Samsung Loses a Ton of User Data – Offers Nothing to Victims
makeuseof.com
makeuseof.com
"Please use the original title, unless it is misleading or linkbait; don't editorialize."
This really needs renamed. Samsung did not 'lose' anything. If I 'rm -rf' data without a backup, that is data loss. This is a breach in which the only loses is 'Samsung loses control of singular ownership of your data putting users at risk'.
Well there is DLP: "Data Loss Prevention is the practice of detecting and preventing data breaches, exfiltration, or unwanted destruction of sensitive data."
There is no reason for things to change if the liability is not on the company that loses the data.
However, the IRS assigns $0 to data. So long as that's the case there will be no liability.
How exactly is this meant to be "assuring"? Who cares in the slightest about credit or debit card numbers? The other stuff matters FAR FAR more.
Dear Samsung: What the fuck was stolen, exactly? Do you even know?
If you know the person’s exact name and city of residence you can use a supposedly legit service to purchase their SSN for $50. I won’t post it here, but should be trivial to find the name of company.
I used this service several years ago when a contractor tried to give my business an obviously fake SSN as he thought he wouldn’t have to report the income.
Address isn’t likely to change. Especially not due to a leak. Phone number changing is a PITA even if easier. Date of birth can’t change ever really.
Addresses are already public records because property ownership and tax records are public.
Samsung smartphones are good in terms of HW and custom ROM compatibilities. Terrible in OS and basically anything SW related.
edit just to make it clear because the downvotes are flooding in: it does not have any consequences for Samsung. Users are fucked of course.
How do I protect myself from such attacks on Samsung in the future?
Haven't tried it myself, but if you want to go further, they have guides for installing /e/OS or other OSes, they support that, and reverting to Fairphone OS if you wish.
https://support.fairphone.com/hc/en-us/articles/440585818958...
You could try running /e/OS on Anbox to get a feel of it and what can and can't be done? That's probably the simplest way forward.
(1) Don't make a Samsung account or otherwise lean in to the ecosystem.
(2) Much of that crap can be uninstalled or disabled.
(2a) There's more nonsense than you think. I replaced the camera and all sorts of things that shouldn't have been phoning home or displaying ads.
(2b) You need a mechanism for handling updates, since all that crap will come back and all your privacy settings will be reverted. You could automate the process the first time and just search for any new stragglers, but I just disable them and manually handle it when some sort of critical RCE comes out. You're not supposed to be allowed to disable them without nagware, so see (3).
(3) DNS blocking is a godsend. The crap you're unable to remove can be effectively neutered with a little work on this front.
(4) You might want a little extra userspace modification on top of that like remapping the Bixby button.
https://technastic.com/remove-samsung-bloatware-safe-to-remo...
Or these are also temporary?
The best way to prevent illegitimate data collection is to run software made by people who don't have it as their business model.
E.g.: Lineage OS.
In India, samsung reinstalls new garbage bloatware with every update. I have to take my mom's phone and uninstall every one of them after every update. Thats the only way they keep prices low I think.
†Contents of backups not assured. Data retrieval not guaranteed. No removal procedure. Access control is on a come and get it basis.
Pretty sure it's the app. If the soundbar is a plain Bluetooth audio device it shouldn't even need any other software than what is already contained in the device you want to connect it to. They however could have replicated or moved some of its controls on the app so that you're encouraged (if not forced) to install it and surrender your personal data in the process.
I hate that practice; almost every device or service today wants to install an app because it brings their brand on the phone main screen and gives full access to users private data. Besides privacy concerns, it can't scale: 100 products or services done the traditional way were 100 addresses in a bookmarks file that used a few KBs combined and no CPU power at all except for the browser (that is, just one app), now they are 100 executables that waste orders of magnitude more storage and can slow a device like molasses even when not in use; all this in the name of sticking a logo on the main page of a phone and exfiltrating users personal data.