Slashdot Mirror


Buying a Samsung TV Online Could Jeopardize Your Data (cnet.com)

An anonymous reader shares a CNET report: If you buy a product from Samsung's online store, your name, address, order information and other data may be accessible to anyone who cares to look. Matt Metzger, a self-described "application security engineer" who said he has worked in shipping-industry compliance, wrote Wednesday on Medium about an accidental discovery. Metzger said he ordered a TV from the Samsung online store and was sent a URL to track his delivery. When he followed the URL, he discovered that his tracking number was the same one used for someone else's previous delivery and that he could see sensitive information, such as the person's name and items ordered, without any security measures getting in the way. Metzger also discovered that more information was attached in a TIFF file to his own order after the delivery was completed. The file included his full name, address and signature.Samsung told CNET it is aware of the issue and is looking into it.

4 of 30 comments (clear)

  1. And your home by OneHundredAndTen · · Score: 2

    Not in vain is Samsung known for its explosive products.

  2. Amazon rules by mi · · Score: 2

    Yeah, but a 1990's style flaw in 2017? It's like they're not even trying.

    No one is trying, it seems. Except Amazon — the only online seller I know, with advanced features like order-correction after placement, etc.

    Maybe, Samsung really should quit trying — stick to manufacturing, which is their area of expertise, and leave retail sales to professionals in that area.

    --
    In Soviet Washington the swamp drains you.
  3. Another BS headline. by gfxguy · · Score: 4, Informative

    Probably 99% of people buying Samsung products online did NOT buy it from Samsung directly.

    --
    Stupid sexy Flanders.
  4. No problem by PPH · · Score: 2

    I buy all my AV gear out of the back of vans in parking lots.

    --
    Have gnu, will travel.