Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

141–150 of 218 posts

Re: Dell Computers Has Been Hacked

#141

I posted about this about 7 months ago on HN, https://news.ycombinator.com/item?id=9881674 , I also tweeted it out. Dell responded to my tweet saying there has been no breach and our data was secure. Obviously I didn't and don't believe them, and their main response was report it to the FTC. That is crap, admit it, fix it and deal with the issue. What totally pissed me off is that it was my sons laptop they called on…

I had the same problem last April, and had a surprisingly difficult time finding any more info about it. All Dell forum threads say that they know nothing about it and refer you to the FTC site. The really disturbing part was they used my mobile number, which had been spam-free until the Dell issue.

I posted about my experience here, with the hopes that others in my cohort would benefit from it, but the thread is still quiet: http://forum.notebookreview.com/threads/scam-calls-from-dell...

Summary of my battle: Keept them on the phone as long as possible, asked stupid questions, and tried to piss them off as much as humanly possible - I managed to get a "find a pen, remove the cap and stick it up your ass" after 2 hours on the phone with them. I kept them on the phone while my 4mb download took 45mins.

Re: Dell Computers Has Been Hacked

#142
post #91

Earlier quoted context omitted.

You mean GoogleAnalytics-tracking on the server side? Please expand on that, I'm not very versed in all that marketing spy-modules. Do you mean that some internet-shop (or blog or whatever) makes a request to GA or some similar service to share that I was at their website? If so, what information do they share? My IP, cookies or what? I always assumed that very point of GA was outsourcing tracking users to some other…

Everytime you access a website a server is serving you files. Apache (and most web servers) keep logs of this. With Apache defaults you get IP address, the route accessed, and the User-Agent of the user. This is rudimentary information, but if you have these logs from multiple sites, it's pretty easy to roughly track someone. Tracking images in emails use this same principle, a unique link to krick.png is put in an e…

Yes fine I know this. My objection is that this data is starting to be compiled on a cross site basis.

Re: Dell Computers Has Been Hacked

#144
post #108

Earlier quoted context omitted.

Everytime you access a website a server is serving you files. Apache (and most web servers) keep logs of this. With Apache defaults you get IP address, the route accessed, and the User-Agent of the user. This is rudimentary information, but if you have these logs from multiple sites, it's pretty easy to roughly track someone. Tracking images in emails use this same principle, a unique link to krick.png is put in an e…

Have you even read my message? Or the thread you are answering to for that matter? The question is not how website owner knows I visited his website, that much is pretty obvious, but if it is the case that server-side tracking somehow allows to use GoogleAnalytics as well (that is, to notify Google from server side who has visited their website) and if this is the case — how does it exactly work. Because that's what…

Are we agreed that my claim was valid? Thank you for digging up a primary source on it btw!

Re: Dell Computers Has Been Hacked

#145
post #3

Am I the only one thinking that we've lost total control over the machines and data we've created. It seems like nothing is safe and or verifiable anymore. Add to this the backdrop of governments wanting backdoors. People calling you in the US pretending to be from the "IRS" and yet nothing is/ can be done about it? Maybe its really high time for C and its buffer overflows to go... And SQL injection. We're tech savy…

It's going to take a lot more than a new programming language to fix the problems. If there's 10 million dollars worth of data to steal, that's enough to pay an entire team of professionals to work full time for a year or more on stealing the data, with a huge payout.

Being secure against that kind of attack is going to require an entire paradigm shift in how we approach security. New languages, new operating systems, and new assumptions about how much an attacker has compromised, including learning to keep things heavily compartmentalized.

Re: Dell Computers Has Been Hacked

#146
post #3

Am I the only one thinking that we've lost total control over the machines and data we've created. It seems like nothing is safe and or verifiable anymore. Add to this the backdrop of governments wanting backdoors. People calling you in the US pretending to be from the "IRS" and yet nothing is/ can be done about it? Maybe its really high time for C and its buffer overflows to go... And SQL injection. We're tech savy…

It's going to take a lot more than a new programming language to fix the problems. If there's 10 million dollars worth of data to steal, that's enough to pay an entire team of professionals to work full time for a year or more on stealing the data, with a huge payout.

Being secure against that kind of attack is going to require an entire paradigm shift in how we approach security. New languages, new operating systems, and new assumptions about how much an attacker has compromised, including learning to keep things heavily compartmentalized.

Re: Dell Computers Has Been Hacked

#147
post #117

Earlier quoted context omitted.

Sometimes I do use several bonus cards, when there's some significant benefit (say, sale-out only for bonus-card owners). Guilty that. But I do not use them often and of course I don't use my real name when signing up for it. Or if I do — only when I use my CC anyway, which is rare.

Surely if you use your CC one time with this card they have your real details. After that every cash purchase where you use this card is tied back to you. Not hard to believe they do this and you should assume the worst.

> every cash purchase where you use this card

When I pay with cash, I usually don't present a card as well.

Re: Dell Computers Has Been Hacked

#148

Earlier quoted context omitted.

I agree with your position. However... You misunderstand. There have been several commentators here on HN saying that they are moving Google Analytics server side. They seem to think that people are only objecting to the cookie or the presence of the JS rather than objecting to the pervasive cross-site tracking.

In that case, f that and f them. Do not track me.

Are you are aware that Google provide you with a method to do this regardless that doesn't rely on random script blocking? Details here https://tools.google.com/dlpage/gaoptout

Re: Dell Computers Has Been Hacked

#149

I'm not seeing any direct evidence of a hack. It seems just as likely that Dell could have simply sold customer data to interested parties.

Superphish showed us that Dell is clearly willing to do something of that nature, but the data the hackers are alleged to possess (shared secrets, support histories, ...) isn't the kind of thing you'd sell. There is no proof, but there the author certainly presents plenty of evidence. Unless you have access to information outside this article, the most likely hypothesis is that their database was compromised.

Re: Dell Computers Has Been Hacked

#150
post #139

Earlier quoted context omitted.

Purchase and transaction histories provide very rich data profiles and are a big business. There are also several companies that match up this "offline" data with online profiles so you can be targeted online. PII is not available, it is anonymized. There are laws around this. Purchase data itself is usually grouped into major purchase types, not amounts or actual goods purchased. For that detail, it would be the CRM…

> PII is not available, it is anonymized. There are laws around this. But we've seen how useless even apparently well meaning anonymisation is—think of the AOL search results. I can't imagine how utterly useless it becomes when it is done by people in whose interest it is to do it poorly, while remaining just within the law.

There is a difference. Yes search results can reveal a lot, even just a few hundred likes on Facebook can reveal your entire personality [1]. However this data is not regulated the same as actual personal information like names, address, gov id numbers, credit card data, etc. even though it should be.

The protection of the law does add to the security. Also anonymization of the PII (scrubbing into just a serial number) combined with the dilution of purchases into larger categories provides lots of protection. Your google search history is lot more detailed and granular than most of the purchase data you can buy through data markets. You might be able to figure out a basic "profile" and maybe use lookalike modeling but it would be incredibly difficult to actually distill that to a discrete person.

There's also been a push to buy "insights" rather than just data to get more ROI with less effort/cost so instead of buying purchase histories you would just buy a segment of people interested in buying washing machines for example.

1. https://soundcloud.com/rawdatapodcast/episode-1-uploaded

Post reply on HN