Live data from Hacker News

Samsung Recent Security Incident

samsung.com

141–150 of 172 posts

Re: Samsung Recent Security Incident

#141
post #92

Earlier quoted context omitted.

You could take someone's identity details and use them to get a death certificate made. This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead. Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."

Undeading yourself in some societies ain’t trivial either. In others it’s nigh on impossible. India has/had a loophole that scammers use to declare someone dead and steal their property.

Source? With biometric identity system Aadhaar and 2FA auth for everything I find this hard to believe.

Re: Samsung Recent Security Incident

#142
post #88

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

I think it's way more common in USA than in europe because here you can't just phone a bank and open an account with your tax agency code. Normally the first time you need to go and show your id.

SSN is certainly not enough. I just recently opened 4 accounts with US banks remotely. All four requested to send them pictures of both sides of my ID card + my selfie holding said ID card. And there were additional steps to confirm my identity before activating the accounts.

Re: Samsung Recent Security Incident

#143

Just here to remind everyone that Samsung televisions take screenshots at regular intervals of what you watch and sends this to be stored with the same level of “security”.

There doesn't seem any kind of smart device that's actually trust worthy. I have an LG TV that I rooted using a vuln in the browser, I got ad-free YouTube, and supposedly less telemetry, but other than that I'm not sure there is a Better option.

I believe the keyword is "public display". The screens they install in shops and other places come without the "smart" bits and are optimised towards surviving an always-on cycle in suboptimal conditions. They're also significantly more expensive than smart tvs.

Re: Samsung Recent Security Incident

#144

Earlier quoted context omitted.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

Several bank loans and store cards were taken out in my name using only my name, address and date of birth, in the UK. The same cynical business logic applies the world over: it's cheaper to clean up after the inevitable fraud than to implement proper identity checks. This calculus is of course aided by the fact that the detection of the fraud and the organising of the cleanup is taken care of entirely by the victim.…

Lenders are "encouraged" to check the password. In your experience, how frequently do they do so?

Re: Samsung Recent Security Incident

#145
post #18

Earlier quoted context omitted.

> I wish we could stop propagating the idea that it's possible to "steal someone's identity" Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality. It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data

If a bank allows someone to open up a bank account with personal details that don't really belong to them, I'd call that fraud and a failure on the banks side. "Stealing someone's identity" sounds like I could and should have been able to prevent that, rather than putting the blame on the bank who accepted false personal details in the first place. As I said, those details, including address and more, are public in s…

Unless the thief gets their hands on my ID and personal ID number (similar to social security), they're not getting there.

Now if they do that, changing in particular the latter is rather hard.

Re: Samsung Recent Security Incident

#146

Just here to remind everyone that Samsung televisions take screenshots at regular intervals of what you watch and sends this to be stored with the same level of “security”.

There doesn't seem any kind of smart device that's actually trust worthy. I have an LG TV that I rooted using a vuln in the browser, I got ad-free YouTube, and supposedly less telemetry, but other than that I'm not sure there is a Better option.

I was able to avoid the 'smart' TV crap by just buying a 60" LCD panel and hooking it up to my htpc. It was quite cheap too, about $600.

The tricky part is finding the places that sell them.

Re: Samsung Recent Security Incident

#147
post #124
post #92

Earlier quoted context omitted.

You could take someone's identity details and use them to get a death certificate made. This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead. Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."

If someone does that- creates a fake 'death certificate' in my name via publicly accessible information and it actually goes through, how do you even go about trying to fix that? is this even fixable?

Here in Poland they would need that person's ID number and a fake signature plus data of an accredited doctor.

(Both of which is easiest done by compromising a doctor fully. They have access to ID database.)

Re: Samsung Recent Security Incident

#148

Earlier quoted context omitted.

I have the feeling this is mostly a US thing, where a social security card with almost nil personal data is widely used for identification. In Europe you won't get very far with a birthday and a name - and you certainly won't get a credit card or anything close to it.

In slovenia, you have your name, surname and date of birth, but also unique citizen number (EMŠO) and your personal tax number. They tell you not to tell anyone your EMŠO... but EMŠO is generated from your date of birth, gender, former yugoslav republic you were born in (slovenia=50) and the sequental number of your birth that day (0-499 boys, 500-999 girls)... plus a checksum. So if you were born in slovenia, are a…

Polish PESEL has the same problem of only having 5 numbers per day, one of which is also checksum so limited.

Tax number NIP is relatively public, any relevant accountant will have it.

The remaining secret thing is indeed the ID card and/or the passport. That's why if it ever gets lost or stolen you're supposed to immediately file for a replacement. Theoretically at that point someone might impersonate you.

Re: Samsung Recent Security Incident

#149
post #88

Earlier quoted context omitted.

I think it's way more common in USA than in europe because here you can't just phone a bank and open an account with your tax agency code. Normally the first time you need to go and show your id.

SSN is certainly not enough. I just recently opened 4 accounts with US banks remotely. All four requested to send them pictures of both sides of my ID card + my selfie holding said ID card. And there were additional steps to confirm my identity before activating the accounts.

All of this thanks to KYC anti money laundering regulation.

Re: Samsung Recent Security Incident

#150

Earlier quoted context omitted.

> If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR. TL;DR : If it is or it is tied to PII (personally identifiable information) you have to: (a) Justify collecting it in the first place (b) Justify s…

The GDPR has a massive enforcement problem though, so in practice, you have little recourse if a company breaches it and misuses your personal information.

Oh, here it's easy enough, you can report misuse or breach of the related Polish RODO to the Office of Personal Data Protection.

They even at times busted telemarketers using databases, much less something grave like this.

Of course you better have a good description and consider that bureaucracy moves at the speed of bureaucracy, somewhere between a snail and a plant.

Post reply on HN