Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

51–60 of 218 posts

Re: Dell Computers Has Been Hacked

#51

I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent. But what else can you expect? If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it. I seriously doubt that Dell tech support is ISO 27000 compliant.

>If you are not paying decent money, be prepared that your data woll be sold,

This is a terrible idea. How do I determine what is decent money enough not to have my information leaked? Do I have to buy Macs for life in order to prove that I don't want my information leaked? that's silly!

Re: Dell Computers Has Been Hacked

#52
post #44

I don't know about you, but where I live (Sweden) there are strict rules on how you can store personal data and who has access to it. It's also against the law to put people in "databases". I guess we still remember WW2 and how the Nazi used such registers ...

There are rules in the United States too, but a lot of places get it wrong. There is HIPPA, FERPA, PII, etc.

More often than not a company thinks they're compliant but then after a break-in is found to be lacking something big like hashing passwords.

Re: Dell Computers Has Been Hacked

#53
post #40

Earlier quoted context omitted.

> If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it From what I can see from a bit of Googling, Dell does pay their tech support people decent money. If Glassdoor is to be believed [1] [2], Dell tech support people in India make about 340k rupees a year, or about 28k per month. That appears to be a middle class income for an Indian city…

ommunist can correct me but I believe he was referring to having Dell tech support being located in a western country, instead of being based in asia. Yes it's more expensive to keep operations here, but we are more familiar with the business practices as well as the laws. Of course this is a price of "the race to the bottom".

> we are more familiar with business practices

Almost everywhere in the world had been doing business for thousands of years before the US existed. It's pretty careless to say that Asians are not 'familiar with business practices'.

They may not be all about your business practices. If yours get too weird and uptight they'll just return to doing business with the rest of the world and won't miss you too much.

Re: Dell Computers Has Been Hacked

#54
post #3

Am I the only one thinking that we've lost total control over the machines and data we've created. It seems like nothing is safe and or verifiable anymore. Add to this the backdrop of governments wanting backdoors. People calling you in the US pretending to be from the "IRS" and yet nothing is/ can be done about it? Maybe its really high time for C and its buffer overflows to go... And SQL injection. We're tech savy…

If they could prevent/stop caller id spoofing, that would be a big help in at least the detection phase of phone system security. It's really hard to identify a threat if they can look like they're anybody.

This is too easy with VoIP.

It should be illegal for anybody to spoof Caller-ID for deception. The only acceptable caller-id transmitted should be one of:

a) the actual origin number;

b) the number for a company switchboard that accepts incoming calls to the originating group; or

c) blocked number.

Re: Dell Computers Has Been Hacked

#55
post #32

Earlier quoted context omitted.

We can't be too far off from a China-style 'citizen credit rating' kind of system.

It already happens unofficially. How do you think banks assess your lending/borrowing habits when you apply for a loan? There are detective agencies who track credit cards and other things (like a few examples someone gave in this very thread).

There is a huge difference between a "private" rating system and a public rating that uses your friends against you as manipulation. See Extra Credit's description[1] of how this works.

We aren't there yet, but consider that Facebook wants to use your social network associations in your credit score[2].

[1] https://www.youtube.com/watch?v=lHcTKWiZ8sI

[2] http://www.theatlantic.com/technology/archive/2015/09/facebo...

Re: Dell Computers Has Been Hacked

#56
post #46

It doesn't sound like Dell has been very effective here: likely attackers downloaded the database raw or it's one of their many contractors who log in remotely. Last time I saw that interface it was a web form that someone could access from any machine! This is serious. If you have customer data, you need to log access to that data, and you need to audit access to that data, and (very important!) you need to have a z…

>If you have customer data, you need to log access to that data, and you need to audit access to that data, and (very important!) you need to have a zero-tolerance policy.

In an ideal world yes, but sadly here on planet reality I would be surprised if Dell even knows where all of its "customer data" is regardless of what certifications they are in compliance with.

They share that data with 100's of 3rd parties from outsourcing some of their own support services to some 5 man consultancy form Singapore that the CFO heard about on his last flight that sells them advanced analytics. While it's true that today customer data isn't shared that easily (at least in newer organizations that care about this) with an organization as old as Dell they might have data sharing relationships going past 2-3 decades that trump that and that sadly many people even C level at Dell might not be aware off. Not to mention that under the various 3rd party clauses many organizations pretty much use customer data as a commodity delegating it's distribution to various low level sale's execs that would send it to who ever would take it as long as they can get more accurate predictions for the next quarter to hit their targets.

Re: Dell Computers Has Been Hacked

#57
post #46

It doesn't sound like Dell has been very effective here: likely attackers downloaded the database raw or it's one of their many contractors who log in remotely. Last time I saw that interface it was a web form that someone could access from any machine! This is serious. If you have customer data, you need to log access to that data, and you need to audit access to that data, and (very important!) you need to have a z…

Second this. In fact, I would rather argue that its better to stop forcing online registration of computers until the privacy of those who register is guaranteed. Its not as if registration is even needed, they already have a tag attached to each device, so they can track sales using that. On the other hand, this problem is not specific to only Dell. Take the online web-forms of any other major Tech seller like Asus,…

It's not just tracking sales though, it's CRM, so every time they speak to someone about replacement/warrantee they need to know who they spoke to and audit frequent complaints either as abuse or something systemic that needs to be chased with a supplier.

I know why Dell needs to do this, but the C-suite is responsible for dieselgate and this kind of thing needs to be developed smartly, with taste, and with a consideration about what can fail (and how bad it can get). Bread and butter: Encrypt everything, long audit trail; Sysadmins don't need to read the databases (and can log need for keys), engineering doesn't need to read personal data, helpdesk don't need to log into servers, and no service needs unauthenticated and unlogged read (even internally; e.g. for automated reporting); Get audited by someone competent.

I handled 1bn daily records with 100% uptime, and max 6hr delay reporting using a single server, so there is no excuse except an incompetent CTO.

Re: Dell Computers Has Been Hacked

#58
post #40

I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent. But what else can you expect? If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it. I seriously doubt that Dell tech support is ISO 27000 compliant.

> If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it From what I can see from a bit of Googling, Dell does pay their tech support people decent money. If Glassdoor is to be believed [1] [2], Dell tech support people in India make about 340k rupees a year, or about 28k per month. That appears to be a middle class income for an Indian city…

The salary is an annual salary not a monthly salary. 340 K INR is 5K USD ie: they are paid $5000 a year.

That would put them squarely in the upper middle bracket in India.

Re: Dell Computers Has Been Hacked

#59

Earlier quoted context omitted.

Assuming an averagely careless programmer, a language made out of shotguns will produce more errors than a language with the occasional presence of shotguns. When simply trying to concatenate 2 strings can result in arbitrary code getting executed, memory leaks, actual data-loss or fatal program instability (or all of those), it's pretty obvious the C language itself is made out of shotguns. Making simple things simp…

C doesn't even have strings, but you would typically be using char arrays instead. All you need is a pointer to the array in order to access it. However, if you just have the pointer then you are lacking to essential pieces of information, the length of the string and the capacity of the string. The length of the string is however by convention determined by the first NULL byte (zero termination), so it is important…

It's much more complicated than it seems. It's one thing to understand how to use C strings in a benign environment and quite another to be sure you don't create a security weakness with them.

Re: Dell Computers Has Been Hacked

#60
post #11

Earlier quoted context omitted.

Axciom, Epsilon and similar companies track your credit card purchases and correlate them with a profile of who they think you are. If you work for a large corporation that is probably easier to identify than a small one. http://www.acxiom.com/ http://www.epsilon.com/

It's the isolating arm of capitalism drilling its elbow grease directly into your personal life.

Because non-capitalist countries have a much better record of protecting and respecting personal privacy. Really?

The answers to this are twofold: Better national information security support* and regulation; Consumer action to chose vendors that demonstrate that they value personal privacy and prioritise information security.

* Which includes not deliberately, as a matter of policy, undermining security technologies and standards.

Post reply on HN