Live data from Hacker News

Samsung Recent Security Incident

samsung.com

131–140 of 172 posts

Re: Samsung Recent Security Incident

#131
post #116

Earlier quoted context omitted.

This is insane. I can't even imagine being at the meeting where this was proposed "Advertisers want to know when their ads are being viewed" - "We could work with advertisers to have them add some metadata to the output signal, and detect that on the client" "Nah, let's just record everything everyone watches, that way we can harvest the data and sell it to advertisers we haven't yet partnered with in the future" - "…

I can't believe they thought they needed multiple 4K screenshots every second. What a waste of bandwidth!

AFAIK most such systems take greyscale screenshots, downsample them to basically not much more than a thumbnail, and compresses that with a lossy algorithm.

Still though, people watch home video of their kids on their televisions! Some people make home-made porn for their own enjoyment.

Meanwhile somewhere in a data centre in South Korea...

Re: Samsung Recent Security Incident

#132

Just here to remind everyone that Samsung televisions take screenshots at regular intervals of what you watch and sends this to be stored with the same level of “security”.

There doesn't seem any kind of smart device that's actually trust worthy. I have an LG TV that I rooted using a vuln in the browser, I got ad-free YouTube, and supposedly less telemetry, but other than that I'm not sure there is a Better option.

I just have an Apple TV hooked up to a Sony TV that's not connected to the internet.

Re: Samsung Recent Security Incident

#133
post #18

Earlier quoted context omitted.

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

There was a push a while back to call it bank fraud. Because the banks are the victims and should be responsible to protect/insure themselves. By calling it identity theft, we are saying individuals are the victims and should protect the banks from someone pretending to be them. Edit: I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be t…

> I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be treated as libel.

This is interesting - do you know if it has ever been tested?

Re: Samsung Recent Security Incident

#134
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

Mitchell and Webb on identify theft

https://m.youtube.com/watch?v=-c57WKxeELY

Re: Samsung Recent Security Incident

#135

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

Semantics. Nobody thinks your password being stolen means someone actually takes it from you or your device getting hacked means someone inflicted a physical blow with a sharp object. Someone illegitimately uses your personal information to claim your identity in recipt of goods and services. They stole your identification information to impersonate you.

"Semantics" is an extremely lazy way to dismiss an argument. Semantics is all that really matters in communication: what is the meaning of what is said?

There is more than a trivial semantic difference between "identity theft" and "bank fraud". The former very clearly identifies the victim as being the individual whose data was used, while the latter makes the victim the bank. There's a compelling argument to be made that it's unreasonable to expect any of the information that we have come to associate with "identity theft" to actually be private any more after repeated data leaks by Equifax et al. And if we cannot expect it to be private, is it fair to drag individuals through hell and back when someone successfully defrauds a bank using their details? That's the question being posed by OP, and the semantics of the terms we use are central to resolving it.

Re: Samsung Recent Security Incident

#136
post #133

Earlier quoted context omitted.

There was a push a while back to call it bank fraud. Because the banks are the victims and should be responsible to protect/insure themselves. By calling it identity theft, we are saying individuals are the victims and should protect the banks from someone pretending to be them. Edit: I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be t…

> I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be treated as libel. This is interesting - do you know if it has ever been tested?

I’d donate to gofundme for the legal costs next time it comes up…

Re: Samsung Recent Security Incident

#137
as a Chinese dissident, if CCP got the leaked data and tracked to my identity via my Samsung device and account information. I may be put into CCP's jail for my internet speech.

Samsung , your carelessness put many lives in danger!!

Re: Samsung Recent Security Incident

#138
Tldr: whilst this incident is absolutely inappropriate; the big business behaviour will not change until users, too, recognise their accountability and responsibility. You purchased that product, accepted it’s usage terms, and supported this behaviour. Accept “some” responsibility in this outcome.

In regards to this security incident; users accepted the terms and conditions, which includes (usually in detail, or lack there of) their handling of the outcome, and impact to you.

It’s a horrible situation. Im not saying it’s acceptable. however; I demonstrate so by not supporting (advocating, purchasing, etc) and accepting these outrageous terms.

This is not isolated to Samsung…

Our home is (wherever possible) a “Samsung” free zone, primarily inspired by their handling of the health incidents in their South Korean factories. Workers sick and dying, directly linked to the workplace.

After years of persistent pressure from the families of these workers, the outcome was a payout and a typical “sorry we got caught” announcement.

There has also been ongoing large-scale corruption in the head/leaders of the organisation, tied closely to South Korea in it’s entirety. It seems the outcome here is; “you’re really bad, but also really good… we’ll meet somewhere in the middle..”.

Ps; am aware that Samsung parts are often included with other brand solutions. Hence “mostly” above. I proactively investigate, and avoid at all costs.

Re: Samsung Recent Security Incident

#139
post #54
post #48

Earlier quoted context omitted.

I've got a fairly common Gmail address as my primary. I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states. I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email. Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to…

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

What should be illegal is companies accepting an email address without verification. My email is my identity. It should be impossible to sign up with an email that you don't have access to.

Re: Samsung Recent Security Incident

#140
post #92

Earlier quoted context omitted.

You could take someone's identity details and use them to get a death certificate made. This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead. Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."

Undeading yourself in some societies ain’t trivial either. In others it’s nigh on impossible. India has/had a loophole that scammers use to declare someone dead and steal their property.

See: Uttar Pradesh Association of Dead People

https://en.wikipedia.org/wiki/Uttar_Pradesh_Association_of_D...

Post reply on HN