Live data from Hacker News

Equifax’s Maddening Unaccountability

nytimes.com

221–230 of 238 posts

Re: Equifax’s Maddening Unaccountability

#221
post #181

Earlier quoted context omitted.

I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…

And even after pushing out chip reader terminals and cards with chips, banks in the US refuse to institute mandatory PIN code entry on all payments with the chip - as its everywhere in Europe. So nothing really changed.

It still amazes that people don't know the chip readers work faster with PINs, too. An argument against PINs I keep hearing is that the chip readers are so slow that PINs would slow things down further. The funny thing is that the chip readers right now are waiting real wall clock time in a "wish-it-were-PIN" system to generate signatures in two different timestamps instead of generate a single signature with a user PIN. It's technically hilarious.

Re: Equifax’s Maddening Unaccountability

#222
post #203
post #159

Earlier quoted context omitted.

>I place the responsibly Nobody cares where you, or I, place it. You don't write for the NYTimes. You don't have that sort of sphere of influence. >with the company using Struts in their product, not the Struts dev. They don't. http://nypost.com/2017/09/08/equifax-blames-giant-breach-on-... It's very easy to explain to the public. "Those software hacker people did this to you. Look, here he is. He made the faulty sof…

Your line of comments is maddening, because you're clearly in total agreement with the article, yet seem to somehow be reading in almost the precise opposite of what its point was. The author was not blaming the Struts guy. She was blaming Equifax, 100%. She would blame the decision to use Struts and assume the unavoidable risk associated with such a decision, not the development of Struts itself. Literally every sin…

"No software system can be free from bugs (or intruders), and users must be mindful of the risks. But the inherent lack of perfect automotive safety doesn’t mean we don’t try to make cars safer. Obviously, people should drive more carefully, but seatbelts, airbags and better car design reduce injury enormously, and that has been great for the industry as well as consumers. The software industry should be no different."

Let me translate that:

Software users, like people who use compilers, should need licenses. Obviously, people need to compile more carefully. Software needs the equivalent of seatbelts, airbags, and other government mandated safety standards. Software cannot JUST ship to github with no warranty or guarantees of safety. These licenses which absolve the developer of responsibility cannot continue to be allowed. Those open source developers should not just produce software for free, but they need to accept responsibility for it. They need to pass government mandated, Apple App store style, approval for all software shipped. Including regulations for safety and compliance with other laws like copyright infringement and decency standards.

She's attacking the foundation of the software freedom movement.

Re: Equifax’s Maddening Unaccountability

#223

Americans woke up to news of yet another mass breach of their personal data. Americans woke up to news of yet another mass breach of data about them. FTFY

could you elaborate on what you mean by making this distinction, please?

People are being pedantic about the actual meaning of words as opposed to the commonly-understood-and-accepted meaning of words.

It's annoying, because it distracts from the immediate issue and causes confusion.

Re: Equifax’s Maddening Unaccountability

#224
post #190

Earlier quoted context omitted.

Well here in europe it didn't happen all at once. It was a gradual rolling of chip based cards, atms and terminals. There was a non-insignificant amount of time where some atms / pos terminals would reject your card because you/it didn't have the right technology. But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choo…

How do banks in Europe verify identity? i.e. I call the bank and claim to be "Margaret Thatcher," what's the next step? Here in the U.S. the next step is usually asking for the social security number. I called VISA/Citi to re-activate my card after traveling and they asked for the associated phone number with my account. Neither of these are especially secure, in my opinion.

Local UK bank after separation from Lloyds (now called TSB) asks for 3 random letters of your security answer which is also used as part of online banking authentication. Additionally, your address and previous transactions if you're calling re. fraud.

Re: Equifax’s Maddening Unaccountability

#225

Earlier quoted context omitted.

I wonder if the legal concept res ipsa loquitur (the thing speaks for itself) could apply here? It's one foundation of tort law. The argument would be that the very fact that PII security was breached demonstrates defendant's negligent data storage/security practices. If those practices had been adequate, the breach would not have occurred.

If that's the case then I'd suggest every software developer on this forum immediately switch careers, this one is doomed.

Well, there is that. Maybe reality is that no set of security practices can ever secure PII. If so, that's an even bigger problem than lackadaisical firms like Equifax.

But I think higher expectations, helped along with civil legal machinery that's likely to mete out meaningful punishment, would move us faster to finding out whether the problems are mostly just sloppy practice (which responds to economic penalties) or whether they're more fundamental and need a different fix.

Re: Equifax’s Maddening Unaccountability

#226

Earlier quoted context omitted.

What gives banks right to consider SSN an authenticator? Is there a law allowing that? Common sense suggests it should only be possible if user explicitly accepted "I agree that knowing my SSN is enough to prove it's me and I agree to be liable to any debts created with just my SSN presented".

You misunderstand US law. Yes, someone can use my SSN (along with other private information) to create a debt. That doesn't make me liable. If it shows up on my credit report, I can disclaim responsibility using existing legal protections. As long as I truly didn't create the debt, it is the debt holder's problem.

But the problem has been created; which you've got to fix by paying at least in your time spent solving this.

What you're saying is probably true in any country; but in reality imo it's way easier not to allow that to happen in the first place.

Re: Equifax’s Maddening Unaccountability

#227

There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?

Part of it is that even the name of the crime Identity Theft insidiously paints it as something purely between the thief and the end consumer, whose identity was "stolen". Alice stole Bill's identity! But where is the company she stole it from? Where is the bank where she fraudulently used this information? These corporations' lack of accountability is built directly into the name we use for the crime! It's as if the…

Something an uncle said:

It used to be called Bank fraud and it was the Banks problem. Now it's called Identity Theft and it's your problem.

Re: Equifax’s Maddening Unaccountability

#228
post #222
post #203

Earlier quoted context omitted.

Your line of comments is maddening, because you're clearly in total agreement with the article, yet seem to somehow be reading in almost the precise opposite of what its point was. The author was not blaming the Struts guy. She was blaming Equifax, 100%. She would blame the decision to use Struts and assume the unavoidable risk associated with such a decision, not the development of Struts itself. Literally every sin…

"No software system can be free from bugs (or intruders), and users must be mindful of the risks. But the inherent lack of perfect automotive safety doesn’t mean we don’t try to make cars safer. Obviously, people should drive more carefully, but seatbelts, airbags and better car design reduce injury enormously, and that has been great for the industry as well as consumers. The software industry should be no different…

If I build an airbag in my garage, and Honda shows up tomorrow and puts it in their car, and it fails because I don't know how to make good airbags, I would not be legally liable for those failures. Honda, however, would be. Your analogy does not hold up. You're reading some _very_ specific things into what is a very general statement.

I get why you'd be upset if she was attacking the things you say she is, but she is emphatically not doing that. Every single paragraph in the article is about how Equifax should be liable for their software, which includes liability for the decision to use types of open-source software.

Re: Equifax’s Maddening Unaccountability

#229
post #209

Earlier quoted context omitted.

Re: Cost of fraud. Agreed. It still amazes me how prevalent credit card fraud is. Certainly that's preventable - if they want it to be. The problem is, the banks don't bear that cost, the consumer does. Even if the bank factors the loss into the cost of doing business, that still gets passed on to the consumer.

Consumers are limited by law to a $50 loss for credit card fraud and every bank I know waives even that. It is merchants (stores, internet sites) that bear the cost of fraud.

But what of the time, stress, etc.?

Merchants don't bear the cost, the consumer does. The merchant might not hand me a bill but that cost is embedded somewhere in the price.

The bottomline is the consumer pays. No matter how you cut it, the consumer always pays.

Re: Equifax’s Maddening Unaccountability

#230

Earlier quoted context omitted.

They don't. I just bought a car from a dealership on August 1 without a credit check. The dealership wanted to run a credit check if I were to pay with a personal check, but not if I paid with certified funds. I called my bank to have my debit card limit raised to $40,000 for 24 hours and paid for the car on my debit card with no credit check.

Did you have to do the IRS form stuff?

It's hard to recall all the forms that I signed that day. I don't remember any IRS forms.
Post reply on HN