Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

131–140 of 218 posts

Re: Dell Computers Has Been Hacked

#131
post #99
post #94

Earlier quoted context omitted.

Jesus. If that first video is true, then that's what should be top-upvoted submission on HN. Why isn't it better known? I mean, at least I personally never heard about it and I might be not the most informed person on the Internet, but certainly I'm not the least. And this is much more important thing to know than… well, everything I usually hear on the news. I don't get often surprised by all that dystopian stuff, b…

That video has been submitted numerous times, but it never got any attention. To be clear, I believe there is some disagreement as if this is one or multiple programs in China, but that doesn't really matter; we need to defend against the establishment of this kind of program regardless. The trick where positive reinforcement is used to trick people into wanting to participate is utterly terrifying... because it will…

For some perspective, the weaponization of cliques and "othering" is very old, and it has worked for just as long. We call it politics.

But a state sponsored gamified social network where the incentives are all designed by the ruling class, and the penalties have the force of law, is pretty darn awful.

Hopefully the affected citizens prove to be as unpredictable and hard to control as others have in the past, because that's really their only hope.

Re: Dell Computers Has Been Hacked

#132
I posted about this about 7 months ago on HN, https://news.ycombinator.com/item?id=9881674, I also tweeted it out. Dell responded to my tweet saying there has been no breach and our data was secure. Obviously I didn't and don't believe them, and their main response was report it to the FTC. That is crap, admit it, fix it and deal with the issue.

What totally pissed me off is that it was my sons laptop they called on and they called him directly since his number was listed when he called in for real Dell support about 3 months prior to the scam call. They had convinced him they were Dell until I walked into his room and heard 30 seconds of the call and asked why he called them, soon as he said he didn't I told him to hang up. They were persistent, calling him back many times over the next 2 months. I had to block the number to finally get it to stop and my son says he got a new call just a few weeks ago, new number same scam but at least he is smarter about it now.

Re: Dell Computers Has Been Hacked

#133
post #85

Earlier quoted context omitted.

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Guess why Google and Apple desperately wants to get in on payments? It fits their data driven business model perfectly.

[deleted]

Re: Dell Computers Has Been Hacked

#134

Earlier quoted context omitted.

Unfortunately people have started putting the tracking server side.

Tracking server-side is fine, it is assumed the server logs contain a record of my visits and I have no problem with that. I think what most people object to is the third-party tracking that so many people use. Company A tracking my visits to Company A's website = OK Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK EDIT: (replying here as we'v…

Just a little HN tip. If you click the time of the comment you can reply to it even if there is no direct reply link.

Re: Dell Computers Has Been Hacked

#135
post #101

Earlier quoted context omitted.

Now you know why some countries like Germany like cash. It's anonymous by design.

True. But there are already solutions in place to undermine this anonymity e.g. the bonus card system (see previous comment).

Yeah, it's a shame that people don't value their privacy to some miniscule percentage of their expenses.

Re: Dell Computers Has Been Hacked

#136
post #85
post #11

Earlier quoted context omitted.

Axciom, Epsilon and similar companies track your credit card purchases and correlate them with a profile of who they think you are. If you work for a large corporation that is probably easier to identify than a small one. http://www.acxiom.com/ http://www.epsilon.com/

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Ok, I'll add to that a couple more details. Many ecommerce companies sell your purchase history to third parties as well, just like the credit card companies. This allows others to market to you more directly.

There is at least one company that has built technology that will monitor most all these purchases, monitor the IP's from them and the browser profile to identify a specific machine that you use. Then when you go to work, or are on your mobile they also will tag that traffic as you too. They have gotten so good they can serve ads that are relevant to your wife if she happens to be on your computer surfing the web for shoes say, but serve you different ads if you are on the same computer. They use data feeds from many sources, but ecommerce transactions, credit card transactions and companies like acxiom that let them match those with real people, incomes and household details make it very powerful.

In marketing we use Axiom and others a lot, their data used to be more vague and educated guesses about people. Now though, they have gotten it down pretty well, including how many animals, kids and your income/debt etc. They collect data from tax collectors offices, county records, city records, plus companies that will sell transaction data and other pieces so they can get a full picture. They of course work with Equifax, TransUnion etc too so they can build a whole economic profile on a person.

These companies are also what allow marketers to send you an email about their product/company after all you have done is visited their website. You don't have to enter anything or click on anything, but they will know who you are, who you work for and whether you fit their market profile in general. Poorly done it is extremely creepy, correctly done it can be an amazing conversion booster.

Re: Dell Computers Has Been Hacked

#137
post #125

Earlier quoted context omitted.

The CTO is responsible here, not some "website hackers". If only that bore up in reality - you need only look at any number of recent high profile breaches (TalkTalk, for instance), to see that the "hacked" (incompetent) party gets sympathy, the exploiter gets prison time. As to how this is happening - quite likely exactly as you say. They have extreme staff churn in their Indian operations, and all it takes is a few…

Wow that's terrifying. I think it's systemic, and we need to be very clear what we want a company (like Dell) to do in this situation. Programmers are not usually held accountable for their own bugs, and I think that needs to change too. I don't recommend prison time, but maybe just some humility? Bankers do the same thing: Past performance is not a guarantee of future results, and I get they're just doing their best…

> Programmers are not usually held accountable for their own bugs, and I think that needs to change too.

I disagree. Bugs are created and will be created; it is up to the proper process to test the system and get rid of them. A bug that goes into production code is a collective failure. Why do you blame the programmer, but won't blame the tester, or the guy who designed the test, or the guy who designed whole workflow, or the architect who planned the system?

Re: Dell Computers Has Been Hacked

#138

Earlier quoted context omitted.

Then I do hope that you do not own a cashback etc bonus card, or your can be quite sure that your personal consumption related high resolution data will end up in some buyers pocket. And all that for a cheaper (and cheap) bread-knife.

This is why I frequently swap bonus cards with random people on the subway :)

A serious question, though I assume that you were joking: is it more creepy to have your own actions tracked and accurately tied to you, or other people's actions tracked and inaccurately tied to you? Both sound pretty awful to me, but I think I'd prefer the former if those were the only two options.

Re: Dell Computers Has Been Hacked

#139
post #85

Earlier quoted context omitted.

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Purchase and transaction histories provide very rich data profiles and are a big business. There are also several companies that match up this "offline" data with online profiles so you can be targeted online. PII is not available, it is anonymized. There are laws around this. Purchase data itself is usually grouped into major purchase types, not amounts or actual goods purchased. For that detail, it would be the CRM…

> PII is not available, it is anonymized. There are laws around this.

But we've seen how useless even apparently well meaning anonymisation is—think of the AOL search results. I can't imagine how utterly useless it becomes when it is done by people in whose interest it is to do it poorly, while remaining just within the law.

Re: Dell Computers Has Been Hacked

#140

Earlier quoted context omitted.

> it's pretty obvious the language itself is made out of shotguns. You are hitting the hammer where there is no nail! In this instance, the Dell WEBSITE was hacked which are (99% of the time) written in high-level programming languages like php, python or Java. No sane business uses C/C++ to develop a website. C/C++ is used for INTERNAL SYSTEM PROGRAMMING and those systems are already linux based and almost impossibl…

> You are hitting the hammer where there is no nail! Pot. Kettle. Black. > In this instance, the Dell WEBSITE was hacked ... I saw absolutely nothing in the article that could even remotely be considered proof of this.

I work with a team in India. I can assure you the Dell tech reps log into Dell's system and are not hacking via the website. This is an inside job and there are no simple ways around it. Cost benefit analysis shows Dell they can allow you to get ripped off. They are still are selling computers and saving tons of money offshoring. They have no reason to correct this problem. Glad I build my own PC's at home.
Post reply on HN