Live data from Hacker News

Samsung Recent Security Incident

samsung.com

1–10 of 172 posts

Re: Samsung Recent Security Incident

#4
> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and

That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason.

If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday (e.g., legal reason to validate you're old enough to open a bank account or whatever), not "i want to send a happy birthday newsletter every year (and also sell it in a package to data brokers)"

Re: Samsung Recent Security Incident

#5
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity

I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are.

What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent that.

Name, contact information and date of birth are so basic level of information, that if you can commit fraud with just those details, something is seriously wrong as the company you're performing the fraud against.

Some countries even have those details publicly for you to find via public websites. So again, if that's all it takes, the company is doing something seriously wrong.

Re: Samsung Recent Security Incident

#7
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

In Sweden, this information is public.

Re: Samsung Recent Security Incident

#9
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday

Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR.

TL;DR : If it is or it is tied to PII (personally identifiable information) you have to:

     (a) Justify collecting it in the first place
     (b) Justify storing it, and storing it no longer than necessary
     (c) Obey with the "right to be forgotten" and delete it on request
Post reply on HN