Dell Computers Has Been Hacked
10zenmonkeys.com
10zenmonkeys.com
What totally pissed me off is that it was my sons laptop they called on and they called him directly since his number was listed when he called in for real Dell support about 3 months prior to the scam call. They had convinced him they were Dell until I walked into his room and heard 30 seconds of the call and asked why he called them, soon as he said he didn't I told him to hang up. They were persistent, calling him back many times over the next 2 months. I had to block the number to finally get it to stop and my son says he got a new call just a few weeks ago, new number same scam but at least he is smarter about it now.
I posted about my experience here, with the hopes that others in my cohort would benefit from it, but the thread is still quiet: http://forum.notebookreview.com/threads/scam-calls-from-dell...
Summary of my battle: Keept them on the phone as long as possible, asked stupid questions, and tried to piss them off as much as humanly possible - I managed to get a "find a pen, remove the cap and stick it up your ass" after 2 hours on the phone with them. I kept them on the phone while my 4mb download took 45mins.
It was a great lesson for him, and while I had sworn off Dell quite a long time ago, this made him now say no thanks to Dell. His new laptop is a Toshiba, not that they or any company is immune, but the fact Dell won't even publicly address it and help to protect their customers to me is really the sign of a bad corporation. He even convinced 3 of the kids in his high school that were buying new laptops to avoid Dell, so hopefully people keep spreading the word and it starts affecting Dell in the only place they will apparently listen.
At least it is good to see word getting out - that is likely the first step to any reasonable resolution.
I hope this changes as we migrate away from passwords and passphrases to mandatory two factor login with physical keyfob tokens, from C to Rust, and from putting things directly onto the internet to putting everything behind a IPS/IDS that updates itself via signatures, honepots, etc. Especially in the home where no one runs IPS, the same way early consumer OS's didn't bother to ship with firewalls.
Phones need something like this too, especially with blocking known spammer numbers/providers. Everyday I get an Indian call center impersonating either state farm or blue cross. I have no way to stop this as they randomize the phone number each time, often in mocking ways like starting with a movie 555 prefix or having a prefix starting with 1.
I also don't want a relationship with companies like Dell where they store all my info. Why can't I buy something via a private OpenID/Persona-like system that has a tokenized version of my credit card and Dell just ships the product? I must have hundreds of accounts spread out with various sites, vendors, etc. Each of them ripe for the taking by scammers and hackers with my real name, stored card, etc.
I hope this stuff is what breaks the camel's back. IT security right now is a nightmare. I suspect it will get much worse before it gets better. Cryptolocker didn't suddenly fix corporate IT security. From what I can tell, its just as bad as its ever been.
Would be nice to be able to opt-in to a "forget everything you know about me" program - Newegg would probably get tons of business from paranoid nerds with an option like that in place.
What always bothers me more is how caviler many companies, especially many marketing companies I have seen, are with our personal details. As recently as just a few years ago I was fixing one such marketing company's issues, like using sequential id's on exposed web links sent in emails. Which all you had to do was increment the id and you could get personal details for other people from the database (which had happened). They fixed that issue and some others but still never addressed security as a whole, which just bugged me. Plain text passwords in a database, no encryption on sensitive data etc. And I see it over and over, a company won't change unless they are forced to, and then it is change only enough to appear secure, not be secure.
At that time I thought that Dell's commercials were unacceptably pushy, googling their private clients to find a way in their employer. It didn't occur to me that this might have been a scam using Dell's database.
If I understand correctly, youre saying my entire purchase history is shared with random third party marketing companies. Full transaction data, PII included, no anonymization.
How is that even remotely OK?
There is at least one company that has built technology that will monitor most all these purchases, monitor the IP's from them and the browser profile to identify a specific machine that you use. Then when you go to work, or are on your mobile they also will tag that traffic as you too. They have gotten so good they can serve ads that are relevant to your wife if she happens to be on your computer surfing the web for shoes say, but serve you different ads if you are on the same computer. They use data feeds from many sources, but ecommerce transactions, credit card transactions and companies like acxiom that let them match those with real people, incomes and household details make it very powerful.
In marketing we use Axiom and others a lot, their data used to be more vague and educated guesses about people. Now though, they have gotten it down pretty well, including how many animals, kids and your income/debt etc. They collect data from tax collectors offices, county records, city records, plus companies that will sell transaction data and other pieces so they can get a full picture. They of course work with Equifax, TransUnion etc too so they can build a whole economic profile on a person.
These companies are also what allow marketers to send you an email about their product/company after all you have done is visited their website. You don't have to enter anything or click on anything, but they will know who you are, who you work for and whether you fit their market profile in general. Poorly done it is extremely creepy, correctly done it can be an amazing conversion booster.
I am from Brazil, and I am openly dissident of our government, and here assassinations (And other unpleasant things) DO happen to dissidents (example: in the last year a couple anti-government bloggers all in the same region where "murdered", the police claim it was just normal murder, but the coincidence is too great to be just normal murder, they were obviously assassinated).
What happen, if some day the government decide to assassinate me? They can just waltz in with a market company, offer a lot of money (or if they refuse, a lot of pain), get my data, and know all that stuff about me.
Then, they can do with me, what they did with Toninho and Celso Daniel: intercept them on the street, kill them, and pretend it was a robbery gone wrong.
Toninho case was very obvious: He was intercepted while fetching some suits he had bought before, using the tech you mentioned, assassins would know for certain that he was there, since they could know he would need to eventually fetch the suits, and that once inside the building, you could intercept him at the exit, indeed as he was exiting the shopping mall that had the clothing store, another car drove by, shot him (not "at his direction", but at him, directly, Toninho died instantly because of direct hits), and sped away. The police claimed it was a random incident where random criminals randomly passing by got pissed off at him cutting them off in the traffic and killed him, beside all that being unlikely, Toninho had some days earlier said to the press that should "something happen" to him, stuff were already set for his successor.
So what matters to me is: How I don't get tracked, unless I go "off grid survivalist style" ?
That said, there are things people can do with companies like Acxiom to help reduce the data collection. At least in the US (not sure overseas) if you as a consumer submit a request to be removed from their lists they must honor your request and remove you, many US states have strict laws about this and I believe the Federal laws also have strict restrictions. The catch 22 to this is that you can wind up back in the collection at a later date because of activity you take or because of a timeout period (from what I understand). You can read about Acxiom's policy and opt-out here: https://isapps.acxiom.com/optout/optout.aspx
As a point too, you may check out the data collection from Acxiom, as I believe they actively collect and use data in your home country, as they do in many counties. Equifax, Experian and TransUnion all also work in the US and overseas and collect/sell vast amounts of data on individuals. The very fact they collect so much data does make people (including me) nervous because I personally feel they do not take security of the data nearly serious enough, as recent security issues have shown at most of them. But that I guess is a different issue/post.
I don't use facebook but do use a credit card. Hard to opt out of that in the modern world. God these people are filth.
And all that for a cheaper (and cheap) bread-knife.
Been buying too much sugar? Dental insurance up. Too much butter? Health insurance up. Bought three times the median amount of headache tablets? That's a paddlin'. Bought more alcohol than normal? Car insurance up.
Opt out to keep off their radar? They assume the worst and charge you double?
Thinking from first principles lets us see incentives and probable outcomes before they are "substantiated" (adopted by the media).
I personally don't think shopper data is affecting insurance policies quite yet. But the groundwork is there (Acxiom etc), and the "great" thing about data is it stays around forever!
I'd guess a timeframe of 10 years, but does it really matter as to when?
Is this a response to my comment? I would guess that the answer is "nothing but the temporary protection of the law", but, assuming that protection is eventually revoked, it makes it all the more worrisome for me to have a random stranger's data taken as my own.
I'm not a tin foil hat type, but I really don't like filling my wallet with tracking cards and can't be bothered to claim the miniscule compensatory benefits provided in return for proffering my purchase (and also location, hygiene, etc.) information.
Saying 'no' is almost more hassle than simply submitting, however, which is probably exactly what the company would like to hear. Suggestions welcome for brushing off this nuisance without a) Avoiding their shops entirely (not practical) or b) Being rude to cashiers.
When I pay with cash, I usually don't present a card as well.
PII is not available, it is anonymized. There are laws around this. Purchase data itself is usually grouped into major purchase types, not amounts or actual goods purchased.
For that detail, it would be the CRM/ERP systems of the manufacturer that has that information tied to a serial number and this is why they ask you to register your product when you buy it. Some manufacturers might work with data providers to exchange this data (serial numbers in exchange for purchase histories) but it's rarely done at scale because of cost, complexity, legal/security risk and lack of options to benefit from it.
But we've seen how useless even apparently well meaning anonymisation is—think of the AOL search results. I can't imagine how utterly useless it becomes when it is done by people in whose interest it is to do it poorly, while remaining just within the law.
The protection of the law does add to the security. Also anonymization of the PII (scrubbing into just a serial number) combined with the dilution of purchases into larger categories provides lots of protection. Your google search history is lot more detailed and granular than most of the purchase data you can buy through data markets. You might be able to figure out a basic "profile" and maybe use lookalike modeling but it would be incredibly difficult to actually distill that to a discrete person.
There's also been a push to buy "insights" rather than just data to get more ROI with less effort/cost so instead of buying purchase histories you would just buy a segment of people interested in buying washing machines for example.
Lumping Apple with Google in terms of data gathering is misleading at best.
Company A tracking my visits to Company A's website = OK
Company A using Google Analytics to track my visits (while also enabling Google to track me across multiple sites) = Not OK
EDIT: (replying here as we've reached max comment depth) - I was unaware that it is possible to use Google Analytics server-side only (is this true?) but I hope my original point is still clear, DIY tracking is fine.
You misunderstand. There have been several commentators here on HN saying that they are moving Google Analytics server side. They seem to think that people are only objecting to the cookie or the presence of the JS rather than objecting to the pervasive cross-site tracking.
You can also just host the ga.js file yourself. Or run a reverse proxy or any of a dozen other methods to collect data and pass it to GA. Using the standard 3rd party tag is just for convenience.
I'm pretty sure it's the same mechanism used for mobile/app non-browser tracking.
I'm not in that particular market, but I know people who are and tbh more often than not I think it's an arms race the individual simply cannot win. Unless there's a conscious effort from browser-makers to actively counter tracking practices, you should assume everything you do on the web is public and can be tracked by multiple parties.
This can be as simple as hosting a copy of GA.js yourself but there are plenty of options like using the server-side API if you have GA enterprise or just using a reverse-proxy like Nginx with some rewriting logic.
3rd-party only means it's a different domain (with security usually implemented at the browser level) - it's not some magical wall of isolation.
That's unsettling.
If you want to see a simplified version of what this log looks like, run 'python -m SimpleHTTPServer' and visit localhost:8000.
Ofcourse people can(and do) sell their server logs to 3. parties anyway...
The answers to this are twofold: Better national information security support* and regulation; Consumer action to chose vendors that demonstrate that they value personal privacy and prioritise information security.
* Which includes not deliberately, as a matter of policy, undermining security technologies and standards.
In a pure capitalist model it is okay if Facebook shares all your data with advertisers – if you don’t like Facebook, just vote with your money and go to Google+.
"Sweden's industry is overwhelmingly in private control; unlike some other industrialized Western countries, such as Austria, Italy or Finland, state owned enterprises were always of minor importance."
In fact I think I can make a strong argument that capitalism relies on property rights and therefore the rule of law, which tends to support individual rights in general including privacy.
Especially in the US the balance has been skewed since forever towards capitalism.
Historically, Social Market Economies evolved in countries where the population was supportive of socialist and communist uprisings, but the ruling class tried to keep the economy, and implemented the same benefits as in a socialist system in the existing market economy (See Bismarck’s Social Welfare model in Germany and the history of Bismarck vs. the Social Democrats on this).
We aren't there yet, but consider that Facebook wants to use your social network associations in your credit score[2].
[1] https://www.youtube.com/watch?v=lHcTKWiZ8sI
[2] http://www.theatlantic.com/technology/archive/2015/09/facebo...
I don't get often surprised by all that dystopian stuff, because I assume we already are quite fucked, but this one did surprise me. That's just crazy.
To be clear, I believe there is some disagreement as if this is one or multiple programs in China, but that doesn't really matter; we need to defend against the establishment of this kind of program regardless.
The trick where positive reinforcement is used to trick people into wanting to participate is utterly terrifying... because it will work. It's obvious that it will work, because it is effectively the weaponization of "high school clique"-style tribalism and carefully re-framed self interest.
But a state sponsored gamified social network where the incentives are all designed by the ruling class, and the penalties have the force of law, is pretty darn awful.
Hopefully the affected citizens prove to be as unpredictable and hard to control as others have in the past, because that's really their only hope.
It sounds like the system does not currently use politics and such, but the government would like to combine it with the existing citizen tracking system which is employer based.
And a BBC article: http://www.bbc.com/news/world-asia-china-34592186
I think the US system is fairly insidious as well and has more government influence than it might seem (look into "redlining" for instance and the role the government played). Creditors can know quite a bit about your private life (particularly if you significantly outside the mainstream) and I don't think it is that uncommon for individuals to share credit scores. In any case, I think it is worth considering how "social trust systems" work everywhere and not just in the worst imagininable case. It is harder to think about in the less obviously centralized cases.
European living in the US here. How do these systems assess recent immigrants who have no credit history in the US?
Look at ways to establish at least some credit history sooner rather than later, as this will make things easier in the future. For example, even if you do not need a store credit card, you might get one and charge routine purchases and pay the full about each month. This avoids any extra costs and builds credit history.
You will probably have to pay a rate premium unless you go through a lender such as a credit union that you have an existing relationship with. Your provable income will be your biggest asset.
As a non-US citizen, it makes sense that you will be perceived as a higher risk of absconding since you could leave the country permanently at any time.
But the banks already know where your paycheck comes from ...
To be fair, I hated the software and wasn't going to buy it. That phone call certainly didn't nudge me in their direction though.
They called to confirm some BS about the order, and mentioned my employer's name. I was pretty stunned. I'm thinking they correlate IP address of your purchase on Dell.com with employer, I've heard such databases are available, but it's pretty surprising to me... not sure what else they do, except yeah, maybe googling their customers.
This is serious.
If you have customer data, you need to log access to that data, and you need to audit access to that data, and (very important!) you need to have a zero-tolerance policy. This isn't trivial to set up, but it's necessary; The CTO is responsible here, not some "website hackers".
In an ideal world yes, but sadly here on planet reality I would be surprised if Dell even knows where all of its "customer data" is regardless of what certifications they are in compliance with.
They share that data with 100's of 3rd parties from outsourcing some of their own support services to some 5 man consultancy form Singapore that the CFO heard about on his last flight that sells them advanced analytics. While it's true that today customer data isn't shared that easily (at least in newer organizations that care about this) with an organization as old as Dell they might have data sharing relationships going past 2-3 decades that trump that and that sadly many people even C level at Dell might not be aware off. Not to mention that under the various 3rd party clauses many organizations pretty much use customer data as a commodity delegating it's distribution to various low level sale's execs that would send it to who ever would take it as long as they can get more accurate predictions for the next quarter to hit their targets.
If only that bore up in reality - you need only look at any number of recent high profile breaches (TalkTalk, for instance), to see that the "hacked" (incompetent) party gets sympathy, the exploiter gets prison time.
As to how this is happening - quite likely exactly as you say. They have extreme staff churn in their Indian operations, and all it takes is a few dishonest individuals to make this sort of thing become widespread. I've even had Dell sales reps contact me from their personal email address trying to get me to scam Dell (buy servers, I get commission, you return, I give you 50% of commission, deal?), so this is as unsurprising as it gets.
I think it's systemic, and we need to be very clear what we want a company (like Dell) to do in this situation.
Programmers are not usually held accountable for their own bugs, and I think that needs to change too. I don't recommend prison time, but maybe just some humility?
Bankers do the same thing: Past performance is not a guarantee of future results, and I get they're just doing their best, so why don't they put their own money in the same pot?
Heck, we expect the cafe to refund our coffee if they mix it up wrong, so why can't we just push that message upwards?
I disagree. Bugs are created and will be created; it is up to the proper process to test the system and get rid of them. A bug that goes into production code is a collective failure. Why do you blame the programmer, but won't blame the tester, or the guy who designed the test, or the guy who designed whole workflow, or the architect who planned the system?
Where did you get the idea that I don't?
I think people make mistakes sometimes (myself included), but I don't somehow think that diminishes the mistake.
I also think the programmer has less responsibility than the architect, or the CTO (which is why we pay them more). I don't like that shit only runs downhill.
So it's a self-defeating strategy for a company to take. Only the desperate need apply.
Better to create an environment like the fabled NASA software lab, where individuals are never blamed -- only the "process". That will attract high-quality applicants.
I don't know. Maybe if we can get top programmers paid more to stop bullshitting we can do something about that.
But as long as they come and cry on stage about how we should trust them and help them make the world more "open and connected" I guess it makes it okay.
If the NSA, Sony and the Director of the CIA can't protect their data, how am I supposed to realistically ensure less educated\tech savvy family members, customers, employees protect theirs?
Even if everything leaks, and there is a story everyday of the week for anyone paying attention, things have become too big to fail.
It's like the Steve Carell character says at the end of the 'Big Short' - "There's going to be a bailout. They knew the taxpayers would bail them out. They just didn't care. And in a few years we'll go back to what we were always doing...blame the immigrants and poor people"
I'm not happy about the status quo, and I'm becoming increasingly convinced that combining criticism and humility is the only way out.
On the other hand, this problem is not specific to only Dell. Take the online web-forms of any other major Tech seller like Asus, Samsung, Motorola or HTC and their website sucks. Almost every one of them looks poorly designed and unprofessional which is more worrying.
I know why Dell needs to do this, but the C-suite is responsible for dieselgate and this kind of thing needs to be developed smartly, with taste, and with a consideration about what can fail (and how bad it can get). Bread and butter: Encrypt everything, long audit trail; Sysadmins don't need to read the databases (and can log need for keys), engineering doesn't need to read personal data, helpdesk don't need to log into servers, and no service needs unauthenticated and unlogged read (even internally; e.g. for automated reporting); Get audited by someone competent.
I handled 1bn daily records with 100% uptime, and max 6hr delay reporting using a single server, so there is no excuse except an incompetent CTO.
The problem with these types of cold call scams is that they do not scale, it seems a bit odd that a group could target a company the the likes of Dell would resort to such tactics (And yes I am fully aware that they could've breached Dell and sold the data but then I'm not sure that phone scammers would be in their price range).
My bet would be on a 3rd party losing some data or getting hit, or even just employees doing it the really old fashion way print out couple of 1000's of profiles and go to work your operation most likely wont scale much beyond that anyhow.
But in general allot of that info could've been fished even the Dell support tag. Dell's own support website has an auto detect feature that scans for it on your machine it supports .NET HTTP distro app, ActiveX and a few other plugin methods and if you have the Dell Support bloat ware installed I think even JavaScript could potentially work.
(Don't remember if Dell was affected but over the years multiple laptop vendors were found to leak support info over LAN/Ethernet as they run various services both during boot and later through the bloatware they ship the machines with)
If you have the support tag you usually can access old tickets opened on that tag either online or by social engineering their support team (With IBM support in the UK if you have the S/N you'll see all past tickets in their system) the rest of the data like name and phone numbers can be found out quite easily.
So if you want to scam people by pretending to be Dell support you should be able to do it without actually needing access to their customer DB.
I, too, have received these "Dell" tech support calls and angrily yell at them as I hang up within 15seconds.
Lately though, I received a bombardment of calls (15 to be exact) in the past 3 days from the same number. I answered the one of them, and it had the same 1minute 10s message saying to call the number back regarding a computer threat they found on my computer (the voicemails are all 1min 10s). These calls woke my kids and I up every..damn..day. The calls kept coming on my work and personal line. Without dialing back the number, I'll never know how this crap even started.
I feel bad for others out there who may actually fall for these kind of tactics
But for people? I try other means of time wasting, so they can't call someone else to scam them.
Last time they called, I told them that it was good that they called, because my computer had detected a virus on their computer and that I wanted them to download an install malware.exe to remove it.
Next time they claim to call from Microsoft, I think I'll tell them I'm glad they've called, because I really need to speak to Bill Gates. Or if he's not available, Steve Ballmer.
I guess Bill might not answer his own phone any more, but I have to admit that I wonder what Bill does if he gets a call from them?
Maybe next time I should say that I'm Bill Gates and they're all fired?
At least this is more amusing than simply hanging up in disgust. And it helps slow down the rate at which they scam new people, even more so the more people who do this.
Tried to do a reverse phish and connect to their TeamViewer[0] but I didn't have time.
At least for an hour I bothered them by being the most clueless user I could get myself to be, "mistyping" urls so I ended up on tech websites instead. I also made notes to add to my previous guesswork on how they manage to fool users.
[0]: Yep, that or another seemingly legitimate remote access tool is what they use around here. Why TeamViewer cannot stop them I have no idea, these kinds of connections (India(?) to rural Western Europe) should stick out like a sore thumb in the data sets IK would guess?
I'd guess the opposite: there are enough legitimate outsourcing firms in India that traffic from fraudsters blends in pretty nicely.
Off the top of my head typical TeamViewer usage should be more like some new, some recurring I think.
I have never been harassed like that, but I have often wished for a feature like that.
Go into your router settings through which you use your landline (or the settings in the phone app on your phone), it should look like this http://www.digiversum.de/wp-content/uploads/2012/05/Rufsperr... and then add the number you want to block.
Maybe its really high time for C and its buffer overflows to go... And SQL injection.
We're tech savy here, yet sometime even we fall for these things. Its starting to get actually expensive.
I hate to be all conspiracy theory about this, but if/when the banks fall down like this....
Because no one ever wrote an insecure website in Java? And certainly PHP must also be completely safe since it has no buffer overflows to worry about.
Are you sure the language is at fault?
When simply trying to concatenate 2 strings can result in arbitrary code getting executed, memory leaks, actual data-loss or fatal program instability (or all of those), it's pretty obvious the C language itself is made out of shotguns.
Making simple things simple and safe will produce fewer errors and fewer security issues. I don't see how anyone can try to argue anything else.
The length of the string is however by convention determined by the first NULL byte (zero termination), so it is important that there is a NULL byte within the bounds of the allocated array.
Concatenating two "strings", is not particularily difficult, it just needs to be done with care.
If you find it complicated, then you should not use C, nor should you use it for things it's not intended for.
In theory, string handling in C is straightforward enough. In practice, string handling in C is the source of a crazy number of security vulnerabilities and other bugs, even in popular and relatively well regarded software written by experts.
No-one should still need to use C in 2016. We know how to fix many of its problems and create much better programming languages now. Unfortunately, there is so much momentum behind the C ecosystem that in reality there are few practical alternatives yet, at least for low-level systems programming or high-performance number crunching work. Worse, there may not be enough commercial justification for the few organisations big enough to significantly move the industry in a better direction to actually commit the resources to do so, and this seems unlikely to change unless and until influential people start to care about the real costs of poor quality software.
Rust.
Driving home is not particularly difficult, it just needs to be done with care. Consequently tens of thousands die every year doing it.
Really, it's probably the case that if you find it simple, you shouldn't be using C. You will make mistakes doing that, and if you don't think so, those mistakes will be released.
Now, about things C was intended for... It was intended for everything. Nowadays we have better options for most uses, but it was indeed intended for web development.
You are hitting the hammer where there is no nail! In this instance, the Dell WEBSITE was hacked which are (99% of the time) written in high-level programming languages like php, python or Java. No sane business uses C/C++ to develop a website. C/C++ is used for INTERNAL SYSTEM PROGRAMMING and those systems are already linux based and almost impossible to hack (Even in the rare instance that they DO get hacked, C/C++ has nothing to do with it).
According to CVEDetails the Linux kernel has 1338 (known) vulnerabilities. http://www.cvedetails.com/product/47/Linux-Linux-Kernel.html...
Pot. Kettle. Black.
> In this instance, the Dell WEBSITE was hacked ...
I saw absolutely nothing in the article that could even remotely be considered proof of this.
Making things simple and safe is what leads an average careless programmmer to develop insecure websites. It's not simple to write a non trivial website that is safe for sensitive data. And the language is a small part of overall system security.
There are lots of alternative "safe" string libraries for C, so string handling is not a good argument against C.
"another dangerous dell root cert dicovered" http://www.pcworld.com/article/3008478/security/and-then-the...
"dell attacks on scada doubled" http://securityaffairs.co/wordpress/35967/hacking/dell-attac...
"in what some experts are calling the biggest data theft in US history." http://www.abc.net.au/news/stories/2011/04/07/3185296.htm
It should be illegal for anybody to spoof Caller-ID for deception. The only acceptable caller-id transmitted should be one of:
a) the actual origin number;
b) the number for a company switchboard that accepts incoming calls to the originating group; or
c) blocked number.
Not quite sure I understand your premise on that one. You can't stop people from pretending to be from the IRS any more than you can stop criminal activity by outlawing it.
Essentially anyone can call anyone else and pretend to be from a government agency. Ultimately you're going to have to verify that or otherwise know better, there is no practical technical means to stop it. There's a certain level of personal responsibility that comes into play there. That goes with similar things like falling for investment scams over the phone as well. Such should be pursued by the authorities obviously - and you're still responsible for your own person regardless, you can't be saved from everything: the IRS doesn't call people like that, it would take 30 seconds to figure that out via google. The same type of problem would arise if an impostor showed up at your door pretending to be from the IRS. How do you stop it completely? You don't, you arrest after the fact if you can; if it gets widespread enough to be a big problem, you attempt education outreach to teach people not to fall for it. These types of scams are ancient, and will never stop existing (the scammers will always adapt); the only highly effective means of stopping it is awareness.
But that doesn't mean there's no solution for tracing calls. It needs just one extra law for telcos to solve most of this issue: "Either you can prove/point to the interconnect which originated this call, or you take full responsibility for this call and its contents." Then law enforcement can just continue to the next company and the next until they get to the subscriber.
Two answers to questions I expect: - What about international numbers? If you get a call from Russia claiming it's IRS, that's really not plausible - that can be understood by everyone. If telco gets a call from Russia with US callerid, then again, its their responsibility to only choose partners which they can query to check if that's valid. (it's not a huge barrier - telcos are already aware of various international issues)
- This will require registration of all subscribers with real details, what about privacy? Yes, yes it will.
Whether or not a call with domestic looking CPN from an international location will be accepted is up to the switches handling it, but they're designed to successfully complete a call in almost any possible circumstance. It's possible that the international gateway might rewrite the CPN field with something else, but I doubt they'd go as far as refusing to let it through.
The screen parameter within SS7 details whether or not the CPN field has been defined by the end user. Most SIP users won't have access to this either, but the vast majority of calls from them (but not from other sources) will look like the number is user provided. For that reason, some voicemail systems that've historically let you log in automatically just by setting your CPN to the subscriber number have started to only let you do that when the screen parameter is set to network provided.
The security there is in the type system at compile time, no Trusted Computing shenanigans, and you still avoid buffer overflows and SQL injections (if you use them properly).
Even something as lowly as Python mostly protects you from buffer overflows.
> That is not what either Rust or Haskell are.
Nor even Python.
What I am talking about is that some languages make writing safe code easier, that is code that behaves well as a program when compiled to machine language (or interpreted as is). Especially in the face of hostile inputs.
As an example, it is pretty hard to make your Python interpreter crash with a segfault using just pure Python code. (It is, of course, easy to generate a Python exception.)
Even though, this safety doesn't come at the expense of power: it is easy to tell the interpreter to get out of the way and let you muck around with raw bytes (ie by calling into C).
In the case of Python, the safety-by-default comes at the expense of performance. In the case of Haskell, it is either performance or program complexity. (Ie you can write fast Haskell code, but it looks weird.)
If you do call into something low level, it will be clearly visibly in your code that something potentially dangerous is going on.
Safe and correct behaviour by default is good. Profiling can help you find the few spots where you want to take over safety obligations from the automatic systems in return for extra performance.
Being secure against that kind of attack is going to require an entire paradigm shift in how we approach security. New languages, new operating systems, and new assumptions about how much an attacker has compromised, including learning to keep things heavily compartmentalized.
I reported this to Dell and got back a very dismissive, abrasive email saying something to the effect of "Well how else are we going to let people unsubscribe?", claiming that they had no other legal option. I just changed all my info to junk and left it at that; eventually they closed that hole, but it wouldn't surprise me if some site exists that still allows people to harvest anybody's information from Dell using nothing but their email address.
Sadly gmail has removed the spam from so long ago and the initial Dell contact email must have been sent from a form as I only have the service desk reply with my correct shipping number to track myself.
This might be even more serious than it looks.
Given wrong numbers and that many people won't answer the phone, be near the computer, have time at that moment, or be willing to cooperate, and then add the time it takes to talk an end user through such a process, will they gain access to even one computer every 2 hours? How can that pay off?
There are many, many more efficient attacks. How about good old-fashioned spam?
My assumption is that the scammers are based in India or somewhere else where dollars go quite a bit farther than the US. Even apart from the potential for fraudulent charges, spending a few days to earn a few hundred dollars is definitely worth it in a country where the average income for a year is around $1300.
More often than not a company thinks they're compliant but then after a break-in is found to be lacking something big like hashing passwords.
I find this very hard to believe. At face value I interpret this as saying that no company doing business in Sweden has any sort of customer database. Is this correct?
What about a CRM system?
You can for example only have someone in your CRM if they are a customer. And if they ask you to remove their data, you must remove all information about them.
You do not have to worry if your company and all your equipment is located outside Sweden though. But as for example Facebook have a data-center in Sweden, you can actually request them to remove all your data.
Example of illegal database is a database for direct marketing. Or a register of race, religion or preferences.
Here in Greece (and most of Europe AFAIK) manufacturers don't sell directly to consumers, hence my confusion.
It seems DNS this was hosted on godaddy, but can't see the content now.
It was pointing to shared hosting on dreamhost.
The domain will expire in August, so that is not the problem.
The domain is in status clientUpdateProhibited, clientTransferProhibited, clientRenewProhibited, clientDeleteProhibited... the whois has been updated today.
Maybe this site was put down?
Thanks !!
We've blocked this page
O2 Wifi takes public wifi seriousl..
From what I can see from a bit of Googling, Dell does pay their tech support people decent money. If Glassdoor is to be believed [1] [2], Dell tech support people in India make about 340k rupees a year, or about 28k per month.
That appears to be a middle class income for an Indian city dweller [3] [4].
[1] https://www.glassdoor.com/Salary/Dell-Technical-Support-Asso...
[2] If the above link does not work without you being logged into a Glassdoor account, try Googling for "how much does dell pay tech support people in india" and clicking the Glassdoor result.
[4] http://www.pewresearch.org/fact-tank/2015/07/16/are-you-in-t...
That would put them squarely in the upper middle bracket in India.
Almost everywhere in the world had been doing business for thousands of years before the US existed. It's pretty careless to say that Asians are not 'familiar with business practices'.
They may not be all about your business practices. If yours get too weird and uptight they'll just return to doing business with the rest of the world and won't miss you too much.
Sweatshops and de facto slavery isn’t everywhere, but you’re kinda right, countries which were colonies before – mostly in Africa, Asia and South America – tend to have less wealth and prosperity.
The US, Canada, and Australia are rather prominent counterexamples.
And even in some of these countries the wealth and prosperity for the native population has been an issue even in the past decades.
The ones that survived have gotten, and are still getting a pretty poor deal, too.
EDIT: let's say you did, even though I doubt it. Even then I feel that it's pretty obvious that I was referring to familiarity with western business practices (and laws) and not business practices in general.
And Dell isn't some too-cheap-to-be-true, fly-by-night operation. Saying that their customers were basically asking for it is bollocks as well.
Desire, maybe, but expect? That's so far from reality are there any grounds for expecting that these days? Has any company successfully kept /all/ sensitive data from hackers?
Complaints got so bad that they re-established the Round Rock organization for corporate customers; retail buyers were still stuck with the offshore staff.
I can't understand why these overseas call centres are do terrible! I don't want to resort to racial stereotyping, what is it though that cause such dreadful customer service experiences?!?
This is a terrible idea. How do I determine what is decent money enough not to have my information leaked? Do I have to buy Macs for life in order to prove that I don't want my information leaked? that's silly!
Can you provide a citation to support your claim about business ethics in India? That's a rather negative statement about a large number of people. I've downvoted your comment but I'm happy to reverse that if you can back up your claim.