Live data from Hacker News

Samsung Recent Security Incident

samsung.com

41–50 of 172 posts

Re: Samsung Recent Security Incident

#42
post #7

Earlier quoted context omitted.

In Sweden, this information is public.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

Several bank loans and store cards were taken out in my name using only my name, address and date of birth, in the UK. The same cynical business logic applies the world over: it's cheaper to clean up after the inevitable fraud than to implement proper identity checks. This calculus is of course aided by the fact that the detection of the fraud and the organising of the cleanup is taken care of entirely by the victim. "Victim", not "customer", because usually there is no business relationship between the company with the shitty identity checks and the person that has to live with the consequences.

I recommend contacting the credit rating agencies and getting them to place a note on your record with a password, eg. [1]. Don't wait until someone "steals your identity". It's the only way to get these companies to do something resembling an actual identity check. Doing it after they've lent in your name (as the rating agencies suggest) rather defeats the object.

[1] https://help.equifax.co.uk/EquifaxOnlineHelp/s/article/Howdo...

Re: Samsung Recent Security Incident

#43
post #27

Luckily I gave all fake information to Samsung. Because I expected this to happen.

From a post above:

> your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software version, MNC, subscription information, and randomized, non-persistent and resettable device identifiers, such as Personalized Service ID (or PSID), and advertising IDs, including Google Ad ID;

Regardless of how fake you think the information you gave them is, if you use your phone, there is more than enough information to attain a real identity and connect that to other identities.

IMEI alone will uniquely identify your device, and therefore you, and it will be connected to a phone company that is probably willing to sell your data.

https://arstechnica.com/tech-policy/2021/03/t-mobile-will-te...

Re: Samsung Recent Security Incident

#44

>At Samsung, security is a top priority. Every company, always.

> At Firefighters, firefighting is our top priority. We recently discovered that our base of operations caught fire and, as the fire hydrants and fire extinguishers did not work, it was incinerated.

An absurd, insane message.

Re: Samsung Recent Security Incident

#45
Just got the email from Samsung saying I was part of the breach. At the end of this (extremely long and excuse-ridden) email they inform me that I'm entitled to a free credit check every year from credit reporting agencies.

Can't we just fast forward to the part where they send me a $5 check for the class action settlement? They'd save a ton on legal fees.

Re: Samsung Recent Security Incident

#46
I feel stupid for ever giving Samsung this much info to begin with. But oh, they had such compelling reasons to do it. Like trading in my old phone to get a deep discount on a new one directly from Samsung, and bypassing all the carrier bullshit! Or locking down all of my devices, so that someone who steals my phone can't factory reset it without supplying my Samsung account credentials!

Re: Samsung Recent Security Incident

#48
post #39

Oh, Samsung. I just went through the most insane account recovery process I've ever seen. Tried to register a Samsung account, but my email was already taken. Guess I must have had an account at some point. If you forget your password, you have to provide your name and date of birth to reset it. If you fail to enter the correct details many times, which I somehow did, eventually they will send you the recovery email…

I've got a fairly common Gmail address as my primary.

I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states.

I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email.

Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account).

Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address.

Post reply on HN