Live data from Hacker News

Samsung Recent Security Incident

samsung.com

51–60 of 172 posts

Re: Samsung Recent Security Incident

#51

"...and have engaged a leading outside cybersecurity firm and are coordinating with law enforcement." Sounds like "we got ransomeware'd".

The whole paragraph suggests it more strongly. Specifically why would you say "affected" rather than exposed / accessed?:

> FAQ: Can you tell us more about what specifically happened? In late July 2022, an unauthorized third party acquired information from some of Samsung’s U.S. systems. On or around August 4, 2022, we determined through our ongoing investigation that personal information of certain customers was affected. We have taken action to secure the affected systems, and have engaged a leading outside cybersecurity firm and are coordinating with law enforcement.

Re: Samsung Recent Security Incident

#52
post #34
post #18

Earlier quoted context omitted.

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

There’s a funny Mitchell and Webb sketch about it: https://youtu.be/CS9ptA3Ya9E

Wonderful! I will be sharing this one a lot. Thank you.

Re: Samsung Recent Security Incident

#53

Just got the email from Samsung saying I was part of the breach. At the end of this (extremely long and excuse-ridden) email they inform me that I'm entitled to a free credit check every year from credit reporting agencies. Can't we just fast forward to the part where they send me a $5 check for the class action settlement? They'd save a ton on legal fees.

I got the same.

I find it insulting to offer a credit check. If I wanted, I would get 20 credit checks just this year. Credit checks are also (mostly) free. Everyone and their mother offers them.

Why would that do me any good for checking? How does it remediate or mitigate the loss I have?

Re: Samsung Recent Security Incident

#54
post #48
post #39

Oh, Samsung. I just went through the most insane account recovery process I've ever seen. Tried to register a Samsung account, but my email was already taken. Guess I must have had an account at some point. If you forget your password, you have to provide your name and date of birth to reset it. If you fail to enter the correct details many times, which I somehow did, eventually they will send you the recovery email…

I've got a fairly common Gmail address as my primary. I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states. I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email. Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to…

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account).

>Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address.

This is illegal, CFAA of 1996.

Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is illegal.

Re: Samsung Recent Security Incident

#55
I requested to have all my info deleted by them. Let's see how long it takes.

The email for my request is towards the bottom of this page: https://www.samsung.com/us/support/securityresponsecenter/

I am aware this does not fix the problem of the already stolen data, but it might make the data collection cost/benefit analysis in favor of discarding collection all-together. Maybe. Let me dream, would you?

Re: Samsung Recent Security Incident

#56
post #54
post #48

Earlier quoted context omitted.

I've got a fairly common Gmail address as my primary. I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states. I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email. Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to…

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

Signing up for services using other people's email? Or canceling services attached to your iwn email?

Re: Samsung Recent Security Incident

#57

Just got the email from Samsung saying I was part of the breach. At the end of this (extremely long and excuse-ridden) email they inform me that I'm entitled to a free credit check every year from credit reporting agencies. Can't we just fast forward to the part where they send me a $5 check for the class action settlement? They'd save a ton on legal fees.

They are offering the free credit check provided by Uncle Sam- not even footing the bill for one of their own

Re: Samsung Recent Security Incident

#58
post #15

I love how they don't say how big the breach was, what systems were affected, or how to opt-out of them stealing your personal information and storing it on poorly secured servers: > Why does Samsung have my data? > We collect information necessary to help deliver the best experience possible with our products and services. We know how important privacy is to our customers, and we provide information about how we're…

> We collect information necessary to help deliver the best experience possible with our products and services.

When I got my first Samsung phone, it came with Samsung's keyboard installed. I looked at the privacy policy and saw that it was sending every single keypress to some third party whose privacy policy said it was used for market research and to guess at things like the education level and intelligence of the user. Who needs malware when Samsung ships keyloggers. I uninstalled it then did the same with every other Samsung app I could. They obviously don't care at all about people's privacy. On the plus side, I found some great apps that way like simple gallery pro and markor.

Re: Samsung Recent Security Incident

#59

I feel stupid for ever giving Samsung this much info to begin with. But oh, they had such compelling reasons to do it. Like trading in my old phone to get a deep discount on a new one directly from Samsung, and bypassing all the carrier bullshit! Or locking down all of my devices, so that someone who steals my phone can't factory reset it without supplying my Samsung account credentials!

When I saw this thread I went and checked my inbox to see if I had received an email telling me I was caught by this breach. I haven't, but what I do have are like five emails from my carrier in the last two weeks desperately trying to get me to upgrade to the latest Samsung phone.

I have a Samsung from three years ago. I don't want to upgrade or replace it until it actually breaks, as constantly upgrading phones strikes me as wasteful. However, when I see this shit as well as all the Samsung apps they don't let you delete or disable from your phone, I am very tempted to just splash out on a Pixel to install GrapheneOS.

Re: Samsung Recent Security Incident

#60
post #14

Earlier quoted context omitted.

Dont give it to them then,

Yes. But it is becoming increasingly difficult with "smart" or "connected" devices. Sometimes you have to fill forms to access services or agree with EULA's with abusive terms. If you disagree with the terms, you become ostracized because everybody else from your circles accepted those terms and nobody is using your open-source/decentralized/federated network or services. You can't expect common people to be reasonab…

My favorite suggestion for a nationwide privacy law is simple:

Clarify that all EULAs are null and void unless they have been reviewed with counsel, signed, and notarized to ensure the user understands what they are agreeing to.

If the companies want to treat them like contracts, so should the other party. Otherwise, it all stinks of duress.

Post reply on HN