Buying a Samsung TV Online Could Jeopardize Your Data (cnet.com) 30
An anonymous reader shares a CNET report: If you buy a product from Samsung's online store, your name, address, order information and other data may be accessible to anyone who cares to look. Matt Metzger, a self-described "application security engineer" who said he has worked in shipping-industry compliance, wrote Wednesday on Medium about an accidental discovery. Metzger said he ordered a TV from the Samsung online store and was sent a URL to track his delivery. When he followed the URL, he discovered that his tracking number was the same one used for someone else's previous delivery and that he could see sensitive information, such as the person's name and items ordered, without any security measures getting in the way. Metzger also discovered that more information was attached in a TIFF file to his own order after the delivery was completed. The file included his full name, address and signature.Samsung told CNET it is aware of the issue and is looking into it.
Re: (Score:1)
Yeah, but a 1990's style flaw in 2017? It's like they're not even trying.
Amazon rules (Score:3)
No one is trying, it seems. Except Amazon — the only online seller I know, with advanced features like order-correction after placement, etc.
Maybe, Samsung really should quit trying — stick to manufacturing, which is their area of expertise, and leave retail sales to professionals in that area.
Re: (Score:2)
It's Samsung. Why should their Webpage be more current than their products?
Slashdot isn't even trying (Score:1)
Re: (Score:2)
Re: (Score:1)
A flaw has no website. Is this what a girl wishes?
Re: (Score:2)
*sniff*
If only Mielke could be alive and see how much we learned from him and how we improved beyond his wildest dreams.
And your home (Score:3)
Re: (Score:2)
As long as you don't get punished for carelessly losing customer data, it's not a liability. At best it's something you can sell. At worst it's something you don't give a fuck about.
Re: (Score:2)
That happens way too rarely to register in risk assessment and management. Look at Sony and how many blunders they had. And? Not even a dent in the sales.
Legal punishment is the only one that is reliable enough to make corporations care. Because it WILL happen, there is no uncertainty involved.
Another BS headline. (Score:5, Informative)
If you ordered from Samsung's store (Score:2)
If you buy a Samsung TV: (Score:2)
No problem (Score:3)
I buy all my AV gear out of the back of vans in parking lots.
Re: (Score:1)
Such clickbait (Score:1)
This is an absurd article.
Having just bought a TV from Samsung, This is one of many shippers that Samsung uses. It is no different from UPS, FedEx, or any other shipper. The IDs sometimes get re-used, and that will include some identifiable information.
This is in no way Samsung's fault... Any more than anybody else that uses this shipper.
Sheer click bait.
Should AGI fix their tracking system to be more secure? sure. Does it have anything to do with Samsung? No, not really. I mean, as a customer Samsung shoul
Re: (Score:2)
I am officially done with this shitty site, I won't be checking to see if I got voted down, I am logging out & never coming back. I submitted this nearly an hour before, but yet this one gets posted instead; so fuck slashdot, and fuck all the owners, they can all go fuck their children which I know they love to do!!!
Don't let the door hit you in the ass on the way out.