Live data from Hacker News

Samsung Recent Security Incident

samsung.com

151–160 of 172 posts

Re: Samsung Recent Security Incident

#151

Earlier quoted context omitted.

> If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR. TL;DR : If it is or it is tied to PII (personally identifiable information) you have to: (a) Justify collecting it in the first place (b) Justify s…

You somehow forgot to mention that most (probably all) EU countries have laws that require you to know the birthdays of your customers - that of course overrides GDPR, or more precisely, the law is the reason to store the information so there's no need to find other reasons. Also, don't forget that these laws also have requirements on you keeping logs, most of the time 3, 5 or more years. So yeah you have to obey a d…

> You somehow forgot to mention that most (probably all) EU countries have laws that require you to know the birthdays of your customers

That is simply not true, not in this very general formulation. What businesses does this statement of yours apply to?

It's certainly not common for an ecommerce site to ask for your birthday on signup.

Re: Samsung Recent Security Incident

#152
post #151

Earlier quoted context omitted.

You somehow forgot to mention that most (probably all) EU countries have laws that require you to know the birthdays of your customers - that of course overrides GDPR, or more precisely, the law is the reason to store the information so there's no need to find other reasons. Also, don't forget that these laws also have requirements on you keeping logs, most of the time 3, 5 or more years. So yeah you have to obey a d…

> You somehow forgot to mention that most (probably all) EU countries have laws that require you to know the birthdays of your customers That is simply not true, not in this very general formulation. What businesses does this statement of yours apply to? It's certainly not common for an ecommerce site to ask for your birthday on signup.

Any online service thanks to DSA, for example: Anything that children might use (yes, so everything - intent doesn't count). Anything where users can upload content (writing comments is enough according to our lawyer).

You picked about the only remaining thing where it's not always a requirement. It's a requirement even there if the transaction is over certain threshold (varies by local law, usually around 10k EUR) or certain categories of items (drugs, alcohol, tobacco-related, sextoys, weapons etc).

Re: Samsung Recent Security Incident

#153

Earlier quoted context omitted.

The GDPR has a massive enforcement problem though, so in practice, you have little recourse if a company breaches it and misuses your personal information.

Oh, here it's easy enough, you can report misuse or breach of the related Polish RODO to the Office of Personal Data Protection. They even at times busted telemarketers using databases, much less something grave like this. Of course you better have a good description and consider that bureaucracy moves at the speed of bureaucracy, somewhere between a snail and a plant.

You can report it sure, but does anyone actually follow up on those reports with penalties high enough to deter such behavior? At least in the UK, the answer is definitely no. Our DPA is absolutely useless and may as well not exist.

Re: Samsung Recent Security Incident

#154
post #54

Earlier quoted context omitted.

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

What should be illegal is companies accepting an email address without verification. My email is my identity. It should be impossible to sign up with an email that you don't have access to.

And email verification has been around forever too! Even obscure forums have it. It's wild to think there's still companies out there allowing account creation without email verification.

Re: Samsung Recent Security Incident

#155

Earlier quoted context omitted.

Semantics. Nobody thinks your password being stolen means someone actually takes it from you or your device getting hacked means someone inflicted a physical blow with a sharp object. Someone illegitimately uses your personal information to claim your identity in recipt of goods and services. They stole your identification information to impersonate you.

"Semantics" is an extremely lazy way to dismiss an argument. Semantics is all that really matters in communication: what is the meaning of what is said? There is more than a trivial semantic difference between "identity theft" and "bank fraud". The former very clearly identifies the victim as being the individual whose data was used, while the latter makes the victim the bank. There's a compelling argument to be made…

You're flubbing the scope of the argument. The second definiton of steal in Webster's is to appropriate (e. g. credit) without permission. Identity theft is when someone appropriates someone else's identifying information, without permission, to impersonate them in a transaction or contract. Full stop. There's no qualification that the appropriated thing must be secret or that it was suited to its its purpose. If you think that the term is misapplied to other financial crimes, that's an entirely different argument, and it doesn't render the actual term a misnomer.

Re: Samsung Recent Security Incident

#156

Earlier quoted context omitted.

"Semantics" is an extremely lazy way to dismiss an argument. Semantics is all that really matters in communication: what is the meaning of what is said? There is more than a trivial semantic difference between "identity theft" and "bank fraud". The former very clearly identifies the victim as being the individual whose data was used, while the latter makes the victim the bank. There's a compelling argument to be made…

You're flubbing the scope of the argument. The second definiton of steal in Webster's is to appropriate (e. g. credit) without permission. Identity theft is when someone appropriates someone else's identifying information, without permission, to impersonate them in a transaction or contract. Full stop. There's no qualification that the appropriated thing must be secret or that it was suited to its its purpose. If you…

I'm not, this is where OP scoped it to. OP is arguing that "identity theft" shouldn't be applied to any kind of crime, because stealing an identity isn't actually possible. What is possible is legally persuading a bank that you are someone else.

Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's using publicly available information to trick gullible banks.

Re: Samsung Recent Security Incident

#157
post #54

Earlier quoted context omitted.

>Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account). >Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address. This is illegal, CFAA of 1996. Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is i…

It's not illegal per cfaa, the individual who signed up did not own the email or have a reasonable/any entitlement to it. Above poster deleting the account is accessed through fully legal and intended means by service provider. The law would treat poster's deletion as fraud protection, which arguably it is. That data you claim its not theirs isn't true.

It is very illegal per CFAA, there is already precedent for this. Here is one such case that is popular in case law curriculum. [0]

https://casetext.com/case/united-states-v-auernheimer-3

Re: Samsung Recent Security Incident

#158
Samsung's disclosure doesn't meet statutory requirements of either jurisdiction I reside in, and Samsung's collection of my information doesn't meet statutory requirements in one of them. I did not set up a Samsung account on my phone or log in, despite constant harassment, and now I got a notice saying my information was compromised.

Re: Samsung Recent Security Incident

#159

Earlier quoted context omitted.

You're flubbing the scope of the argument. The second definiton of steal in Webster's is to appropriate (e. g. credit) without permission. Identity theft is when someone appropriates someone else's identifying information, without permission, to impersonate them in a transaction or contract. Full stop. There's no qualification that the appropriated thing must be secret or that it was suited to its its purpose. If you…

I'm not, this is where OP scoped it to. OP is arguing that "identity theft" shouldn't be applied to any kind of crime, because stealing an identity isn't actually possible. What is possible is legally persuading a bank that you are someone else. Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's usin…

Identity:

identity, n. 4. "the state or fact of being the same one as described."

Those companies aren't trying to verify that information for its intrinsic suitability, and their goal isn't to facilitate a transaction with someone who merely has all of someone else's personal information- they're trying to make sure the person engaging in that transaction is the person indicated on the form. If they switched to say, a finger print, voice sample, DNA, and an in-person interview with an ID check, they would still be trying to validate your identity.

> stealing an identity isn't actually possible. What is possible is legally persuading a bank that you are someone else.

That's like saying murdering someone with a gun is incredibly difficult because unless you actually beat them to death with the gun itself, you're just aiming and pulling a trigger, which isn't even illegal in many cases.

Theft:

steal, v. 2. "to appropriate (ideas, credit, words, etc.) without right or acknowledgment,"

Appropriating your identity for the duration of a transaction certainly fits.

> Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's using publicly available information to trick gullible banks.

Nothing in that definition requires the thing in question was suitably protected or appropriate for the job. Nothing requires that it be permanently stolen or that anything be removed from anyone's possession.

---

I agree that the data and mechanisms used are not up to the task, but only using arbitrary definitions of theft and identity and looking at the mechanisms of theft while ignoring the purpose of those mechanisms doesn't mean the term is wrong or that people aren't, by definition, stealing people's identities. You don't get to decide that people can't use specific, existing dictionary definitions to evaluate whether a term makes sense. And that's just from a technical perspective-- English is a descriptive language and terms mean what popular usage dictates they mean.

So unless you have some convincing arguments that nothing, by any definition, was stolen, that personal data wasn't being used to determine identity, and that the colloquial usage of the term doesn't actually matter, then identity theft is undeniably the correct term. The heistiness of the acts, other non-applicable definitions of the words, and the suitability of the methods of verifying identity are entirely irrelevant.

Re: Samsung Recent Security Incident

#160
post #157

Earlier quoted context omitted.

It's not illegal per cfaa, the individual who signed up did not own the email or have a reasonable/any entitlement to it. Above poster deleting the account is accessed through fully legal and intended means by service provider. The law would treat poster's deletion as fraud protection, which arguably it is. That data you claim its not theirs isn't true.

It is very illegal per CFAA, there is already precedent for this. Here is one such case that is popular in case law curriculum. [0] https://casetext.com/case/united-states-v-auernheimer-3

Which part of Auernheimer do you think applies here, setting aside the fact it was overturned on appeal for improper venue?
Post reply on HN