Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> AT&T blamed an “illegal download” on a third-party cloud platform

WTF does this even mean?

The cloud employees downloaded it? If its so sensitive, why wouldn't this be heavily e2e encrypted?



This is related to the snowflake breach. Snowflake is blaming customers for not enabling MFA.


Looks like more than enough blame to go around. Not enabling MFA is pretty egregious by ATT. Snowflake creating a platform where such a high consequence mistake is apparently easy to make, and obviously without sufficient compensating controls to detect or limit impact of such a single point of failure. That's egregious too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: