Earlier quoted context omitted.
I suppose at a very high level your thesis might be true, but at a practical level, I don't think it is. The banks have simply seen it's cheaper to eat the cost of fraud (and ensure the victim has the burden of proof wherever possible) than implement stricter security measures. This goes from the transaction terminal to the bank's server room. Europe has had chip cards for over 20 years. In the US, it was very recent…
And even after pushing out chip reader terminals and cards with chips, banks in the US refuse to institute mandatory PIN code entry on all payments with the chip - as its everywhere in Europe. So nothing really changed.
Equifax’s Maddening Unaccountability
221–230 of 238 posts
Re: Equifax’s Maddening Unaccountability
#222Earlier quoted context omitted.
>I place the responsibly Nobody cares where you, or I, place it. You don't write for the NYTimes. You don't have that sort of sphere of influence. >with the company using Struts in their product, not the Struts dev. They don't. http://nypost.com/2017/09/08/equifax-blames-giant-breach-on-... It's very easy to explain to the public. "Those software hacker people did this to you. Look, here he is. He made the faulty sof…
Your line of comments is maddening, because you're clearly in total agreement with the article, yet seem to somehow be reading in almost the precise opposite of what its point was. The author was not blaming the Struts guy. She was blaming Equifax, 100%. She would blame the decision to use Struts and assume the unavoidable risk associated with such a decision, not the development of Struts itself. Literally every sin…
Let me translate that:
Software users, like people who use compilers, should need licenses. Obviously, people need to compile more carefully. Software needs the equivalent of seatbelts, airbags, and other government mandated safety standards. Software cannot JUST ship to github with no warranty or guarantees of safety. These licenses which absolve the developer of responsibility cannot continue to be allowed. Those open source developers should not just produce software for free, but they need to accept responsibility for it. They need to pass government mandated, Apple App store style, approval for all software shipped. Including regulations for safety and compliance with other laws like copyright infringement and decency standards.
She's attacking the foundation of the software freedom movement.
Re: Equifax’s Maddening Unaccountability
#223Americans woke up to news of yet another mass breach of their personal data. Americans woke up to news of yet another mass breach of data about them. FTFY
could you elaborate on what you mean by making this distinction, please?
It's annoying, because it distracts from the immediate issue and causes confusion.
Re: Equifax’s Maddening Unaccountability
#224Earlier quoted context omitted.
Well here in europe it didn't happen all at once. It was a gradual rolling of chip based cards, atms and terminals. There was a non-insignificant amount of time where some atms / pos terminals would reject your card because you/it didn't have the right technology. But ultimately I think its the people themselves that demand more security from their banks. E.g. Bank one introduces chip based cards and more people choo…
How do banks in Europe verify identity? i.e. I call the bank and claim to be "Margaret Thatcher," what's the next step? Here in the U.S. the next step is usually asking for the social security number. I called VISA/Citi to re-activate my card after traveling and they asked for the associated phone number with my account. Neither of these are especially secure, in my opinion.
Re: Equifax’s Maddening Unaccountability
#225Earlier quoted context omitted.
I wonder if the legal concept res ipsa loquitur (the thing speaks for itself) could apply here? It's one foundation of tort law. The argument would be that the very fact that PII security was breached demonstrates defendant's negligent data storage/security practices. If those practices had been adequate, the breach would not have occurred.
If that's the case then I'd suggest every software developer on this forum immediately switch careers, this one is doomed.
But I think higher expectations, helped along with civil legal machinery that's likely to mete out meaningful punishment, would move us faster to finding out whether the problems are mostly just sloppy practice (which responds to economic penalties) or whether they're more fundamental and need a different fix.
Re: Equifax’s Maddening Unaccountability
#226Earlier quoted context omitted.
What gives banks right to consider SSN an authenticator? Is there a law allowing that? Common sense suggests it should only be possible if user explicitly accepted "I agree that knowing my SSN is enough to prove it's me and I agree to be liable to any debts created with just my SSN presented".
You misunderstand US law. Yes, someone can use my SSN (along with other private information) to create a debt. That doesn't make me liable. If it shows up on my credit report, I can disclaim responsibility using existing legal protections. As long as I truly didn't create the debt, it is the debt holder's problem.
What you're saying is probably true in any country; but in reality imo it's way easier not to allow that to happen in the first place.
Re: Equifax’s Maddening Unaccountability
#227There's something very disturbing about the fact that they can collect my personal information (without my approval); profit on that info (without compensating me); and then get hacked and I have no reasonable recourse for what they've done?? How can they not be liable? How is this not negligence?
Part of it is that even the name of the crime Identity Theft insidiously paints it as something purely between the thief and the end consumer, whose identity was "stolen". Alice stole Bill's identity! But where is the company she stole it from? Where is the bank where she fraudulently used this information? These corporations' lack of accountability is built directly into the name we use for the crime! It's as if the…
It used to be called Bank fraud and it was the Banks problem. Now it's called Identity Theft and it's your problem.
Re: Equifax’s Maddening Unaccountability
#228Earlier quoted context omitted.
Your line of comments is maddening, because you're clearly in total agreement with the article, yet seem to somehow be reading in almost the precise opposite of what its point was. The author was not blaming the Struts guy. She was blaming Equifax, 100%. She would blame the decision to use Struts and assume the unavoidable risk associated with such a decision, not the development of Struts itself. Literally every sin…
"No software system can be free from bugs (or intruders), and users must be mindful of the risks. But the inherent lack of perfect automotive safety doesn’t mean we don’t try to make cars safer. Obviously, people should drive more carefully, but seatbelts, airbags and better car design reduce injury enormously, and that has been great for the industry as well as consumers. The software industry should be no different…
I get why you'd be upset if she was attacking the things you say she is, but she is emphatically not doing that. Every single paragraph in the article is about how Equifax should be liable for their software, which includes liability for the decision to use types of open-source software.
Re: Equifax’s Maddening Unaccountability
#229Earlier quoted context omitted.
Re: Cost of fraud. Agreed. It still amazes me how prevalent credit card fraud is. Certainly that's preventable - if they want it to be. The problem is, the banks don't bear that cost, the consumer does. Even if the bank factors the loss into the cost of doing business, that still gets passed on to the consumer.
Consumers are limited by law to a $50 loss for credit card fraud and every bank I know waives even that. It is merchants (stores, internet sites) that bear the cost of fraud.
Merchants don't bear the cost, the consumer does. The merchant might not hand me a bill but that cost is embedded somewhere in the price.
The bottomline is the consumer pays. No matter how you cut it, the consumer always pays.
Re: Equifax’s Maddening Unaccountability
#230Earlier quoted context omitted.
They don't. I just bought a car from a dealership on August 1 without a credit check. The dealership wanted to run a credit check if I were to pay with a personal check, but not if I paid with certified funds. I called my bank to have my debit card limit raised to $40,000 for 24 hours and paid for the car on my debit card with no credit check.
Did you have to do the IRS form stuff?