• 0 Posts
  • 233 Comments
Joined 3 years ago
cake
Cake day: June 18th, 2023

help-circle


  • Valve shares delivery-related information with CEVA so that it can ship Steam hardware in Europe, and it appears that this personal data is what was stolen. This personally identifiable information (PII) may include your name, address, country, phone number, email address, and the details of the products you ordered. CEVA stores customer data for up to 90 days after an order is assigned to them, which means that the data for lots of customers may have been leaked. Fortunately, payment information, Steam account details, authentication codes, and more are not stored at CEVA.

    The leak was not from Valve but from the shipping company used to distribute their hardware in Europe. Your Steam account details are not leaked, but any information related to shipping probably is.

    Following this breach and the subsequent exfiltration of data, Valve has asked customers to be wary of contact attempts from fraudulent entities who have taken hold of your leaked information and may use it to prove that they are genuine. Customers do not need to change their passwords, but they definitely should not share their account details with any person identifying them as a courier service for your hardware.













  • They should be powered on if you want to retain data on them long-term. The controller should automatically check physical integrity and disable bad sections as needed.

    I’m not sure if just connecting them to power would be enough for the controller to run error correction, or if they need to be connected to a computer. That might be model specific.

    What server OS are you using? Are you already using some SSDs for cache drives?

    Any backup is better than no backup, but SSDs are really not a good choice for long-term cold storage. You’ll probably get tired of manually plugging them in to check integrity and update the backups pretty fast.


  • You’re right that it’s not a complete solution. Offhand, it seems like this won’t help graphic designers that make advertising graphics if the advertiser doesn’t really care about copyright protection - or basically anything that is expected to have a short lifespan (who cares if an ad campaign that runs for a week is copyrighted?).

    Are those jobs worth fighting over? There are probably a lot more graphic artists making a living producing bilboards and web ads &etc than there are making a living selling their own art, but are those jobs something that society at large should make an effort to protect?

    I do think that manipulating incentives is the most effective strategy. A high-budget film without copyright is not profitable, and therefore anything that leads to gaps in copyright protection is unlikely to be adopted by the film industry. This removes all of the potential burden of government regulation, oversight, auditing, labor union rules, legal battles, etc… it just obviates all that because it kills the profitability of using generative AI to replace people.





  • NaibofTabr@infosec.pubtoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    1 year ago

    It’s highly unlikely that this thing would be able to operate without an Internet connection. There’s no way it would have enough compute power on board to do a significant amount of image recognition (find the socks, pick up the socks, find the laundry hamper, deposit the socks in the laundry hamper) or voice command processing.

    I hate to disappoint but I am not some secret agent hiding a bunch of shit.

    This is a very bad attitude to take towards your personal security, and part of the point I was trying to make is that there’s a very high chance that a device like this would have poorly secured software. When you look at incidents like the multiple Wyze security camera breaches, you have to expect that consumer security is always an afterthought for companies that make these kind of products. They will only start to care about it after something goes wrong and gets public attention (because it threatens sales), after which they will make a token effort to fix the problem (just enough to get a headline saying they did, so that it will stop hurting sales). So, don’t just think about the manufacturer/distributor having access to the surveillance data this thing will collect. Think about random people on the internet, a criminal with an interest in blackmailing people, or some random van driving by with a bunch of network gear on the back.