Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

181–190 of 218 posts

Re: Dell Computers Has Been Hacked

#181

Earlier quoted context omitted.

Maybe its really high time for C and its buffer overflows to go... And SQL injection. Because no one ever wrote an insecure website in Java? And certainly PHP must also be completely safe since it has no buffer overflows to worry about. Are you sure the language is at fault?

Assuming an averagely careless programmer, a language made out of shotguns will produce more errors than a language with the occasional presence of shotguns. When simply trying to concatenate 2 strings can result in arbitrary code getting executed, memory leaks, actual data-loss or fatal program instability (or all of those), it's pretty obvious the C language itself is made out of shotguns. Making simple things simp…

Making simple things simple and safe will produce fewer errors and fewer security issues. I don't see how anyone can try to argue anything else

Making things simple and safe is what leads an average careless programmmer to develop insecure websites. It's not simple to write a non trivial website that is safe for sensitive data. And the language is a small part of overall system security.

There are lots of alternative "safe" string libraries for C, so string handling is not a good argument against C.

Re: Dell Computers Has Been Hacked

#182
post #84

Earlier quoted context omitted.

It would be nice - not a solution, but an improvement nevertheless - if there was something like a "firewall" for phones, that allowed you to block calls based on the caller. I have never been harassed like that, but I have often wished for a feature like that.

There are? Go into your router settings through which you use your landline (or the settings in the phone app on your phone), it should look like this http://www.digiversum.de/wp-content/uploads/2012/05/Rufsperr... and then add the number you want to block.

Thanks for the hint! I'll look into that!

Re: Dell Computers Has Been Hacked

#183
post #135

Earlier quoted context omitted.

True. But there are already solutions in place to undermine this anonymity e.g. the bonus card system (see previous comment).

Yeah, it's a shame that people don't value their privacy to some miniscule percentage of their expenses.

People have absolutely no idea what trade off they're making I these cases. They just think they're getting a discount.

Re: Dell Computers Has Been Hacked

#184

Earlier quoted context omitted.

> we are more familiar with business practices Almost everywhere in the world had been doing business for thousands of years before the US existed. It's pretty careless to say that Asians are not 'familiar with business practices'. They may not be all about your business practices. If yours get too weird and uptight they'll just return to doing business with the rest of the world and won't miss you too much.

Either chaostheory edited their post o you missed a "the" before "business practices", presumably referring to the business practices of western countries.

I cut and paste the quote directly.

Re: Dell Computers Has Been Hacked

#185

I posted about this about 7 months ago on HN, https://news.ycombinator.com/item?id=9881674 , I also tweeted it out. Dell responded to my tweet saying there has been no breach and our data was secure. Obviously I didn't and don't believe them, and their main response was report it to the FTC. That is crap, admit it, fix it and deal with the issue. What totally pissed me off is that it was my sons laptop they called on…

I've accepted that we live in an age where no one can secure data that is coveted by determined attackers. Even companies with the best infosec are often taken down by the simplest social engineering or clumsy spear-phisihng attempts that work well enough. I hope this changes as we migrate away from passwords and passphrases to mandatory two factor login with physical keyfob tokens, from C to Rust, and from putting t…

Because retailers figured out a while ago that having a personal relationship with their customers (knowing everything about them) is EXTREMELY valuable. Think of the merchant wars with MC/Visa/ApplePay...etc as well as how much they sink into loyalty programs. Knowing your customer pays off in spades (until you have a security breach and get sued into oblivion).

Would be nice to be able to opt-in to a "forget everything you know about me" program - Newegg would probably get tons of business from paranoid nerds with an option like that in place.

Re: Dell Computers Has Been Hacked

#186

Earlier quoted context omitted.

What stops these guys from selling to all the major health insurers. Been buying too much sugar? Dental insurance up. Too much butter? Health insurance up. Bought three times the median amount of headache tablets? That's a paddlin'. Bought more alcohol than normal? Car insurance up. Opt out to keep off their radar? They assume the worst and charge you double?

I've heard stories of this happening (shopper club data -> insurance companies), but it's never been substantiated.

Example sentence from mid-naughts: "I've heard several stories of USG bulk tapping Internet interconnection points, but it's never been substantiated."

Thinking from first principles lets us see incentives and probable outcomes before they are "substantiated" (adopted by the media).

I personally don't think shopper data is affecting insurance policies quite yet. But the groundwork is there (Acxiom etc), and the "great" thing about data is it stays around forever!

I'd guess a timeframe of 10 years, but does it really matter as to when?

Re: Dell Computers Has Been Hacked

#187
post #85
post #11

Earlier quoted context omitted.

Axciom, Epsilon and similar companies track your credit card purchases and correlate them with a profile of who they think you are. If you work for a large corporation that is probably easier to identify than a small one. http://www.acxiom.com/ http://www.epsilon.com/

I assumed that when I buy something on a card, it's more or less private. The transaction should be known only to: me, the merchant, our respective banks, Visa, and I guess the IRS if they come and ask for it. If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization. How is that even remotely OK?

Literally every interaction with a 3rd party should be considered public knowledge as it is almost always shared with enough 3rd parties to guarantee that is the case.

Re: Dell Computers Has Been Hacked

#188
post #135

Earlier quoted context omitted.

True. But there are already solutions in place to undermine this anonymity e.g. the bonus card system (see previous comment).

Yeah, it's a shame that people don't value their privacy to some miniscule percentage of their expenses.

Tbh, $4-5k/year isn't a minuscule percentage of my expenses.

Re: Dell Computers Has Been Hacked

#189
post #94
post #55

Earlier quoted context omitted.

There is a huge difference between a "private" rating system and a public rating that uses your friends against you as manipulation. See Extra Credit's description[1] of how this works. We aren't there yet , but consider that Facebook wants to use your social network associations in your credit score[2]. [1] https://www.youtube.com/watch?v=lHcTKWiZ8sI [2] http://www.theatlantic.com/technology/archive/2015/09/facebo..…

Jesus. If that first video is true, then that's what should be top-upvoted submission on HN. Why isn't it better known? I mean, at least I personally never heard about it and I might be not the most informed person on the Internet, but certainly I'm not the least. And this is much more important thing to know than… well, everything I usually hear on the news. I don't get often surprised by all that dystopian stuff, b…

It looks like it is starting to get some attention at least. Here is HN discussion of the article that seems possibly the primary source for the video: https://news.ycombinator.com/item?id=10329733

It sounds like the system does not currently use politics and such, but the government would like to combine it with the existing citizen tracking system which is employer based.

And a BBC article: http://www.bbc.com/news/world-asia-china-34592186

I think the US system is fairly insidious as well and has more government influence than it might seem (look into "redlining" for instance and the role the government played). Creditors can know quite a bit about your private life (particularly if you significantly outside the mainstream) and I don't think it is that uncommon for individuals to share credit scores. In any case, I think it is worth considering how "social trust systems" work everywhere and not just in the worst imagininable case. It is harder to think about in the less obviously centralized cases.

Re: Dell Computers Has Been Hacked

#190
post #173

It's been some time (10 years or so) since I've last bought a prepackaged computer (I build my desktops from parts) but do you really have to register your personal information with the manufacturer when you buy a prebuilt computer? Why would there be a need to do that anyway, wouldn't the serial number of the machine be enough for warranty purposes?

Well, generally speaking, if you order a computer online (as most people probably do) you give them your name, address, and phone number so they can ship it to you.

Thanks for pointing that out.

Here in Greece (and most of Europe AFAIK) manufacturers don't sell directly to consumers, hence my confusion.

Post reply on HN