Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

121–130 of 218 posts

Re: Dell Computers Has Been Hacked

#121
post #97

Earlier quoted context omitted.

Well, I don't know how hard is it in the USA, but I use cash most of the time and know several people who do the same. Sure, sometimes you need to make wire transfer, or pay with credit card, or paypal for that matter. But at least shopping in the supermarket is possible with cash.

Then I do hope that you do not own a cashback etc bonus card, or your can be quite sure that your personal consumption related high resolution data will end up in some buyers pocket. And all that for a cheaper (and cheap) bread-knife.

This is why I frequently swap bonus cards with random people on the subway :)

Re: Dell Computers Has Been Hacked

#122
post #97

Earlier quoted context omitted.

Well, I don't know how hard is it in the USA, but I use cash most of the time and know several people who do the same. Sure, sometimes you need to make wire transfer, or pay with credit card, or paypal for that matter. But at least shopping in the supermarket is possible with cash.

Then I do hope that you do not own a cashback etc bonus card, or your can be quite sure that your personal consumption related high resolution data will end up in some buyers pocket. And all that for a cheaper (and cheap) bread-knife.

I avoid these for sure. As you say the reward is nothing - they can stick it.

Re: Dell Computers Has Been Hacked

#123
post #120

14:43 UTC+1, site not loading, DNS error (domain not resolved). It seems DNS this was hosted on godaddy, but can't see the content now. It was pointing to shared hosting on dreamhost. The domain will expire in August, so that is not the problem. The domain is in status clientUpdateProhibited, clientTransferProhibited, clientRenewProhibited, clientDeleteProhibited... the whois has been updated today. Maybe this site w…

Looks up to me, 08:55 UTC-5. If it's still not working for you try the archive: https://web.archive.org/web/20160105091436/http://www.10zenm...

Re: Dell Computers Has Been Hacked

#124
post #117

Earlier quoted context omitted.

Then I do hope that you do not own a cashback etc bonus card, or your can be quite sure that your personal consumption related high resolution data will end up in some buyers pocket. And all that for a cheaper (and cheap) bread-knife.

Sometimes I do use several bonus cards, when there's some significant benefit (say, sale-out only for bonus-card owners). Guilty that. But I do not use them often and of course I don't use my real name when signing up for it. Or if I do — only when I use my CC anyway, which is rare.

Surely if you use your CC one time with this card they have your real details. After that every cash purchase where you use this card is tied back to you. Not hard to believe they do this and you should assume the worst.

Re: Dell Computers Has Been Hacked

#125
post #46

It doesn't sound like Dell has been very effective here: likely attackers downloaded the database raw or it's one of their many contractors who log in remotely. Last time I saw that interface it was a web form that someone could access from any machine! This is serious. If you have customer data, you need to log access to that data, and you need to audit access to that data, and (very important!) you need to have a z…

The CTO is responsible here, not some "website hackers". If only that bore up in reality - you need only look at any number of recent high profile breaches (TalkTalk, for instance), to see that the "hacked" (incompetent) party gets sympathy, the exploiter gets prison time. As to how this is happening - quite likely exactly as you say. They have extreme staff churn in their Indian operations, and all it takes is a few…

Wow that's terrifying.

I think it's systemic, and we need to be very clear what we want a company (like Dell) to do in this situation.

Programmers are not usually held accountable for their own bugs, and I think that needs to change too. I don't recommend prison time, but maybe just some humility?

Bankers do the same thing: Past performance is not a guarantee of future results, and I get they're just doing their best, so why don't they put their own money in the same pot?

Heck, we expect the cafe to refund our coffee if they mix it up wrong, so why can't we just push that message upwards?

Re: Dell Computers Has Been Hacked

#126
post #120

14:43 UTC+1, site not loading, DNS error (domain not resolved). It seems DNS this was hosted on godaddy, but can't see the content now. It was pointing to shared hosting on dreamhost. The domain will expire in August, so that is not the problem. The domain is in status clientUpdateProhibited, clientTransferProhibited, clientRenewProhibited, clientDeleteProhibited... the whois has been updated today. Maybe this site w…

Looks up to me, 08:55 UTC-5. If it's still not working for you try the archive: https://web.archive.org/web/20160105091436/http://www.10zenm...

Still does not resolve here... maybe the problem is just in my network. I can see it now using translate.google.com as a proxy and it works.

Thanks !!

Re: Dell Computers Has Been Hacked

#127
post #2

I don't know if it's related but I found something deeply worrying a couple of months ago. I purchased a laptop on Dell's website at my home address using a personal email and my personal paypal account. No reference anywhere to my job or employer. A couple of weeks later I receive a call from India on the mobile number provided to Dell, from a guy pretending to be from Dell (and he might have been) who wanted to dis…

I recently experienced this with a software vendor after trialing some of their software. It's one of those forms where you have to enter some personal info before downloading the installer, and while I provided them with my email address I deliberately dodged entering my employer information. Imagine my surprise when I get a phone call from them at work asking how that software was working out for me.

To be fair, I hated the software and wasn't going to buy it. That phone call certainly didn't nudge me in their direction though.

Re: Dell Computers Has Been Hacked

#128
post #85

Earlier quoted context omitted.

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Guess why Google and Apple desperately wants to get in on payments? It fits their data driven business model perfectly.

Apple has a data-driven business model?

Re: Dell Computers Has Been Hacked

#129
post #91

Earlier quoted context omitted.

You mean GoogleAnalytics-tracking on the server side? Please expand on that, I'm not very versed in all that marketing spy-modules. Do you mean that some internet-shop (or blog or whatever) makes a request to GA or some similar service to share that I was at their website? If so, what information do they share? My IP, cookies or what? I always assumed that very point of GA was outsourcing tracking users to some other…

Yes. It's all just data in the end. Javascript can handle collecting all the information outside of setting cookies. But cookies are outdated and just a fallback now so all you need is the javascript to run. This can be as simple as hosting a copy of GA.js yourself but there are plenty of options like using the server-side API if you have GA enterprise or just using a reverse-proxy like Nginx with some rewriting logi…

Oh well. Indeed, I skimmed through their server-side tracking API: https://developers.google.com/analytics/devguides/collection...

That's unsettling.

Re: Dell Computers Has Been Hacked

#130
post #98
post #60

Earlier quoted context omitted.

Because non-capitalist countries have a much better record of protecting and respecting personal privacy. Really? The answers to this are twofold: Better national information security support* and regulation; Consumer action to chose vendors that demonstrate that they value personal privacy and prioritise information security. * Which includes not deliberately, as a matter of policy, undermining security technologies…

The best track record of protecting have Social Market countries. Social Capitalism, also called "Social Democracy", "Nordic Model", "Democratic Socialism", etc is generally the best model. In a pure capitalist model it is okay if Facebook shares all your data with advertisers – if you don’t like Facebook, just vote with your money and go to Google+.

Sure but no country on earth, not even the USA, has anything close to a pure capitalist system in that sense. Furthermore Nordic Model countries vary, but are very much capitalist. From wikipedia:

"Sweden's industry is overwhelmingly in private control; unlike some other industrialized Western countries, such as Austria, Italy or Finland, state owned enterprises were always of minor importance."

In fact I think I can make a strong argument that capitalism relies on property rights and therefore the rule of law, which tends to support individual rights in general including privacy.

Post reply on HN