Live data from Hacker News

Samsung Recent Security Incident

samsung.com

11–20 of 172 posts

Re: Samsung Recent Security Incident

#11
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

I don't spend much of my time worrying about this, but if you do:

Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.)

Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard target.

Re: Samsung Recent Security Incident

#12
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR. TL;DR : If it is or it is tied to PII (personally identifiable information) you have to: (a) Justify collecting it in the first place (b) Justify s…

You somehow forgot to mention that most (probably all) EU countries have laws that require you to know the birthdays of your customers - that of course overrides GDPR, or more precisely, the law is the reason to store the information so there's no need to find other reasons.

Also, don't forget that these laws also have requirements on you keeping logs, most of the time 3, 5 or more years. So yeah you have to obey a deletion request when that time is up, not "on request" - that would be illegal in most cases.

In many EU countries birthdate (and more) is public information, btw - my own birthdate is made public by the state itself (on the business registry website), together with my name and residence address. Same for any owner of real estate - be it land, house or unit - names, residence addresses and birthdates are publicly available in the online cadastre.

Re: Samsung Recent Security Incident

#13
> may have affected information such as name, contact and demographic information, date of birth, and product registration information.

No. No matter how safe of how carefully you take your security, a vendor should NOT keep these pieces of my private information with them.

Re: Samsung Recent Security Incident

#14

> may have affected information such as name, contact and demographic information, date of birth, and product registration information. No. No matter how safe of how carefully you take your security, a vendor should NOT keep these pieces of my private information with them.

Dont give it to them then,

Re: Samsung Recent Security Incident

#15
I love how they don't say how big the breach was, what systems were affected, or how to opt-out of them stealing your personal information and storing it on poorly secured servers:

> Why does Samsung have my data?

> We collect information necessary to help deliver the best experience possible with our products and services. We know how important privacy is to our customers, and we provide information about how we're planning to use customer data, in strict compliance with relevant privacy laws. You may visit the U.S. Privacy Policy section of our website for more details on how we may obtain data and for what purposes: https://www.samsung.com/us/account/privacy-policy/.

Re: Samsung Recent Security Incident

#16
This ship kinda sailed after Equifax data breach, but I wish we could make data a real liability ( as in, if you store it, you are on an actual legal hook for it ). 2017 settlement[1] was largely a joke if not an insult to all the affected individuals. The company still operates, no one went to jail and the company got a hard cap on potential claim from affected people.

I don't know what the solution is exactly though ( I mean how to effect actual change instead of posting in this forum ).

[1]https://www.ftc.gov/enforcement/refunds/equifax-data-breach-...

Re: Samsung Recent Security Incident

#18
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

> I wish we could stop propagating the idea that it's possible to "steal someone's identity"

Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality.

It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

Re: Samsung Recent Security Incident

#19
I would like to delete my Samsung account (which I was forced to create to access some feature of my phone). But I can't even access my profile because I'd need to accept some new user agreement which I won't do. I guess I could try sending them a letter.

Re: Samsung Recent Security Incident

#20
post #7

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

In Sweden, this information is public.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.
Post reply on HN