Live data from Hacker News

Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

abc.net.au

91–100 of 169 posts

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#91

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#92

Earlier quoted context omitted.

> very common Are there statistics on this somewhere?

ALPRs are everywhere these days. "Very common" is probably understatement in this situation.

>"Very common" is probably understatement in this situation.

"very common" has no standard meaning, so the statement is meaningless either way.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#93
post #39

If she was compromised by credential stuffing at PayPal, I have to say I'm disappointed. I actually wrote the anti-credential-stuffing code 20 years ago. It was one of the core component of PayPal security. We were one of the first sites to get those kinds of attacks so we got good at stopping them. I would be sad if that skillset had been lost.

If Paypal required non-sms based 2FA on all logins, would that help stop the issue?

Paypal had it, then removed it, then added it again recently.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#94
post #42
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

It’s entirely possible to do this digitally and have it working seamlessly. In Denmark we have a thing called “MitID” (MyID) which is basically a government login and which you can use to sign and also login to all kinds of things that need to confirm your identity (e.g. Phone subscription, taxes, 3DS verification for Credit Card transactions, etc). It’s essentially 2FA, works by the site sending a confirmation to an…

And then...your govt login is stolen and you are back to square one with "identity theft".

National ID systems are such nonsense it is appalling there are people stupid enough to think this is a Good Thing.

Easy is NOT always better. The best things in life are definitely not free.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#95

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

Classic skit on identity theft by Mitchell & Webb https://www.youtube.com/watch?v=CS9ptA3Ya9E

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#96
post #53
post #42

Earlier quoted context omitted.

It’s entirely possible to do this digitally and have it working seamlessly. In Denmark we have a thing called “MitID” (MyID) which is basically a government login and which you can use to sign and also login to all kinds of things that need to confirm your identity (e.g. Phone subscription, taxes, 3DS verification for Credit Card transactions, etc). It’s essentially 2FA, works by the site sending a confirmation to an…

That's the thing I don't understand about people who live in the USA and their absolute hatred towards a National ID system. It would be a political nightmare for them to even suggest anything like that. Even their "new" FedNow service is being as governmental overreach for "reasons".

Most non-it people I know who are opposed to FedNow are the kinds of folks who get a lot of 'gifts' that they conveniently get around reporting, alongside a CPA they always owe favors to.

I am against government overreach yet these people really seem to want to change my mind.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#97
post #79

Earlier quoted context omitted.

Cop oversight stats largely don’t exist because it would challenge their authority

Isn't that basically conspiracy theory logic? ie. "This thing is totally true! Evidence? That doesn't exist because The Powers That Be are suppressing it!"

No, you’re just uninformed and eager to trust power. Asking for cop stats as prerequisite to critique is a pledge to their supremacy

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#98

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

> I would be interested in learning if this problem exists in other countries

In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you.

This in turn can help a bit because it results in most attempts at making loans in your name not being possible.

https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv...

There are four companies in Norway that do credit assessments. You have to individually register your desire to not allow credit assessments for your name with all four of these.

https://tfinans.no/blogg/frivillig-kredittsperre

But then, what protects you against someone simply requesting that your credit is unlocked and then taking loans in your name after all? Well, from what I gather one would have to use BankID to confirm that credit is to be unlocked.

So even if someone steals my passport, they will not immediately be able to unlock my credit. They’d have to jump through a bunch of hoops to also steal my BankID.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#99
post #79

Earlier quoted context omitted.

Isn't that basically conspiracy theory logic? ie. "This thing is totally true! Evidence? That doesn't exist because The Powers That Be are suppressing it!"

There have been a series of US Supreme Court decisions that allow local law enforcement and prosecutors to a.) not have to reveal any statistics on crime and race b.) enormous discretion on powers to stop and arrest such that law enforcement can give conflicting reasons for each action, i.e. this person was suspicious because they were driving too fast, this person was driving too closely to speed limit and every var…

None of that tells us anything about whether something is "very common". In fact, as I mentioned in another comment, "very common" isn't even defined and is purely subjective. If there was some medical condition that affects 1000 people in the entire country, I doubt many would call it "very common". The same applies for most other things. A collectible where only 1000 exists in the entire country wouldn't exactly be called "very common". However, "police shootings being common" isn't exactly a rare sentiment despite also occurring approximately 1000 times per year[1]. Obviously this isn't to say that 1000 police shootings per year is fine because that's on the same magnitude as rare diseases, but the phrase "very common" is clearly in the eye of the beholder. In the context of police shootings or people being brutalized, when people say "very common" they're not actually saying it's "very common", they're actually saying "it's unacceptably high", which is an entirely different statement.

Or maybe I'm too sheltered living in my gated community or whatever, and this is actually "very common" in the usual colloquial definition. Feel free to prove me wrong.

[1] https://www.washingtonpost.com/graphics/investigations/polic...

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#100

Earlier quoted context omitted.

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

Interesting. This should be adopted by the EU. (I know Norway is not a member state but this makes good sense and that's why I would love to see the EU to adopt it.)
Post reply on HN