AT&T says criminals stole phone records of 'nearly all' customers in data breach
techcrunch.com
techcrunch.com
Laws related to data breaches need to have much sharper teeth. Companies are going to do the bare minimum when it comes to securing data as long as breaches have almost no real consequences. Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible. Maybe have fines that are so massive that company leadership and stockholders face real consequences.
The years of lost time argument is disingenuous. Over that number of people, 209 years of lost time from 700 million years of lives is nothing.
I am sympathetic to the overall sentiment here, but between any web browser + server stack you are looking at hundreds of millions of lines of code written in unsafe languages.
Add on the human factor and there is just no hope of really securing this.
Companies that don’t take security seriously and lose peoples data should be punished accordingly.
Companies that sell customers data should be identified.
But if we treat them all the same, then we let the bad companies off the hook, and punish the responsible companies unfairly.
new security holes get introduced faster than old ones get patched, and that will remain true for the foreseeable future
Like, it might be an unending atrocity beyond all human comprehension, but, $666/hr soothes a lot of conscience and quiets a lot of tongues.
"Google Referrer Header Privacy Settlement has sent you $0.11 USD."
I wonder if this will push companies to stop using external vendors to store and process data. If companies stored all of their info in house, it would prevent the case where compromising one vendor compromises everyone's data. But it would also mean that each individual company needs to do a good job securing their data, which seems like a tall ask.
Not really the point though, is it.
I really dislike this attitude.
AT&T were attacked, by criminals. The criminals are the ones who did something wrong, but here you are immediately blaming the victim. You're assuming negligence on the part of AT&T, and to the extent you're right, then I agree that they should be fined in a bigger manner.
But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.
Put another way - you trust a classical bank, with a money, to secure your money from criminals. But you don't expect it to protect your money in the case of an army attacking it. But that's exactly the situation these organizations are in - anyone on Earth can attack them, very much including basically armies. We cannot expect organizations to be able to defend themselves forever, it is an impossible ask in the long run. This has to be solved by the equivalent of a standing army protecting a country, and by going after the criminals who do these breaches.
And more importantly - the police exist. If someone were to actually physically rob a bank, enormous resources would be spent trying to find and capture them, then they'd be thrown in jail.
If they could do the same thing, but also be physically located in another country while doing it, with no chance at all of going to jail... more banks would be robbed!
A better analogy is not a bank defending against an army, but a bank forgetting to install doors, locks, cameras, or guards. _Yes_, the criminals are the root cause, but human nature being what it is it's negligent to leave a giant pile of money and data completely unprotected.
Some breaches are certainly preventable. But is that the case here? I didn't see the technical details, I think they aren't released yet, but this is the conclusion everyone seems to jump to automatically, without necessarily good reason.
More importantly - these companies employ thousand of employees, all of whom could be doing something wrong that is causing a security threat. And there are thousands, maybe tens of thousands of people trying to find their way in. my point is that even without any negligence, if you have thousands of people trying to hack your company every day for years, it's easy to slip up, even if it's preventable-in-hindsight.
One of the first things you learn in working in security is that there is no perfect security, and you have to understand the nature of the threat you are facing. For these companies, the threat might very well be "North Korea decides to dedicate state-level resources to breaking into your company, plus thousands of criminals are doing the same every day". How is any company supposed to protect against that?
And if this turns out to be a sophisticated attack then who’s to say they didn’t backdoor a bunch of systems? I heard a talk from a big Norwegian company that got attacked. Every single server, every single switch, every single laptop, all had to be reformatted and reinstalled. I assume that AT&T would have to end up doing the same.
Mind you, Snowflake is the problem here, not AT&T, if it was their leak. AT&T is big enough that no meaningful sanctions will fall on them. It's not like they fell out of the sky and killed a bunch of people.
The bank is expected to have people trying to break into it. Sure would be nice if they didn’t, but that’s not the reality. As such, failing to provide adequate defences is absolutely a failing on the banks behalf.
If they were keeping even more data than necessary, that’s just extra failure on their behalf.
I am sure LEOs will do what they are paid to do and catch criminals. In the meantime, I would like to focus on service provider not being able to provide a reasonable level of privacy.
I am blaming a corporation, because for most of us here it is an ongoing, recurring pattern that we have recognized and corporations effectively codified into simple deflection strategy.
Do I assume the corporation messed up? Yes. But even if I didn't, there is a fair amount of historical evidence suggesting that security was not a priority.
<< Put another way - you trust a classical bank, with a money, to secure your money from criminals.
Honestly, if average person saw how some of those decisions are made, I don't think a sane person would.
<< But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.
Ahh, yes. Poor corporation has become too big of a target. Can you guess my solution to that? Yes, smaller corporation with MUCH smaller customer base and footprint so that even if the criminal element manages to squeeze through those defenses that the corporation made such a high priority ( so high ), the impact will be sufficiently minimal.
I have argued for this before. We need to make hoarding data a liability. This is the only way to make this insanity stop.
You picked the wrong point to counter with. The real problem is that the corporate decision-makers who bear the most responsibility will never be held accountable. They will always be able to shift blame to someone below them in the corporate hierarchy.
The other points are dubious too.
> But the truth is, given the size and international nature of the internet, there are effectively armies of criminals, sometimes actually linked to governments, that have incredible incentives to breach organizations. It doesn't require negligence for a data breach to occur - with enough resources, almost any organization can be breached.
So given that this is known, why was the data stored such that it could be taken? Why was it kept at all? Oh.. to sell.
> Put another way - you trust a classical bank, with a money, to secure your money from criminals. But you don't expect it to protect your money in the case of an army attacking it.
Yes I do expect that. And it’s protected and insured by my government.
AT&T's data was compromised as one of Snowflake's many customer breaches (Ticketmaster/LiveNation, LendingTree, Advance Auto Parts, Santander Bank, AT&T, probably others [0][1]), which occurred and were notified in 4/2024 (EDIT: some reports says as far back as 10/2023). Supposedly these happened because Snowflake made it impossible to mandate MFA; some customers had credentials stolen by info-stealing malware or obtained from previous data breaches. Snowflake called it a “targeted campaign directed at users with single-factor authentication”. The Mandiant report tried to blame unnamed Snowflake employee (solutions engineer) for exposing their credentials.
How much responsibility Snowflake had, vs its clients, is not clear (for example, seems they only notified all other customers May 23, not immediately when they suspected the first compromise). Reducing the analysis to pure "victims" and "criminals" is not accurate. When you say "criminally prosecute those whose negligence made this possible", it wouldn't make sense to prosecute all of Snowflake's clients but not Snowflake too. Or only the cybercriminals but not Snowflake or its clients.
[0]: The Ticketmaster Data Breach May Be Just the Beginning (wired.com) https://news.ycombinator.com/item?id=40553163
[1]: 6/24 Snowflake breach snowballs as more victims, perps, come forward (theregister.com) https://news.ycombinator.com/item?id=40780064
Snowflake built its business on making it really easy for data teams to spin up an instance and start importing a massive amount of their org's data. By default, the only thing you need to access that from anywhere on the internet is a username and a password. Locking down a snowflake instance ends up requiring a lot more effort.
And very few users actually end up interacting with snowflake directly -- they're logging into a BI tool like Looker, which accesses snowflake behind the scenes. So the fact that an org's Snowflake instance doesn't require being on the VPN or login via okta/azure ad/whatever SSO can fly under the radar pretty easily. Attackers realized this, and started targeting snowflake credentials.
Seems similar to all the S3 breaches that have come out over the years -- it's not that s3 has some giant security hole (in the traditional sense) -- it was just really easy throw shit on S3 and accidentally make it totally public.
Reports say password-stealing breaches were happening as far back as Oct 2023. But Snowflake didn't notify people (customers, FBI, SEC) until May 2024.
What's crazy is that Snowflake made MFA enforcement available only 5 days ago.
Some software engineers are licensed. A company must hire these software engineers, and any changes to what data is saved or how is saved must be signed by these engineers. If a breach occurs, an investigation occurs and if these licensed software engineers are found to be negligent, they lose their license. If they are found to be at fault, they get criminal penalties.
This, of course, must be coupled with penalties for management personals as well.
What you want here is for them not to be holding the data to begin with. The solution to which is to just let customers sue them. Not for $0.30 and "free credit monitoring" but for actual money. Then companies can choose whether they want to mitigate their risk by doing actual security or by not storing the data to begin with, but most likely the second one is their better option.
That is indeed the intention. To counteract the financial incentives of shareholders (which result in bridges collapsing or data breaches) with the financial and legal incentives of a special class of employees - licensed engineers.
The reasons this works better than letting people sue after the accident has already happened [1] is because that it gets the incentives right. In sue-after model the responsibility before an accident has happened to make the product safe is quite diffuse across the whole organization, and the decision makers (C-suite) do not in fact have the expertise to determine if the product is unsafe.
Giving licensed engineers veto powers over the entire C-suite and the shareholders is indeed how you concentrate responsibility at a single point. This type of licensing model has worked wonders in civil engineering, electronics engineering, law, medicine etc in improving safety standards for the public. Software engineering is not special.
[1] Think letting the victims of the bridge collapse suing as the only method of preventing bridge collapses. This is not how things operate.
But now you have a special class of employees whose incentives are wrong in the opposite direction. They make decisions that are overly conservative, because they lose their license if the bridge collapses but by design no one can overrule them if they unnecessarily make the bridge cost four times as much.
This not only makes the bridge cost many times more, it thwarts the original intention because now building new things is so expensive that we avoid doing it and instead continue to use the old things that are grandfathered in or maintained well past the end of their design life, which is even less safe in addition to being less efficient. This is why so much of our infrastructure is crumbling -- we made it prohibitively expensive to build new.
> This type of licensing model has worked wonders in civil engineering, electronics engineering, law, medicine etc in improving safety standards for the public.
And these things are now unaffordable as a result. Ordinary people have been priced out of legal representation and are being bankrupted by medical bills. It's not a solution, it's just a new problem.
> Think letting the victims of the bridge collapse suing as the only method of preventing bridge collapses. This is not how things operate.
The reason this doesn't work in that specific case is that the damage from a bridge collapse can easily exceed the entire value of the bridge-building company, so then if you go to sue them they just file bankruptcy. Which they know ahead of time and then don't have the right incentives to prevent the damage. That hardly applies to the likes of AT&T, which is not going to be bankrupted by a large damages award, but is going to want to avoid paying it out.
> In sue-after model the responsibility before an accident has happened to make the product safe is quite diffuse across the whole organization, and the decision makers (C-suite) do not in fact have the expertise to determine if the product is unsafe.
Neither are they expected to. They're expected to hire someone who does, but then they have the incentive to balance the cost against the harm, so they neither end up with the incentive to abandon quality nor the incentive to make everything prohibitively expensive.
A real issue here is limited liability. The CEO comes in, hires low quality workers or puts them under unreasonable time constraints, gets a bonus for cutting costs and is then at another company by the time the lawsuit comes. Forget about licensing, make them personally liable for what happened under their watch (regardless of whether they still work there) and you'll get a different result.
Limited liability should be for shareholders, not decisionmakers.
That way the same party suffers both in the case of unreasonably high costs and in the case of unreasonably low quality and doesn't have a perverse incentive to excessively sacrifice one for the other.
This is not a bug. Having fewer bridges that don't collapse is better than having one fall over every day which is what's happening with data leaks now.
Everything related to personal data is currently at the slum without firecodes level. But it also has a few unregulated nuclear reactors in the mix.
We now have < 10 megabanks in the US, any of which can bring down the entire US economy.
Instead , we could have 1000s of smaller banks. Tons of smaller banks is the natural state of things, like restaurants. This was true before the banking cartel, TARP, ZIRP, most recently, PPP (genius backdoor to bail out wall st.). In such system, any 1 collapsing bank wont bring the entire system down.
Having fewer bridges means that inevitable when they collapse, there will be far more victims and the event will be catastrophic.
Tech is one of the few bright spots in our moribund economy. Don't introduce a cartel that will blow up eventually.
I honestly don't even know where to start with this.
It's the same for all the rest of it. You're not helping people to nominally make something better unless the better thing is actually available to them.
You are only succeeding at keeping 1 engineering firm alive, who can afford to bid and build mega-expensive projects.
Eventually, the megafirm will adopt poor practices. And now, those practices will literally spread out across every single bridge built in the world. You now have a mono-culture of engineering that includes cancer as part of its DNA. Congratulations - you have granted a monopoly to a firm that sells ticking time bombs to your own citizens
This is, in essence, NASA, banking, Fannie/Freddie.
Errors are a part of nature. They must happen. We are humans and fallible. The question, when errors do happen, how big and hurtful will they be? Small or big ?
You can't buy your way out of human error and hubris. This is the fatal conceit.
The crowd here on HN intends to make fun of governments and banks and similar regulated entities… but smug startup culture will not exist if you got what you say you want.
It's not surprising. But what should not be surprising is that sooner or later, software engineering will be regulated [1]. The question is simply whether software engineers will let politicians do it to them in an unreasonable way, or whether they do it themselves in a more reasonable way.
[1] Well, it has already begun. EU has the notion of the GDPR Data Protection Officer [1] https://www.gdpreu.org/the-regulation/key-concepts/data-prot...
The standard legal philosophy across the world is that you can't actually predicate protection of a right on ability to pay (under reasonable limits). So, for example, nobody gets to build unsafe bridges and charge less for it, because it violates the right to life.
This is precisely how we end up in a world where we’re all running twenty five year old software.
Linux?
Then the MAX crashes happened and Boeing is about to negotiate a sweetheart plea deal and there's absolutely zero talk of any of the engineering licenses that were used to sign off on the bad systems getting revoked.
If the licensing system doesn't actually include a threat of career-ending penalties for knowingly signing off on bad designs, or if the system allows executives to bypass engineer signatures, then it seems like the general consensus on here is right: it's useless overhead at best and regulatory capture at worst.
The larger legal change has to happen is
1. Do not store user personal data if you don't have to (EU already has laws about it)
2. If you store user personal data, you have to guarantee up front that it is stored and processed in a safe way (what I am suggesting). Of course, exception can be made for sites/software with small number of users, or give some time bound leeway, so startups can grow before having to hire a licensed engineer.
I've met too many recent university graduates that don't even know you need to sanitize database inputs. Which, not their fault, but the university system as it currently exists in relation to software is not set up do do the thing you're asking.
The alternative is to have a really long exam (or a series of them like actuaries do?). Here are 10 random architectures. Describe the security flaws of each and what you would change to mitigate them.
The other change that needs to be made, is that engineers need to be able to describe the bounds of their software. This happens in the other engineering disciplines. A civil engineer can design a bridge with weight capacity X, maybe a pedestrian bridge. If someone builds it and drives semi-trucks over it, that's kinda their problem (and liability).
We would need some sort of way to say "this code is rated for use on an internal network or local only" and, given that rating, hooking it up to the open internet would be legally hazardous.
Look at the same problem with environmental disasters that were created by corporations. The problem with security liabilities is similar? Externalities are hard to get shareholders to pay for.
Shareholders can vote and decide the direction of a company. They should also be held liable for any problems the company causes.
If the company is fined it should come out of company and then shareholder pockets. I might even add courts should be able to award damages by directly fining share holders.
If a company does something severely illegal then very large shareholders should risk jail time.
It’s your company after all as a shareholder. You own it.
It’s no different if your dog bites someone or child breaks the law. You have to pay the fines.
The shareholders are mostly the pension funds that will eventually pay your money and the banks that already do.
Meanwhile, currently businesses are doing shit all about data breaches except handing out the absolutely useless "2 years identity monitoring", so from a consumer view it really can't get much worse.
In general, the idea that penalties make people hide their bad behavior, so we shouldn't penalize bad behavior, is just extremely misguided. Because without penalties, we normalize bad behavior.
As an Australian I am absolutely horrified that we continue to put people in jail who have blown the whistle on the government here, and it makes me think that large organisations are absolutely terrified about strong whistleblowing protections.
This all suggests to me that whistleblower laws would be very effective.
Maybe a reasonable first step is third-party standards, audits, and certifications around data security to make privacy- and security-conscious consumers aware of what a company is doing. If consumers really find value in that, then they will preferentially deal with that company, and other companies will follow suit.
Why should the software industry be any different?
And some call themselves code monkeys, they know how to follow orders, but have no incentives at all to think by themselves for proper security.
Only a tiny fraction call themselves engineers.
I favor non-licensed free professions, but if you're free you should be able to follow best practices and be able to think for yourself.
Anyone reading this, if you are of the “well the employee whole typed the command is to blame!” opinion, could you please reply to this comment? I need to know what you think the purpose of a hierarchy is in the workplace.
..needless to say, responsibility for your direct reports is yours. If they fuck up, you fucked up. You have the choice to hire and fire at will. You choose who has access to take chances. You own the wins and the losses. If you’re a good leader you redistribute the wins and dissolve the losses. It’s the entire job.
It’s 2024. There are no kings or dictators in the workplace.
The percentage of no backups seem to be crazy. I only read about the Central bank of Sambia being able to restore from backups, everyone else was down. All these responsible should be fired.
This isn't what's being suggested.
Higher ups set the incentive structures that result in dwindling security resources.
If their ass is on the line, they will actually listen to the developers and security experts telling them they are vulnerable, instead of brushing them off to divert resources that boost the reports which determine their bonuses.
What if this isn't the problem at all? What if a company invests a huge amount in data security, but still gets owned? That happens all the time.
I don't understand why people leap to the conclusion that these events are inevitably the outcome of neglect.
> If their ass is on the line, they will actually listen to the developers and security experts telling them they are vulnerable, instead of brushing them off to divert resources that boost the reports which determine their bonuses.
Again, why are you making this assumption? But let's say, for the sake of argument, that you're right. Now we go implement some draconian, top-down "you must be secure or the C-suite goes to jail" mandate. Corporations, out of fear of liability and prosecution, lock up tight, and refuse any and all changes that might undermine their security posture. Nobody builds anything new, because why take a risk?
Expensive "security expert" consultants start appearing out of nowhere to help with "compliance" with the new rule, and companies pay for them -- because it provides a veil of responsibility for the company, even if the consultant is useless. Worse, a certain percentage of these "experts" will be hucksters (or more likely: morons) themselves, and will always tell people that "they are vulnerable", because that essentially ensures a payday. You can't prove that a system is "secure", so who can say otherwise?
If you doubt that any of this is plausible, I suggest you take a hard look at our existing top-down security rules (e.g. ISO 27000, HIPAA, GDPR, PCI DSS, NIST SP 800-88 and SOC2, just to name a few) and the bureaucratic industrial complex that has erupted around them, and ask yourself it these things actually make you safer. I guarantee that AT&T was "compliant" by any conventional IT standard with these, employed an army of IT staff to document said compliance, and otherwise invested a huge amount of money in that kind of performative nonsense. Because that's what every company does.
But they still got owned.
Another option is we can empower red teams (security researchers) to test the security of all systems even without permission, so long as they report their findings responsibly.
It's currently quite convenient for companies. They get to deny security researchers from testing their security, and they also have no liability if a security breach does happen. Or, to make it personal, if I want to investigate the security of a company by trying to hack their system, I risk going to jail, but if they lose my data in a breach I have no recompense.
It's impossible to ensure what you're asking for. That's the problem with all of these kinds of rules, but worse, because at least something like SOC2 is providing a safe haven if you do the right things. Making companies "liable" for breaches is tantamount to saying that companies will never develop software again, because the risk is simply too great. Certainly, if I were in that kind of a situation, I'd rarely use a third-party service, and never use a startup, or a smaller company. I can't be responsible for the risks of AT&T, and every software company AT&T uses. That's crazy!
We're going to have to come to terms with the fact that "security" is a verb, not a noun, and that data leaks are going to happen, even in the best secured institutions. Punitive rules might improve security in the marginal case, but only at huge costs industry wide.
It would be kind of nice if companies would say "we've grown to our level of competence, we cannot safely do more, so we will keep doing the same, no more, no less, and make sure we do it well, and we will allow innovation to come from other companies". Instead, they say "let's recklessly chase every fad and who cares about poor security, it's not our liability".
Do you want to be held personally responsible when they're breached? If your wireless access point is hacked because you waited too long to update it, and it is used to launch DoS attacks, do you want to be liable? Do you want to be held personally responsible when you click on the just-good-enough phishing attack in your corporate inbox?
If not, then consider why you'd ask the same thing from a corporation of tens of thousands of people.
No, I don't. I don't want anyone to be held personally responsible.
> consider why you'd ask the same thing from a corporation
I'm not asking the same from companies. I don't consider putting liability on a company the same as putting liability on an individual, and neither do our laws. Companies may pay liabilities out of profits, companies may have to sell assets, companies may go out of business and people lose their jobs. None of that is the same as someone being personally liable.
This is a strawman, corporations are suppose to have a process in place to make sure stuff is up to date. You don’t jail like a random rank and file guy for a huge breach.
Making humans liable for car crashes is tantamount to saying that humans will never drive again, because the risk is simply too great.
Replace with any complex activity - nuclear reactor development, aircraft, etc.
How is it that in your head data breaches are this special human activity where Boone should ever be held accountable?
Snowflake's entire business model is based on selling the idea of "data lakes", "data warehouses", etc...
The basic premise of data lakes, etc, is to replicate and dump all your company data into easily queryable database instances, like Snowflake. I'm not disagreeing that this is a stupid thing to do, but just pointing out that this is something basically every Fortune 500 company is doing. Because big data is cool. (Or was cool)
Specifically since the article called out no 2fa... I'm actually very surprised how difficult 2fa is to set up with Snowflake. It's been 2-3 years since I set up a Snowflake instance, but I remember there being no obvious or easy way to enable it. (I wanted it on, but at the time enabling it was a multi-hour task, not just a setting to enable)
2fa is not the answer. The answer is compartmentalization. Just like a battleship is divided into many watertight compartments, because someone will poke a hole in it.
The Titanic needed 6 compartments to be breached before it was in danger of sinking.
Because that’s what happens 90%. Of the time.
In most cases I’ve seen, there are zero people on the team who could describe themselves as having any kind of expertise in security. Developers explicitly know about at least several vulnerabilities, but management doesn’t care to allocate resources to fix them, etc. that’s what’s happening in most shops.
To draw an analogy, if someone’s 16-year-old child is texting while driving and gets in a car accident, is their parent to blame? Most people could see that there is some fault on the part of both the parent (for perhaps not emphasizing enough the importance of safety while driving), and the child (for doing something they know is unsafe). And this fault exists in a continuum; maybe the parent told their child every day to not text while driving, and the child did it anyway. Maybe the parent never told them anything about safe driving habits, so the child had never considered that texting while driving was unsafe.
My point is that pretending that the highest C-suite executive is wholly responsible for everything that goes on in the company is extreme. Everyone along the entire chain of command has to do their part to ensure secure products are shipped - the executive needs to prioritize it, hire the right people to develop a plan, ensure people are enforcing the plan, etc., all the way down to the software engineers, the cleaning staff, etc. If one link in that chain breaks, the entire system fails, and it could be because of a weakness anywhere along the chain.
2. Nothing to no consequence to the executives.
3. Lawlessness of such events. Very poor consumer protection laws in this country.
4. Cybersecurity illiterate leadership making cybersecurity decisions.
5. Investing absolute little in Cybersecurity to meet bare-minimum standards.
6. Or all of the above?
How about instead of even more meaningless standards without teeth that don't affect the people pushing for profits over essentials like security, regulators impose punishments that actually affect the investors that ultimately create these perverse incentives in the first place? Nobody should be profiting off of a company that does wrong by over a hundred million people.
Why are we using SMS for 2FA everywhere? Why does AT&T have to have residential addresses and KYC for all of its customers? These are the things that should be banned. The government official that mandated all this crap should be forced to sleep with scorpions for 9 years and stink bugs for 3 more years.
If so the leak would be of much less consequence.
Is the argument that governments don't have a good reason to mandate record collection?
Why can't I ask my government to keep me safe from terrorists but also expect that companies will not just be careless with the data they collect as part of that?
We need to change our approach. We need to look at why these kinds of data are valuable, and then make them not valuable. Then nobody will bother with hacking to get it.
Expect every SMS and MMS sent or received to be part of a spam mitigation and profiling program where it's stored indefinitely.
Apple not encrypting RCS is likely due to similar factors, where they have seen existing spam problems on RCS that are much harder to root out when you have end-to-end encryption.
There needs to be a firm timeline -- maybe a year maybe a decade, I don't know the details but something that allows customers to transition to a system where all calls can be traced through the network with 100% guarantee.
Step zero is actually having a process/protocol where any phone is tamper evident meaning we can tell 100% that this call came from this operator and the operator knows the call came from this user.
Perhaps the first phase allows individual users to opt in. So we would ask our operators to only route us calls and texts that positively identify themselves as fully traced with whatever the new protocol is that will replace SS7/sigtran so the origin of a call or text is positively identified. If this guarantee is not available, route the call to spam inbox somehow.
Then the hard part I'm guessing is fixing all the defects?
The second phase is to say after this date, no operator in the US is allowed to relay calls that are from legacy systems. This will likely take many years as I don't know how we will handle international calls and texts. But at some point we have to put our foot down and say enough is enough.
This basically doesn't work because the mapping between phone numbers, users and operators isn't exactly 1:1:1.
Some businesses have a single number that they use as Caller ID on all their calls , despite having one corporate HQ in New York, one branch in New Orleans and one customer support callcenter in New Delhi. All of these use different carriers and are based in different countries, yet they're all legally authorized to use that number.
If you want to read more about why this is such a hard problem to solve, see https://computer.rip/2023-08-07-STIRred-AND-SHAKEN.html
Thank you for sharing it!
Now I need to lean SS7 signaling.
But why? I get that they want a unifed appearance, but as a phone subscriber I want to know if it's BigCo calling from New Delhi vs. BigCo calling from Chicago.
And then people wonder why privacy has a difficult time getting public support.
The big three wireless carriers in the USA today formed a cartel called The Campaign Registry that seeks out TINs/EINs and the SSNs of the owners of Sole Proprietorships and LLCs as part of a lengthy approval process to be allowed to send texts.
It's a great extra judicial rent seeking machine that bans any SHAFT content (sex hate alcohol, tobacco, firearms and anything tangentially related) along with hefty fines for anyone that they feel has crossed said boundaries.
Letting the morality police run amok on our Telecom networks here in the USA is happening, and they also want all the data they can get along with bribes from businesses.
Ajit Pai created the opening for this mess, and the current FCC has done nothing to clean this up (though given recent SCOTUS rulings, who knows if they ever had the authority...)
There's possibly a FISA court requirement (too secret to reveal), but AT&T has long been an exceedingly willing part of the gov's spying apparatus. It fed these records and Internet data to the feds without any court order, and only escaped legal troubles when Obama, contrary to his campaign promises, gave AT&T, Verizon and more retroactive immunity
It was well known in the wireless industry that ATT collected and kept the most data on all of the carriers: 7 years for text metadata, "7 years" for call history (I put that in quotations because it was rumored that ATT kept them indefinitely, but, there were technical limitations for restoring data that far back), and 7 years for the contents of the text messages themselves. Verizon was up there as well, but, I don't remember specifics.
The carrier that I worked with kept only 3 days content of the actual messages, 28 days for the text message metadata, and 28 days for the call records for their enforcement database, but, they could get calling records and sms envelope information for billing back 7 years, and at the time, we had to implement sharding at the database layer that maintained the warrant database due to the amount of traffic that we were receiving from the calling systems and the amount of queries/data that we were sending out, in near realtime, to law enforcement users who paid $10,000/month for access to that data.
AT&T wasn't storing this data out of the kindness of their heart, it was a (probably small) revenue stream for them.
Sometimes they had warrants, but mostly just bought the data.
A year or so after 9/11 and that relationship lasted years.
https://nymag.com/intelligencer/2016/11/new-yorks-nsa-listen...
I believe there was another similar nexus downtown near the World Trade Center, which was destroyed on 9/11. For at least a couple of weeks we had very limited communications and credit cards were hard to use as a result.
I am sure the employees were told SOME kind of legend, because that building begs questions.
I came very close to buying a long lines microwave relay site, and got to tour it a few times. It had a hardened tower, as well as copper grounding that went deep into the ground. Mining the copper would have paid for the site, but alas.
These buildings were built based on the 1950s threat of Soviet bombers attacking the United States. The New York City metro area was protected by air defense missile sites and interceptors. The air defense systems would air burst small nukes in wartime to destroy bomber formations.
Once the threat shifted to ICBMs in the 1970s hardening was moot.
There's some good sites out there that go into detail like http://coldwar-c4i.net/
Most Americans wouldn't even know what GDPR is, let alone have a reason to complain about it.
Well, that's kinda the point, but way too many website owners rather torture their users with barely compliant implementations than do what the GDPR intended: get rid of third parties.
including official EU websites
[ACCEPT] [REJECT]
without any dark patterns whatsoever.
The EU wants LEOs to have access to the contents of your messages/emails/metadata and keeps extending the Chat Control V1 law in order to not have to delete the data that it already has.
You may not be able to buy that data outright but it will be out there and collected by the messaging providers on behalf of the EU.
It even had a data retention law that forced providers to keep up to 8 years of data related to their customers so that it could be handed over to LEOs.
The EU's stance on privacy is just lipstick on a pig. When you pick under the curtain of the privacy laws in the EU, you'll see that it's not better here than in the US.
Something does not compute. Either you are pro privacy and you act like it or you are not.
It kills me to hear that Europe is pro privacy, because it is not true. Not if you look under the veneer and start peeling back the layers.
These sorts of data breaches should be a wake up call for any state actors who are planning on collecting massive amounts of data on their citizens.
It should make them pause and say, you know maybe we should not just give away all our data to Russia or China if they manage to break in our system.
Maybe the best way to avoid such data breaches is to not store the data in the first place.
It is strange to say they wanted it when we have proof it is voted down and widely unsupported. A part of the EU government apparatus wants it, but taking that and saying the EU wants it is not honest.
I have talked about it around me a bit and most people who do not work in tech or who don't have a certain interest in online privacy or privacy in general don't know about it.
Of course when you ask the citizens of the EU if they are cool about being monitored at all times by the EU LEOs then they don't want it but the commission wants it bad. All this is due from the heavy lobbying that has been happening in Brussels.
The worst part is that this is happening while the EU is saying that it wants data sovereignty, and wants to become less dependent on the software coming from the US, but it's ready to get in bed with a US company in order to deploy this mass surveillance system who supposedly is very good at finding CP.
Nevermind the fact that it means that every bit of online communication will be analyzed and dissected by a corporation that is out of reach of the EU.
But the commission is not stupid, they carved themselves a nice little clause so that they can be exempted from such mass surveillance. I guess they understand that having all telecommunications monitored by a for profit company that is not from the EU could lead to some embarrassing data leaks, just like we saw with AT&T but they don;t care if it's our data that leaks as long as it's not theirs.
That is why to me GDPR is just a facade. You can't seriously say that you are pro privacy and pro democracy if you keep trying to recreate the Stasi on a larger scale.
I don't know who Europe's biggest telco is, but if they got breached, the damage would be just as bad.
This is false? https://www.law.cornell.edu/uscode/text/18/2703 https://www.usnews.com/news/articles/2015/05/22/how-long-cel...
CALEA requires phone (and later broadband) equipment to conform to wiretapping standards, and if a carrier gets a court order to wiretap it has to provide that data from warrant receipt til warrant expiration.
Landlines have some data retention requirements.
But there's no law on broadband or wireless data retention.
There may well and likely is a secret FISA court order under section 702 that's been served to telecoms, but an astonishingly small number of people in govt and industry know whether that actually says that they just have to hand over records in real time or whether they need to keep records for some period of time.
What, nobody is allowed to make money anymore?
Perhaps that's not the whole story, but if true then blame certainly lies with AT&T to a significant degree.
Databases are not historically internet facing so data compromise also meant getting network access. But Snowflake provided web access to your database so they were “easy to use” database as a service (“cloud data warehouse”). Snowflake did not offer you a way to host data within your network or within your dedicated subnets within a cloud provider, so companies could not solely rely on those networking barriers to limit malicious counterparties.
Snowflake has apparently begun requiring MFA for new accounts since this incident I’ve heard. If shutting the gate after the horses have left implies culpability, Snowflake has some.
I don't like it, but accept it as the lesser evil. I'm from Europe and I believe the number of reported prevented terror attacks. The agencies need data access for that. Not good, but necessary.
But are you aware that Meta, Google, Apple, MS, etc. collect every kind of information about every user of Android, iPhone or WhatsApp, Insta, Facebook, Windows? Phone manufacturer, huge apps like TicToc as well. The kind and size of that data is crazy beyond imagination. I don't care if the government can get access to my WhatsApp messages when some of the most irresponsible companies, collect and use everything to their advantage. Are you really that naive and think that Meta doesn't analyse their gigantic data lake including billions of WhatsApp messages to predict the results of elections? That is the real danger to democracy.
This is all voluntary. You give those companies your data. You don't have to. I use grapheneos and do not use any of those socials, for example.
Your address, cell metadata, phone number, email address, and passwords are leaked pretty well contsantly though.
It's not that corporations are incompetent. The laws and regulations mean it's not worth the cost to treat your personal information with any real respect.
Citation: The Onion?
The Payment Card Industry Data Security Standard (PCI DSS) is the main information security standard for organizations that process credit or debit card information must abide by. The guidelines established in PCI DSS cover how to secure data handling processes.
So here are the top 5 info breaches:
https://www.goanywhere.com/blog/the-5-biggest-pci-compliance...
To be fair, if what happened to Heartland happened more often, PCI compliance would be taken more seriously, and breached less often.
You pointed out how there are guidelines for holding that information, I'm saying there are consequences [1]. I'm following that up by saying that the consequences for mishandling customer information are not nearly as severe. They do not result in 6 figure fines.
I'm saying the severe consequences to mishandling CC data have led to the incredible disparity shown in the first paragraph
[0] https://haveibeenpwned.com/PwnedWebsites
[1] https://resourcehub.bakermckenzie.com/en/resources/global-da...
* https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte...
* https://www.vice.com/en/article/m7vqkv/how-fbi-gets-phone-da...
* https://www.vice.com/en/article/3a87bv/fcc-propose-fines-ver...
* https://krebsonsecurity.com/2024/04/fcc-fines-major-u-s-wire...
Joseph Cox is basically the only investigative journalist that digs into constant PII violations before the leaks happen.
Oh but they do, try taking some data that belongs to a corporation and see how quickly law enforcement responds. Aaron Swartz found out the hard way
It’s only when you steal personal data that nobody cares.
Cloud computing companies, so-called "tech" companies, and the people who work for them, including many HN commenters, advise the public to store data "in the cloud". They encourage the public, whether companies or individuals, to store their data on someone else's computer that is connected to the open internet 24/7 instead of their own, nevermind offline storage media.
Countless times in HN threads readers are assured by commenters that storing data on someone else's computer is a good idea because "cloud" and "_____ as a service". Silicon Valley VC marketing BS.
"Maybe pierce the corporate veil and criminally prosecute those whose negligence made this possible."
Piercing the veil refers to piercing limited liability, i.e., financial liability. Piercing the veil for crimes is relatively rare. Contract or tort claims are the most common causes of action where it is permitted.
There is generally no such thing as "criminal negligence" under US law. Negligence is generally a tort.
As for fines, if there were a statute imposing them, how high would these need to be to make Amazon, Google, Microsoft or Apple employees and shareholders face "real consequences".
Is it negligent for AT&T to decide to give data to a cloud computing company such as Snowflake? HN commenters will relentlessly claim that storing data on someone else's computers that are online 24/7 as a "service", so-called cloud computing, is a sensible choice.
Data centers are an environmental hazard in a time when the environment is becoming less habitable, they are grossly diminishing supplies of clean water when it is becoming scarce, and these so-called "tech" companies are building them anyway.
Data centers are needed so the world can have more data breaches. Enjoy.
It wasn't really a Snowflake breach, if it's like the other Snowflake data leaks, AT&T didn't set up MFA for a privileged account and someone got in with a password compromised by other means. For smaller companies I'd be willing to put more blame on Snowflake for not requiring MFA, but AT&T is large enough to have their own security team that should know what they are doing.
This is yet another wakeup call for all companies - passwords are not secure by themselves because there are so many ways for passwords to be leaked. Even though SMS MFA is weak, it's far better than a password alone.
The comment is about the risk created by transferring data to a third party for online storage.
It is not about the specific details of how data is obtained by unauthorised recipients from the third party.
The act of storing data with third parties who keep it online 24/7 creates risk.
Obviously, the third parties will claim there is no risk as long as ["security"] is followed
If we have a historical record that shows there will always be some deficiency in following ["security"], for whatever reasons,^1 then we can conclude that using the third parties inherently creates risk.
1. HN commenters who focus on the reasons are missing the point of the comment or trying to change the subject.
If customer X gives data to party A because A needs the data to perform what customer has contracted A to do, and then party A gives the data to party B, now customer X needs to worry about both A _and_ B following ["security"]. X should only need to trust A but now X needs to trust B, too. If the data is further transferred to third parties C and D, then there is even more risk. Only A needs the data to perform its obligation to customer X. B, C and D have no obligations to X. To be sure, X may not even know that B, C and D have X's data.
A good analogy is a non-disclosure agreement. If it allows the recipient to share the information with third parties, then the disclosing party needs to be concerned about whether the recipient has a suitable NDA with each third party and will enforce it. Maybe the disclosing party prohibits such sharing or requires that the recipient obtain permission before it can disclose to other parties.^2 If the recipient allows the information to be shared with unknown third parties, then that creates more risk.
2. Would AT&T customers have consented to their call records being shared with Snowflake. The people behind so-called "tech" companies like Snowflake know that AT&T customers have no say in the matter.
Prison time being on the table for officers of the corporation is the only thing that will change this behavior.
Piercing the veil to prosecute those “responsible” seems like it would just incentivise the business to carry on as normal but with employees that are contractually designated (i.e. forced) to be fall guys if anything goes wrong.
Monopolies can always just pass the cost of the fine to their customers.
AT&T would be nearly equivalent to an E2E service overnight.
The lines wouldn’t be encrypted, so the NSA would still tap them, but at least there would be zero mutable storage in the AT&T data centers (except boot drives, SMS message queues, and a mapping between authorized sims and phone numbers).
In this day and age, why do they even maintain call records? They don’t need them for billing purposes, which was the original purpose of keeping them.
[0] https://www.tlp.law/2023/08/01/fcc-proposes-20-million-fine-....
If you want corporate-death-sentence level fines, are you willing to work in environment with exceedingly strict regulatory oversight? Will you work from an office where the computing infrastructure is strictly controlled? Where you can't bring personal devices to work? Where you have no privileges to alter your work station without a formal security review?
Why not advocate for more resources to capture and try the actual criminals? Or, as elsewhere in this thread, simply make this kind of data collection illegal?
If it means that privacy and safety is actually respected then yes. Working in an environment with "exceedingly strict" regulatory oversight would be a reassurance that observed violations will be dealt with in a timely fashion instead of put in the backlog and never addressed.
> Why not advocate for more resources to capture and try the actual criminals?
Yes, why not? While we're at it, let's try and capture the easily-spotted criminals who perform the most trivial of attacks to servers. Just open up your SSH server logs and start going after and preventing the fecktons of log spam that hide real attacks.
> Or, as elsewhere in this thread, simply make this kind of data collection illegal?
Making something illegal is great! Unfortunately it doesn't really do anything to help people after it's been stolen a second time (first time was by AT&T if it were illegal).
So what is Snowflake normally doing with all that AT&T data? Redistributing it to "marketing partners"? Apparently. Snowflake's mission statement, from their web site:
"Our mission is to break down data silos, overcome complexity and enable secure data collaboration between publishers, advertisers and the essential technologies that support them."
So this was not, apparently, a break-in to the operational side of AT&T. Someone unauthorized got hold of data they were already selling to marketers. Is that correct?
"Alternate credit scoring, hyper-targeted marketing and more... an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries." was the blurb for the unit Snowflake specially set up for Telco data in early 2023 touting "location data", but this product is not aimed at the telco's use-case; coincidentally this was also around the time Snowflake was touting integration with GenAI.
(It's not "competitor analysis" either, because if it was they would have obscured the 68m former phone numbers to prevent abuse by direct-marketing.)
[0]: "Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/
That pretty much says it.
It's disappointing that TechCrunch didn't point this out. Nor did the New York Times.[1] Yet it's right there on Snowflake's site.
[1] https://www.nytimes.com/2024/07/12/business/att-data-breach....
- Yes about Snowflake's cloud telco unit explicitly marketing the fact that telco data contains location. See my updated post: https://news.ycombinator.com/item?id=40949640
It's possible they were operating from a privacy first principle and storing only the exact data they needed for a specific internal objective.
As to who would be the end-user for the social graph of 110m users with location data but without dates and times, show us any use-case that's telco-related (not even spam prevention). It's not going to be. You'd want timestamps to disambiguate who are they contacting at work, at home, on their commute, at weekends, etc. So without that it'll be more like alternate credit scoring, surveillance, national-security. And why was Snowflake so eager to promote industries building business models on users' location data? For growth, sure, but who is this mystery industry sector that suddenly sprang up at the same time as GPT-4?
> [Eric Scott] AT&T was using the data to build a social graph. They didn't record the date and time because they didn't need it.
That isn't "internal analytics". The end-customers who would be buying that aren't telcos. Like I said.
e.g. a startup doing an Alternate credit scoring model isn't "internal analytics" wrt a telco.
Service A can access the dataset with the location hidden while Service B can access the dataset with the timestamp hidden while Service C can access the full dataset.
So Snowflake probably has the full dataset, and the account that was used in the breach only had access to a part of it, where the timestamp was hidden.
It's hard to come to any conclusion about what was done with the data on this account.
We can even go as far as saying that the account never used the data but had access to it because it was part of a group of accounts with access to it.
[x] Objective Achieved
Given the nature of the data in the database and the platform it was stored in, it seems extremely likely this data was not meant to be used internally by AT&T but was instead meant to be used externally by either a 3rd party partner (like advertisers and consumer analytics partners) or a government agency.
In other words, if it were my data in this datastore, I’d consider my data as already having been “leaked” when it went into the store - the issue here appears to be that this data was “leaked” to the wrong people from the perspective of AT&T and the FBI.
Doesn't matter if it's AT&T, a bank, or the government. Never under any circumstances can you expect anything sensitive to stay private. This used to be taught as gospel when introducing kids to the internet - it's crazy how much things have changed in 20 years.
I would bet any effects you’re seeing in stocks is unrelated to this news.
Also as corroboration here's MarketWatch: "AT&T’s stock slides 3% after company discloses hack of calls and texts" [https://www.marketwatch.com/story/at-ts-stock-slides-2-9-aft...]
While this price movement is very well correlated, perhaps causal even, but marketwatch (and all similar bottom feeders that are just trying to make ad revenue), it's a case of a broken clock being right. Those financial news sites which link recent news to stocks, eg Yahoo, benzings, - those recent news headlines are just the same as ad tech now. It is noise.
This is precisely why breaches keep happening and will keep happening. It cost money to implement security. There's no cost benefit to spending that time and money since there are no consequences.
Businesses do not spend money unless it will make them money or save them money.
There needs to be a hefty federal fine on a per-affected-user basis for data breaches. Also a federal fine for each day a breach is unreported.
That money should go into a pool which can be accessed by people who have their identity stolen.
But it appears $5 or credit monitoring from an agency that also gets hacked is sufficient for class action lawsuits.
The lawyers work on contingency
I don’t think that there is a room for a meaningful and honest discussion about individuals in these circumstances.
Yes, but no amount of money will stop the data in a big database being stolen by someone sufficiently motivated to steal it. It's just bits on someone's disk.
The only true solution is to not create the database. But then what would all the data scientists and their MBA masters so with their time?
OTOH this could be an opt in decision with a warning on the consequences
https://www.comparitech.com/blog/information-security/data-b...
"Stocks of breached companies on average underperformed the NASDAQ by -3.2% in the six months after a breach disclosure"
That said, it's not clear what the long term impact is on stock price (if there is any).
Pick 118 random companies at 118 random points in time. It's vanishingly unlikely that the average returns of that group will exactly track the NASDAQ returns over the following 60 days. It might underperform, or it might overperform. An underperformance of 3.2% could easily just be the result of random chance, and have nothing to do with data breaches.
This wouldn't be that hard to test. I suspect that the breached companies underperformed in the six months before the breach as well as the six months after.
This might also explain why there's little visible effect on other cloud database services either. After all, the attack is pretty simple and potentially affects any cloud database that allows access from the Internet.
We need regulations with massive fines, class action lawsuits (a ban on arbitration clauses), and maybe automatic minimum level compensation to those customers.
In this case, Snowflake was also the cause for the Ticketmaster and Lending Tree breaches according to the article so…
real lack of trust in Snowflake now.
Credential rotation, SSO, PrivateLink or IP allowlists all should be used with PII.
class action lawsuit just going to result in everyone’s $2 being given as a free trial of a ringtone addon from the early 2000s that converts into more recurring revenue
There's really no reason why any service providers should save this stuff in the first place, and it isn't hard to fix with legislation. Just make it illegal to even keep.
[1] https://curia.europa.eu/juris/document/document.jsf?text=&do...
Some service providers in Europe don't even want to save any data. The linked judgement above was the German state suing Telekom, which didn't want to save that data, and losing. Given the state of affairs, the question of "illegal or not" doesn't really come up as much. At least I'm not aware of any high profile judgements.
Besides Telekom, which always tried to minimize they data they keep to the point of fighting it all the way to Europe's highest courts, most other telcos don't really care and pick whichever middle-ground is available between "must" and "must not". Whatever is least-likely to get them into trouble. Right now that just happens to mean "save little".
* It's not stated explicitly in article 2, but the German constitutional court decided that it follows from those personal rights: https://en.wikipedia.org/wiki/Informational_self-determinati...
<https://www.ecfr.gov/current/title-15/subtitle-A/part-4a?toc...>
https://en.m.wikipedia.org/wiki/Fourth_Amendment_to_the_Unit...
In either regard, unambiguous comments are preferable to ambiguous ones.
The principle function of speech or writing is to accurately convey one's own state of mind to others.
(edited for grammar)
Whereas if they can get the telcos to keep it then the cops can get it using the third party doctrine. This is basically an end run around the constitution, which is why they like it.
The NSA’s power is in being boring and unnoticed. This could be a revenue rider.
Just saying.
<https://abcnews.go.com/blogs/headlines/2014/05/ex-nsa-chief-...>
As Bruce Schneier has noted, metadata equals surveillance, as it's actually far more amenable to analysis and inference than whole-text or audio capture. Though that latter may have shifted significantly with the rise of LLM AI techniques.
<https://www.schneier.com/blog/archives/2014/03/metadata_surv...>
The USPS takes images of most or all postal mail as part of its delivery and postal sorting/routing processes. Those covers are retained for a limited period of time, and actually have, so far as I understand, significant privacy protections associated with them, of the sort notably absent in most electronic communications.
See:
Mail Cover (Wikipedia):
Mail cover is a law enforcement investigative technique in which the United States Postal Service, acting at the request of a law enforcement agency, records information from the outside of letters and parcels before they are delivered and then sends the information to the agency that requested it.[1] The Postal Service grants mail cover surveillance requests for about 30 days and may extend them for up to 120 days.
<https://en.wikipedia.org/wiki/Mail_cover>
MICT: Mail Isolation Control and Tracking (Wikipedia):
[A]n imaging system employed by the United States Postal Service (USPS) that takes photographs of the exterior of every piece of mail that is processed in the United States.[1] The Postmaster General has stated that the system is primarily used for mail sorting,[2] though it also enables the USPS to retroactively track mail correspondence at the request of law enforcement.[2] It was created in the aftermath of the 2001 anthrax attacks that killed five people..
<https://en.wikipedia.org/wiki/Mail_Isolation_Control_and_Tra...>
39 CFR § 233.3 - Mail covers. <https://www.law.cornell.edu/cfr/text/39/233.3>
(I was ... vaguely aware of this.)
The court case I linked is evidence of that. The German state wanted Telekom to save more data, but the telco refused and won in court.
There are many reasons! Most of them are simply contrary to how folks think business should operate. Unfortunately the US seems to value "disruption" over "customer protection", so legally protecting data is unpopular on the hill.
On the contrary, many European countries have mandatory data retention periods that meet or exceed the 6 months of records that were supposedly included in this breech.
Germany has one of the shorter retention periods at 10 weeks, but they still have to keep those records.
Saying that it would be illegal to collect these records in Europe is patently false, and furthermore the record collection is generally mandated for a period of time that depends on the country.
> There's really no reason why any service providers should save this stuff in the first place,
Billing. You need phone records for billing purposes. You need to keep them for a while longer because people will dispute their bills all the time.
No they don't, because it's "suspended" by the federal network agency until courts are through with it. In fact they suspended it three days before the law would've come into force and thus it never was. The current state of affairs is this: the retention was ruled incompatible with German and European law in an injunction and it does not look like that is about to change.
There's a similar picture in many EU countries: There's a law on the books, but it can't be enforced/is being challenged/was already invalidated/is being rewritten/repeat.
Also note that to courts location data/phone records is a different issue than retaining information that merely associates an IP address with the subscriber that used it at some time (knowing which subscriber has what phone number is not an issue either, after all). The latter was ruled to be unproblematic by the ECJ just this year, while for the former the latest ruling is what I outlined earlier.
Besides Germany, some other countries that had data retention laws that were ruled unconstitutional are: Belgium, Bulgaria, Czech Republic, Cyprus, Romania, Slovenia, Slovakia.
In many other places that currently do have mandatory retention in force, it is being challenged.
> Saying that it would be illegal to collect these records in Europe is patently false
It is illegal to mandate in such a manner. There's a difference.
> Billing. You need phone records for billing purposes. You need to keep them for a while longer because people will dispute their bills all the time.
You must've not read the part where I said "beyond what is necessary to operate". Telekom for instance is doing just fine deleting phone records after 80 days - or within 7 days if you use a flat-rate and they're not relevant to billing.
My concern was the complete opposite - I assume that my social security number and address are already for sale for a fraction of a cent somewhere, bundled with 10,000 other identities. But if money gets stolen, that's a whole rigamarole, with banks wringing their hands and saying "identity theft" as if that clears them from any responsibility.
When I need a legitimate large withdrawal, I can go through the required effort.
Most businesses don’t even accept cash anymore. Can’t get “hacked” although it’s prone to many other issues — space, humidity, physical theft.
For example, let's say you have $100k in savings. I think you would be absolutely bonkers to store that in some secret part of your (flammable! break-in-able!) house.
I guess you could put it in a safety deposit box, and if you needed to spend it in a non-cash way, you could walk it directly to the teller and deposit it and make it available? The equivalent of a cold wallet, I suppose.
Really? I've been using cash almost exclusively for the past several months and haven't had any real problems. Sure, the overpriced hipster vegan Thai place in the McMall district may not take cash, but the family-owned ramen restaurant a couple miles down the road is more than happy to do so. Personally I find the "won't take cash" attribute to be a strong indicator that the business isn't worth supporting.
(Nothing against Abu Dabi— I just picked a random place not under US jurisdiction where plenty of people have Escalade Platinum money.)
Bank: "No, you see it was your identity that they stole!"
Customer: "Well I don't know because I seem to have my identity whereas you seem to have lost several thousands of dollars. I'm not clear why you think it's my identity that was stolen rather than your money."
Where are you getting your information from? The levels of security negligence I hear about aren't even a big ask. Huge companies neglect to do basic things like "don't store your passwords in plain text" or "make sure you salt and hash your passwords".
I don't think it's fair to say cyber security teams are failing if companies are blatantly doing the worst and most obviously wrong things on the daily at the highest levels.
Good cyber security people are expensive because they are highly skilled: they typically need to have been a software engineer to understand software architectures and have intuition about them, have spent significant time sharpening their skills at hacking by participating in CTFs, and have probably also spent significant time doing reverse engineering and have a few CVEs attributed to them. (Why are these skills needed? Because they are the skills needed by the red team. Every company that takes cyber security seriously will have a red team.) Now tell me whether these people are worth $500,000 per year.
Start issuing multi billion dollar fines for these breaches and suddenly companies are invested in security.
Unfortunately with government agencies getting defanged as part of recent SCOTUS ruling, it’s likely not possible.
Have to rely on civil court to issue fines now (ie, class action lawsuits).
The fact we don't have decent legislation to materially punish incompetent organizations is beyond absurd.
Security is not a concern. There is no real incentive to change the status quo. Make them pay for monitoring indefinitely .
In my country you can calculate our own national id (mix of date of birth, autoincreasing number by each birth that day + 1 checksum number), and if you do/have any kind of personal business, your personal tax number has to be written everywhere, on every receipt you hand out or anything you buy as a business.
Somehow knowing that first boy born today will have an ID number of 120702450001X (too lazy to calculate the checksum, but the algorithm is public), doesn't help anyone with anyting bad.
It's also treated as evidence of who you are, but it isn't tied to identification like an ID is. These institutions use it without ever truly validating it.
It's similar to how records fraud can occur - people can record anything to the local registrar office, including fraudulent documents, without any checks. Once it's registered, it becomes evidence against the real owner. It's really messed up.
+ e.g. until very recently there were US states that used your SSN as your driver license number.
We need a national (preferably RFID-ish) password system.
head -c 20 /dev/random | base64
And keep track of the result in your favorite password manager.Fortunately, fewer and fewer orgs are using security questions, but there are still some important ones that only use that and no MFA.
Better to randomly select a long dictionary word or hypenate a few together. Equally unguessable but easily verified, so it won't be weakened during a phone conversation.
Congress could solve this by enacting a simple law. Something to the effect of SSNs shall not be used as a means of identification by any party, governmental or otherwise other than the Social Security Administration. Use of an SSN as identification shall be subject to a $100 fine per each SSN used as identification, per day.
The problem is banks/financial services do a piss-poor job validating identity when issuing credit/opening accounts. "Oh, you provided an address, a SSN, and [non-random, easily discoverable personal fact]! Sure, here's a CC with a $150k limit!"
It's not the leak that's the problem; it's the ease with which that leaked data is used to either obtain fraudulent credit or access accounts.
I don't have a good answer, because at some point, a financial institution needs to trust people to do business. Customer loses their phone, so MFA doesn't work, ok, now what? I guess the customer needs to have one-time use recovery tokens saved somewhere that can't be lost? How many people do that (not nearly enough)? How many banks even issue those tokens? And what if the token store gets hacked? Now you're really fucked.
In my experience with banking in Brazil and Sweden this is easily solved with a OTP device you get from your bank.
Brazilian banks before that used to provide a card of 50-100 tokens you'd use for authenticating, which is obviously dangerous as people would carry them in their wallets with their cards (and associated banking details). Since the early 2010s banks have instead provided a physical OTP generator that you associate with your account.
In Sweden if I lose access to my phone with my digital identification app (BankID) I can fall back to my hardware OTP generator to login into my account, and authorise a new BankID installation in case I need a new phone.
It's a solved problem, even though the US developed a lot of the tech industry it feels like digital infrastructure is still in the late 90s for a lot of stuff; banking is a clear case, and government systems are another good example, e.g.: the DHS website for visa application is atrocious, we are in 2024 and applying for a visa feels like an experience from when I navigated the web on Netscape in the early 2000s.
So, do you get a physical OTP generator for every financial institution? I guess that works, but that would mean I’d have a drawer full (2x bank, 1x work, current 401k, past IRA, and a brokerage account - x2 because my wife has about the same).
I was thrilled last year when I discovered I could renew my passport online! In 2023! That should have been available eons ago.
1) SSN was not intended as a national ID, but it so happened to fit the shape of one, in that almost everyone has one and they're unique.
2) It has never been possible to institute an intentional national ID system in the US for political reasons
That is the recipe for the problem we have now. Strong demand for a national ID from many business purposes, the existence of something that looks a lot like, but is an imperfect form of, national ID, and the refusal to create a proper national ID, has naturally led to a de facto system of abusing the SSN as a national ID and just kind of everyone being a little annoyed and sketched out about it but putting up with it anyway for lack of alternatives.
Incidentally, did you know anyone can generate a valid new EIN (which is a lot like an SSN, and can be used where an SSN can be used for some but not all purposes, specifically filing taxes and ) at this page https://www.irs.gov/businesses/small-businesses-self-employe... ? This isn't legal advice and I'm not a lawyer and I don't know in what situations you personally would be legally permitted to use this (it's meant for businesses, absolutely not some kind of personal alias) -- but technologically, it's just honor system, and anyone can certify they need and are entitled to a new EIN and the IRS web site will provide you with a new unique one. I don't think you even need a legal entity, since you don't need a legal entity to run a business in the US.
It's even worse. Only post-2011 IIRC births have an algoirthmic SSN. So everyone over the age of 13 still has old fashioned sequential SSNs, where XXX-YY-ZZZZ is determined by
1) XXX is the code for the office that issues your card. Can be guessed precisely and accurately by knowing birth location. For example, I can guess what region of the US you were born in (or lived in when you immigrated) by the first digit. 0 or 1 is probably northeast. 4 or 5 is probably near Texas. 7 might be near Arkansas. Etc.
2) YY-ZZZZ is sequential by date! So by knowing just birth day, can be guessed to within a range. In practice, this means it's easy to guess YY alone, but harder to get all 4 digits of ZZZZ
3) For some stupid reason it got popular to print SSNs with all but the last four digits masked. This is horribly bad because those four are ACTUALLY THE MOST SECRET PART! It's the only part that might not be guessable. But since it's common to be more lax with securing them..... it is super easy to recover the full SSN if you find a piece of paper that says something like
JOHN SMITH
123 Main St
Alabama City, AL 76543
In ref acct: XXX-XX-1234 (2001-03-14)
Dear Mr Smith,
Your account is overdrawn. Have a nice day.
Thinking of you,
The Bank
It also means if someone is personally known to me, even vaguely, I may be able to reconstruct their social seeing nothing but a scrap of paper that has just the last four, if I can guess approximately where and when they were born or first entered the US. If I'm in a situation where I can try several guesses, it's even easier.
While the first sentence is true, the second is only true if you were born after the mid-1980s, when a Reagan-era tax reform was enacted. (It required a SSN when claiming dependents.) Prior to that, most people did not get a SSN until they got a job.
https://www.ssa.gov/policy/docs/ssb/v69n2/v69n2p55.html
tl;dr: If you had a bank account, applied for a federal benefit, were on food stamps, applied for school lunch, or did any number of other financial or government transactions, you needed a SSN starting in the 1970s. That's enough of an incentive that many parents might've just applied at birth, figuring that their kid will eventually need it. Also everyone born 1968-1981 would've likely gotten one in 1986, when the change you mentioned about dependents was enacted, and then after 1988 they started being required for issuance of a birth certificate.
I didn't know the reasons for the matches but them being my age and likely born in the same place as me made me realize those were identifiers and the last 4 were the unique bit.
Go Jackets.
Without global internetification, there was not as much an average person could really do or would know to do with an SSN alone to exploit it.
This story is a good parable for so much of what has changed in the world the last couple decades -- we had a world built for less globalization, then we globalized, and we've been gradually adapting to / dealing with the unintended consequences since then.
A real life door can only be picked by your neighbors or anyone else nearby -- attack surface is limited by the nature of physical distance.
A virtual door can be picked at by 7 billion people.
Would have been dank to see 666-66-6666 next to your name
(Payouts are expected to drop in about ten years if no action is taken, but that doesn’t render the SSA irrelevant or cause it to suddenly collapse and shut down, so I assume you mean something else)
What about people who have called suicide helplines, abortion clinics, loan servicing, etc...
With the numbers available, that will be possible to find out...
https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...
When no one is on the hook for secure practices, like enabling MFA on your effin data stores that contain massive amounts of customer PII, this is the result. Not even an apology, just report it and move on. woops! those gosh darned cyber criminals.
Most people aren't going to have their identity stolen (or insert w/e crime). Those that do will have trouble proving it was from this leak.
A lot of this could also be solved by encouraging the federal government to enforce federal privacy law as written more aggressively. A good incentive would be to amend the privacy statutes to permit the FTC to keep the funds extracted from settlements and penalties in-house. This would allow them to increase staffing and create a positive feedback loop to deter wrongdoing. This would have a negative effect on incumbent companies and practices, but it would not take long for the message to get across and for practices to change accordingly.
Congress tends to prefer keeping agencies on its own budgetary string which paradoxically limits what the agencies are capable of doing. The laws that we think protect us do not protect us because many of them are within the exclusive jurisdiction of a federal agency with very limited powers and funds. In the US the leadership likes to create the illusion that it has made "Bad Problem" illegal by writing it into the law, but it does not like creating the conditions in which "Bad Problem" could be solved, whether it's because the tradeoffs involved are tough to contemplate or because keeping "Bad Problem" around as a visible enemy is clever politics.
There's a hidden assumption here. The expectation is that data retention and potential privacy violations are a necessary evil because anyone may later be under investigation for a crime. The data could go uncollected, it isn't AT&Ts job to retain private information on all of us just in case an investigator wants it.
Take telecoms out of it and consider a convenience store. Police would like to have video recordings of whatever moment in time they are investigating, but that doesn't mean the video has to be recorded and retained. A shop owner can choose to record videos and only retain them for a week if they want, or they can have cameras installed but not even recording if they're okay with just the effect of deterrence.
A lot of this is on the federal government and Congress for leaving an area in which it has power dormant and within its relatively exclusive control. Thanks for the conversation.
I agree that deleting all your data after a year makes sense practically, but they'll never do it because it makes them too much money to keep it around.
It is high time for the US to have a privacy law with real teeth, and to enforce it with vigour.
But my guess it is few tens of cents, if that... While lawyer will get nice couple million pop...
Not the company. You.
Not many but is that because they don't get sued or because professionals who face consequences for negligence make fewer stupid decisions?
A Sarbanes-Oxley style law that makes the CEO personally criminally responsible for breaches will be vastly more effective than pursuing individual engineers - many of whom will be on the types of visa where they have no effective route of pushback on orders anyway.
We shouldn't choose between holding engineers or executives responsible. Each should be held responsible for their part.
My worry is not only that consumers get numb to breaches, but they consume rampant misinformation and have no idea how to hold appropriate parties accountable.
How many times have you held AWS accountable for stolen access keys?
Was it AWS fault when rabbit leaked their own keys?
Is it snowflakes fault when you lose your creds to infostealing malware?
How should snowflake enforce mfa on machine service account credentials?
The answers are no, no, and they can not possibly. Not even hyperscalers have this magic.
It was actually Snowflakes fault.
The threat actors were able to find a test/demo account they could log into and from there they were able to access prod things they shouldnt have.
https://cloud.google.com/blog/topics/threat-intelligence/unc...
"In April 2024, Mandiant received threat intelligence on database records that were subsequently determined to have originated from a victim’s Snowflake instance. Mandiant notified the victim, who then engaged Mandiant to investigate suspected data theft involving their Snowflake instance. During this investigation, Mandiant determined that the organization’s Snowflake instance had been compromised by a threat actor using credentials previously stolen via infostealer malware. The threat actor used these stolen credentials to access the customer’s Snowflake instance and ultimately exfiltrate valuable data. At the time of the compromise, the account did not have multi-factor authentication (MFA) enabled."
https://www.symmetry-systems.com/blog/what-we-know-so-far-ab...
"Snowflake has confirmed that a threat actor obtained credentials of a single former employee and accessed demo accounts they had access to. Snowflake asserts these accounts contained no “sensitive” data and were isolated from production and corporate systems. However, unlike Snowflake’s core systems, which are protected by Okta and Multi-Factor Authentication (MFA), these dormant demo accounts lacked such safeguards. "
"Mandatory MFA option unveiled by Snowflake" - Jul 11, 2024 https://www.scmagazine.com/brief/mandatory-mfa-option-unveil...
> "US cloud storage firm Snowflake has already required the implementation of multi-factor authentication across all user accounts a month following the widespread breach of customer accounts, including those of Ticketmaster and Santander Bank, reports The Register."
ATT is a technology infrastructure company. Secure transmission of data is one of their core business competencies (theoretically). They are a corporation that we trust to handle incredibly sensitive info. Call records are, in fact, incredibly sensitive data.
They should be telling Snowflake what best practices to be using, not the other way around!
So they used to develop cutting edge technology, they sell technology, they buy technology, they operate technology, they work with manufacturers to develop new technology, they operate the infrastructure underpinning the modern technology economy, but they aren't a technology company?
Even if you want to argue that they aren't a technology company, they sure spend enough time doing everything a technology company does to hold them accountable for their technology failures.
They also invented the transistor, C, the photovoltaic cell, radio astronomy, and … the telephone. ;)
Yes that’s the past, but AT&T labs still employs almost two thousand people. It’s very funny to try to claim AT&T isn’t a technology company and only peddles services on top of equipment made by others.
Calling AT&T a tech company because they operate technological infrastructure is like calling Spirit Airlines an aerospace technology company because they operate jet airplanes.
If they don’t have the core competency, they need to obtain it as a requirement of doing business.
Are you claiming AT&T outsourced security and have contracts to back that up? Buying security equipment surely doesn’t amount to having security, that would be hilariously naïve. Equipment manufactures are not responsible for AT&T’s data security, AT&T is. There are laws around security that can hold AT&T liable, in the US and Europe and elsewhere. Whether they will hold the company liable is another question, but these laws will not accept an excuse that AT&T purchased security equipment from another company.
Well the _actual_ compromise started from one of their employees, so it's pretty unsurprising that they're getting (some of) the blame.
They attributed it to a lack of 2FA
If all the lockboxes in a bank get broken into, is it respectable to say "ah all of the customers should have used better locks"? The bank is the party who is supposed to be giving the insight into secure storage. They're not just renting space.
[1] https://cloud.google.com/blog/topics/threat-intelligence/unc...
"Snowflake allows its corporate customers, like tech companies and telcos, to analyze huge amounts of customer data in the cloud. It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say."
Finally journalists are asking the question why customer data must be stored with third party cloud providers. AT&T is a long way from Bell Labs, shame on them.
You go from being a potentially-small-fry target to getting your data collated in massive breaches. There's risks to both.
AT&T was not using MFA, while it was possible. Someone leaked credentials and this is the result. Only thing Snowflake could have done was to force MFA for everyone.
Any servers or admins which need to talk to the data store should instead use a private overlay (2) network.
Any users (likely just remote admins) should do the same.
(1) Same root cause as 99% of breaches and yet it is too often swept under the rug while we focus on the infinite # of proximate causes
(2) Software, not private circuits.
What does that have to do with 'underlay networks' and wow is that "the root cause of 99% of breaches"?
Yes, because 99% of attacks use the underlay network to access the target and exfiltrate the data. Said the other way, an attacker didn't physically walk into a Snowflake data center, console into the right server, and walk out with all the data.
After all, plenty of private overlay networks use simple username/password auth or no auth at all.
The critical part the overlay adds to traditional auth is making the server unreachable from the underlay networks, reducing attack surface by billions. Meaning:
+ Let's say the server did have good auth, but there was a bug, misconfig, zero day, etc. (one of the myriads of proximate causes).
+ Since the server is available on the underlay network, that vulnerability can be exploited by anyone on the underlay (billions Internet nodes).
+ In contrast, making the server only available on the overlay, reduces the attack surface from billions of Internet nodes to the nodes which can ID, authN and authZ (for that particular server) on the overlay.
But we should remember why it's not always considered best practices... you shouldn't assume that your private network is any more secure than the public network. When you have too many devices attached to that private (overlay?) network, it can be at just as much risk as if it was on the public internet. So, the zero-trust model is that you don't trust anything... public... private... it should all be untrusted.
Given that this was a "third-party cloud provider", I'm assuming that it was a credential leak and they only have username/password protections. Moreover, I doubt you'd have been able to add the provider's DB to an ATT based private VPN/network.
zero implicit trust is likely the best term? you have to trust something, but enforce (and therefore trust) strong (not network based) identity, authN and authZ. this can be done anywhere via a software-only overlay.
a litmus test is server iptables (to use an example) looks like: iptables -P INPUT DROP iptables -P FORWARD DROP
and the only route outbound from the server is to the private overlay on one port, and that server still can't make those connections unless it is strongly identified and authenticated, and the overlay will not connect the client and server unless they are both authorized to communicate for that particular service(1)
(1)so for example if there is a zero day causing the 'server' to try to communicate with some_IP then the private overlay will not accept the connection, even though it is coming from the server
I don't think any of this would have mattered to ATT, as the breach was from a third party that wouldn't have been on a private network anyway.
But, that would be a great service bonus -- only being able to connect to a service via a user-configurable private overlay network. It would be nice, but highly impractical... I can't even begin thinking about how customer support would be able to handle a scheme like this.
For more traditional single-entity networks, you’re right. But with more and more BYOD, those networks are at a higher risk than they used to be. That’s the reason for the shift… VPN tech is still sound, but it requires that you trust the devices that are connected to it.
If you’re now also trying to trust devices from your company and your customers, that’s harder to work my head around.
If only AT&T had some kind of way for its computers to talk to one another without going over the public internet…
https://www.usa.gov/credit-freeze
You can unfreeze through an app whenever you want/need to.
Also, all the big bank websites seem to offer real time credit history monitoring for free, so I am betting I’ll just deal with any problem if/when they happen.
Doing all 3 takes ~5minutes now - which can usually happen in parallel with whatever paperwork the vendor needs to get in order.
I've had no problems. Someone will try to run my credit, it will fail, then I ask which one they're trying to use, and I unfreeze it for a day. Some of them have the option to unfreeze for a single pull with a 1 time code (if I remember correctly), but when I tried to use that the person trying to pull the report seemed clueless, so I had to do the 1 day unfreeze.
At some point, I wonder if folks will realize that having an unfrozen credit report is a sign of imprudence.
> A credit freeze restricts access to your credit report
So if I freeze my credit, this will also deny access to the monitoring services AND financial institutions, right?
Side note: financial institutions often do “soft” credit pulls on active account holders to determine if they are eligible for credit limit increases. Have been growing my existing credit line for some time now without having to obtain additional credit cards. So far, close to $500K in unsecured credit.
Seems more like a nuclear option.
If I have to fight the credit bureaus anyway, I might as well get something out of it. Stealing my own identity seems pretty straightforward.
https://www.chexsystems.com/security-freeze/place-freeze
It was recommended that I do this after a checking account was opened using my identity.
As others have stated, my default is "frozen." I put temporary thaws on when applying for credit, though in some cases, you'll be informed exactly which agency/agencies will be queried, and may not need to unfreeze all of them.
Credit companies take our data, without consent or compensation, then turn around and charge you if you want to prevent abuse of that collection. It's a racquet.
- Records downloaded from Snowflake cloud platform
- "AT&T will notify 110 million AT&T customers"
- Compromised data includes customer phone numbers ("for 77m customers"), metadata (but not actual content or timestamp of calls and messages), and location-related data. Not SSNs or DOBs. Mostly during a six-month period 5/1-10/31/2022, but more recent records from 1/2/2023 for a smaller but unspecified number of customers. TechCrunch [1] has more details including Mandiant's response, the name and suspects location of the cybercriminal group
[1]: https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...
I wonder if Congress manages to summon TikTok-like levels of anger on regulating this one.
These records should have been deleted at the latest at the point where they're no longer relevant for billing. (Which also means that for customers with unlimited calling/texting, there shouldn't be any records in the first place.)
[1] https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-new-...
Did you know that AT&T has a commercial product where they sell Metadata of websites visited (unclear if it's only Netflow or if it includes DNS lookups too) to law enforcement and private investigators?
AT&T is a blight on the privacy of U.S. citizens.
Do you think that only AT&T does it ? Welcome to democracy, my friend. /s
> Joseph P. Nacchio was the only head of a communications company to demand a court order, or approval under the Foreign Intelligence Surveillance Act, in order to turn over communications records to the NSA.[11]
This is from the Snowflake breach, meaning this database was an "AI Powered Unified Data Platform." It almost feels like the erosion of our privacy is fueling the growth of allot companies.
I really hope that the boogeyman is real and all this was worth it.
All i can think of is billing for a fraction of plans from the early 2000s who still pay per min/per text. Or maybe for capacity metrics but even then you only need the overall data point not the actual records once collaborated.
What's the US law for keeping data as long as its relevant and needed?
Still not good, but headline feels clickbait if I think my text messages leaked
I've been wondering this since the Office of Personnel breach[1] back in 2015.
[1] https://en.m.wikipedia.org/wiki/Office_of_Personnel_Manageme...
As far as this breach goes, I think it just confirms my gut feel that Snowflake are heading to the wood chipper.
If we don't hold companies accountable for keeping far more access and retention than should be legal, and securing their systems poorly, this situation will never get better
It's very rare for someone at the highest level to be held to any kind of liability, and paying fines rarely, if ever, causes these too-big-to-fail corporations to materially impact them.
Strictly speaking about the US here.
These companies have scale as their moat and that's called a monopoly. We need to be aggressively pursuing corporate malfeasance, closing loopholes, and breaking up companies. In my ideal world the entire doctrine of the "corporate veil" would be overturned, but that seems unlikely to happen without drastic upheaval. Antitrust action and large-scale suits can happen and to some degree those wheels are already in motion, but it would help a lot to stop buying this bullshit about how we should think of this as a "crime" for which we should uniquely blame hackers. These megacorps want to pretend that they and their customers are in solidarity as victims of the hackers. In reality, these companies get hit with essentially none of the consequences, and their practices are most of the relevant causal factors. A better model would be that the customers (and often non-customers on whom they collect data without even the figleaf of manufactured consent) are victims of the companies and the hackers
Insurance Underwriters pour through corpo infosec documents, and require only the most basic level of protections.
I think instead, a stricter certification standard needs to be created, and all these large companies must pass ANNUAL audits, or simply lose access to government leased spectrum.
Just make the fine a % of the annual revenue and that will change.
That means the fines aren’t big enough. They should probably be scaled according to the business’ revenue.
If our only tool is fines, we must scale those fines not by some monetary definition of the harm, but by what will make the necessary impact on the decisionmakers involved.
I think we should use tools other than fines, like criminal conspiracy liability for controlling shareholders and executives, and the threat of dissolution of businesses to pay out to the victims, but if it's fines or bust, the marginal value of dollars is just on a different scale for these businesses and we should grow the fines accordingly
1. Preventing data breaches
2. Properly anonymizing aggregated personally identifiable data
3. Having and using a secure ID and verification system
If they knew, they would care, and that's why representatives care on their behalf.
You could say the same about health and nutrition, but people very much do care when a medical issue tangibly affects them negatively.
With the latest scandals and breaches though, I feel it's gradually starting to change.
Does anybody have any advice? Proving damages means showing actual monetary harm.
Google certainly made more off of my data than that.
> Please read this Agreement carefully. It requires you and AT&T to resolve disputes through arbitration on an individual basis rather than jury trials or class actions.
https://www.att.com/legal/terms.consumerServiceAgreement.htm...
> Please read this Agreement carefully. It requires you and AT&T to resolve disputes through arbitration on an individual basis rather than jury trials or class actions.
https://www.att.com/legal/terms.consumerServiceAgreement.htm...
That could get pretty expensive for them quickly.
I still (or at least try to still) have this naive opinion that if you make a good product, the money will come.
We sometimes spend too much time counting the beans and not enough time growing them. Not saying you don't need to count the beans, you do, but when your whole team is counting, they may forget to water them.
Also - to be on topic - don't forget to protect the beans!
I can only imagine the quality of mobile and fiber networking we could have had if that money was spent on telecommunications. And maybe they would have spent a few million on having proper security.
An infrastructure utility such as ATT typically has to offer dividends because it is not going to experience the type of growth that would result in a return via share price increase.
Of course, ATT’s prices are not regulated like a proper utility, even though they should be, but it is still subject to the same market forces that prevent it from growing like a tech company would, who would have the option of foregoing dividends (or share buybacks).
I do know that not every employee designation required universal 2FA but more or less all IT/ATO staff did.
Wondering what is the significance that most of the stolen records were from the period 5/1-10/31/2022? Does it mean that AT&T enabled 2FA on more recent records, or that more recent records were on a different cloud bucket (or that they mostly stopped using Snowflake since)?
Regarding 2FA, it probably means they just enabled it in their access rules for any access to snowflake, but it's highly unlikely AT&T will walk away from Snowflake anytime soon because it had become their preferred BI/Data Analytics platform and they were actively migrating several hundred TBs of data out of Hadoop to Snowflake.
Well, now I feel better. 8^)
how can we keep such accumulations of sensitive data from arising in the first place? only countries that figure it out are likely to survive the turbulent coming decades
(the last, hypothetically, to destroy the data rather than use it for leverage in investigations—if not, it's in effect just another spy agency)
In other words, your phone number and name is likely in a public record somewhere. It's not that private.
The info leak should not have happened but in the grand scheme of things it's not that big a deal. "The content of the calls and messages was not compromised." The worst it does is reveal who has been sending messages to or calling each other.
That said the few abusive people I know are not smart enough to find data dumps of AT&T call records on the dark web. Nor could they pay for them. Nor could they likely make sense of them. But I'm sure some could.
the message content wasn't leaked here
Way easier to target phish people's bank logins, if you know what banks they are regularly communicating with.
> It’s not clear for what reason AT&T was storing customer data in Snowflake, and the spokesperson would not say.
[1] https://techcrunch.com/2024/07/12/att-phone-records-stolen-d...
If wiretapping laws didn't exist then most of this data would not be justified to exist. Flat-rate billing doesn't need to keep track of this information. Even usage-based plans could keep cumulative records rather than individual ones, or at least delete them at the end of a billing period.
Where there is a trough, pigs gather.
I'm an AT&T customer, and in my case I don't have a risk, but I can imagine this info could be very handy for divorce, custody, and corporate IP lawsuits. So worse than it might look to ordinary folks.
Why was this not disclosed on AT&T’s earnings call on April 24? At least someone will get compensated for the breach, although it’ll be the lawyers for the class action lawsuit that’s about to hit instead of the customers that got their information stolen.
Edit: I must have read that from a different article than the TFA though.
That's what they always say, honey, before calling the police. /s
Shouldn't data like this be stored completely independently of the Internet? Yes, I realize that does not guarantee it is secure since there has to be some point of access. On the other hand, it would reduce opportunities for people to breech the databases.
And this is why consumers will continue to see their information compromised by companies who collect and retain more data than they need and then fail to invest the time and resources to protect it.
https://www.snowflake.com/en/customers/all-customers/case-st...
My guess is that the tech leaders a AT&T are going to have sore wrists for a few minutes because of this.
Such a law would seriously impact current practices of the majority of IT firms, including small app developers, which is why we see little push from silicon valley for such changes.
And is that going to change?
Should all databases be capped at a few million rows total or something? I don't quite understand where you're going with this.
WTF does this even mean?
The cloud employees downloaded it? If its so sensitive, why wouldn't this be heavily e2e encrypted?
I guess maybe a cop would still need a warrant to use the data, but what about civil court cases?
A lot of information can be derived from analysis of call records. If this information becomes public, it could be disastrous.
Isn't it even worse if it doesn't become public? It's been downloaded by an unauthorized party after all, so if they're not publishing the data, I'd wager they've found another way to profit from it. I.e. blackmail or similar.
I guess it depends on your viewpoint wherever that's better or worse.
- [security expert] "This [logs without timestamps] isn’t one of their main databases; it is metadata on who is contacting who. Its only real use is to know who is contacting whom and how many times."
- [commenter] "I have a theory that this call log was being used for a national security investigation. Otherwise why would this rise to the level of public safety/national security exemption?" [with two DOJ-approved 1-month delays for disclosure]
So, someone set up a separate Snowflake instance with mostly May-Oct 2022 AT&T data (90% former customers) apparently for that purpose. And left it up. Will anyone in Congress (e.g. Sen Ron Wyden) ask who did and why? (Another commenter on HN pointed out that Roe v Wade was overturned 6/2022, presumably that was not the intent of the original national-security investigation, but there's a potential for privacy abuse by the hackers' customers beyond everyday spam)
- In early 2023, Snowflake set up a unit especially for Telco data. But when you read the blurb (below), this product is not aimed at the telco's use-case; coincidentally this was also around the time Snowflake was touting integration with GenAI.
"Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/
"Telecoms are the connecting tissue of the modern economy. They run everything... growing importance... hyperconnectivity.
What makes telecom service providers unique is that they have access to consumer location data. For most other industries, a consumer can go into their phone’s privacy settings and turn off the location access in the smartphone app. But in the world of telecom, as long as the phone is connected to a network, the telecom provider can use triangulation to find the approximate location of a consumer. This is why there is an emerging trend of companies [which ones?] building partnerships with telecoms to power use cases across multiple industries from competitor intelligence, alternate credit scoring, hyper-targeted marketing and more.
... Yet, despite the importance of telecommunications for society and in connecting industries, network operators are not yet fully embracing the value of the data they have at their fingertips"
But the value of this data (90% former customers) was clearly not to the telco itself... so who is the unnamed partnership and who is the end-customer? And was one of Snowflake's AI partners involved?
Which is exactly the type of info that would be used to find evidence of an affair.
Though this is specific to SMS so it would not include iMessage or other messaging apps.
No it isn't. Not even close to some of the larger data sets that Snowflake most likely manages.
We're talking about the public cloud. You don't "hog" AWS's network with a one-time download in numbers like what we're seeing from the article.
Let's be generous and estimate that there are 1k records for each customer. That's almost certainly an overestimation for the time period that TFA specified, but for the sake of argument let's run with it. There are about 100M customers. So that's only 100B records. Assuming each record is on the order of 1kB in size, again likely a huge overestimation, then that would be just 100TB. AWS would charge $7k to egress 100TB, which would be a rounding error in AT&T's cloud spend.
The real amount is most likely less than half of that, if not a quarter.
There’s going to be a lot of “dark compute” once we throw these lazy assholes out.
Speaking for myself, I’m thinking of what the economics look like when HBM is abundant.
I see lots of outrage at the companies and why isn't the government doing more to punish them and how do I get compensated ...
But, I feel like everyone is blaming the victim. Is it the home owners fault when someone breaks in and steals stuff?
Where's the outrage at the hackers breaking into these accounts? Where's the "why aren't the governments tracking these people down?" Why is no one demanding that the hackers be brought to justice?
> Where's the outrage at the hackers breaking into these accounts?
The internet is essentially every hooligan in the world about to kick in your dooor. So yes, I blame the home owner.
It seems silly to me to condemn anonymous users of the internet.
Back in the days when nothing of importance was done on the internet the view was way more healty.
If you have sensitive data, don't expose it to the hooligans. Easy as that.
This is a straw man argument. Companies should use best practices in order to prevent most intrusions. When they do not, as in this case, criticism is warranted.
They literally kept everyone's information in a machine that was connected to the internet and then didn't make any effort to treat that with the gravitas it deserves. They are not the victim here, we are. It's a little shameful that you don't see that.
AT&T said it launched an investigation, hired cybersecurity experts and took steps to close the “illegal access point.””
That's pretty rich: “it wasn't misconfigured, it was just illegally open, and now we're closing it”.
I have nearly given up; like smoking, it will be decades before the harms are understood. We have to wait for your neighbour's brother to have died in a targetted political killing, because someone didn't like his Substack and borrowed the number and likeness of a friend; for his daughter's credit score to have been crushed by an anti-abortioneer who borrowed her face and likeness and number knew her first-grade teacher; for his son to die a death of despair, after making the wrong friends, and getting doxxed along with the rest of them.
This should be a five-foot headline moment. But no; CNN will lead with Biden-mumbles or Trump-grumbles.
How is it that the things that are killing us --- inequality, climate change, privacy collapse -- all have this same shape? Hamlets, all of us.
Then there is no data left to breach.
Instead develop systems to audit the usage of that blockchain and send to jail/military anyone who attempts to use that information in an unauthorized manner.
Even then, you'll still have an HTTP 403 response layer filtering those auth attempts based on IP... where we can assume these failed to implement it.
So far between TechCrunch, Wired, and other reporting it seems most claim creds get owned, sold, then used against under-restrictive Snowflake tenants which are exposed by default.
i.e; https://epa06486.snowflakecomputing.com/console/login#/ here's someone's tenant, if you were able to go buy some creds for it, should walk right in.
[edit] I have a more detailed Snowflake comment with references that might fill in better gaps here; https://news.ycombinator.com/item?id=40554753
- guessing it was some GenAI startup looking into consumer tracking, alternate credit scoring, surveillance or other national-security use-case.
- Very unusually, the DOJ ordered two ~month-long "delay periods" in disclosure: ("The Justice Department determined on May 9 and again on June 5 that a delay in providing public disclosure was warranted"). Yet this didn't happen for Ticketmaster or MOVEit breaches revealed around the same time. "Cybersecurity delay period requests" is a new power quietly authorized by the DOJ+SEC+FBI, 18 Dec 2023 [0]. Note that [1] emphasizes this as "Corporate Alert - guidance for delay requests [on SEC 8-K]". Might Congress already have known/suspected, when it authorized the cybersecurity delay request powers, of the Snowflake/AT&T breach? Either way, whoever is involved seems to have very powerful friends. Also, the big FISA renewal vote was Apr 19 2024 [2].
- Seems the cloud instance was set up the same time GPT-4 was released (March 2023), also when Snowflake set up a Telco business unit [3] ("Location data... Alternate credit scoring, hyper-targeted marketing and more... an emerging trend of companies building partnerships with telecoms to power use cases across multiple industries"). This product is not aimed at the telcos' use-cases, but at new revenue streams. (Who might the unnamed Snowflake AI partner(s) be?)
- They set up the Snowflake instance with AT&T/MVNO customers with timestamps removed, but with location data, yet the phone numbers not obscured or removed. Doesn't sound like "internal analytics" or "competitor analysis". What sorts of end-users want to pay for the entire social-graph of 110m, regardless whether those customers never make a phone call again? [EDIT: I confused the details of this AT&T breach with the other (2019) one disclosed on 3/2024: 77m AT&T/MVNO customers, 90% of them former customers]
[0]: "FBI Guidance to Victims of Cyber Incidents on SEC Reporting Requirements: FBI Policy Notice Summary" https://www.fbi.gov/investigate/cyber/fbi-guidance-to-victim...
[1]: "US Corporate Alert - DOJ, FBI, and SEC provide guidance for delay requests relating to disclosure of cybersecurity incidents under form 8-K" https://www.klgates.com/DOJ-FBI-and-SEC-Provide-Guidance-for...
[2]: US House approves FISA renewal – warrantless surveillance and all https://news.ycombinator.com/item?id=40041784
[3]: Snowflake cloud Telco unit, 4/2023: "Unlocking the Value of Telecom Data: Why It’s Time to Act" https://www.snowflake.com/blog/telecom-data-partnerships/
I know there are some historical reasons for non-SMS because of text pricing outside the US but everyone I know in the US would look at you funny if you wanted to use some special app for texting.
>I can share baby pictures without them being stored in google forever.
>We can organize whose bringing the coke without leaving a paper trail that lasts forever.
I HAVE 3
3 IS MORE THAN 1
I'm genuinely curious: what was the pitch that you used to get others to start using signal?
It's much easier when it's a group. I got some of my family to get on it too and they pretty much exclusively use it to talk to me.
In the mid 2010s it wasn't that hard of a call because the various Google apps kept getting deprecated (we were all in hangouts before), iPhone users wanted something rcs like and they couldn't for android users with mms, in general the app scene was taking off with Snapchat wechat etc. so people were easier to convince to dl it.
My pitch was 'you know how randomly Facebook or YouTube will serve you some adds about something you were talking about about, even though you didn't search with them? You're much less likely to have that happen with signal'
Then if they pressed I'd share a link from the net neutrality fight days about DNS hijacking etc and having them remember when all their failed urls would go to an ISP run search domain
I definitely used some FUD but it worked.
Actually I think some of the FUD was 'what if the carrier gets hacked?'.... Which, I mean for all carriers and all systems is just a matter of time. As t-> inf the probability of a breach converges to 1.
Also if any of your friends do drugs, of any sort, that was a great motivator for them to switch lol. Weed has only been legal for recreational since 2013 in any state.
Oh, and pretty much every techie friend I had went 'yo that's awesome' and changed over, even if they don't have a tech job.
Finally, back in the day/for many years, signal could default to normal MMS messaging, so the pitch was 'if they don't have signal, you can just text like normal'
I'm genuinely curious: what was the pitch that you used to get others to start using signal?
Otherwise to answer your question it is a bit of a game. I also like to remind them how, being creeped out by Aunt Matilda putting microphones and keyloggers all over, at least Aunt Matilda [most likely] has better interests for you at heart. GOOG/AAPL/MSFT have no such kinship connection yet they are surveilling in precisely the same ways. That was a decade ago, now add in the Universal Function Approximators! *Demo stable-diffusion.* *Demo lm-studio.* *Present to them a performance of Orwell's 1984.* *Show them a few documentaries on social control.* "See? Now would you like to try it?"
Not everyone switched, but a surprising amount did, and only more have switched over time.
It's because there are almost no consequences to them if they lose the customer data, beyond a day or two of bad press. If they faced significant fines, fines that get worse the more sensitive the data is, then they'd have an incentive to do better.
- Records downloaded from Snowflake cloud platform
- AT&T will notify 110 million AT&T customers
- Compromised data includes customer phone numbers, metadata (but not actual content or timestamp of calls and messages), and location-related data. Not SSNs or DOBs. Mostly during a six-month period 5/1-10/31/2022, but more recent records from 1/2/2023 for a smaller but unspecified number of customers. TechCrunch report has more details including Mandiant's response, the name and suspects location of the cybercriminal group
I wonder if Congress manages to summon TikTok-like levels of anger on regulating this one.
So AT&T put all our call information somewhere and hid it probably behind a weak password with no additional factors. IMO that's actionable negligence and I hope they get sued to oblivion.
Remember the massive Yahoo 2014 hack which Yahoo management failed to notify its own users for 2 years?
If SOX violation only literally covers users' own passwords getting breached, but not 2FA or other passwords to access the same data, will Congress amend it urgently?
EDIT: apparently they're hiding behind the 3/20 disclosure [0] which is all they disclosed until [1],[2] today.
[0]: March 30, 2024 - "AT&T Addresses Recent Data Set Released on the Dark Web" https://about.att.com/story/2024/addressing-data-set-release...
> "AT&T has determined that AT&T data-specific fields were contained in a data set released on the dark web; source is still being assessed...
> "AT&T has launched a robust investigation supported by internal and external cybersecurity experts. Based on our preliminary analysis, the data set appears to be from 2019 or earlier [incorrect], impacting... approx 7.6m current and 65.4m former AT&T account holders"*
> "Currently, AT&T does not have evidence of unauthorized access to its systems resulting in exfiltration of the data set.... As of today, this incident has not had a material impact on AT&T’s operations."* [but did it have a material impact on the customers/ex-customers?!]
[1]: Jul 12, 2024 - "AT&T Addresses Recent Incidents Regarding Access to Data" https://about.att.com/pages/data-incident.html
[2]: Jul 12, 2024 - "AT&T Addresses Illegal Download of Customer Data" https://about.att.com/story/2024/addressing-illegal-download...
> "Based on our investigation, the compromised data includes files containing AT&T records of calls and texts of nearly all of customers of [AT&T’s cellular and (MVNOs) using AT&T’s wireless network], as well as AT&T’s landline customers who interacted with those cellular numbers between May 1, 2022 - October 31, 2022. The compromised data also includes records from January 2, 2023, for a very small number of customers. The records identify the telephone numbers an AT&T or MVNO cellular number interacted with during these periods. For a subset of records, one or more cell site identification number(s) associated with the interactions are also included."
> The Justice Department determined on May 9 and again on June 5 that a delay in providing public disclosure was warranted, so the company is now timely filing the report.
> The company [AT&T] is working with law enforcement and believes at least one person has been apprehended, according to the filing. It does not expect the event to have a material impact on its financials.
MarketWatch: [https://www.marketwatch.com/story/at-ts-stock-slides-2-9-aft...]
“The company said the US Department of Justice Department determined in May and in June that a delay in public disclosure was warranted. It’s not clear why that the US government requested that data be delayed. CNN has reached out to the Justice Department for comment.”
public disclosure of a cataclysmic security breach in a darling of the stock market could have significant repercussions.
Source: me. My data was included in the leak and it included my SSN. It’s been a cluster fuck of a cleanup.
I guess the new methodology is that a company cannot be sued if they just all leak data, that way nobody knows which one is responsible for your identity theft.
(I was going to link to the 14 other submissions but the list is too long and it'd just come across as obnoxious.)
AT&T customer? Prepare for phone calls / text messages from your most frequent contacts saying "I got stranded / I'm Officer Blahblahman helping your friend get home... please send gift card / venmo"
It's only metadata...
At least I do anyway.
> Because dwm is customized through editing its source code, it's pointless to make binary packages of it. This keeps its userbase small and elitist.
Everyone only has so much attention to give.
> Protecting your data is one of our top priorities. We have confirmed the affected access point has been secured.
> We hold ourselves to a high standard and commit to delivering the experience that you deserve. We constantly evaluate and enhance our security to address changing cybersecurity threats and work to create a secure environment for you. We invest in our network’s security using a broad array of resources including people, capital, and innovative technology advancements.
I hope there's an enormous fine for this kind of negligence
This is just trivial pivoting done with some guesswork done fairly well.
> hundreds of Snowflake customer credentials ... of staffers who have access to their employer’s Snowflake environment ... credentials available online linked to Snowflake environments suggests an ongoing risk to customers who have not yet changed their passwords or enabled MFA.
Edward Snowden published several slide decks about it a few years ago, before he defected to Russia.