Slashdot Mirror


Samsung Plants Keyloggers On Laptops

Saint Aardvark writes "Mohammed Hassan writes in Network World that he found a keylogger program installed on his brand-new laptop — not once, but twice. After initial denials, Samsung has admitted they did this, saying it was to 'monitor the performance of the machine and to find out how it is being used.' As Hassan says, 'In other words, Samsung wanted to gather usage data without obtaining consent from laptop owners.' Three PR officers from Samsung have so far refused comment."

16 of 515 comments (clear)

  1. Re:WTF? by FlatEric521 · · Score: 5, Informative

    They should be prosecuted over crap like this.

    They will be. Sony got hit with tons of lawsuits, and they weren't using software that could steal your password. This just took corporate big brother behavior to a whole new level of invasive.

  2. Yet another example by milbournosphere · · Score: 1, Informative

    of why one should ALWAYS wipe the hard drive of a new machine and install a clean copy of Windows (or Linux).

  3. Re:Without obtaining consent? by v1 · · Score: 4, Informative

    They can put anything they darn well please into the EULA, it doesn't guarantee it to be binding or legally enforceable.

    They could sneak a line in somewhere in the middle of page 28 of 45 that says by using this software you're required to send them a check for $500. It would be very hard to enforce.

    The practice of installing hidden software like that already has been condemned by the FTC. (from TFA: In the words of the of former FTC chairman Deborah Platt Majoras, "Installations of secret software that create security risks are intrusive and unlawful." (FTC, 2007).) So they're probably going to get hammered on this. And rightfully so.

    Usually when their legal department refuses to reply when you're requesting comments before someone goes public, it's because they're busy batoning down the hatches and polishing up their resumes.

    --
    I work for the Department of Redundancy Department.
  4. Re:WTF? by Missing.Matter · · Score: 4, Informative

    Samsung's CEO is Korean. Samsung is Korean company, you know.

  5. Re:Only one case? by echucker · · Score: 3, Informative

    Some of the comments on the article reach the same conclusion. One even suggests it was someone at the store where they were purchased that installed the logger. Problem is, Samsung's tech support guy already admitted to it.

  6. Re:Not once, but twice by Anonymous Coward · · Score: 3, Informative

    He's saying this is this is lame. the real shiza is in the chip.

  7. Re:WTF? by Anonymous Coward · · Score: 2, Informative

    Sony America and Samsung America are actually separate financial entities. They can be sued in one area and not another for example they can be sued in the U.S. but the same suit may not apply to the EU.

    I wonder if they are doing this with their phones also?

  8. Samsung and Sprint do this with Android phones too by chrisj_0 · · Score: 5, Informative
  9. Re:WTF? by Wyatt+Earp · · Score: 3, Informative
  10. Re:WTF? by erroneus · · Score: 5, Informative

    Oh please. Take it from me -- I work for an "American Company" that is completely owned by a Japanese company and is completely run by employees of that same Japanese company. It's a lie. It's a huge lie. It's a lie on the scale of saying "santa claus is real." It's clearly and obviously not the truth.

  11. Re:And we do this how? by SCPRedMage · · Score: 3, Informative

    He didn't say download it from a "warez" site; you can download it from Microsoft's own servers.

    --
    My sig can beat up your sig.
  12. Re:WTF? by BitterOak · · Score: 2, Informative

    Yes they should, it is a felony after all.

    Technically it isn't. It is a felony to gain unauthorized access to someone else's computer, but there is no law against installing this sort of software before the computer is sold.

    A car analogy: I can't break into your car to install a GPS tracking device, but many new car manufacturers install devices with similar functions at the factory, eg. GM's ONSTAR system.

    --
    If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
  13. Re:WTF? by Anubis+IV · · Score: 5, Informative

    Wow. [citation needed] much? Let's go down the list, shall we?

    1) Not only can I find no evidence of a $500M figure ever having existed before your comment, but if they had made a settlement for a half billion dollars, Sony wouldn't exist today. Their operating income last year was just $342M (source). Fat chance that Sony could survive a $500M settlement hit. By all indications (i.e. because it's not mentioned in their annual filings from that year and there are no followup stories to be found), this did not impact their bottom line in any sort of meaningful way.

    2) As for what the settlement actually was, they paid up to $150-175 per customer that damaged their PC in an attempt to remove the rootkit (see here), plus $5.75M in settlements to various states (source). That's it. It probably cost them less than $10M to settle the whole thing.

    3) For a quick example of a company that can take a hit like the one you talked about, we all remember the Microsoft EU antitrust case from a few years back, right? The one regarding media players, where they were fined roughly $600M, and had followup fines of roughly $250M and $1.44B, all of which were extensively covered in the news since they were, at the time, the largest fines ever handed down by the EU (more info). But Microsoft was able to absorb the hit. Of course, they could do that since their operating income last year was about $24B (source), which is roughly 70x that of Sony's.

    4) As for your DOJ claims, I can't find anything about government computers being infected (though I wouldn't doubt it) or the DOJ being involved at all. In fact, they never got involved, despite the public outcry and requests that a criminal investigation be launched.

    Aside from government computers getting infected, is anything you said true, or are you just routinely off by a few orders of magnitude when quoting figures, as well as prone to making up stories that have little basis in fact?

  14. Samsung's official? response in Korea by Anonymous Coward · · Score: 2, Informative

    saw this posted on samsung blog.

    http://samsungtomorrow.com/1070

    What they are saying is that the user was using security program called Vipre which reports \SL folder (slovenian language) created by Microsoft Live app as keylogger.

  15. it's all a lie. by herojig · · Score: 4, Informative
    --
    I think therefore I can't be ~TTNH
  16. Utter bullshit by igorthefiend · · Score: 4, Informative

    False positive from a rarely used AV package - detects the same thing in an empty folder on a clean machine.
    http://www.f-secure.com/weblog/archives/00002133.html