Samsung Recent Security Incident
samsung.com
samsung.com
That's all you need to steal someone's identity. Major reason why I never give any website my real birthday, and use a password manager to remember all the various "birthdays" I've been required to provide for no ostensible reason.
If we wanted to hammer out a quick and effective privacy legislation, it would be: you need a demonstrable reason to ask for someone's birthday (e.g., legal reason to validate you're old enough to open a bank account or whatever), not "i want to send a happy birthday newsletter every year (and also sell it in a package to data brokers)"
I wish we could stop propagating the idea that it's possible to "steal someone's identity". No, you cannot take my identity from me, I am who I am, you are who you are.
What you can do however, with those details, is tricking companies and committing fraud. But it should not be up to me to make sure companies are not being defrauded, the burden is on them to prevent that.
Name, contact information and date of birth are so basic level of information, that if you can commit fraud with just those details, something is seriously wrong as the company you're performing the fraud against.
Some countries even have those details publicly for you to find via public websites. So again, if that's all it takes, the company is doing something seriously wrong.
I recommend contacting the credit rating agencies and getting them to place a note on your record with a password, eg. [1]. Don't wait until someone "steals your identity". It's the only way to get these companies to do something resembling an actual identity check. Doing it after they've lent in your name (as the rating agencies suggest) rather defeats the object.
[1] https://help.equifax.co.uk/EquifaxOnlineHelp/s/article/Howdo...
In countries where this doesn’t exist, obtaining credit requires providing proof of income (payslip, etc) to the lender which they verify. A mere name/address/date of birth might be enough to open inconsequential accounts such as loyalty cards, but will absolutely not get you credit - therefore the damage to identity theft victims is greatly reduced or even nullified.
Bad payers are still penalised even without a credit bureau system by a register the government operates onto which a debtor is registered for a certain period after legal action by a lender (so this requires significant effort from the lender - you don’t get on this register because of a telecoms billing mishap for example).
With regards to setting a password, I wouldn’t trust CRAs to enforce this. What you can do however is pay for CIFAS protective registration - it’s usually for victims or those at high risk of identity theft but there’s no legal requirement so anyone can pay the admin fee and get added to the register. Lenders check this during credit applications and this puts an instant block on any kind of automated approval and requires them to do further verification.
That only works because of low friction lending.
They tell you not to tell anyone your EMŠO... but EMŠO is generated from your date of birth, gender, former yugoslav republic you were born in (slovenia=50) and the sequental number of your birth that day (0-499 boys, 500-999 girls)... plus a checksum. So if you were born in slovenia, are a boy, and were a third boy born on 20th december 1970 (970... because why waste numbers?!?!), your emšo would be 201297050003K (K=checksum, too lazy to calculate).
We also have a tax number, that they also tell you not to share... but then you open up an independent contractor business (technically, it's a not a seprate company, but "you" are the company), and your personal tax number is published in many many online systems, info pages, you have to put it on receipts, ads, you have to tell it when you're buying toilet paper for work use, etc.
But yeah... if you want to open a bank account, you need a government issued id card (or passport), and they check it very very throughly.
Tax number NIP is relatively public, any relevant accountant will have it.
The remaining secret thing is indeed the ID card and/or the passport. That's why if it ever gets lost or stolen you're supposed to immediately file for a replacement. Theoretically at that point someone might impersonate you.
Why not share, if it's so harmless? Isn't that the point you're trying to make?
https://www.ratsit.se/19290708-Bertil_Thomas_Andersson_Taby/...
> Bertil Thomas Andersson - 1929-07-08 (93 years old) - Address: Lyktgränd 2 lgh 1706, 183 36 Täby, phone number 070-208 35 86
The website also adds information about income:
> (machine translation) In Täby, Bertil Thomas Andersson's home municipality, there are 5218 income millionaires. The proportion of people with payment notes in his postcode 183 36 is 7.3% and the average income is 295 679 SEK ($27,378) per year.
If the person runs any companies, that would be visible as well.
All of this is public information, for each individual and company in Sweden (except the ones that have requested to not be visible, or are protected)
Identity theft is a term that comes from the fact that you can use this information to open up a bank account or become someone digitally, not because they steal your personality.
It’s a great term because exemplifies the gross negligence and liability that comes with egregious misuse of personal data
By calling it identity theft, we are saying individuals are the victims and should protect the banks from someone pretending to be them.
Edit: I also believe there was an argument that banks reporting to credit agencies based on fraudulent activity from a 3rd party should be treated as libel.
This is interesting - do you know if it has ever been tested?
As I said, those details, including address and more, are public in some countries. Those countries have learned to live that just being able to say my name, date of birth, address and telephone number is not enough to open a bank account, why can other "modern" countries not adjust accordingly too?
There is a reason why the majority of these frauds are US based
Now if they do that, changing in particular the latter is rather hard.
This is very close to "stealing" your identity — in that you yourself don't have the ability to use your identity any more in any useful way, because your identity is now (legally) dead.
Then again, they don't possess it after that point, either. So maybe it's more like "identity destruction" or "identity defacement."
India has/had a loophole that scammers use to declare someone dead and steal their property.
https://en.wikipedia.org/wiki/Uttar_Pradesh_Association_of_D...
(Both of which is easiest done by compromising a doctor fully. They have access to ID database.)
Pretending the catalyst isn't culpable in the indirect effects of identity theft is every bit as wilfully obtuse as pretending the institutions aren't.
There is more than a trivial semantic difference between "identity theft" and "bank fraud". The former very clearly identifies the victim as being the individual whose data was used, while the latter makes the victim the bank. There's a compelling argument to be made that it's unreasonable to expect any of the information that we have come to associate with "identity theft" to actually be private any more after repeated data leaks by Equifax et al. And if we cannot expect it to be private, is it fair to drag individuals through hell and back when someone successfully defrauds a bank using their details? That's the question being posed by OP, and the semantics of the terms we use are central to resolving it.
Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's using publicly available information to trick gullible banks.
identity, n. 4. "the state or fact of being the same one as described."
Those companies aren't trying to verify that information for its intrinsic suitability, and their goal isn't to facilitate a transaction with someone who merely has all of someone else's personal information- they're trying to make sure the person engaging in that transaction is the person indicated on the form. If they switched to say, a finger print, voice sample, DNA, and an in-person interview with an ID check, they would still be trying to validate your identity.
> stealing an identity isn't actually possible. What is possible is legally persuading a bank that you are someone else.
That's like saying murdering someone with a gun is incredibly difficult because unless you actually beat them to death with the gun itself, you're just aiming and pulling a trigger, which isn't even illegal in many cases.
Theft:
steal, v. 2. "to appropriate (ideas, credit, words, etc.) without right or acknowledgment,"
Appropriating your identity for the duration of a transaction certainly fits.
> Calling it identity theft when all someone has to do is get on to one of the many public data leaks and find your information is weird. It's not some kind of heist, it's using publicly available information to trick gullible banks.
Nothing in that definition requires the thing in question was suitably protected or appropriate for the job. Nothing requires that it be permanently stolen or that anything be removed from anyone's possession.
---
I agree that the data and mechanisms used are not up to the task, but only using arbitrary definitions of theft and identity and looking at the mechanisms of theft while ignoring the purpose of those mechanisms doesn't mean the term is wrong or that people aren't, by definition, stealing people's identities. You don't get to decide that people can't use specific, existing dictionary definitions to evaluate whether a term makes sense. And that's just from a technical perspective-- English is a descriptive language and terms mean what popular usage dictates they mean.
So unless you have some convincing arguments that nothing, by any definition, was stolen, that personal data wasn't being used to determine identity, and that the colloquial usage of the term doesn't actually matter, then identity theft is undeniably the correct term. The heistiness of the acts, other non-applicable definitions of the words, and the suitability of the methods of verifying identity are entirely irrelevant.
Not much help for the American cousins, but this already exists throughout Europe and has done for years .... its called GDPR.
TL;DR : If it is or it is tied to PII (personally identifiable information) you have to:
(a) Justify collecting it in the first place
(b) Justify storing it, and storing it no longer than necessary
(c) Obey with the "right to be forgotten" and delete it on requestAlso, don't forget that these laws also have requirements on you keeping logs, most of the time 3, 5 or more years. So yeah you have to obey a deletion request when that time is up, not "on request" - that would be illegal in most cases.
In many EU countries birthdate (and more) is public information, btw - my own birthdate is made public by the state itself (on the business registry website), together with my name and residence address. Same for any owner of real estate - be it land, house or unit - names, residence addresses and birthdates are publicly available in the online cadastre.
That is simply not true, not in this very general formulation. What businesses does this statement of yours apply to?
It's certainly not common for an ecommerce site to ask for your birthday on signup.
You picked about the only remaining thing where it's not always a requirement. It's a requirement even there if the transaction is over certain threshold (varies by local law, usually around 10k EUR) or certain categories of items (drugs, alcohol, tobacco-related, sextoys, weapons etc).
They even at times busted telemarketers using databases, much less something grave like this.
Of course you better have a good description and consider that bureaucracy moves at the speed of bureaucracy, somewhere between a snail and a plant.
Put credit freezes on yourself and maintain them that way as the default. This cuts your attack surface significantly. Plant your flag with any large government entities that are used for collecting benefits (IRS, your state's stuff, etc.)
Do I love the state of affairs? No, but if it were something I worried about, I'd at least make myself a hard target.
What does this mean?
https://www.consumerlawfirm.com/credit-reporting-agencies.ht...
'Nationwide', 'Check and Bank' and 'Supplimentary/Alternative' are probably the minimum.
I wish we had privacy and security by default instead of "opt in"
I have this information for many billionaires. Now tell me how to steal their identity. I would like to live their life.
This is making the problem worse I think.
I get all kinds of account sign-ups, and also home purchase paperwork and sheriff's office employment offers, from multiple states.
I used to feel bad, and spent a couple years trying to get in contact and correct whoever used my email.
Now? Fuck em. If you use my email, it's my account. I just deleted "my" Roku account and unsubscribed to the services attached to it (required to delete an account).
Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address.
>Me deleting "your" account is the least-abusive thing I could do if you sign up with my email address.
This is illegal, CFAA of 1996.
Them signing up with your email is a mistake, you deliberately modifying data that isn't your own because of that is illegal.
Same if you were confused by "your" Roku account, so you decide to remove it.
Mind you, if Roku doesn't want to do business with you, there's no correct way to trick them into it
Think of it like an ATM that suddenly thinks your balance is 5 quadrillion dollars, and you empty it because if their system says you have it, then it's your prerogative to appropriate those funds, according to your assertion. Unfortunately, this is not how the courts have decided this should be handled. In US v Auernheimer the question is whether publicly accessible and sequential (read: guessable) routes being accessed by those they're not intended for is criminal. The improper venue appeal has nothing to do with the essence and spirit of this segment of case law, it means that the suit was brought forward improperly. That act itself was deemed criminal, otherwise Auernheimer would have remained safely in Arkansas rather than absconding to the then-stateless Republic of Abkhazia.
Saying all of this, it is important to me that I communicate to you Ethbr0, that I'm responding objectively and not at all trying to tell you that I feel one way or the other, or that I am judging you as criminal. If that's how this was taken, I wholeheartedly apologize. You are free to do what you want, and you're granted the right to speak freely publicly. To me it doesn't seem like a good idea to say what you said, and I would not act similarly, but I will not judge you for doing what you feel is right.
Which stands to reason and is in line with my understanding of the CFAA: that circumventing and breaching security is a crime, but the severe penalties kick in when one shares the results of those actions.
I'm not sure it is. The system you are accessing is not the user's, it's the company's. The company let you in with your own email address.
Discord was horrible about this. They kept sending automated emails about someone else's account, because the user signed up with my email address. I told them it wasn't mine and they should make the user fix their email address. Instead, they asked me to confirm I wanted to delete the account. I refused, telling them it wasn't mine. This all happened in Spanish, because the user spoke Spanish, even though my inquiry was originally in English.
So clearly, not all companies care all that much who you are and will freely let you take over other people's accounts.
Can't we just fast forward to the part where they send me a $5 check for the class action settlement? They'd save a ton on legal fees.
I find it insulting to offer a credit check. If I wanted, I would get 20 credit checks just this year. Credit checks are also (mostly) free. Everyone and their mother offers them.
Why would that do me any good for checking? How does it remediate or mitigate the loss I have?
I'm pretty sure the US government offers them for free, and anyone else doing it "for free" is only using at a means to collect and sell your personal information. Using some random site like getmemyfreecreditcheck.com or whatever is pretty much asking for your privacy to be violated.
> "Roughly twice per second, a Roku TV captures video “snapshots” in 4K resolution. These snapshots are scanned through a database of content and ads, which allows the exposure to be matched to what is airing. For example, if a streamer is watching an NFL football game and sees an ad for a hard seltzer, Roku’s ACR will know that the ad has appeared on the TV being watched at that time. In this way, the content on screen is automatically recognized, as the technology’s name indicates. The data then is paired with user profile data to link the account watching with the content they’re watching." (https://advertising.roku.com/resources/blog/insights-analysi...!)
"Advertisers want to know when their ads are being viewed"
- "We could work with advertisers to have them add some metadata to the output signal, and detect that on the client"
"Nah, let's just record everything everyone watches, that way we can harvest the data and sell it to advertisers we haven't yet partnered with in the future"
- "Yes, that sounds like a perfectly reasonable thing to do and couldn't possibly have any negative consequences. That is unless consumers have a problem with it..."
"Who?"
Still though, people watch home video of their kids on their televisions! Some people make home-made porn for their own enjoyment.
Meanwhile somewhere in a data centre in South Korea...
I have an LG TV that I rooted using a vuln in the browser, I got ad-free YouTube, and supposedly less telemetry, but other than that I'm not sure there is a Better option.
The tricky part is finding the places that sell them.
https://www.consumerreports.org/privacy/how-to-turn-off-smar...
Not instilling a ton of confidence.
> Why does Samsung have my data?
> We collect information necessary to help deliver the best experience possible with our products and services. We know how important privacy is to our customers, and we provide information about how we're planning to use customer data, in strict compliance with relevant privacy laws. You may visit the U.S. Privacy Policy section of our website for more details on how we may obtain data and for what purposes: https://www.samsung.com/us/account/privacy-policy/.
> Information we may collect automatically includes information about
>· your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software version, MNC, subscription information, and randomized, non-persistent and resettable device identifiers, such as Personalized Service ID (or PSID), and advertising IDs, including Google Ad ID;
>· your use of the Services, including clickstream data, your interactions with the Services (such as the web pages you visit, search terms, and the apps, services and features you use, download, or purchase), the pages that lead or refer you to the Services, how you use the Services, and dates and times of use of the Services; and
>· your use of third-party websites, apps and features that are connected to certain Services.
So essentially, they're saying that they can log everything that you do on your device.
When I got my first Samsung phone, it came with Samsung's keyboard installed. I looked at the privacy policy and saw that it was sending every single keypress to some third party whose privacy policy said it was used for market research and to guess at things like the education level and intelligence of the user. Who needs malware when Samsung ships keyloggers. I uninstalled it then did the same with every other Samsung app I could. They obviously don't care at all about people's privacy. On the plus side, I found some great apps that way like simple gallery pro and markor.
https://www.samsung.com/us/privacy/ccpa/
I was surprised I even had a Samsung account so I can't think of any reason to keep one after this.
I don't know what the solution is exactly though ( I mean how to effect actual change instead of posting in this forum ).
[1]https://www.ftc.gov/enforcement/refunds/equifax-data-breach-...
The credit system is a scam anyway. Oh wow thanks Equifax, you think I should be allowed to go up to my eyeballs in debt. What an honor, I'm flattered.
Every company, always.
An absurd, insane message.
We know your stuff not catching on fire is important to you. That’s why we gather it up into large fpiles, then do the minimal we’re legally required to technically avoid committing arson. For more information on how we and our trusted partners douse our pile of your stuff with gasoline while using our warehouses to hotbox cigars, weed and crack, see our 1000 page “not stealing and then getting high and catching your stuff on fire policy”.
Samsung , your carelessness put many lives in danger!!
I have a Samsung from three years ago. I don't want to upgrade or replace it until it actually breaks, as constantly upgrading phones strikes me as wasteful. However, when I see this shit as well as all the Samsung apps they don't let you delete or disable from your phone, I am very tempted to just splash out on a Pixel to install GrapheneOS.
At this point I would recommend a Pixel of any variety. It's much much simpler to root and get GrapheneOS installed. Save yourself the headache (and the data leaks).
No. No matter how safe of how carefully you take your security, a vendor should NOT keep these pieces of my private information with them.
You can't expect common people to be reasonable and spontaneously boycott abusive vendors. Most people are not educated enough for that. Among those who are, most don't care.
We need laws to prevent this kind of abuse so vendors can't take advantage of people who are willing to share such information even if they are knowledgeable about its implications.
Clarify that all EULAs are null and void unless they have been reviewed with counsel, signed, and notarized to ensure the user understands what they are agreeing to.
If the companies want to treat them like contracts, so should the other party. Otherwise, it all stinks of duress.
The email for my request is towards the bottom of this page: https://www.samsung.com/us/support/securityresponsecenter/
I am aware this does not fix the problem of the already stolen data, but it might make the data collection cost/benefit analysis in favor of discarding collection all-together. Maybe. Let me dream, would you?
Sounds like "we got ransomeware'd".
> FAQ: Can you tell us more about what specifically happened? In late July 2022, an unauthorized third party acquired information from some of Samsung’s U.S. systems. On or around August 4, 2022, we determined through our ongoing investigation that personal information of certain customers was affected. We have taken action to secure the affected systems, and have engaged a leading outside cybersecurity firm and are coordinating with law enforcement.
Complying with the law is the bare minimum.
I couldn't find a way to close an account, but this is probably the next best thing.
Reset password > get into account > delete the account.
A useless account that i shouldn't have used anyway.
Pixel + Calyx FTW.
Samsung shipped so many millions of phones with insecure encryption:
> your device, including MAC address, IP address, log information, device model, hardware model, IMEI number, serial number, subscription information, device settings, connections to other devices, mobile network operator, web browser characteristics, app usage information, sales code, access code, current software version, MNC, subscription information, and randomized, non-persistent and resettable device identifiers, such as Personalized Service ID (or PSID), and advertising IDs, including Google Ad ID;
Regardless of how fake you think the information you gave them is, if you use your phone, there is more than enough information to attain a real identity and connect that to other identities.
IMEI alone will uniquely identify your device, and therefore you, and it will be connected to a phone company that is probably willing to sell your data.
https://arstechnica.com/tech-policy/2021/03/t-mobile-will-te...
Maybe some viewing habits data. In which case they'll probably conclude I mostly like cartoons about ponies and talking, people rescuing dogs...
Although it could scan for nearby wifi access points. Maybe also for bluetooth devices. It also got a microphone...
Business idea: A service to strip microphones and antennas out of brand new TVs?
Supposedly amazon set up an AWS service to leverage 5G (https://aws.amazon.com/private5g/) allowing significantly more devices. The idea being that our fridges, TVs and other household devices could talk directly to a private service without having to be subject to your in home firewalls/DNS blocking/etc.
If they have collected any information from me, I never authorized the collection.
What falls under "product registration information"?
Nice way to gloss over how much ‘demographic information’ they actually collect…
—
In regards to this security incident; users accepted the terms and conditions, which includes (usually in detail, or lack there of) their handling of the outcome, and impact to you.
It’s a horrible situation. Im not saying it’s acceptable. however; I demonstrate so by not supporting (advocating, purchasing, etc) and accepting these outrageous terms.
This is not isolated to Samsung…
Our home is (wherever possible) a “Samsung” free zone, primarily inspired by their handling of the health incidents in their South Korean factories. Workers sick and dying, directly linked to the workplace.
After years of persistent pressure from the families of these workers, the outcome was a payout and a typical “sorry we got caught” announcement.
There has also been ongoing large-scale corruption in the head/leaders of the organisation, tied closely to South Korea in it’s entirety. It seems the outcome here is; “you’re really bad, but also really good… we’ll meet somewhere in the middle..”.
Ps; am aware that Samsung parts are often included with other brand solutions. Hence “mostly” above. I proactively investigate, and avoid at all costs.