Live data from Hacker News

Samsung Recent Security Incident

samsung.com

121–130 of 172 posts

Re: Samsung Recent Security Incident

#122

Earlier quoted context omitted.

Several bank loans and store cards were taken out in my name using only my name, address and date of birth, in the UK. The same cynical business logic applies the world over: it's cheaper to clean up after the inevitable fraud than to implement proper identity checks. This calculus is of course aided by the fact that the detection of the fraud and the organising of the cleanup is taken care of entirely by the victim.…

The fact that the UK has this nasty concept of “credit history” helps with this, since now all that’s needed to take out credit is basic details to lookup the credit bureau profile and then they “vouch” for you. In countries where this doesn’t exist, obtaining credit requires providing proof of income (payslip, etc) to the lender which they verify. A mere name/address/date of birth might be enough to open inconsequen…

You’d have to see it to believe it how easy and normal credit is over here in USA. Even coming from uk it surprised me. You can even buy tyres on tick.

That only works because of low friction lending.

Re: Samsung Recent Security Incident

#123
post #27

Luckily I gave all fake information to Samsung. Because I expected this to happen.

From a post above: > your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software version, MNC, subscription information, and randomized, non-persistent and resettabl…

I beg to differ. I am using a Galaxy S8+, I've used it for years. I have never received any emails from Samsung. I never used the Samsung apps. Having never signed up for an account it is therefore unsurprising that I have not received an email from Samsung.

If they have collected any information from me, I never authorized the collection.

Re: Samsung Recent Security Incident

#124
post #92

Earlier quoted context omitted.

> That's all you need to steal someone's identity I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are. What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent t…

You could take someone's identity details and use them to get a death certificate made. This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead. Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."

If someone does that- creates a fake 'death certificate' in my name via publicly accessible information and it actually goes through, how do you even go about trying to fix that? is this even fixable?

Re: Samsung Recent Security Incident

#125

Earlier quoted context omitted.

I don't even know why I got an email from them to my work email. AFAIK I've never used a samsung device at work and I have dedicated work devices.

Discount maybe? I got one to my work address because I signed up for discounts through my employer.

Right, my almost bricked "smart" TV had a nice discount

Re: Samsung Recent Security Incident

#126

Earlier quoted context omitted.

When I saw this thread I went and checked my inbox to see if I had received an email telling me I was caught by this breach. I haven't, but what I do have are like five emails from my carrier in the last two weeks desperately trying to get me to upgrade to the latest Samsung phone. I have a Samsung from three years ago. I don't want to upgrade or replace it until it actually breaks, as constantly upgrading phones str…

Many of the Samsung devices can be rooted. Example: https://forum.xda-developers.com/t/samsung-galaxy-s8-root-sn... The forum itself is a good place to start looking.

I've had the opposite experience. S8, S9 Plus, S22+, all of them for some reason cannot unlock the bootloader.

At this point I would recommend a Pixel of any variety. It's much much simpler to root and get GrapheneOS installed. Save yourself the headache (and the data leaks).

Re: Samsung Recent Security Incident

#127
post #116

Earlier quoted context omitted.

Roku does this too. > "Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way…

This is insane. I can't even imagine being at the meeting where this was proposed "Advertisers want to know when their ads are being viewed" - "We could work with advertisers to have them add some metadata to the output signal, and detect that on the client" "Nah, let's just record everything everyone watches, that way we can harvest the data and sell it to advertisers we haven't yet partnered with in the future" - "…

I can't believe they thought they needed multiple 4K screenshots every second. What a waste of bandwidth!

Re: Samsung Recent Security Incident

#129

Earlier quoted context omitted.

I don't spend much of my time worrying about this, but if you do: Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.) Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard targ…

> Plant your flag with any large government entities that are used for collecting benefits What does this mean?

Sillystuff answered correctly.

Re: Samsung Recent Security Incident

#130
post #4

> but in some cases, may have affected information such as name, contact and demographic information, date of birth, and That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason. If we wanted to hammer out a quick and effective privacy legislatio…

This is a game of whack-a-mole, and no amount of regulation will help if the fundamental identity is founded up on bits of information like this. We should pass regulation for verification of identity using secure means, not giving out SSN + Birthday and call it a day.

This is making the problem worse I think.

Post reply on HN