7 ms·
Samsung Loses a Ton of User Data – Offers Nothing to Victims
- t0bia_s 4y agoAnother reason why not use stock ROM with tons of bloatware from manufacturer. Samsung smartphones are good in terms of HW and custom ROM compatibilities. Terrible in OS and basically anything SW related.
- ars 4y ago"We want to assure our customers that the issue did not impact Social Security numbers or credit and debit card numbers, but in some cases, may have affected information such as name, contact and demographic information, date of birth" How exactly is this meant to be "assuring"? Who cares in the slightest about credit or debit card numbers? The other stuff matters FAR FAR more.
- metadat 4y agoAgreed. Our SSNs are already for sale on the dark web. Dear Samsung: What the fuck was stolen, exactly? Do you even know?
- bushbaba 4y agoWorse yet, maybe people's TV viewing habits.
- bequanna 4y agoUmm, you don’t need the dark web to get SSNs. If you know the person’s exact name and city of residence you can use a supposedly legit service to purchase their SSN for $50. I won’t post it here, but should be trivial to find the name of company. I used this service several years ago when a contractor tried to give my business an obviously fake SSN as he thought he wouldn’t have to report the income.
- gtirloni 4y agoName, phone number, current location and date of birth that are easy to find are more important than SSN and actual financial information? How so?
- vineyardmike 4y agoFinancial info are easy to change. Financial info that is stolen and used won’t hold the victim liable for the damages (in us). SSN is basically universally leaked and also deterministically generated. Again, no harm to victim for any fraudulent uses. Address isn’t likely to change. Especially not due to a leak. Phone number changing is a PITA even if easier. Date of birth can’t change ever really.
- grammarnazzzi 4y ago> Address isn’t likely to change Addresses are already public records because property ownership and tax records are public.
- vuln 4y agoBummer. I was looking forward to stacking on some more “free” credit monitoring.
- SteveNuts 4y agoAt this rate I'm going to be covered for the rest of my life.
- bushbaba 4y agoMaybe I should get into the credit monitoring business. Seems like the average person will end up with many lifetimes worth of 'free' monitoring from settlments.
- godzillabrennus 4y agoI wouldn't be shocked if those services are compromised. There is no reason for things to change if the liability is not on the company that loses the data. However, the IRS assigns $0 to data. So long as that's the case there will be no liability.
- codazoda 4y agoI’m going to guess that “free” is quoted because of an experience similar to my own. I signed up for free credit reporting after a breach years ago. Months later they started to deduct around $12 a month from my account. It was free with a monthly subscription following. If that’s still a thing the credit bureaus are making serious money from these leaks.
- dtx1 4y agoAnd why should they? It's not like it has any consequences edit just to make it clear because the downvotes are flooding in: it does not have any consequences for Samsung. Users are fucked of course.
- petre 4y agoWhy should they? Bribery, embezzlement, stock manipulation and accounting fraud is the norm for Samsung's VP, Kee Jae-young, who was just pardoned at home in Korea. Data breaches are 'the cost of doing business' for Samsung. /s
- deleted 4y ago[deleted]
- cptskippy 4y agoThey told me I could get a free credit report every year!
- pixl97 4y agoArticle headline: Samsung Suffers Another Massive Data Breach: Should You Be Worried? This really needs renamed. Samsung did not 'lose' anything. If I 'rm -rf' data without a backup, that is data loss. This is a breach in which the only loses is 'Samsung loses control of singular ownership of your data putting users at risk'.
- autoexec 4y agoYou can bet that Samsung doesn't have singular ownership of any customer data in their possession. If Samsung isn't selling it to someone else already the state will be buying or taking it.
- hungryforcodes 4y agoWhich state? They're South Korean.
- autoexec 4y agoCertainly any operations within the US will be subject to data collection by one three letter agency or another. I'm not sure how much South Korea likes to spy on their own companies, but I think it's a safe bet they're collecting data too.
- hungryforcodes 4y agoSo basically speculation.
- oxplot 4y ago> Samsung did not 'lose' anything. Well there is DLP: "Data Loss Prevention is the practice of detecting and preventing data breaches, exfiltration, or unwanted destruction of sensitive data."
- pvg 4y agoDiscussed yesterday: https://news.ycombinator.com/item?id=32693134 https://news.ycombinator.com/item?id=32693134
- abdullahkhalids 4y agoI am buying a new phone, and might end up buying a Samsung, though I absolutely hate all the garbage they default install. How do I protect myself from such attacks on Samsung in the future?
- poisonborz 4y agoProbably by not registering a Samsung account and not using their services. While the phone OS will push you for it, it's only used for their bloatous offerings, and is skippable.
- cik 4y agoExactly what I did. I get hassled at least weekly, and with every update - but I've yet to create an account.
- marak830 4y agoOnly way to be sure, would to not buy their hardware. I wouldn't trust their preinstalled software to follow the rules.
- abdullahkhalids 4y agoWhat smartphone company would you recommend?
- yosito 4y agoApple, or a Google Pixel with a custom ROM if you're technical enough. I couldn't otherwise recommend an Android smartphone in good conscience.
- marak830 4y agoSecond, custom ROM all the way. If stuck with stock, I run a no root firewall and choose what gets access to the internet and when.
- naniwaduni 4y agoSamsung offers accidental backups to their users!† †Contents of backups not assured. Data retrieval not guaranteed. No removal procedure. Access control is on a come and get it basis.
- solarkraft 4y agoCompanies can not be trusted with your data. Don't give it to them.
- hypertele-Xii 4y agoEagerly awaiting for the consumer data storage solution that doesn't involve doing any business with a company.
- yosito 4y agoCryptomator
- bennysomething 4y agoJust got a new Samsung sound bar. Can anyone explain why when I connect via Bluetooth (or maybe it was their smart things app) it wants access to my phone contacts and messages!?
- squarefoot 4y ago> or maybe it was their smart things app Pretty sure it's the app. If the soundbar is a plain Bluetooth audio device it shouldn't even need any other software than what is already contained in the device you want to connect it to. They however could have replicated or moved some of its controls on the app so that you're encouraged (if not forced) to install it and surrender your personal data in the process. I hate that practice; almost every device or service today wants to install an app because it brings their brand on the phone main screen and gives full access to users private data. Besides privacy concerns, it can't scale: 100 products or services done the traditional way were 100 addresses in a bookmarks file that used a few KBs combined and no CPU power at all except for the browser (that is, just one app), now they are 100 executables that waste orders of magnitude more storage and can slow a device like molasses even when not in use; all this in the name of sticking a logo on the main page of a phone and exfiltrating users personal data.
- BuildTheRobots 4y agoNot sure about messages, but most Bluetooth speakers prompt if I want to give them access to my contacts - I've always assumed it's so they can display/say the caller ID for an incoming call.
- onphonenow 4y agoThey want location settings on for smarthings too even though I don't want to be tracked all the time
- dang 4y agoPlease don't editorialize titles like this. From the site guidelines: "Please use the original title, unless it is misleading or linkbait; don't editorialize." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html