Blu-ray Update Sent To User Via Credit Card Records
wmoyes writes "Back in September I ran into a Best Buy store to buy a Samsung BD-P2550 Blu-ray player. I didn't give the clerk my name, telephone number, or address, just my debit card. The player has sat happily in my living room without ever being networked or registered. Today I was shocked to find a package waiting for me at home from Best Buy — inside was a firmware update CD for the player. I used to think Windows Update was scary, but Samsung's update service tracked me to my house using the mag stripe from my bank card. Has this happened to any other Blu-ray owners?" Or is there a simpler explanation?
First, the facts: The Chase policy, which is similar to those of many other credit card companies, states: "You may tell us not to share information about you with non-financial companies outside of our family of companies. Even if you do tell us not to share, we may do so as required or permitted by law..."
According to the Wikipedia article, the credit card number, expiration date, and PIN verification info. I've seen tweekers do it with stolen cards. Magstripe readers are available for 50 bucks online.
The midget in the back seat of the Lincoln crawls in your basement window at night, and takes inventory of your firmware revisions on all your hardware.
He then runs to the forest to find out what updates you might need.
Don't talk to him, it sounds like he's talking backwards.
BTW, you need to replace that printer cartridge in the computer room on the first floor, and we have photographs of your youngest daughter going to school. Have a nice day, we'll be in touch.
This is why I use federal reserve notes for everything I can. I bought my Wii with federal reserve notes. I bought my PS3 with federal reserve notes.
--
End The Fed
That is great news
if someone ever use your credit card number,
YOU receive the driver upgrade.
then you know something wrong happened
The world belongs to those who get up early. - I'm far from being the king of Earth then
Have you EVER used that debit card at the same store and provided your address or phone number? If you've ever done that then they have that information readily available.
The blueray player used the nearest WiFi access point (it can hack into secured ones). It sent its GPS position, which was cross referenced to your address at the server. It has also been sending information about all the discs you have put in it, whether you played them or not. You haven't put any pirate stuff in there, have you?
In addition, on the HDMI back channel it has been gathering information about what you watch on TV, and reporting that as well. The company sells this information to Nielson.
And you wondered why that player was so expensive.
This is not unusual. I have benefited from several class action suits where they have somehow tracked me down years after the fact, which is particularly impressive because as a student/young professional/grad student, I moved almost every year.
What probably happens is they give the debit card number (which is unique and remains unique long after you cancel/close the account) to a credit reporting agency (e.g. Equifax), and the credit agency has a record of your most recent address, which they got when you changed your address at your bank or any of your other credit cards.
The 'update' DVD came from Best Buy, not the manufacturer- of course Best Buy has access to your home address, via your credit card. Samsung probably just shipped a bunch of discs to Best Buy, asking them to mail them out to owners of the player. No big conspiracy or identity theft going on, so relax.
If you have signed up with best buy's reward zone program and have used that credit card at least once with your reward zone card, they will know it is you...even if you didn't flash your reward zone card during the purchase of your blu ray player. Likewise, if you sent a rebate to best buy (although not necessarily to a 3rd party) using that credit card, its likely they will know it is you. Similar things happened with people who bought HD DVD players at best buy...when HD DVD was killed off, best buy decided to send folks $50 gift cards as a 'sorry things didn't work out with HD DVD' gesture...they mostly fed off info they already had from reward zone, rebates, or extended warranties to send the cards out.
Once people get used to this, what keeps naughty people from sending out legitimate looking upgrade disks that scramble your player or install software that lets them use your network connected player as a spam server? Urgh, basically virus laden spam for snail mail.
I Am My Own Worst Enemy
As they say on Wikipedia, "citation needed". I've bought a hundreds of things at BB, and even worked there for a spell when I was between real jobs; never once was I asked for my phone number during a purchase.
Slightly disreputable, albeit gregarious
You purchase an item on Credit you're entering into an agreement to pay for something they are going to want to know your billing address so that they can verify payment. If you're that concerned about your privacy you need to not enter into such agreements and pay for everything with cash (which protects both sides). As a side note isn't this potentially a good thing that they sent you an update? You can decide not to use it if you fear its updating drm as opposed to improving the product.
A similar thing happened to me. I bought a blu-ray player, then one day I came home and found my house ransacked and my blu-ray player was gone. I'm still waiting for Samsung to send my blu-ray player back with the updates. I don't have any problems with these companies being vigilant about their update services. I just really wish they wouldn't spraypaint swastikas on my furniture.
I have nothing compelling to say
Check you card for any bill BB wants $30 to do this.
http://consumerist.com/5122504/watch-out-for-firmware-shenanigans-at-best-buy
A few years ago there was an interesting device being sold that acted as an email dumb terminal. The device was sold sans any real license but the expectation by the vendor was that you would sign up for their service since otherwise the hardware was "useless". Except that folks figured out how to hack it and turn it into a remote terminal for various OS. I was interested....
I trotted down to my local Circuit City only to find that many others were also interested and that they were sold out. No worries, they let me go ahead and buy one and would let me know when stock arrived so that I could pick it up.
Meanwhile the company figured out what was going on and began trying to stop efforts to repurpose their hardware - unsuccessfully. I got a letter in the mail from the company a few weeks after I had made my purchase at CircuitCity. The letter was informing me that they had decided to change the license terms on their hardware - after my purchase, that signing up for their service was "mandatory", and that if I did not do so within X number of days or receiving my device they would CHARGE MY CREDIT CARD.
Now, I had never contacted this company, I had no intentions of ever dealing with them or of buying their service, and I had not shared my contact information with them. CircuitCity however HAD shared my name and home address with them and if the letter was to be believed was also willing to share my credit card account information to facilitate a charge! I trotted back down to the CircuitCity, canceled my order, and demanded an explanation - naturally they had NO clue.
I was beyond angry to say the least and fired off a letter to CircuitCity HQ. Their response was that no way did they share my CC information with this 3rd party but they said nothing about having shared my HOME ADDRESS! I let them know that I would never shop in their stores again and have told this story more times than I can count - it's been YEARS and I have held true to my promise not to give them a cent. Seeing them go under warms my heart - the jerks. The sad thing is that I nearly made this purchase with cash, I wish I had!
As a side note, the CircuitCity I went into was one I'd never visited as it was closer to work and not my home. When I gave them my phone number they had my complete address on file! Turns out that my girlfriend's daughter had shopped there about 3 years prior and made a single purchase. They STILL had our address on file tied to that phone number when I made my purchase. So yeah, these companies do cough up data and they also hold onto it a REALLY long time - thank you TJMax!
Build it, Drive it, Improve it! Hybridz.org
I dine out at a local eatery and they give change in 50c and $2 bills as appropriate based on your order. I tend to re-use the bills at other local places, and usually get some combination of NOOP and Cool! I've never had any issues, but also don't tend to hand them to someone who may die due to drooling on themselves.
Numerous companies either breach the policies or work around them.
Tthere was a big flap last year when the parent company of Winners and Home Sense was found to have been capturing all their customer's credit card numbers, which are supposed to be passed directly the the banks' clearing house without ever being seen by the retailer. See http://www.cbc.ca/money/story/2007/01/18/winnersbreach.html
Yes, they got stolen (;-))
--dave
davecb@spamcop.net
I once (and only once) bought an expensive Hermes tie at a shop in a Las Vegas casino's mall, paying with a credit card. I never gave them my address, so it had to come from my credit card info. Ever since, I've been getting Hermes catalogs in the mail. They're expensive things too, zillion-color offset printings on expensive paper, stencil cuts, etc. By now, whatever profit they made on that one tie has long vanished in the costs of producing and sending me that catalog.
Clearly you need help...but as long as you keep cranking out creepy, funny posts like this one, I'm certainly not going to give it to you.
Just once I'd like someone to call me 'Sir' without adding 'You're making a scene.'
When you use a debit card, your using Visa or MasterCard's good name and network to check with your bank to see if your account has the appropriate funds for the transaction.
If your bank account does have enough funds, Visa/MasterCard requests the transaction amount to be placed on hold on your account until such a time as when the funds can be actually transferred from your bank account to the merchant's account with a credit card merchant office (e.g. Nova). This transfer can happen instantly during business hours or can hold as pending until the next available business day if done during off hours or weekends.
You sign/confirm to an agreement that the funds will still be there when the transaction electronically resolves itself. If you don't have the funds, Visa/Mastercard can come rape you. If the merchant sold you damaged goods and will not issue you a refund, you can use Visa/Mastercard's thugs to force their hand. If you didn't make the purchase (identity theft), your bank can use Visa/Mastercard's thugs to track things down, issue you a provincial credit, and other fun things.
Anytime you pay for something electronically, your info will be made known to the merchant and Visa/Mastercard. How do you think Visa has that promo for debit cards allowing you to be the big mystery winner just for using your debit card to make purchases?
Up, Up, Down, Down, Left, Right, Left, Right, B, A, START
I purchased something from the Apple store (brick-and-mortar, not online), and after the guy swiped my credit card, he asked if I wanted the receipt emailed to me. I said "sure, do you need my email address", and he said "no, we have it". And sure enough they did, because I got the receipt in my email. I assume they have the information from my iTunes account.
I did one better. The next time I went there I used pay-at-the-pump and filled my car in $0.50 increments. It didn't cost me anything extra and I'm sure it screwed them over in credit card fees ;) That was a really amusing credit card statement to look at too.......
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
.ria eht ni cisum syawla s'ereht dna ,gnos ytterp a gnis sdrib eht .kcab dneb smra ym semitemos tub ,reh wonk i ekil leef i
Join the Free Software Foundation
I have a merchant credit card account for V,MC,D, you know the telephone swipe box that sits on the store counter.
It's pretty easy for the merchant, BestBuy whoever, to get your name and address from it.
And this is one of the reasons I always use cash. I do have a debit card, but it'll only get used in an emergency. Even then I'll probably claim I don't know the PIN so that I can sign instead.
Samsung asked BestBuy to pass on the update to whoever purchased the SKU. It's a tremendous courtesy, actually.
Well, yes you could see it as a courtesy, but it won't be. A business never ever does anything unless it thinks it will be benefitting from the action. This includes charitable contributions - the cost there will be seen as buying good will, or some other BS.
There was probably some kind of contractual obligation to send out these disks, but why the keenness to make sure the user's players were up to date? I can't imagine that Bestbuy or Samsung want to add features to the players, as if the players are lacking the user might buy a new one instead. I am guessing that the update is DRM updates... something like the ability for the player to identify copied disks, or maybe blacklisted keys or something.
There is no privacy. Get over it.
Well, there are various laws in various countries that try and give people rights to privacy, but like all rights they have to be continually defended. It doesn't help that penises like you make statements like that.... you might not care about your privacy and are willing to give it away, but when you do that you are often giving away others' privacy too.
Car analogies break down.
I've stopped shopping at stores that use my credit card as a way to get me on their mailing list. On vacation, we bought some chocolates at Harry & David. When we got back, there was a catalog from them in our mail with my name (not "Resident") in the address.
I'm not saying you're wrong but you do realize it is far more likely that they got your name and address from a local mailing list vendor than from your credit card? Especially around the holidays. There are countless services available that can target promotional mailings for a fee. There are all sorts of public sources for this information including housing records. (seriously - buy a house and you will get spammed with more refinancing offers than you can imagine)
I get Harry & David catalogs too (no I don't want them), with my name on them and I've never purchased anything from H&D. They also will send you catalogs if someone else buys you a gift from H&D.
That's not to say they don't use credit card into. I never give a zip code, phone number or any other info when checking out because it can be cross referenced. I nearly called the cops on the guys at Jiffy Lube once because they drained the oil in my car and then insisted they needed my address to put oil back in. They do have a legal right to ask and can refuse service if I don't provide the information but then I have a legal right to shop elsewhere as well.
I used to work for a moderately sized ski resort in Vermont, when I was in high school back in the 80's. This was back when credit card impressions were made on multi-part carbon paper receipts. Customer got one copy, merchant got another.
At the end of the day on a busy weekend, there would be thousands of credit card swipes, and the receipts locked in a vault in the offices. Part of my job was doing data entry at night during downtime. I'd check out a box of credit card receipts and enter the last name (from the signature) and the phone number (written by the customer on the slip) into a terminal. That was sent to a company in Ohio in batches of 50-60 thousand names. They matched name with phone number and sent back full addresses for our marketing department.
In 1989.
So, it's not at all surprising that they were able to piece this info together, and like others have pointed out, it's very possible they're matching your info to past purchases, returns or warranty information.
It's not that hard to do - credit card companies make big money selling lists of customers. they probably got it from your card issuer.
See subject.
I'm fairly sure being sent anything unsolicited doesn't allow you to flaunt copyright or patents.
If you can't see the value in jet powered ants you should turn in your nerd card. - Dunbal (464142)
I don't understand. I have a PO box, too, but the post office delivers my mail to mine. Is it different for you?
We've known that a shopper has no privacy for a while now, retail chains, credit card companies etc are watching your every move through any distinguishing information they can possibly find, discount cards, rewards cards, credit cards and even debit cards, this surprises nobody that is not living under a rock. The difference is that here, the companies in question sent this guy a firmware update disc. The upshot of this is not only does he get to upgrade his firmware on his Blueray without any additional effort, but things like this serve to remind shoppers that they are not anonymous unless they are extremely careful, which is a damn good lesson.
When Argumentum ad Hominem falls short, try Argumentum ad Matrem