Live data from Hacker News

Samsung Recent Security Incident

samsung.com

161–170 of 172 posts

Re: Samsung Recent Security Incident

#161
post #160
post #157

Earlier quoted context omitted.

It is very illegal per CFAA, there is already precedent for this. Here is one such case that is popular in case law curriculum. [0] https://casetext.com/case/united-states-v-auernheimer-3

Which part of Auernheimer do you think applies here, setting aside the fact it was overturned on appeal for improper venue?

In case law studies it is debated whether or not something that is erroneously made available to you can still be construed as fraud or theft when you take advantage of it.

Think of it like an ATM that suddenly thinks your balance is 5 quadrillion dollars, and you empty it because if their system says you have it, then it's your prerogative to appropriate those funds, according to your assertion. Unfortunately, this is not how the courts have decided this should be handled. In US v Auernheimer the question is whether publicly accessible and sequential (read: guessable) routes being accessed by those they're not intended for is criminal. The improper venue appeal has nothing to do with the essence and spirit of this segment of case law, it means that the suit was brought forward improperly. That act itself was deemed criminal, otherwise Auernheimer would have remained safely in Arkansas rather than absconding to the then-stateless Republic of Abkhazia.

Saying all of this, it is important to me that I communicate to you Ethbr0, that I'm responding objectively and not at all trying to tell you that I feel one way or the other, or that I am judging you as criminal. If that's how this was taken, I wholeheartedly apologize. You are free to do what you want, and you're granted the right to speak freely publicly. To me it doesn't seem like a good idea to say what you said, and I would not act similarly, but I will not judge you for doing what you feel is right.

Re: Samsung Recent Security Incident

#162
Does this apply to those who use Samsung devices without having made explicitly registered for an "account" with samsung.com? They must be made to reveal the extent to which keylogging and other surreptitious means of data collection are being used on their devices.

Re: Samsung Recent Security Incident

#163
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

This information is immediately available for anyone in the country, after they turn 18, via whitepages. This security via obscurity effort isn’t providing any meaningful protection.

Re: Samsung Recent Security Incident

#164
post #88

Earlier quoted context omitted.

I think it's way more common in USA than in europe because here you can't just phone a bank and open an account with your tax agency code. Normally the first time you need to go and show your id.

SSN is certainly not enough. I just recently opened 4 accounts with US banks remotely. All four requested to send them pictures of both sides of my ID card + my selfie holding said ID card. And there were additional steps to confirm my identity before activating the accounts.

Can't you easily forge that?

Re: Samsung Recent Security Incident

#165
post #161
post #160

Earlier quoted context omitted.

Which part of Auernheimer do you think applies here, setting aside the fact it was overturned on appeal for improper venue?

In case law studies it is debated whether or not something that is erroneously made available to you can still be construed as fraud or theft when you take advantage of it. Think of it like an ATM that suddenly thinks your balance is 5 quadrillion dollars, and you empty it because if their system says you have it, then it's your prerogative to appropriate those funds, according to your assertion. Unfortunately, this…

I'm honestly curious, because my reading of US v Auernheimer was that the majority of the penalties were linked with sharing the records obtained.

Which stands to reason and is in line with my understanding of the CFAA: that circumventing and breaching security is a crime, but the severe penalties kick in when one shares the results of those actions.

Re: Samsung Recent Security Incident

#166
post #35

Earlier quoted context omitted.

We don't need laws just dont buy their products. You're asking a business to change it's business practices because you don't like them. Free market.

It's becoming more and more difficult to do so. I can't remember the last time I bought a piece of electronics that didn't have a EULA. At this point, I half expect my breakfast cereal to come with a T&C.

dont buy it then. Or even better since we are on an SV incubator website create a product that doesnt need it. Big market?

Re: Samsung Recent Security Incident

#167
post #157

Earlier quoted context omitted.

It's not illegal per cfaa, the individual who signed up did not own the email or have a reasonable/any entitlement to it. Above poster deleting the account is accessed through fully legal and intended means by service provider. The law would treat poster's deletion as fraud protection, which arguably it is. That data you claim its not theirs isn't true.

It is very illegal per CFAA, there is already precedent for this. Here is one such case that is popular in case law curriculum. [0] https://casetext.com/case/united-states-v-auernheimer-3

What precedent? You linked a case where the defendant '...began to write a program that he called an “accountslurper” '. Hard disagree with your statements as protecting your identify is no where similar to maliciously accessing and manipulating data.

Re: Samsung Recent Security Incident

#168
post #133

Earlier quoted context omitted.

There was a push a while back to call it bank fraud. Because the banks are the victims and should be responsible to protect/insure themselves. By calling it identity theft, we are saying individuals are the victims and should protect the banks from someone pretending to be them. Edit: I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be t…

> I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be treated as libel. This is interesting - do you know if it has ever been tested?

I don't know, and I don't even remember where I heard it, I think it was on here but I dont know. I think maybe I was wrong about 'bank fraud' and the term being pushed was 'bank libel' instead of identity theft. Because all the negative sides of supposed 'identity theft' were from the banks saying the individual did something they did not.

Re: Samsung Recent Security Incident

#169

Earlier quoted context omitted.

Semantics. Nobody thinks your password being stolen means someone actually takes it from you or your device getting hacked means someone inflicted a physical blow with a sharp object. Someone illegitimately uses your personal information to claim your identity in recipt of goods and services. They stole your identification information to impersonate you.

And framing. "Identity theft" makes it sounds like you lost something. In reality, it's the financial institution that lost something.

If someone stole your idea, did you lose something tangible? Also, crimes generally consider cause and effect, including indirect effects if they're foreseeable. Is having to expend time, energy, and perhaps resources to protect the usage of information institutions use to identify you an unexpected side effect? Is it worth nothing?

Pretending the catalyst isn't culpable in the indirect effects of identity theft is every bit as wilfully obtuse as pretending the institutions aren't.

Re: Samsung Recent Security Incident

#170
post #165
post #161

Earlier quoted context omitted.

In case law studies it is debated whether or not something that is erroneously made available to you can still be construed as fraud or theft when you take advantage of it. Think of it like an ATM that suddenly thinks your balance is 5 quadrillion dollars, and you empty it because if their system says you have it, then it's your prerogative to appropriate those funds, according to your assertion. Unfortunately, this…

I'm honestly curious, because my reading of US v Auernheimer was that the majority of the penalties were linked with sharing the records obtained. Which stands to reason and is in line with my understanding of the CFAA: that circumventing and breaching security is a crime, but the severe penalties kick in when one shares the results of those actions.

sharing is what is known as an 'enhancement' like committing a crime vs committing it with a gun.
Post reply on HN