Live data from Hacker News

Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

abc.net.au

141–150 of 169 posts

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#141
post #4

Situations like these keep bringing me back to the idea that important actions should require an actual, in person, human notary seal. Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).

Eh, I was forced to have a notary do something and it ended up being an apparently 20 year old dude at a UPS store looking at some papers for a few seconds. Not exactly the high trust exercise it’s made out to be.

It doesn't have to be perfect trust. The benefit is having a third party involved under oath, with a known identity, purpose, and personal liability.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#142

Earlier quoted context omitted.

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

> I would be interested in learning if this problem exists in other countries In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you. This in turn can help a bit because it results in most attempts at making loans in your name not being possible. https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv... There are four companies in Norway that do credit assessmen…

European countries are ten yrs ahead of the US as far as regulations on technology are. Some people have to learn the hard way I guess...

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#143

"Identity Theft" shouldn't even be a thing. Someone falsifies documents and takes out a loan or something that should not have been approved. That's bank fraud and should be an issue entirely between the fraudster and the lender/bank. Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was sto…

Yes thank you. This is my "actually it's GNU + Linux" tic, please fellow Americans (and I would be interested in learning if this problem exists in other countries) do not accept the framing that a bank giving a loan to someone they thought was you is _your problem_! It's their problem! We should not be normalizing this phrase or practice.

> the framing that a bank giving a loan to someone they thought was you is _your problem_

Brings to mind the tale that jaywalking laws were the creation of early-days automobile manufacturers and dealers who wanted to clear the streets for the vehicles they wanted to sell. [0]

[0] https://www.vox.com/2015/1/15/7551873/jaywalking-history

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#144
post #103

To give context to people who may have not heard; there has been a MASSIVE amount of high profile data breaches in the Australia in the past 12 months with zero consequences for the businesses involved. In a 6 month period I had; - My private health insurance data leaked (AHM/Medibank) - including claim history, medicare number, password, username, email, phone - My old phone account (Optus) - including my phone numb…

> Until governments legislate that the punishment for exposing personal data is more expensive The EU did. Everyone, for some inexplicable reason hates it; and not the casual hate one spews when it rains or traffic is bad but a deep visceral hatred normally reserved for war criminals or kiddie fiddlers.

I'n my experience people hate cookie warnings, but few people hate companies being punished for leaks.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#145

Earlier quoted context omitted.

In the US property rights trump most other considerations, and courts are often biased in favor of property owners. Drivers frequently ignore cyclists and pedestrians, because they feel the road belongs to them, and to some extent the larger and fancier the vehicle the more carelessly they drive. Commercial drivers, who typically don't own the vehicle but can easily lose their commercial driving license, tend to be m…

Drivers of nicer vehicles actually drive better around cyclists as they are incentivized to not acquire dents and scratches in their precious. It's the hoopty drivers who DGAF about damage and are likely most ignorant of their legal obligations who are the biggest threat.

Although I dont have a link to the studies, there have been some that both showed an inverse relationship and correlation between income and driver care. Not super definitive. Notably, "nicer" meaning newer is not a static state. Higher income drivers can more easily absorb the costs of minor damage, meaning theres some downward pressure on the reporting stats from both sides.

Despite the bigger risks/penalties involved with being unlicensed (driver and/or vehicle) and uninsured, it does seem that these at-risk drivers are less safe. Uninsured driver premiums are explicitly bundled. Accidents lead to worse physical outcomes for at-risk drivers (https://www.sciencedirect.com/science/article/pii/S259019822...)

This would correlate with your outlook.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#146
post #115

Looking at the court documents, it seems shady organizations registered a bunch of domain names that are used in the trade of brand-name athletic gear. The victim's identity was used to register one of those domain names, but just looking at the other registrations it's pretty clear the organizations are based out of China. In this context, the case brought by the brand owners is a little more reasonable -- if they d…

globalsupport@icann.org and contacting the registrar to start. File a police report (this will help if anyone comes to visit your address) regarding identity theft. Contact the IRS regarding identity theft and possible foreign dba. Contact the post office if you dont have a locked mailbox..also, if you get any domain related mail, it can elevate the federal response. Talk to your bank about invalidating all checks and putting a limit on daily withdrawls/spending.

This is just off the top of my head. It is a huge headache that will trouble you for a few years.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#147
post #45

Earlier quoted context omitted.

I expect they want a judgement for a specific damage, then when they can’t collect they have insurance to cover that specific amount. Without a judgement for an amount, their insurance would pay out a lesser amount.

Then I assume that the woman they harassed will get a cut of the insurance money for the unnecessary stress they endured? Otherwise the court should just throw this out. It’s only 1.2m.

I don’t see any evidence that the company thought they were harassing someone. It seems they were just routinely pursuing someone they thought harmed them.

Hopefully, the judgement will be dismissed since it’s based on identity fraud.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#148
post #74
post #45

Earlier quoted context omitted.

I expect they want a judgement for a specific damage, then when they can’t collect they have insurance to cover that specific amount. Without a judgement for an amount, their insurance would pay out a lesser amount.

>Without a judgement for an amount, their insurance would pay out a lesser amount. Who in their right mind would insure Adidas (or any other internationally famous brand) for trademark infringement? You're almost guaranteed to pay out millions in "damages" per year.

Corporations insure for all sorts of things and a company as big as Adidas must certainly have operational risk insurance [0] for things like this.

I remember many years ago, the startup I worked for was required to have insurance as part of our funding round and it covered stuff like officers freaking out in public and all sorts of odd things I didn’t think was insurable.

Corporate insurance is pretty interesting in this regard.

And no matter who is insuring, in the US it’s probably reinsured by Marsh McClellan [1], a huge reinsurance firm.

[0] https://content.naic.org/cipr-topics/operational-risk

[1] https://en.wikipedia.org/wiki/Marsh_McLennan

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#149
post #57

Earlier quoted context omitted.

Some countries/jurisdictions do exactly that, and trust me, it's a massive pain in the ass. Would you really want to visit a notary just to set up an eBay account? Because that's what you're proposing. The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy…

Well, acktually... I just tried to set up an eBay account to buy an exhaust part. I created the account, sent the seller a message and twenty minutes later, I got a notification from eBay that I (and anyone from my household) was permanently banned because I was a "threat to the eBay community". I haven't been on eBay for ages, and as far as I know, was certainly never threatening to anyone on or off eBay. Nobody at…

I just had the same thing happen last week.

I’m moving away and selling some of our stuff that we can’t take with us. I have a spare 5G/LTE router that I thought I’d throw up on eBay as well as Facebook Marketplace.

I followed their onboarding process to the letter to create a listing, verify my email and mobile phone, add a bank account, etc.

About an hour later I got an email saying I’ve been “permanently suspended because of activity that we believe was putting the eBay community at risk”.

Apparently doing nothing but following their onboarding process is putting the community at risk. They also tell you that “this decision (that was made 100% by an automated system) was not made lightly”.

Get fucked, eBay.

Re: Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts

#150

Earlier quoted context omitted.

If Paypal required non-sms based 2FA on all logins, would that help stop the issue?

Sure, but also it would piss off unsophisticated users and also cause a huge increase in customer service issues with people getting locked out. That why it keeps flipping between required and optional. Way back then we would send RSA tokens to the top users to stop them from getting hacked, but since they cost $10 each and required training and setup with an agent, only top users would get them.

If you're talking about RSA tokens as in the tokens sold by RSA Security the company, my company uses them and my team is in charge of their issuance. We've estimated the total including man-hours cost of issuing a single token at about 250€. Sure in the grand scheme of things it isn't much but I can't imagine it'd be better for PayPal, and that gets expensive fast if you send them to clients and not just employees.

Part of this is of course genuine security verifications but a lot of it is due to RSA Security's obtuse design decisions. We tend to avoid them entirely and instead rely on modern SAML providers with app-based 2FA whenever we can now.

Post reply on HN