Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

151–160 of 218 posts

Re: Dell Computers Has Been Hacked

#151
post #44

I don't know about you, but where I live (Sweden) there are strict rules on how you can store personal data and who has access to it. It's also against the law to put people in "databases". I guess we still remember WW2 and how the Nazi used such registers ...

Wasn't Sweden a lukewarm half assed ally of Germany in World War 2, at least for the first few years?

Re: Dell Computers Has Been Hacked

#152

Earlier quoted context omitted.

Tracking server-side is fine, it is assumed the server logs contain a record of my visits and I have no problem with that. I think what most people object to is the third-party tracking that so many people use. Company A tracking my visits to Company A's website = OK Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK EDIT: (replying here as we'v…

Yes. GA has server-side API's available to premium accounts. You can also just host the ga.js file yourself. Or run a reverse proxy or any of a dozen other methods to collect data and pass it to GA. Using the standard 3rd party tag is just for convenience.

how can GA correlate between site then ? The server-side does not have access to my GA cookie. Browser fingerprinting ?

Re: Dell Computers Has Been Hacked

#153
post #148

Earlier quoted context omitted.

In that case, f that and f them. Do not track me.

Are you are aware that Google provide you with a method to do this regardless that doesn't rely on random script blocking? Details here https://tools.google.com/dlpage/gaoptout

Why would I trust google with this ? I'd rather do it myself.

Re: Dell Computers Has Been Hacked

#154

Earlier quoted context omitted.

Assuming an averagely careless programmer, a language made out of shotguns will produce more errors than a language with the occasional presence of shotguns. When simply trying to concatenate 2 strings can result in arbitrary code getting executed, memory leaks, actual data-loss or fatal program instability (or all of those), it's pretty obvious the C language itself is made out of shotguns. Making simple things simp…

> it's pretty obvious the language itself is made out of shotguns. You are hitting the hammer where there is no nail! In this instance, the Dell WEBSITE was hacked which are (99% of the time) written in high-level programming languages like php, python or Java. No sane business uses C/C++ to develop a website. C/C++ is used for INTERNAL SYSTEM PROGRAMMING and those systems are already linux based and almost impossibl…

> C/C++ is used for INTERNAL SYSTEM PROGRAMMING and those systems are already linux based and almost impossible to hack

According to CVEDetails the Linux kernel has 1338 (known) vulnerabilities. http://www.cvedetails.com/product/47/Linux-Linux-Kernel.html...

Re: Dell Computers Has Been Hacked

#155
post #115
post #110

Earlier quoted context omitted.

Even just your UA string is enough in most cases to make educated guesses. See here: https://www.eff.org/deeplinks/2010/01/tracking-by-user-agent... . The server will get that UA string, and it can make subsequent calls (or serve you content that will automatically make calls, like hidden tags...) to further restrict the search space. You can have middleware that does this transparently. I'm not in that particular ma…

But the question is if GA and others actually accept these kind of requests: remember that someone with such and such UA (or IP, or whatever) has visited that website? And if people actually use it? I still have my doubts that tracking someone by UA is possible — there will be collisions for the large part of the market — but that some analytics service is actually doing it? It's easy to track me if Google can "reach…

Not just the UA, but there are ways : https://panopticlick.eff.org/

Re: Dell Computers Has Been Hacked

#156
post #152

Earlier quoted context omitted.

Yes. GA has server-side API's available to premium accounts. You can also just host the ga.js file yourself. Or run a reverse proxy or any of a dozen other methods to collect data and pass it to GA. Using the standard 3rd party tag is just for convenience.

how can GA correlate between site then ? The server-side does not have access to my GA cookie. Browser fingerprinting ?

Yes, cookies are outdated and just a fallback. Also, unless you never go to a google-owned domain name, you'll be cookied regardless.

Re: Dell Computers Has Been Hacked

#157
Suggestion: if you are affected by this, get your attorney to reach out to Dell and get a response on record. You might be surprised. Their legal team will understand the risks of sweeping under the carpet or denying something they know about.

Re: Dell Computers Has Been Hacked

#158
post #49

I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent. But what else can you expect? If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it. I seriously doubt that Dell tech support is ISO 27000 compliant.

At one point in the 1990s, Dell shifted all of its tech support to India, ruining its world-class staff in Round Rock (TX). Complaints got so bad that they re-established the Round Rock organization for corporate customers; retail buyers were still stuck with the offshore staff.

Funny how the more things change the more they stay the same. In Australia they outsourced all their support to India. They nearly lost numerous big corporate and government accounts, so they brought back support to Ausyralua for corporates pretty quickly.

I can't understand why these overseas call centres are do terrible! I don't want to resort to racial stereotyping, what is it though that cause such dreadful customer service experiences?!?

Re: Dell Computers Has Been Hacked

#159

I posted about this about 7 months ago on HN, https://news.ycombinator.com/item?id=9881674 , I also tweeted it out. Dell responded to my tweet saying there has been no breach and our data was secure. Obviously I didn't and don't believe them, and their main response was report it to the FTC. That is crap, admit it, fix it and deal with the issue. What totally pissed me off is that it was my sons laptop they called on…

I had the same problem last April, and had a surprisingly difficult time finding any more info about it. All Dell forum threads say that they know nothing about it and refer you to the FTC site. The really disturbing part was they used my mobile number, which had been spam-free until the Dell issue. I posted about my experience here, with the hopes that others in my cohort would benefit from it, but the thread is sti…

Just read your description, it is nearly identical to what they were trying to get my son to do. They wanted remote access and telling him that his computer was attacking other people and their "monitoring" caught it. Really was an elaborate explanation when I heard it, but so insane to anyone that knows how this all works. But to a 17 yr old it seemed reasonable, even plausible especially with the quick talking, pushy nature of these guys. That was until I got my son to stop and think about it for a minute, then he saw the stupidity in what they were saying.

It was a great lesson for him, and while I had sworn off Dell quite a long time ago, this made him now say no thanks to Dell. His new laptop is a Toshiba, not that they or any company is immune, but the fact Dell won't even publicly address it and help to protect their customers to me is really the sign of a bad corporation. He even convinced 3 of the kids in his high school that were buying new laptops to avoid Dell, so hopefully people keep spreading the word and it starts affecting Dell in the only place they will apparently listen.

Re: Dell Computers Has Been Hacked

#160
post #138

Earlier quoted context omitted.

This is why I frequently swap bonus cards with random people on the subway :)

A serious question, though I assume that you were joking: is it more creepy to have your own actions tracked and accurately tied to you, or other people's actions tracked and inaccurately tied to you? Both sound pretty awful to me, but I think I'd prefer the former if those were the only two options.

What stops these guys from selling to all the major health insurers.

Been buying too much sugar? Dental insurance up. Too much butter? Health insurance up. Bought three times the median amount of headache tablets? That's a paddlin'. Bought more alcohol than normal? Car insurance up.

Opt out to keep off their radar? They assume the worst and charge you double?

Post reply on HN