overlay (2) network.
|
| Any users (likely just remote admins) should do the same.
|
| (1) Same root cause as 99% of breaches and yet it is too often
| swept under the rug while we focus on the infinite # of proximate
| causes
|
| (2) Software, not private circuits.
| jodrellblank wrote:
| It seems from the article that AT&T uploaded data to a cloud
| service, protected by username and password, and someone
| obtained credentials or breached the cloud service.
|
| What does that have to do with 'underlay networks' and wow is
| that "the root cause of 99% of breaches"?
| gz5 wrote:
| An attacker who gets username/pw still can't get on the
| overlay network (the overlay requires credentials which can't
| easily be stolen or compromised, e.g. a private key signed
| X.509 certificate).
|
| Yes, because 99% of attacks use the underlay network to
| access the target and exfiltrate the data. Said the other
| way, an attacker didn't physically walk into a Snowflake data
| center, console into the right server, and walk out with all
| the data.
| Aloisius wrote:
| That sounds more like the lack of certificate-based
| authentication (or some other stronger authentication
| method) was the problem, not the lack of a private overlay
| network.
|
| After all, plenty of private overlay networks use simple
| username/password auth or no auth at all.
| gz5 wrote:
| Agree, good point, the overlay needs to do strong
| identity, authN, authZ.
|
| The critical part the overlay adds to traditional auth is
| making the server unreachable from the underlay networks,
| reducing attack surface by billions. Meaning:
|
| + Let's say the server did have good auth, but there was
| a bug, misconfig, zero day, etc. (one of the myriads of
| proximate causes).
|
| + Since the server is available on the underlay network,
| that vulnerability can be exploited by anyone on the
| underlay (billions Internet nodes).
|
| + In contrast, making the server only available on the
| overlay, reduces the attack surface from billions of
| Internet nodes to the nodes which can ID, authN and authZ
| (for that particular server) on the overlay.
| jvanderbot wrote:
| I doubt they "breeched the cloud service" _provider_. They
| almost certainly exploited no 2fa controls _on the clients
| access_ via _the clients network_ , which is what GP was
| saying. If you're on a businesses network it's too easy to
| get at their cloud storage or dbs because they should be on a
| secure overlay network.
| wmf wrote:
| OP is using weird terminology. It would probably be clearer
| to say "Anything connected to the Internet is a ticking time
| bomb. Any servers or admins which need to talk to the
| database should instead use a VPN." which indeed was best
| practice until recently.
| mbreese wrote:
| _> indeed was best practice until recently_
|
| But we should remember why it's not always considered best
| practices... you shouldn't assume that your private network
| is any more secure than the public network. When you have
| too many devices attached to that private (overlay?)
| network, it can be at just as much risk as if it was on the
| public internet. So, the zero-trust model is that you don't
| trust anything... public... private... it should all be
| untrusted.
|
| Given that this was a "third-party cloud provider", I'm
| assuming that it was a credential leak and they only have
| username/password protections. Moreover, I doubt you'd have
| been able to add the provider's DB to an ATT based private
| VPN/network.
| gz5 wrote:
| yep was trying to avoid word which carry varying
| connotations, e.g. vpn or zero trust.
|
| zero implicit trust is likely the best term? you have to
| trust something, but enforce (and therefore trust) strong
| (not network based) identity, authN and authZ. this can
| be done anywhere via a software-only overlay.
|
| a litmus test is server iptables (to use an example)
| looks like: iptables -P INPUT DROP iptables -P FORWARD
| DROP
|
| and the only route outbound from the server is to the
| private overlay on one port, and that server still can't
| make those connections unless it is strongly identified
| and authenticated, and the overlay will not connect the
| client and server unless they are both authorized to
| communicate for that particular service(1)
|
| (1)so for example if there is a zero day causing the
| 'server' to try to communicate with some_IP then the
| private overlay will not accept the connection, even
| though it is coming from the server
| mbreese wrote:
| For highly secured services, I completely see the
| rationale for a private overlayed network. Tailscale, et
| al are great for this, where you're only exposing
| services to members of the private network. The problems
| start when people make the assumption that the private
| network is a secured network.
|
| I don't think any of this would have mattered to ATT, as
| the breach was from a third party that wouldn't have been
| on a private network anyway.
|
| But, that would be a great service bonus -- only being
| able to connect to a service via a user-configurable
| private overlay network. It would be nice, but highly
| impractical... I can't even begin thinking about how
| customer support would be able to handle a scheme like
| this.
| biggc wrote:
| What? Has anyone published an RCA that confirms this? Is this
| how the data was ex filtrated from Snowflake? Or did ATT's
| Snowflake credentials leak?
| reaperducer wrote:
| _Software, not private circuits_
|
| If only AT&T had some kind of way for its computers to talk to
| one another without going over the public internet...
| nequo wrote:
| @dang Could I ask why this topic gets systematically penalized in
| the HN ranking? There have been 15 submissions so far, I assume
| partly because previous submissions are not shown on the main
| page so HN users keep re-submitting it. This topic is both
| newsworthy and high interest.
|
| (I was going to link to the 14 other submissions but the list is
| too long and it'd just come across as obnoxious.)
| behnamoh wrote:
| The new HN voting mechanism is broken imo. Useless posts and
| articles of low value make it to the frontpage but valuable
| ones get shadowed.
| arrowsmith wrote:
| There's a new voting mechanism?
| robxorb wrote:
| And where do we go to find out about these things? Is there
| a discussion space or something?
| nvr219 wrote:
| Nah
| nanidin wrote:
| At the moment this is #1 on the frontpage.
| bloopernova wrote:
| The threads have probably tripped the flamewar detector.
| Certain amount of comments plus some other metrics will hide
| the thread from the front page.
| DarkmSparks wrote:
| Isnt this just a legally mandated api for all phone operators in
| the US?
|
| Edward Snowden published several slide decks about it a few years
| ago, before he defected to Russia.
| lfmunoz4 wrote:
| think you don't know the definition of defected
| booleandilemma wrote:
| What do you think would have happened to him if he had stayed
| here?
|
| The last whistleblower the US government got to was
| imprisoned for seven years and identifies as a woman now.
|
| Snowden would be crazy to come anywhere near the US.
| 1d22a wrote:
| I'm not sure why gender identity is relevant. I agree that
| the punishments he would have gotten for whistleblowing
| justify him not staying in the US.
| nolok wrote:
| He didn't disagree with the need to leave for Snowden, he
| said it wasn't a defection.
|
| Snowden hasn't defected the US anymore than the Dalai Lama
| has been deflected Tibet.
|
| I guess "went into exile" would be the proper naming.
| blueblob wrote:
| The parent wasn't arguing he should come back but saying
| that "defected" is not the correct word. The correct phrase
| is probably "took asylum."
| hn92726819 wrote:
| Why are you booing him? He's right!
|
| > to forsake one cause, party, or nation for another often
| because of a change in ideology
|
| I don't think he left because of a change in ideology.
| slim wrote:
| he was not heading to russia. he's just trapped there
| DarkmSparks wrote:
| Of course. He accidentally tripped, fell, and landed in
| Sheremetyevo International Airport with a nice cushy job
| in the Russian government, with Russian citizenship and a
| nice estate worth 10s of millions of dollars, and clearly
| just accidentally mispoke when he swore allegiance to
| Russia. All the nsa secrets he took with him were
| irrelevant to that story, typical of any asylum seeker
| arriving anywhere.
|
| lol, oops, I forgot how triggered some people get for
| calling it defecting.
| not2b wrote:
| It doesn't appear to be, though it was speculated that it might
| be. Companies keep all that data in the hope of making money by
| mining it.
| wly_cdgr wrote:
| Why did it take them over a year and a half to disclose this?
| u32480932048 wrote:
| Something, something, national security?
| smcin wrote:
| The DOJ approved two 1-month "delay periods", first in May,
| then in June, as part of the criminal investigation. We found
| that out earlier this morning, see earlier discussion.
| JohnMakin wrote:
| It didn't. The breach happened in april of this year. The data
| is from 2022.
| advael wrote:
| It's disgusting that we still write headlines as "hackers steal"
| rather than "enormous company fumbles security for data they
| should never have retained"
| SJMG wrote:
| That is a good reframe.
| mrbluecoat wrote:
| How can I upvote this a million times?!
| not2b wrote:
| "It remains unclear why so many major corporations persist in the
| belief that it is somehow acceptable to store so much sensitive
| customer data with so few security protections."
|
| It's because there are almost no consequences to them if they
| lose the customer data, beyond a day or two of bad press. If they
| faced significant fines, fines that get worse the more sensitive
| the data is, then they'd have an incentive to do better.
| Jaygles wrote:
| No consequences, the cost can be great, and it can negatively
| impact productivity by introducing hurdles to legitimate uses.
| Those are immense pressures a soulless company will need to
| overcome to do the right thing.
| fnord77 wrote:
| so just metadata, not the actual texts or PII
| macintux wrote:
| "Just" is a dubious adjective in this context.
| wordpad25 wrote:
| your phone number is PII and everybody you ever called or
| texted is VERY VERY PII
| RyanAdamas wrote:
| Criminal charges need to be filed and class action lawsuit for
| fraudulent services for all the customers duped into renewing
| monthly services ignorant of the fact the service is not secure
| as plainly stated it must be in federal law.
| advael wrote:
| At the scale of this kind of incompetent failure, no human being
| should be on board with the narrative that we should be blaming
| "criminals" for this
|
| If we don't hold companies accountable for keeping far more
| access and retention than should be legal, and securing their
| systems poorly, this situation will never get better
| balls187 wrote:
| Who is the "we" here? And how should companies be held
| accountable?
|
| It's very rare for someone at the highest level to be held to
| any kind of liability, and paying fines rarely, if ever, causes
| these too-big-to-fail corporations to materially impact them.
|
| Strictly speaking about the US here.
| advael wrote:
| Needs to be at the level of enforcement by regulatory
| agencies, large scale lawsuits backed by state governments,
| and maybe even congressional action
|
| These companies have scale as their moat and that's called a
| monopoly. We need to be aggressively pursuing corporate
| malfeasance, closing loopholes, and breaking up companies. In
| my ideal world the entire doctrine of the "corporate veil"
| would be overturned, but that seems unlikely to happen
| without drastic upheaval. Antitrust action and large-scale
| suits can happen and to some degree those wheels are already
| in motion, but it would help a lot to stop buying this
| bullshit about how we should think of this as a "crime" for
| which we should uniquely blame hackers. These megacorps want
| to pretend that they and their customers are in solidarity as
| victims of the hackers. In reality, these companies get hit
| with essentially none of the consequences, and their
| practices are most of the relevant causal factors. A better
| model would be that the customers (and often non-customers on
| whom they collect data without even the figleaf of
| manufactured consent) are victims of the companies and the
| hackers
| balls187 wrote:
| These companies are so massively large that they price in
| the risk of databreaches as a cost of doing business.
|
| Insurance Underwriters pour through corpo infosec
| documents, and require only the most basic level of
| protections.
|
| I think instead, a stricter certification standard needs to
| be created, and all these large companies must pass ANNUAL
| audits, or simply lose access to government leased
| spectrum.
| advael wrote:
| It seems that we agree that regulatory enforcement is a
| great framework through which to make this happen. I
| think we should regulate both security and data retention
| far more aggressively, and be willing to destroy
| companies if they fail to comply. The lack of an
| existential risk makes it easier for them to maneuver
| around other solutions
| tuxone wrote:
| > These companies are so massively large that they price
| in the risk of databreaches as a cost of doing business.
|
| Just make the fine a % of the annual revenue and that
| will change.
| slg wrote:
| > paying fines rarely, if ever, causes these too-big-to-fail
| corporations to materially impact them.
|
| That means the fines aren't big enough. They should probably
| be scaled according to the business' revenue.
| waterhouse wrote:
| From a justice perspective, it should be scaled according
| to the number of customers impacted (and how bad the impact
| was). Which is likely to be about the same as scaling with
| revenue.
| Animats wrote:
| _" still-unfolding data breach involving more than 160 customers
| of the cloud data provider Snowflake.'_
|
| So what is Snowflake normally doing with all that AT&T data?
| Redistributing it to "marketing partners"? Apparently.
| Snowflake's mission statement, from their web site:
|
| _" Our mission is to break down data silos, overcome complexity
| and enable secure data collaboration between publishers,
| advertisers and the essential technologies that support them."_
|
| So this was not, apparently, a break-in to the operational side
| of AT&T. Someone unauthorized got hold of data they were already
| selling to marketers. Is that correct?
| biggc wrote:
| ATT could be using Snowflake for internal analytics
| smcin wrote:
| It's not "internal analytics", because a) 90% of the data was
| former customers and b) it has location data but timestamps
| were removed, so it's social-graph information plus location.
| Start asking yourself what sorts of end-users want to pay for
| the entire social-graph of 77m, regardless whether those
| customers never make a phone call again.
|
| _" Alternate credit scoring, hyper-targeted marketing and
| more... an emerging trend of companies building partnerships
| with telecoms to power use cases across multiple
| industries."_ was the blurb for the unit Snowflake specially
| set up for Telco data in early 2023 touting "location data",
| but this product is not aimed at the telco's use-case;
| coincidentally this was also around the time Snowflake was
| touting integration with GenAI.
|
| (It's not "competitor analysis" either, because if it was
| they would have obscured the 68m former phone numbers to
| prevent abuse by direct-marketing.)
|
| [0]: "Unlocking the Value of Telecom Data: Why It's Time to
| Act" https://www.snowflake.com/blog/telecom-data-
| partnerships/
| Animats wrote:
| Snowflake PR, from the link above: _" What makes telecom
| service providers unique is that they have access to
| consumer location data. For most other industries, a
| consumer can go into their phone's privacy settings and
| turn off the location access in the smartphone app. But in
| the world of telecom, as long as the phone is connected to
| a network, the telecom provider can use triangulation to
| find the approximate location of a consumer. This is why
| there is an emerging trend of companies building
| partnerships with telecoms to power use cases across
| multiple industries from competitor intelligence, alternate
| credit scoring, hyper-targeted marketing and more."_
|
| That pretty much says it.
|
| It's disappointing that TechCrunch didn't point this out.
| Nor did the New York Times.[1] Yet it's right there on
| Snowflake's site.
|
| [1] https://www.nytimes.com/2024/07/12/business/att-data-
| breach....
| smcin wrote:
| - [EDIT: I confused the details of this AT&T breach with
| the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO
| customers, 90% of them former customers]. This one is
| 110m customers, presumably all their current
| customerbase.
|
| - Yes about the Snowflake's cloud telco unit explicitly
| marketing the fact that telco data contains location. See
| my updated post:
| https://news.ycombinator.com/item?id=40949640
| lokar wrote:
| It's a cloud database, mostly olap. The ATT account was secured
| with a bad password and no mfa.
| jmspring wrote:
| This would probably be no different if someone like Salesforce
| had a breach and a large customer of theirs being impacted.
| There are large companies using SaaS services for a chunks of
| their back office stuff.
| Root_Denied wrote:
| If that's the case then they're probably more upset that
| they're not getting paid for this data than anything else.
| declan_roberts wrote:
| I would like to sue AT&T in small claims for this and for leaking
| my Social Security number. But it's difficult to prove damages in
| these situations.
|
| Does anybody have any advice? Proving damages means showing
| actual monetary harm.
| josh-sematic wrote:
| IANAL but this would seem like a "class action" situation.
| vdqtp3 wrote:
| I also ANAL but if I recall correctly, you can decline to be
| represented in the class, and file your own lawsuit
| whalesalad wrote:
| can't wait to get that check in the mail for $1.32
| reaperducer wrote:
| I got a check in the mail last week for 12C/ from Google
| hoovering up my data. Yes, that's _twelve cents!_
|
| Google certainly made more off of my data than that.
| whalesalad wrote:
| costs more to mail a letter
| josh-sematic wrote:
| True but personally I also wouldn't want to go through the
| time and expense to sue them solo. At least in a class
| action the company faces _some_ penalty that's possibly
| meaningful to them (even if it's not meaningful to most of
| the claimants).
| voxic11 wrote:
| At&t customers are bound to individual arbitration so there
| will be no class action lawsuit for this.
|
| > Please read this Agreement carefully. It requires you and
| AT&T to resolve disputes through arbitration on an individual
| basis rather than jury trials or class actions.
|
| https://www.att.com/legal/terms.consumerServiceAgreement.htm.
| ..
| arcimpulse wrote:
| Very difficult to run these days. Since 2018, federal courts
| have ground away many of the legal routes needed to run a
| successful class action suit against a national or
| multinational corporation.
| djbusby wrote:
| And look for Arbitration clause in your contract. Might limit
| your options.
| voxic11 wrote:
| You likely cannot file in small claims and would need to pursue
| arbitration instead.
|
| > Please read this Agreement carefully. It requires you and
| AT&T to resolve disputes through arbitration on an individual
| basis rather than jury trials or class actions.
|
| https://www.att.com/legal/terms.consumerServiceAgreement.htm...
| quercusa wrote:
| _- AT &T will usually pay all of the arbitration fees (with
| some exceptions). _
|
| That could get pretty expensive for them quickly.
| 1attice wrote:
| this breach is of course appalling. But nearly as appalling is
| the experience of _explaining why this matters_ to non-technical
| friends who stare at you with blank, distracted eyes, but only
| for a second; for their phone (yes, the very phone that just
| exposed them to uncountable future ills) has chimed.
|
| I have nearly given up; like smoking, it will be decades before
| the harms are understood. We have to wait for your neighbour's
| brother to have died in a targetted political killing, because
| someone didn't like his Substack and borrowed the number and
| likeness of a friend; for his daughter's credit score to have
| been crushed by an anti-abortioneer who borrowed her face and
| likeness and number knew her first-grade teacher; for his son to
| die a death of despair, after making the wrong friends, and
| getting doxxed along with the rest of them.
|
| This should be a five-foot headline moment. But no; CNN will lead
| with Biden-mumbles or Trump-grumbles.
|
| How is it that the things that are killing us --- inequality,
| climate change, privacy collapse -- all have this same shape?
| Hamlets, all of us.
| whyenot wrote:
| AT&T has 110 million customers. Let's be optimistic and assume
| that each customer only has to spend one minute of extra time
| managing their account due to the break-in. That is more than 209
| years of lost time.
|
| Laws related to data breaches need to have much sharper teeth.
| Companies are going to do the bare minimum when it comes to
| securing data as long as breaches have almost no real
| consequences. Maybe pierce the corporate veil and criminally
| prosecute those whose negligence made this possible. Maybe have
| fines that are so massive that company leadership and
| stockholders face real consequences.
| pcblues wrote:
| Personal data cannot be secured. The only way is to not store
| it. That will (imaginationaly) cost companies in lost revenue
| for being unable to mine and sell it. Only government can make
| laws against a company taking your personal information and
| selling it. Even passwords shouldn't be stored by a company.
|
| The years of lost time argument is disingenuous. Over that
| number of people, 209 years of lost time from 700 million years
| of lives is nothing.
| compootr wrote:
| Whether or not it's disingenuous, it's our time that didn't
| need to be wasted in the first place by them not storing
| phone records
| dopylitty wrote:
| I'd take it a step further. If a technology is impossible to
| secure it shouldn't be used. Maybe it's time to rethink all
| the parts of our lives we've handed over to software.
| tomComb wrote:
| There are lots of companies that take security seriously and
| don't lose their customers data. Which is good, because there
| are companies that need to hold customer data.
|
| Companies that don't take security seriously and lose peoples
| data should be punished accordingly.
|
| Companies that sell customers data should be identified.
|
| But if we treat them all the same, then we let the bad
| companies off the hook, and punish the responsible companies
| unfairly.
| voisin wrote:
| But hey, in 5-7 years there will be a settlement to the
| inevitable class action lawsuit and each of these customers
| (that fills in a form, ensuring only a small fraction actually
| do) gets a $3.75 credit on their next bill. The lawyers will
| get 30% of the settlement and each walk away with several
| million dollars. Justice! _chef's kiss_
| wkcheng wrote:
| Yeah, you're right. Data breaches are essentially just slaps on
| the wrist to companies like AT&T. Maybe it's possible to fine
| them based on the proportion of the userbase that was affected
| and the profits they generated for a certain time period.
|
| I wonder if this will push companies to stop using external
| vendors to store and process data. If companies stored all of
| their info in house, it would prevent the case where
| compromising one vendor compromises everyone's data. But it
| would also mean that each individual company needs to do a good
| job securing their data, which seems like a tall ask.
| hnlmorg wrote:
| The reason some companies use external vendors is to
| outsource the risk.
| choppaface wrote:
| The AT&T app and website are so bad it takes way longer than 1
| minute to log in to e.g. pay your bill. The United States needs
| to raise the bar for large-cap negligent operators and fine the
| company enough to make shareholders listen.
| AnthonyMouse wrote:
| In approximately 100% of cases, if your intuition is to say
| "this company is too large should be fined/regulated more,"
| what you should actually say is "this company is too large
| and should be broken into many smaller entities."
| physhster wrote:
| We should break down AT&T. Oh wait. We tried already and
| re-consolidated? Ow.
| AnthonyMouse wrote:
| Part of breaking them up is supposed to be not letting
| them re-consolidate. Mergers involving any entity that
| already has 15% market share should just be flatly
| disallowed.
| edanm wrote:
| > Laws related to data breaches need to have much sharper
| teeth. Companies are going to do the bare minimum when it comes
| to securing data as long as breaches have almost no real
| consequences. Maybe pierce the corporate veil and criminally
| prosecute those whose negligence made this possible. Maybe have
| fines that are so massive that company leadership and
| stockholders face real consequences.
|
| I really dislike this attitude.
|
| AT&T were attacked, by criminals. The criminals are the ones
| who did something wrong, but here you are immediately blaming
| the victim. You're assuming negligence on the part of AT&T, and
| to the extent you're right, then I agree that they should be
| fined in a bigger manner.
|
| But the truth is, given the size and international nature of
| the internet, there are effectively armies of criminals,
| sometimes actually linked to governments, that have incredible
| incentives to breach organizations. It doesn't require
| negligence for a data breach to occur - with enough resources,
| almost any organization can be breached.
|
| Put another way - you trust a classical bank, with a money, to
| secure your money from criminals. But you don't expect it to
| protect your money in the case of an army attacking it. But
| that's exactly the situation these organizations are in -
| anyone on Earth can attack them, very much including basically
| armies. We _cannot_ expect organizations to be able to defend
| themselves forever, it is an impossible ask in the long run.
| This _has_ to be solved by the equivalent of a standing army
| protecting a country, and by going after the criminals who do
| these breaches.
| dwattttt wrote:
| In this analysis, the effort the bank puts towards defending
| themselves is relevant. We wouldn't blame the bank for an
| army attacking them, but if they left the door unlocked and
| the neighbours kids made off with your money you very rightly
| would feel differently.
| Kailhus wrote:
| Which does make me wonder why we never really hear of banks
| being attacked and robbed in such a way? One would think
| they would be the most obvious targets to throw an army of
| criminals at.
| edanm wrote:
| Banks don't really physically store much money any more.
|
| And more importantly - the police exist. If someone were
| to actually physically rob a bank, enormous resources
| would be spent trying to find and capture them, then
| they'd be thrown in jail.
|
| If they could do the same thing, but also be physically
| located in another country while doing it, with no chance
| at all of going to jail... more banks _would_ be robbed!
| cellis wrote:
| Crypto Exchange has entered the chat.
| ufmace wrote:
| It's pretty much the definition of a functional state
| that the police can gather more resources faster than any
| group of criminals. By the time you gather enough
| criminals to hold off the police for even a few minutes,
| most of the time, combined with the sibling's point of
| not that much physical money being stored at banks,
| there's not much money to go around to that many people.
| mikeweiss wrote:
| Companies could also stop storing customer information for
| purposes unrelated to the core product that you are
| using..... But that's not going to happen because it's still
| far more profitable to mine customers data even with the risk
| of theft or breach.
| hansvm wrote:
| I think the implicit assumption is that the vast majority of
| these breaches are obviously preventable (basic incompetence
| like leaving a non-password-protected database connected to
| the public internet is common).
|
| A better analogy is not a bank defending against an army, but
| a bank forgetting to install doors, locks, cameras, or
| guards. _Yes_, the criminals are the root cause, but human
| nature being what it is it's negligent to leave a giant pile
| of money and data completely unprotected.
| edanm wrote:
| > I think the implicit assumption is that the vast majority
| of these breaches are obviously preventable (basic
| incompetence like leaving a non-password-protected database
| connected to the public internet is common).
|
| Some breaches are certainly preventable. But is that the
| case here? I didn't see the technical details, I think they
| aren't released yet, but this is the conclusion everyone
| seems to jump to automatically, without necessarily good
| reason.
|
| More importantly - these companies employ thousand of
| employees, all of whom could be doing something wrong that
| is causing a security threat. And there are thousands,
| maybe tens of thousands of people trying to find their way
| in. my point is that even without any negligence, if you
| have thousands of people trying to hack your company every
| day for years, it's easy to slip up, even if it's
| preventable-in-hindsight.
|
| One of the first things you learn in working in security is
| that there is no perfect security, and you have to
| understand the nature of the threat you are facing. For
| these companies, the threat might very well be "North Korea
| decides to dedicate state-level resources to breaking into
| your company, plus thousands of criminals are doing the
| same every day". How is any company supposed to protect
| against that?
| hmottestad wrote:
| Would assume someone would notice all the data that is
| being transferred.
|
| And if this turns out to be a sophisticated attack then
| who's to say they didn't backdoor a bunch of systems? I
| heard a talk from a big Norwegian company that got
| attacked. Every single server, every single switch, every
| single laptop, all had to be reformatted and reinstalled.
| I assume that AT&T would have to end up doing the same.
| usea wrote:
| If a breach is so inevitable like you say, then it's
| negligent to store the information in the first place.
| They're accumulating and organizing data with the inescapable
| conclusion of handing it out to criminal organizations.
| A4ET8a8uTh0 wrote:
| << AT&T were attacked, by criminals. The criminals are the
| ones who did something wrong, but here you are immediately
| blaming the victim. You're assuming negligence on the part of
| AT&T,
|
| I am sure LEOs will do what they are paid to do and catch
| criminals. In the meantime, I would like to focus on service
| provider not being able to provide a reasonable level of
| privacy.
|
| I am blaming a corporation, because for most of us here it is
| an ongoing, recurring pattern that we have recognized and
| corporations effectively codified into simple deflection
| strategy.
|
| Do I assume the corporation messed up? Yes. But even if I
| didn't, there is a fair amount of historical evidence
| suggesting that security was not a priority.
|
| << Put another way - you trust a classical bank, with a
| money, to secure your money from criminals.
|
| Honestly, if average person saw how some of those decisions
| are made, I don't think a sane person would.
|
| << But the truth is, given the size and international nature
| of the internet, there are effectively armies of criminals,
| sometimes actually linked to governments, that have
| incredible incentives to breach organizations. It doesn't
| require negligence for a data breach to occur - with enough
| resources, almost any organization can be breached.
|
| Ahh, yes. Poor corporation has become too big of a target.
| Can you guess my solution to that? Yes, smaller corporation
| with MUCH smaller customer base and footprint so that even if
| the criminal element manages to squeeze through those
| defenses that the corporation made such a high priority ( so
| high ), the impact will be sufficiently minimal.
|
| I have argued for this before. We need to make hoarding data
| a liability. This is the only way to make this insanity stop.
| abdullahkhalids wrote:
| The correct way is to follow what all other engineering and
| trade (medicine/law) already follow.
|
| Some software engineers are licensed. A company must hire these
| software engineers, and any changes to what data is saved or
| how is saved must be signed by these engineers. If a breach
| occurs, an investigation occurs and if these licensed software
| engineers are found to be negligent, they lose their license.
| If they are found to be at fault, they get criminal penalties.
|
| This, of course, must be coupled with penalties for management
| personals as well.
| AnthonyMouse wrote:
| This kind of system has consistent led to regulatory capture
| by the licensed industry. Even the mechanism of operation de
| facto assumes a significant gatekeeping barrier to getting a
| license, since otherwise companies would just pick one most
| willing to cut corners to save costs, or pay the license fee
| to get greenhorns certified because that costs less than
| adding two years to the development schedule to do it well.
| Making everything cost quadratically more than it already
| does is not a good solution.
|
| What you want here is for them not to be holding the data to
| begin with. The solution to which is to just let customers
| sue them. Not for $0.30 and "free credit monitoring" but for
| actual money. Then companies can choose whether they want to
| mitigate their risk by doing actual security or by not
| storing the data to begin with, but most likely the second
| one is their better option.
| zombiwoof wrote:
| User: admin Password: password
| chmod775 wrote:
| Over in Europe this blanket saving of phone records beyond what
| it is necessary to operate would have been illegal in many
| countries, and is in general incompatible with the European
| Convention for the Protection of Human Rights and Fundamental
| Freedoms outside of active threats to national security and
| temporary measures overseen by a court.[1]
|
| There's really no reason why any service providers should save
| this stuff in the first place, and it isn't hard to fix with
| legislation. Just make it illegal to even keep.
|
| [1]
| https://curia.europa.eu/juris/document/document.jsf?text=&do...
| Aerroon wrote:
| I was under the impression that the government wasn't allowed
| to create a mandate that a telco has to save all phone records
| like that, but it doesn't stop a telco from doing it
| themselves. I think that would fall more under GDPR
| limitations?
| chmod775 wrote:
| I believe you are correct. That's what I was referring to
| with "illegal in many countries". Most judgements on this
| issue predate GDPR, but before GDPR, many countries already
| had similar laws and attitudes. For example article 2* and 10
| of the German constitution protect personal data and
| communication, not just from others, but also from the
| government. Not unlike the GDPR.
|
| Some service providers in Europe don't even want to save any
| data. The linked judgement above was the German state suing
| Telekom, which didn't want to save that data, and losing.
| Given the state of affairs, the question of "illegal or not"
| doesn't really come up as much. At least I'm not aware of any
| high profile judgements.
|
| Besides Telekom, which always tried to minimize they data
| they keep to the point of fighting it all the way to Europe's
| highest courts, most other telcos don't really care and pick
| whichever middle-ground is available between "must" and "must
| not". Whatever is least-likely to get them into trouble.
| Right now that just happens to mean "save little".
|
| * It's not stated explicitly in article 2, but the German
| constitutional court decided that it follows from those
| personal rights:
| https://en.wikipedia.org/wiki/Informational_self-
| determinati...
| bobmcnamara wrote:
| Historically we handled this with fiber taps at AT&T, as well
| as other ISPs. Some of them even knew about it.
| kevin_thibedeau wrote:
| What the NSA wants, the NSA gets. No legislation is needed when
| the system is working as intended.
| ldoughty wrote:
| According to the article, the data was being made available
| to other businesses... From the detail level involved, I
| imagine the NSA has some sweeter deal with telcos... And they
| have much richer data.
| VonGuard wrote:
| New lines of business. Another way for them to sell your
| data. The NSA is quaint. The Valley knows everything about
| everyone already, and even has their current GPS
| coordinates.
| kevin_thibedeau wrote:
| The NSA buys _all_ of the data available from data brokers.
| 4A? What 4A? With telcos they have the extra advantage of
| ordering them around with an NSL.
| dredmorbius wrote:
| For those not deeply versed in US federal regulations:
| Part 4a of Title 15 of the Code of Federal Regulations
| (CFR), which covers the "Classification,
| Declassification, and Public Availability of National
| Security Information" for the National Security Agency
| (NSA).
|
| <https://www.ecfr.gov/current/title-15/subtitle-A/part-4a
| ?toc...>
| arcticbull wrote:
| The NSA shouldn't need the telcos to retain these records,
| just hand them over to the NSA to retain right?
| ASalazarMX wrote:
| It's a good business decision to make others do your work.
| arcticbull wrote:
| Government is not a business!
| erikig wrote:
| Which leads me to wonder - were any of the NSA's own
| employee, call and SMS records at AT&T part of the
| comprised data?
|
| (edited for grammar)
| stainforth wrote:
| Right, if phone records for Congressmen and known (or
| deduced) DOD were made public would that sway any changes
| AnthonyMouse wrote:
| It's not so much the NSA as various other government
| agencies. The NSA is hoovering everything up, but if the
| local cops call them and want access to it, the NSA is
| going to tell them that they're not even authorized to know
| whether or not the NSA has that information. Also,
| something something due process something something
| American citizens.
|
| Whereas if they can get the telcos to keep it then the cops
| can get it using the third party doctrine. This is
| basically an end run around the constitution, which is why
| they like it.
| JumpCrisscross wrote:
| > _What the NSA wants, the NSA gets_
|
| The NSA's power is in being boring and unnoticed. This could
| be a revenue rider.
| ChumpGPT wrote:
| Every txt and phone call, every email and letter sent to your
| address along with every utility bill (list goes on) has been
| saved since at least 1999/2000 to present day. People like
| Bernie went to jail because they pushed back and it was all
| because of this....
|
| Just saying.
| tomrod wrote:
| ... letter?
| ChumpGPT wrote:
| Anything you receive via post office. Sender/Receiver
| address is scanned. Post office uses OCR's for sortation
| and that information is captured.
| tomrod wrote:
| Ah. The metadata. Inconsequential, then, to a degree.
| fsagx wrote:
| who's Bernie?
| kolbe wrote:
| You live in a place where the government is for the people, not
| for themselves.
| chmod775 wrote:
| If it wasn't for the courts and a decent de-facto
| "constitution" (collection of treaties really), governments
| would absolutely love to expand the amount of data _they_
| (police, spy apparatus, etc.) have access to. That they also
| try to reduce the amount of data _companies_ are allowed to
| save for themselves is tangential.
|
| The court case I linked is evidence of that. The German state
| wanted Telekom to save more data, but the telco refused and
| won in court.
| nxobject wrote:
| I look forward to receiving my 30 cents in settlement money in
| five years.
| exabrial wrote:
| The only "criminals" is AT&T for leaving the doors wide open.
| TriangleEdge wrote:
| When are we going to see the technical report of what happened?
| Since this data has a specific time frame, it makes sense to me
| that a backup was stolen. But, we'll see.
|
| My guess is that the tech leaders a AT&T are going to have sore
| wrists for a few minutes because of this.
| smcin wrote:
| Joining the dots on the facts so far, people don't seem to have
| grasped the apparent huge significance:
|
| - guessing it was some GenAI startup looking into consumer
| tracking, alternate credit scoring, surveillance or other
| national-security use-case.
|
| - Very unusually, the DOJ ordered two ~month-long "delay periods"
| in disclosure: _( "The Justice Department determined on May 9 and
| again on June 5 that a delay in providing public disclosure was
| warranted")_. Yet this didn't happen for Ticketmaster or MOVEit
| breaches revealed around the same time. "Cybersecurity delay
| period requests" is a new power quietly authorized by the
| DOJ+SEC+FBI, 18 Dec 2023 [0]. Note that [1] emphasizes this as
| "Corporate Alert - guidance for delay requests [on SEC 8-K]".
| Might Congress already have known/suspected, when it authorized
| the cybersecurity delay request powers, of the Snowflake/AT&T
| breach? Either way, whoever is involved seems to have very
| powerful friends. Also, the big FISA renewal vote was Apr 19 2024
| [2].
|
| - Seems the cloud instance was set up the same time GPT-4 was
| released (March 2023), also when Snowflake set up a Telco
| business unit [3] _( "Location data... Alternate credit scoring,
| hyper-targeted marketing and more... an emerging trend of
| companies building partnerships with telecoms to power use cases
| across multiple industries")_. This product is not aimed at the
| telcos' use-cases, but at new revenue streams. (Who might the
| unnamed Snowflake AI partner(s) be?)
|
| - They set up the Snowflake instance with AT&T/MVNO customers
| with timestamps removed, but with location data, yet the phone
| numbers not obscured or removed. Doesn't sound like "internal
| analytics" or "competitor analysis". What sorts of end-users want
| to pay for the entire social-graph of 110m, regardless whether
| those customers never make a phone call again? [EDIT: I confused
| the details of this AT&T breach with the other (2019) one
| disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former
| customers]
|
| [0]: "FBI Guidance to Victims of Cyber Incidents on SEC Reporting
| Requirements: FBI Policy Notice Summary"
| https://www.fbi.gov/investigate/cyber/fbi-guidance-to-victim...
|
| [1]: "US Corporate Alert - DOJ, FBI, and SEC provide guidance for
| delay requests relating to disclosure of cybersecurity incidents
| under form 8-K" https://www.klgates.com/DOJ-FBI-and-SEC-Provide-
| Guidance-for...
|
| [2]: US House approves FISA renewal - warrantless surveillance
| and all https://news.ycombinator.com/item?id=40041784
|
| [3]: Snowflake cloud Telco unit, 4/2023: "Unlocking the Value of
| Telecom Data: Why It's Time to Act"
| https://www.snowflake.com/blog/telecom-data-partnerships/
| jdlyga wrote:
| It's one more reason to use an end to end encrypted messaging app
| like iMessage or Telegram. Even WhatsApp is end to end encrypted.
| Don't use SMS/RCS.
| menacingly wrote:
| unless I'm misunderstanding, the same data could be pulled from
| those services.
|
| the message content wasn't leaked here
| purpleblue wrote:
| WHY IS THIS DATA EVEN AVAILABLE TO BE DOWNLOADED??? Why do we not
| have protection in place so that hackers can't even download this
| data even if they wanted to?? What purpose does 2 year old data
| serve AT&T except to monitor us and to create social networks of
| people and associations?
| demondemidi wrote:
| Would be great if some of the smart people here could help
| explain why this is such a big deal to my less tech savvy
| friends. I know that I _don't know_ how the data broker to dark
| web hacker pipeline works, I just know security is important. But
| my family is like "big deal".
| benreesman wrote:
| The old-timers remember a term: "dark fiber".
|
| There's going to be a lot of "dark compute" once we throw these
| lazy assholes out.
|
| Speaking for myself, I'm thinking of what the economics look like
| when HBM is abundant.
___________________________________________________________________
(page generated 2024-07-12 23:00 UTC)