Live data from Hacker News

Samsung Recent Security Incident

samsung.com

31–40 of 172 posts

Re: Samsung Recent Security Incident

#31
post #7

Earlier quoted context omitted.

In Sweden, this information is public.

I always find it curious that allegedly Swedish people on HN post this sentiment over and over, but then never link to their own personal information. Why not share, if it's so harmless? Isn't that the point you're trying to make?

I'm not Swedish, but a friend of mine showed me a website for it. Here is a random example of a person who lives in Täby, Sweden:

https://www.ratsit.se/19290708-Bertil_Thomas_Andersson_Taby/...

> Bertil Thomas Andersson - 1929-07-08 (93 years old) - Address: Lyktgränd 2 lgh 1706, 183 36 Täby, phone number 070-208 35 86

The website also adds information about income:

> (machine translation) In Täby, Bertil Thomas Andersson's home municipality, there are 5218 income millionaires. The proportion of people with payment notes in his postcode 183 36 is 7.3% and the average income is 295 679 SEK ($27,378) per year.

If the person runs any companies, that would be visible as well.

All of this is public information, for each individual and company in Sweden (except the ones that have requested to not be visible, or are protected)

Re: Samsung Recent Security Incident

#33
post #15

I love how they don't say how big the breach was, what systems were affected, or how to opt-out of them stealing your personal information and storing it on poorly secured servers: > Why does Samsung have my data? > We collect information necessary to help deliver the best experience possible with our products and services. We know how important privacy is to our customers, and we provide information about how we're…

From that privacy policy:

> Information we may collect automatically includes information about

>· your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software version, MNC, subscription information, and randomized, non-persistent and resettable device identifiers, such as Personalized Service ID (or PSID), and advertising IDs, including Google Ad ID;

>· your use of the Services, including clickstream data, your interactions with the Services (such as the web pages you visit, search terms, and the apps, services and features you use, download, or purchase), the pages that lead or refer you to the Services, how you use the Services, and dates and times of use of the Services; and

>· your use of third-party websites, apps and features that are connected to certain Services.

So essentially, they're saying that they can log everything that you do on your device.

Re: Samsung Recent Security Incident

#34
post #18

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

There’s a funny Mitchell and Webb sketch about it: https://youtu.be/CS9ptA3Ya9E

Re: Samsung Recent Security Incident

#35
post #14

Earlier quoted context omitted.

Dont give it to them then,

Yes. But it is becoming increasingly difficult with "smart" or "connected" devices. Sometimes you have to fill forms to access services or agree with EULA's with abusive terms. If you disagree with the terms, you become ostracized because everybody else from your circles accepted those terms and nobody is using your open-source/decentralized/federated network or services. You can't expect common people to be reasonab…

We don't need laws just dont buy their products. You're asking a business to change it's business practices because you don't like them. Free market.

Re: Samsung Recent Security Incident

#36
post #15

I love how they don't say how big the breach was, what systems were affected, or how to opt-out of them stealing your personal information and storing it on poorly secured servers: > Why does Samsung have my data? > We collect information necessary to help deliver the best experience possible with our products and services. We know how important privacy is to our customers, and we provide information about how we're…

From that privacy policy: > Information we may collect automatically includes information about >· your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software versio…

I don't even know why I got an email from them to my work email. AFAIK I've never used a samsung device at work and I have dedicated work devices.

Re: Samsung Recent Security Incident

#39
Oh, Samsung. I just went through the most insane account recovery process I've ever seen. Tried to register a Samsung account, but my email was already taken. Guess I must have had an account at some point. If you forget your password, you have to provide your name and date of birth to reset it. If you fail to enter the correct details many times, which I somehow did, eventually they will send you the recovery email anyway. When I received it, it was in a language I'd never seen. Then I discovered that it was actually somebody else's account from Indonesia that was using my email address without me ever knowing. So I now have a Samsung account that was someone else's but it was using my email so it was really mine?
Post reply on HN