Live data from Hacker News

Samsung Recent Security Incident

samsung.com

91–100 of 172 posts

Re: Samsung Recent Security Incident

#91
post #72

California residents can request their data to be deleted here: https://www.samsung.com/us/privacy/ccpa/ I was surprised I even had a Samsung account so I can't think of any reason to keep one after this.

I received this email to a CCPA "removed" email address.

Re: Samsung Recent Security Incident

#92
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

You could take someone's identity details and use them to get a death certificate made.

This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead.

Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."

Re: Samsung Recent Security Incident

#93
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

Semantics. Nobody thinks your password being stolen means someone actually takes it from you or your device getting hacked means someone inflicted a physical blow with a sharp object. Someone illegitimately uses your personal information to claim your identity in recipt of goods and services. They stole your identification information to impersonate you.

Re: Samsung Recent Security Incident

#94

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

Semantics. Nobody thinks your password being stolen means someone actually takes it from you or your device getting hacked means someone inflicted a physical blow with a sharp object. Someone illegitimately uses your personal information to claim your identity in recipt of goods and services. They stole your identification information to impersonate you.

And framing. "Identity theft" makes it sounds like you lost something. In reality, it's the financial institution that lost something.

Re: Samsung Recent Security Incident

#95
post #63
post #54

Earlier quoted context omitted.

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

It wouldn’t also fall under CFAA to fraudulently sign up with the wrong email?

Fraud has intent as a component. If it was an honest mistake and no fraud was intended, the sign-ups was an error but not a crime.

Same if you were confused by "your" Roku account, so you decide to remove it.

Re: Samsung Recent Security Incident

#96
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

I don't spend much of my time worrying about this, but if you do: Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.) Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard targ…

> Plant your flag with any large government entities that are used for collecting benefits

What does this mean?

Re: Samsung Recent Security Incident

#97
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

I don't spend much of my time worrying about this, but if you do: Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.) Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard targ…

There are _a lot_ of credit reporting agencies to place freezes with. I put freezes at several credit reporting agencies. It took quite a bit of time to work through a small subset of this list:

https://www.consumerlawfirm.com/credit-reporting-agencies.ht...

'Nationwide', 'Check and Bank' and 'Supplimentary/Alternative' are probably the minimum.

I wish we had privacy and security by default instead of "opt in"

Re: Samsung Recent Security Incident

#98
post #44

>At Samsung, security is a top priority. Every company, always.

> At Firefighters, firefighting is our top priority. We recently discovered that our base of operations caught fire and, as the fire hydrants and fire extinguishers did not work, it was incinerated. An absurd, insane message.

> Why did firefighters have my stuff?

We know your stuff not catching on fire is important to you. That’s why we gather it up into large fpiles, then do the minimal we’re legally required to technically avoid committing arson. For more information on how we and our trusted partners douse our pile of your stuff with gasoline while using our warehouses to hotbox cigars, weed and crack, see our 1000 page “not stealing and then getting high and catching your stuff on fire policy”.

Re: Samsung Recent Security Incident

#99

Earlier quoted context omitted.

I don't spend much of my time worrying about this, but if you do: Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.) Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard targ…

> Plant your flag with any large government entities that are used for collecting benefits What does this mean?

I think GP means create your account on these sites before a fraudster does it for you. I.e., if you already have an account, they need your login credentials to access your account. But, if you have not established an account, they can often establish a new account using nothing but publicly available data like your birthday and street address for identity verification, then access your data (IRS experienced a lot of fraudulent accounts being created to steal peoples' tax refunds; their new verification system is less susceptible, but IMO too invasive [biometric data]).

Re: Samsung Recent Security Incident

#100
post #72

California residents can request their data to be deleted here: https://www.samsung.com/us/privacy/ccpa/ I was surprised I even had a Samsung account so I can't think of any reason to keep one after this.

Mine was linked to my college email. I have no idea how that got linked as I have been out of school for more than 20 years. I may have used it to get a "student" discount at some point in the recent past but who knows?
Post reply on HN