Live data from Hacker News

Samsung Recent Security Incident

samsung.com

71–80 of 172 posts

Re: Samsung Recent Security Incident

#71
post #66

Earlier quoted context omitted.

I wonder what kind of information they got out of my TV. Well, obviously at least IP address. Maybe some viewing habits data. In which case they'll probably conclude I mostly like cartoons about ponies and talking, people rescuing dogs...

TV's can probably scan your local network which means at the very minimum getting MAC addresses which can tell you the manufacturer and maybe more, of various devices on your network.

It can do that all it wants, won't be able to see any other devices on my network.

Although it could scan for nearby wifi access points. Maybe also for bluetooth devices. It also got a microphone...

Business idea: A service to strip microphones and antennas out of brand new TVs?

Re: Samsung Recent Security Incident

#73
post #7

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

In Sweden, this information is public.

Which is absolutely demented.

Re: Samsung Recent Security Incident

#74
post #54

Earlier quoted context omitted.

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

What is the correct course of action one should take, e.g. if OP now wants to sign up for a Roku account with their own address and now can't?

Make a different address?

Mind you, if Roku doesn't want to do business with you, there's no correct way to trick them into it

Re: Samsung Recent Security Incident

#76
post #71

Earlier quoted context omitted.

TV's can probably scan your local network which means at the very minimum getting MAC addresses which can tell you the manufacturer and maybe more, of various devices on your network.

It can do that all it wants, won't be able to see any other devices on my network. Although it could scan for nearby wifi access points. Maybe also for bluetooth devices. It also got a microphone... Business idea: A service to strip microphones and antennas out of brand new TVs?

There is no winning via tech, only regulation.

Supposedly amazon set up an AWS service to leverage 5G (https://aws.amazon.com/private5g/) allowing significantly more devices. The idea being that our fridges, TVs and other household devices could talk directly to a private service without having to be subject to your in home firewalls/DNS blocking/etc.

Re: Samsung Recent Security Incident

#77

Earlier quoted context omitted.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

Several bank loans and store cards were taken out in my name using only my name, address and date of birth, in the UK. The same cynical business logic applies the world over: it's cheaper to clean up after the inevitable fraud than to implement proper identity checks. This calculus is of course aided by the fact that the detection of the fraud and the organising of the cleanup is taken care of entirely by the victim.…

The fact that the UK has this nasty concept of “credit history” helps with this, since now all that’s needed to take out credit is basic details to lookup the credit bureau profile and then they “vouch” for you.

In countries where this doesn’t exist, obtaining credit requires providing proof of income (payslip, etc) to the lender which they verify. A mere name/address/date of birth might be enough to open inconsequential accounts such as loyalty cards, but will absolutely not get you credit - therefore the damage to identity theft victims is greatly reduced or even nullified.

Bad payers are still penalised even without a credit bureau system by a register the government operates onto which a debtor is registered for a certain period after legal action by a lender (so this requires significant effort from the lender - you don’t get on this register because of a telecoms billing mishap for example).

With regards to setting a password, I wouldn’t trust CRAs to enforce this. What you can do however is pay for CIFAS protective registration - it’s usually for victims or those at high risk of identity theft but there’s no legal requirement so anyone can pay the admin fee and get added to the register. Lenders check this during credit applications and this puts an instant block on any kind of automated approval and requires them to do further verification.

Re: Samsung Recent Security Incident

#78

Earlier quoted context omitted.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

Several bank loans and store cards were taken out in my name using only my name, address and date of birth, in the UK. The same cynical business logic applies the world over: it's cheaper to clean up after the inevitable fraud than to implement proper identity checks. This calculus is of course aided by the fact that the detection of the fraud and the organising of the cleanup is taken care of entirely by the victim.…

[deleted]

Re: Samsung Recent Security Incident

#79
post #18

Earlier quoted context omitted.

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

There was a push a while back to call it bank fraud. Because the banks are the victims and should be responsible to protect/insure themselves. By calling it identity theft, we are saying individuals are the victims and should protect the banks from someone pretending to be them. Edit: I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be t…

[deleted]

Re: Samsung Recent Security Incident

#80
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

There needs to be better laws protecting individuals that use aliases and what not for registration. Technically, there are certain federal laws that can make doing so illegal in certain circumstances.. while not enforced at a high rate, I do see them occasionally being applied unfairly and don't like knowing that by using aliases and what not that I could be opening myself to criminal prosecutions.
Post reply on HN