Jump to content

Damn Dirty Dell. Potential leak allows scammers to know your personal info.

Source:
ArsTechnica

 

Quotes/Excerpts:

Quote

 a tech-support scam targeting Dell computer owners continues to raise questions about how the callers know sensitive information, including PC serial numbers and the names, phone numbers, and email addresses... uses sensitive details tied to their specific PC purchase, including the PC model, service tag number, and the contact information the customers provided at the time they made the purchase. Armed with those details, the caller has a much better chance of tricking the person into thinking the call is legitimate... According to an interview and posts made to Dell customer-support forums, the unusual scam continues now ... Neither the blog post nor the support website alert makes any mention that the scammers targeting Dell customers know sensitive purchase details. The spokeswoman's email also erroneously lumps the scams in with the "industry-wide" problem even though there's no evidence tech-support scammers are using customer data from other computer makers.

 

My thoughts:

This is clearly and obviously a data breach by Dell or an unprotected API. Dell should come clean with consumers and businesses based on their positions within the market place and industries (along others such as HP and Lenovo). This is an issue specific to them.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, rcmaehl said:

Source:
ArsTechnica

 

Quotes/Excerpts:

 

My thoughts:

This is clearly and obviously a data breach by Dell or an unprotected API. Dell should come clean with consumers and businesses based on their positions within the market place and industries (along others such as HP and Lenovo). This is an issue specific to them.

Or this information can easily be read and gained from malicious software that the users have come in contact with. This could be something as nasty as a .exe they downloaded or something as simple as a malicious java add or script on a webpage.

 

There are many much easier ways to get this information than targeting dell directly. If dell was breached and PII stolen then they are legally obligated to let people know. Do you think a company as big as dell would risk the backlash of NOT doing so?

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, AngryBeaver said:

Or this information can easily be read and gained from malicious software that the users have come in contact with. This could be something as nasty as a .exe they downloaded or something as simple as a malicious java add or script on a webpage.

I would think so however the fact is they know information not available on the computer such as purchase date, customer number (web only), email, phone number, and full first and last name. Additionally, reports have including information from the computer savvy. This is definitely NOT the cause of malicious software as the article states if read.

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Dell sells ALL of this info. We get calls all the time offering extended warranties on specific products right at the end of the warranty terms. Seems that all the major tech vendors sell and trade their customer data. 

Lets play connect the dots!

::::::::::

::::::::::

::::::::::

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, AGrider said:

Dell sells ALL of this info. We get calls all the time offering extended warranties on specific products right at the end of the warranty terms. Seems that all the major tech vendors sell and trade their customer data. 

Data that should not so easily be jeopardized by tech savvy social engineers.  

Link to comment
Share on other sites

Link to post
Share on other sites

Its not jeopardized, its for sale to anyone who asks. You can go buy that data right now. While it may be data about you, it is not your data.

Lets play connect the dots!

::::::::::

::::::::::

::::::::::

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, AGrider said:

Its not jeopardized, its for sale to anyone who asks. You can go buy that data right now. While it may be data about you, it is not your data.

Do you consider the last part of your sentence (While it may be data about you, it is not your data.) legally questionable? 

 

Let me be more precise, is it legal for a corporation to treat private data of individuals as their own?  I know it seems like a silly question, particularly when one considers the Cambridge Analytica fiasco, so you will be tempted to say yes, but I would like to be clarified on that if possible. 

Link to comment
Share on other sites

Link to post
Share on other sites

Its a Dell account, Dell controls what they do with it and how they share that data, not me. If I want the option to do business with Dell, I submit myself and my company to that kind of data use. What data about the dell systems they sold me isnt my data, its theirs, and they can choose to monetize that data without my input. 

Lets play connect the dots!

::::::::::

::::::::::

::::::::::

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, AGrider said:

Its a Dell account, Dell controls what they do with it and how they share that data, not me. If I want the option to do business with Dell, I submit myself and my company to that kind of data use. What data about the dell systems they sold me isnt my data, its theirs, and they can choose to monetize that data without my input. 

So the client has no authority over how their data is managed? 

Link to comment
Share on other sites

Link to post
Share on other sites

In the case of Dell, when you purchase from them you agree to that. They will provide the details of you and your purchase to third parties. Im not saying its right or wrong, Im simply pointing out that there doesn't have to be any maliciousness to happen for this data to be simply acquired through entirely legal means directly from Dell. It can then be used for nefarious purposes. 

 

 

 

Lets play connect the dots!

::::::::::

::::::::::

::::::::::

Link to comment
Share on other sites

Link to post
Share on other sites

Just gonna love this here, I know it's unrelated to this topic really, but it evolves Dell so I just have to.
 

Spoiler


HP AND DELL LAPTOPS ARE SHIT. DON'T GIVE THEM YOUR MONEY.

 

Well... That goes for the majority of Windows laptops, but ESPECIALLY Dell and HP. Being the family "tech guy" is a pain in the ass when you can't talk anyone out of these pieces of garbage. They never want to listen to me when a purchase is on the table, but a year later when the piece of shit craps the bed, who they gonna call?

 

But yeah, Dell sucks. The only positive experiences I've had with them were their Optiplexes from the 2000s. I've owned everything from GX100s all the way to gx780s and they were all solid as hell. Their laptops though, never EVER had a good experience. Not one.

 

i7 2600k @ 5GHz 1.49v - EVGA GTX 1070 ACX 3.0 - 16GB DDR3 2000MHz Corsair Vengence

Asus p8z77-v lk - 480GB Samsung 870 EVO w/ W10 LTSC - 2x1TB HDD storage - 240GB SATA SSD w/ W7 - EVGA 650w 80+G G2

3x 1080p 60hz Viewsonic LCDs, 1 glorious Dell CRT running at anywhere from 60hz to 120hz

Model M w/ Soarer's adapter - Logitch g502 - Audio-Techinca M20X - Cambridge SoundWorks speakers w/ woofer

 

Link to comment
Share on other sites

Link to post
Share on other sites

Oh I see, I appreciate the candor. One more thing before I forget, when you say "purchase from them you agree to that", are customers made aware, at least clearly, that their data will be shared by third parties? 

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, Deus Voltage said:

Oh I see, I appreciate the candor. One more thing before I forget, when you say "purchase from them you agree to that", are customers made aware, at least clearly, that their data will be shared by third parties? 

Every purchase has certain terms and conditions, some are more explicitly stated than others, some are merely implied by federal law; regardless, they're there.  For Dell:

http://www.dell.com/learn/us/en/vn/terms-of-sale-consumer?c=us&l=en&s=corp&cs=vn

 

I don't see anything in there that expressly defines the sell-ability of purchasing information, but it does have this:

Quote

"By providing us with a phone number (including mobile) as your contact number, you expressly authorize us to contact you regarding your account for non-telemarketing communications, via text message or telephone, including the use of prerecorded or auto-dialed calls, using that number."

This would seem to imply Dell (or their agents) can call you all they want to try to up-sell you anything that is related to your purchase.

Link to comment
Share on other sites

Link to post
Share on other sites

Wonder if this is why a pc I custom ordered got rerouted the day it was supposed to be delivered to me.  I checked tracking and saw that it was going to some random address all the way across the the country.  Dell customer support claimed they called FedEx to have it delivered back to my house... but that didn't happen and some dude accepted delivery of my PC.  Thankfully paypal refunded me because Dell wouldn't do anything... worst buying experience I've ever had.  

 

It was freaky that it happened after emailing back and forth with Dell support on a certain issue and I was convinced this guy somehow was involved in what happened to my pc.  I immediately changed all my passwords and started monitoring all my shit.

 

bright side is that if that didn't happen I wouldn't have decided to do my first build?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Entry does not meet posting guidelines of the Tech News section and so the thread was moved out:

What's missing:

  • The news needs to be explained in your own words.
Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, GoodBytes said:

Entry does not meet posting guidelines of the Tech News section and so the thread was moved out:

What's missing:

  • The news needs to be explained in your own words.

Aren't they already?
 

Quote

Your thread must include some original input to tell the reader why it is relevant to them, and what your personal opinion on the topic is. This needs to be MORE than just a quick, single comment to meet the posting guidelines.

 

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×