Live data from Hacker News

Dell Computers Has Been Hacked

10zenmonkeys.com

71–80 of 218 posts

Re: Dell Computers Has Been Hacked

#71

I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent. But what else can you expect? If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it. I seriously doubt that Dell tech support is ISO 27000 compliant.

Who cares where it is? Regardless of the country or the salary, phone support workers can be corrupted by a relatively small chunk of cash. Since when has first line tech support ever been a comfortable, dependable 'job for life'. Go blame India if it makes you happy, but bored and broke workers will sell you out anywhere in the world.

Re: Dell Computers Has Been Hacked

#72

Earlier quoted context omitted.

ommunist can correct me but I believe he was referring to having Dell tech support being located in a western country, instead of being based in asia. Yes it's more expensive to keep operations here, but we are more familiar with the business practices as well as the laws. Of course this is a price of "the race to the bottom".

> we are more familiar with business practices Almost everywhere in the world had been doing business for thousands of years before the US existed. It's pretty careless to say that Asians are not 'familiar with business practices'. They may not be all about your business practices. If yours get too weird and uptight they'll just return to doing business with the rest of the world and won't miss you too much.

It's fairly well known and accepted that regulations and rules in western countries are FAR stricter than those in Asian and Indian countries. If you care about privacy EU > US > everywhere else (any non western country has literally zero protections or laws about privacy that are enforced), if you care about workers being treated decently EU and US are bastions of fairly mediocre to bad treatment, everywhere else is sweatshops and de facto slavery.

Re: Dell Computers Has Been Hacked

#73
post #48

Earlier quoted context omitted.

These scams rely on nobody tracing them back. The phone system is completely insecure, loses are too small to prosecute properly, and it hits mostly people who don't know how to defend themselves. The whole idea of unauthorized phone systems and impersonating officials is probably only going to go away after it actually hits someone who "matters". For example soon after a well known politician's house gets swated a f…

SS7, which carries telephony routing and ID info, doesn't have anything like message signing or SSL certs. It was designed with the assumption that telcos trusted each other. Then came VoIP, and with it, signal transfer points which forward call ID info. There's firewall-type filtering at signal transfer points, but it doesn't help much with validating the original source of a call.

I know that too well unfortunately - worked in a voip telco which allowed users to set any callid as long as they signed a paper promising to be good. (standard procedure) The funny thing is that SIP does allow signing signaling via TLS, it's just not used that way.

But that doesn't mean there's no solution for tracing calls. It needs just one extra law for telcos to solve most of this issue: "Either you can prove/point to the interconnect which originated this call, or you take full responsibility for this call and its contents." Then law enforcement can just continue to the next company and the next until they get to the subscriber.

Two answers to questions I expect: - What about international numbers? If you get a call from Russia claiming it's IRS, that's really not plausible - that can be understood by everyone. If telco gets a call from Russia with US callerid, then again, its their responsibility to only choose partners which they can query to check if that's valid. (it's not a huge barrier - telcos are already aware of various international issues)

- This will require registration of all subscribers with real details, what about privacy? Yes, yes it will.

Re: Dell Computers Has Been Hacked

#74

Earlier quoted context omitted.

ommunist can correct me but I believe he was referring to having Dell tech support being located in a western country, instead of being based in asia. Yes it's more expensive to keep operations here, but we are more familiar with the business practices as well as the laws. Of course this is a price of "the race to the bottom".

> we are more familiar with business practices Almost everywhere in the world had been doing business for thousands of years before the US existed. It's pretty careless to say that Asians are not 'familiar with business practices'. They may not be all about your business practices. If yours get too weird and uptight they'll just return to doing business with the rest of the world and won't miss you too much.

Either chaostheory edited their post o you missed a "the" before "business practices", presumably referring to the business practices of western countries.

Re: Dell Computers Has Been Hacked

#75
post #61

Earlier quoted context omitted.

Well, I block GoogleAnalytics with uBlock and uMatrix.

Unfortunately people have started putting the tracking server side.

Tracking server-side is fine, it is assumed the server logs contain a record of my visits and I have no problem with that. I think what most people object to is the third-party tracking that so many people use.

Company A tracking my visits to Company A's website = OK

Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK

EDIT: (replying here as we've reached max comment depth) - I was unaware that it is possible to use Google Analytics server-side only (is this true?) but I hope my original point is still clear, DIY tracking is fine.

Re: Dell Computers Has Been Hacked

#76

I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent. But what else can you expect? If you are not paying decent money, be prepared that your data woll be sold, unless you are ReallY able to enforce control over it. I seriously doubt that Dell tech support is ISO 27000 compliant.

> I'd rather bet that real Dell outsourced tech support to some company in India, where very often business ethics towards customer records is virtually non-existent.

Can you provide a citation to support your claim about business ethics in India? That's a rather negative statement about a large number of people. I've downvoted your comment but I'm happy to reverse that if you can back up your claim.

Re: Dell Computers Has Been Hacked

#77
Back in February of 2013 I bought an XPS 13" convertible (nice btw, shocked it doesn't ship with Pro) and whilst it was on the way I got 2 very convincing looking shipping tracking scam emails that ask to run some executable and enter some details. They had the correct model of laptop and very specific timing. I've never had any other spam like in before it since.

Sadly gmail has removed the spam from so long ago and the initial Dell contact email must have been sent from a form as I only have the service desk reply with my correct shipping number to track myself.

This might be even more serious than it looks.

Re: Dell Computers Has Been Hacked

#78
post #11
post #2

I don't know if it's related but I found something deeply worrying a couple of months ago. I purchased a laptop on Dell's website at my home address using a personal email and my personal paypal account. No reference anywhere to my job or employer. A couple of weeks later I receive a call from India on the mobile number provided to Dell, from a guy pretending to be from Dell (and he might have been) who wanted to dis…

Axciom, Epsilon and similar companies track your credit card purchases and correlate them with a profile of who they think you are. If you work for a large corporation that is probably easier to identify than a small one. http://www.acxiom.com/ http://www.epsilon.com/

But in my defense I have a very common name, in fact the same name of a major politician. The email address I provided Dell was a single use disposable email address. So I have no idea of how they managed to correlate me to my employer.

Re: Dell Computers Has Been Hacked

#79

Earlier quoted context omitted.

Unfortunately people have started putting the tracking server side.

Tracking server-side is fine, it is assumed the server logs contain a record of my visits and I have no problem with that. I think what most people object to is the third-party tracking that so many people use. Company A tracking my visits to Company A's website = OK Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK EDIT: (replying here as we'v…

I agree with your position. However...

You misunderstand. There have been several commentators here on HN saying that they are moving Google Analytics server side. They seem to think that people are only objecting to the cookie or the presence of the JS rather than objecting to the pervasive cross-site tracking.

Re: Dell Computers Has Been Hacked

#80
post #69

Earlier quoted context omitted.

It already happens unofficially. How do you think banks assess your lending/borrowing habits when you apply for a loan? There are detective agencies who track credit cards and other things (like a few examples someone gave in this very thread).

> It already happens unofficially. European living in the US here. How do these systems assess recent immigrants who have no credit history in the US?

You're a "ghost". Your FICO credit score will probably be pretty OK (in the 600s) if you have no derogatory credit, but with no (US) history of high credit, and no established history of attachment to your job and address, any loan analyst worth their salary will be skeptical.

You will probably have to pay a rate premium unless you go through a lender such as a credit union that you have an existing relationship with. Your provable income will be your biggest asset.

As a non-US citizen, it makes sense that you will be perceived as a higher risk of absconding since you could leave the country permanently at any time.

Post reply on HN