Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

161–170 of 218 posts

Re: Dell Computers Has Been Hacked

#161

Earlier quoted context omitted.

Tracking server-side is fine, it is assumed the server logs contain a record of my visits and I have no problem with that. I think what most people object to is the third-party tracking that so many people use. Company A tracking my visits to Company A's website = OK Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK EDIT: (replying here as we'v…

Yes. GA has server-side API's available to premium accounts. You can also just host the ga.js file yourself. Or run a reverse proxy or any of a dozen other methods to collect data and pass it to GA. Using the standard 3rd party tag is just for convenience.

FYI, server-side APIs don't require premium accounts. :)

I'm pretty sure it's the same mechanism used for mobile/app non-browser tracking.

Re: Dell Computers Has Been Hacked

#162

Earlier quoted context omitted.

I had the same problem last April, and had a surprisingly difficult time finding any more info about it. All Dell forum threads say that they know nothing about it and refer you to the FTC site. The really disturbing part was they used my mobile number, which had been spam-free until the Dell issue. I posted about my experience here, with the hopes that others in my cohort would benefit from it, but the thread is sti…

Just read your description, it is nearly identical to what they were trying to get my son to do. They wanted remote access and telling him that his computer was attacking other people and their "monitoring" caught it. Really was an elaborate explanation when I heard it, but so insane to anyone that knows how this all works. But to a 17 yr old it seemed reasonable, even plausible especially with the quick talking, pus…

It's good that you managed to intervene - I know a lot of Dell owners that are not well equipped to handle these sorts of calls. Hopefully the worst that comes of it is a small fee.

At least it is good to see word getting out - that is likely the first step to any reasonable resolution.

Re: Dell Computers Has Been Hacked

#163

I posted about this about 7 months ago on HN, https://news.ycombinator.com/item?id=9881674 , I also tweeted it out. Dell responded to my tweet saying there has been no breach and our data was secure. Obviously I didn't and don't believe them, and their main response was report it to the FTC. That is crap, admit it, fix it and deal with the issue. What totally pissed me off is that it was my sons laptop they called on…

I've accepted that we live in an age where no one can secure data that is coveted by determined attackers. Even companies with the best infosec are often taken down by the simplest social engineering or clumsy spear-phisihng attempts that work well enough.

I hope this changes as we migrate away from passwords and passphrases to mandatory two factor login with physical keyfob tokens, from C to Rust, and from putting things directly onto the internet to putting everything behind a IPS/IDS that updates itself via signatures, honepots, etc. Especially in the home where no one runs IPS, the same way early consumer OS's didn't bother to ship with firewalls.

Phones need something like this too, especially with blocking known spammer numbers/providers. Everyday I get an Indian call center impersonating either state farm or blue cross. I have no way to stop this as they randomize the phone number each time, often in mocking ways like starting with a movie 555 prefix or having a prefix starting with 1.

I also don't want a relationship with companies like Dell where they store all my info. Why can't I buy something via a private OpenID/Persona-like system that has a tokenized version of my credit card and Dell just ships the product? I must have hundreds of accounts spread out with various sites, vendors, etc. Each of them ripe for the taking by scammers and hackers with my real name, stored card, etc.

I hope this stuff is what breaks the camel's back. IT security right now is a nightmare. I suspect it will get much worse before it gets better. Cryptolocker didn't suddenly fix corporate IT security. From what I can tell, its just as bad as its ever been.

Re: Dell Computers Has Been Hacked

#164
post #85

Earlier quoted context omitted.

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Ok, I'll add to that a couple more details. Many ecommerce companies sell your purchase history to third parties as well, just like the credit card companies. This allows others to market to you more directly. There is at least one company that has built technology that will monitor most all these purchases, monitor the IP's from them and the browser profile to identify a specific machine that you use. Then when you…

To me, well done, is still creepy.

I am from Brazil, and I am openly dissident of our government, and here assassinations (And other unpleasant things) DO happen to dissidents (example: in the last year a couple anti-government bloggers all in the same region where "murdered", the police claim it was just normal murder, but the coincidence is too great to be just normal murder, they were obviously assassinated).

What happen, if some day the government decide to assassinate me? They can just waltz in with a market company, offer a lot of money (or if they refuse, a lot of pain), get my data, and know all that stuff about me.

Then, they can do with me, what they did with Toninho and Celso Daniel: intercept them on the street, kill them, and pretend it was a robbery gone wrong.

Toninho case was very obvious: He was intercepted while fetching some suits he had bought before, using the tech you mentioned, assassins would know for certain that he was there, since they could know he would need to eventually fetch the suits, and that once inside the building, you could intercept him at the exit, indeed as he was exiting the shopping mall that had the clothing store, another car drove by, shot him (not "at his direction", but at him, directly, Toninho died instantly because of direct hits), and sped away. The police claimed it was a random incident where random criminals randomly passing by got pissed off at him cutting them off in the traffic and killed him, beside all that being unlikely, Toninho had some days earlier said to the press that should "something happen" to him, stuff were already set for his successor.

So what matters to me is: How I don't get tracked, unless I go "off grid survivalist style" ?

Re: Dell Computers Has Been Hacked

#165
post #125

Earlier quoted context omitted.

Wow that's terrifying. I think it's systemic, and we need to be very clear what we want a company (like Dell) to do in this situation. Programmers are not usually held accountable for their own bugs, and I think that needs to change too. I don't recommend prison time, but maybe just some humility? Bankers do the same thing: Past performance is not a guarantee of future results, and I get they're just doing their best…

> Programmers are not usually held accountable for their own bugs, and I think that needs to change too. I disagree. Bugs are created and will be created; it is up to the proper process to test the system and get rid of them. A bug that goes into production code is a collective failure. Why do you blame the programmer, but won't blame the tester, or the guy who designed the test, or the guy who designed whole workflo…

> Why do you blame the programmer, but won't blame the tester, or the guy who designed the test, or the guy who designed whole workflow, or the architect who planned the system?

Where did you get the idea that I don't?

I think people make mistakes sometimes (myself included), but I don't somehow think that diminishes the mistake.

I also think the programmer has less responsibility than the architect, or the CTO (which is why we pay them more). I don't like that shit only runs downhill.

Re: Dell Computers Has Been Hacked

#167
post #3

Am I the only one thinking that we've lost total control over the machines and data we've created. It seems like nothing is safe and or verifiable anymore. Add to this the backdrop of governments wanting backdoors. People calling you in the US pretending to be from the "IRS" and yet nothing is/ can be done about it? Maybe its really high time for C and its buffer overflows to go... And SQL injection. We're tech savy…

If they could prevent/stop caller id spoofing, that would be a big help in at least the detection phase of phone system security. It's really hard to identify a threat if they can look like they're anybody.

I wonder how much of a pain in the ass putting X509 (or something like it) into POTS/caller ID. It would stop spoofing dead in it's tracks.

Re: Dell Computers Has Been Hacked

#168
It's been some time (10 years or so) since I've last bought a prepackaged computer (I build my desktops from parts) but do you really have to register your personal information with the manufacturer when you buy a prebuilt computer? Why would there be a need to do that anyway, wouldn't the serial number of the machine be enough for warranty purposes?

Re: Dell Computers Has Been Hacked

#169
post #85
post #11

Earlier quoted context omitted.

Axciom, Epsilon and similar companies track your credit card purchases and correlate them with a profile of who they think you are. If you work for a large corporation that is probably easier to identify than a small one. http://www.acxiom.com/ http://www.epsilon.com/

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

This kind of thing is why the EU has data protection law.

Re: Dell Computers Has Been Hacked

#170

It's been some time (10 years or so) since I've last bought a prepackaged computer (I build my desktops from parts) but do you really have to register your personal information with the manufacturer when you buy a prebuilt computer? Why would there be a need to do that anyway, wouldn't the serial number of the machine be enough for warranty purposes?

You technically don't have to, but the Out of Box Experience pushes you towards it.
Post reply on HN