Live data from Hacker News

Samsung Recent Security Incident

samsung.com

81–90 of 172 posts

Re: Samsung Recent Security Incident

#82
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR. TL;DR : If it is or it is tied to PII (personally identifiable information) you have to: (a) Justify collecting it in the first place (b) Justify s…

The GDPR has a massive enforcement problem though, so in practice, you have little recourse if a company breaches it and misuses your personal information.

Re: Samsung Recent Security Incident

#83

Other companies keep the lid on when it happens to them. Samsung has the decency to inform you quickly and clearly, gotta give them that.

No, I won't give them anything. They don't need to take this information. They shouldn't have it. I think they and everyone else collecting data should be held far more accountable than they are for the damage they do when that data leaks.

Re: Samsung Recent Security Incident

#84
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

That info is generally already public and easily accessible. Try googling yourself or a relative. You can find their date of birth, address, phone numbers, and neighbors in a couple of minutes.

Re: Samsung Recent Security Incident

#85
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity

I have this information for many billionaires. Now tell me how to steal their identity. I would like to live their life.

Re: Samsung Recent Security Incident

#86
post #54
post #48

Earlier quoted context omitted.

I've got a fairly common Gmail address as my primary. I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states. I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email. Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to…

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

[deleted]

Re: Samsung Recent Security Incident

#87

> may have affected information such as name, contact and demographic information, date of birth, and product registration information. No. No matter how safe of how carefully you take your security, a vendor should NOT keep these pieces of my private information with them.

Most of that info is already public and easily searchable. There are data brokers that gather public records (like real estate) and resell them to marketers, sales people, other data brokers, etc. It's an enormous business. Privacy is, sadly, an illusion.

Re: Samsung Recent Security Incident

#88
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

I think it's way more common in USA than in europe because here you can't just phone a bank and open an account with your tax agency code. Normally the first time you need to go and show your id.

Re: Samsung Recent Security Incident

#89
post #7

Earlier quoted context omitted.

In Sweden, this information is public.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

In slovenia, you have your name, surname and date of birth, but also unique citizen number (EMŠO) and your personal tax number.

They tell you not to tell anyone your EMŠO... but EMŠO is generated from your date of birth, gender, former yugoslav republic you were born in (slovenia=50) and the sequental number of your birth that day (0-499 boys, 500-999 girls)... plus a checksum. So if you were born in slovenia, are a boy, and were a third boy born on 20th december 1970 (970... because why waste numbers?!?!), your emšo would be 201297050003K (K=checksum, too lazy to calculate).

We also have a tax number, that they also tell you not to share... but then you open up an independent contractor business (technically, it's a not a seprate company, but "you" are the company), and your personal tax number is published in many many online systems, info pages, you have to put it on receipts, ads, you have to tell it when you're buying toilet paper for work use, etc.

But yeah... if you want to open a bank account, you need a government issued id card (or passport), and they check it very very throughly.

Re: Samsung Recent Security Incident

#90
post #18

Earlier quoted context omitted.

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

If a bank allows someone to open up a bank account with personal details that don't really belong to them, I'd call that fraud and a failure on the banks side. "Stealing someone's identity" sounds like I could and should have been able to prevent that, rather than putting the blame on the bank who accepted false personal details in the first place. As I said, those details, including address and more, are public in s…

Rather than just banks, you can say it is also a systemic problem if the details like ssn is such an important number yet it is so easily obtained.

There is a reason why the majority of these frauds are US based

Post reply on HN