Live data from Hacker News

Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

abc.net.au

121–130 of 169 posts

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#121

Earlier quoted context omitted.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

Interesting. This should be adopted by the EU. (I know Norway is not a member state but this makes good sense and that's why I would love to see the EU to adopt it.)

I imagine they already exist in EU states. I got one in Finland after my ID card was stolen and someone was trying to buy stuff on credit with my ID. Paid a small fee of like 10€ to get a two-year credit freeze. They also give you a certificate from it that you can use to verify that the black mark in your credit history is a voluntary block. Never actually had to use it, was a student back then and I didn't have any credit to apply to, mobile phone plans to buy, apartments to rent etc.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#122
post #39

If she was compromised by credential stuffing at PayPal, I have to say I'm disappointed. I actually wrote the anti-credential-stuffing code 20 years ago. It was one of the core component of PayPal security. We were one of the first sites to get those kinds of attacks so we got good at stopping them. I would be sad if that skillset had been lost.

If Paypal required non-sms based 2FA on all logins, would that help stop the issue?

Sure, but also it would piss off unsophisticated users and also cause a huge increase in customer service issues with people getting locked out. That why it keeps flipping between required and optional.

Way back then we would send RSA tokens to the top users to stop them from getting hacked, but since they cost $10 each and required training and setup with an agent, only top users would get them.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#123
post #92

Earlier quoted context omitted.

ALPRs are everywhere these days. "Very common" is probably understatement in this situation.

>"Very common" is probably understatement in this situation. "very common" has no standard meaning, so the statement is meaningless either way.

Yet everybody has an idea what (or how much) it means. Including you.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#124
post #61

Earlier quoted context omitted.

Jesus.. It's really bleak. It's mostly a link to this website: https://servingnotice.com/Da29d1x/index.html Apparently "Serving Notice dot com" is sufficient to say someone has been served? I downloaded the Pacer documents with Recap enabled so you should be able to see them on the CourtListener website.

>Apparently "Serving Notice dot com" is sufficient to say someone has been served? Apparently, because the judge allowed it. Looking at the relevant document[1], the reason that was allowed was that: 1. the defendant is foreign 2. "the defendants conducted their businesses over the Internet" 3. "the defendants used e-mail regularly in their businesses" 4. "the plaintiff shows e-mail is likely to reach defendants" [1]…

> 4. "the plaintiff shows e-mail is likely to reach defendants"

JFC

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#125
post #99

Earlier quoted context omitted.

None of that tells us anything about whether something is "very common". In fact, as I mentioned in another comment, "very common" isn't even defined and is purely subjective. If there was some medical condition that affects 1000 people in the entire country, I doubt many would call it "very common". The same applies for most other things. A collectible where only 1000 exists in the entire country wouldn't exactly be…

You said it's a conspiracy because it can't be proven, the Supreme Court made it impossible to prove racial discrimination by law enforcement/prosecution but said it's not OK to do it, with a wink wink. https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5614457/ African Americans make up roughly ten percent of the US population, but are incarcerated at a much higher rate for drug related offenses. Two simple possibilities…

You didn’t list option C: African Americans commit crimes other than drug possession more frequently and then drug charges are either added on, or it happens during probation.

A quick look at my county jail roster shows that a lot of the drug cases - but not all - are of that sort.

Areas with more overall crime are going to have more police officers patrolling as well.

Of course, it’s probably a bit of A, B, and C.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#126
post #44

Earlier quoted context omitted.

The politicians will probably only care when they themselves become the victims.

You can bet politicians will never feel the pain of this fraud. They are VIPs so they have a staff of assistants who "handle" these things. That and the fact that the ones that should feel the pain (banks and lenders) are campaign donors means that things will not change.

A point that supports this. Friend of mine worked for a high wealth person. One day their company website went down. Because it turned out they forgot to renew it and it was now in the hands of a squatter. When the boss asked asked to approve paying $X to the squatter to get the site back he said no. Made a phone call and the site was back up 10 minutes later.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#127

Earlier quoted context omitted.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

Interesting. This should be adopted by the EU. (I know Norway is not a member state but this makes good sense and that's why I would love to see the EU to adopt it.)

I disagree with this system, banks can instead require the exact same Auth process they'd use to unblock your "no credit" request when they want to start a new credit for anyone. Why would there be more checks to "remove block" than to "start credit"? I can think of one reason that's good for the banks.

The "locked" state should be the default, whatever extra checks they need to do to a person that has it "frozen", that should just be the default to start any credit!

If anyone has some dire need for easy credit all the time they can do the opposite and go to some "light checks" state like TSA pre-check.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#128
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

Some countries/jurisdictions do exactly that, and trust me, it's a massive pain in the ass. Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing. The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy…

> Would you really want to visit a notary just to set up an eBay account?

If that would allow me to 100% regain control of a hacked account. The answer is yes.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#129
post #106

Earlier quoted context omitted.

The bar to stealing it is way different now though. You would have to steal a username + phone + PIN code for phone + PIN code for MitID app. If that happens, then it would also be trivial to unlink the app from that phone. At no point in time would you be unaware of the theft here. Contrast this to what happens in the US often: your personal info is leaked from the plethora of places it’s kept. Someone can now in pe…

"You would have to steal a username + phone + PIN code for phone + PIN code for MitID app." And when your phone is hacked then all three are up for grabs? "Contrast this to what happens in the US often: your personal info is leaked from the plethora of places it’s kept." And yes, totally never is your govt info leaked from the plethora of places it is kept. /s The problem is not having govt information, the problem i…

> And when your phone is hacked then all three are up for grabs?

No.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#130

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

You’re right, both morally and legally. My friend a government law professor told me that in the EU you could probably even construct a pretty solid case arguing this.

The argument would be that If there is not a single slip of evidence tying you physically to the money Except your PII Then the banks anti-money laundering should have catched it. That gets their attention right away since the fines in that cases are proper billions.

If they don’t settle, you go for the kill and settle that PII is not uniquely tied to legal intent (heck, it wasn’t you! The intent is missing and that’s what you point out as well.)

The problem is that that case will take you 7+ years, all the way to the various supreme courts (local, European). It’s why Max Schrems is a hero, except banks are worse adversaries than government regulators.

This whole digital world has had some impact on our two thousand years plus of contract law. It’s sad judges don’t go back to the basics in these cases. Show me the contract (into the abyss).

Post reply on HN