Live data from Hacker News

Canada's tax revenue agency tries to ToS itself out of hacking liability

riskybiznews.substack.com

11–20 of 192 posts

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#11
post #7

Also noteworthy is that compared to leading commercial websites (Amazon, Facebook, etc.), the Canada Revenue Agency website: Responds an order of magnitude slower (like 3000 ms vs. 300 ms), and has maintenance downtime hours (instead of being up 24/7). > However, the Internet is a public network and there is the remote possibility of data security violations. They conveniently ignore the fact that HTTPS is pervasive…

Personally i would rather my tax money be spent elsewhere than latency optimizing a website that i have to use once a year.

The maintenance hours thing is unconsiable though. Sometimes i want to know how much tfsa room i have on sunday evening.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#12
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

> Imagine going to an amusement park and signing a waiver that the park takes no responsibility for your injuries. If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible

I don't know Canadian law, just for fun this is my understanding of it under US laws which are likely similar although Canada usually has more consumer protections.

You generally can't waive negligence. Those waivers can be useful for things like a trampoline park - someone lands on their ankle wrong and injurs it, the waiver deals with assumption of the risk - landing incorrectly is a reasonable risk due to the nature of the event. However if a net was missing and you hit the concrete floor - that would be under negligence of the premises owner.

My guess (not a lawyer just guessing) is that if they followed all best practices and someone bruteforced an RSA 2048 key which is currently understood to not be (reasonably) possible - that might be covered? However if they left a S3 bucket open without a password, that would be under negligence?

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#13
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

Legal structures and especially state or state sponsored entities in Canada work much differently than in the US.

The ICBC has a literal state sponsored monopoly over car insurance, titling a vehicle and driver licensing, whereas in the US no state handles car insurance, while titling a vehicle and driver licensing are not necessarily the same state organizations.

This state sponsored vertical integration enables abuse of authority in cases like https://www.reddit.com/r/nottheonion/comments/xa9j3x/church_...

Whereas here in the US I know many people that mix and match between different states DOLs and DORs for a variety of reasons, and your not going to get stuck with the same stubborn employee who can control every facet of your ability to identify yourself and also legally drive a vehicle on the road.

The DUI checkpoints up in BC are wild too, I'm glad they are banned in Washington and Oregon. Suspicionless stopping of cars en masse followed by interrogation by police seems like an overreach.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#14
post #4
post #2

Do government agencies generally have that kind of liability in the first place?

No, normally the government in Canada can be sued for this sort of thing. not exactly the same thing, but this is a $500,000 class action lawsuit for losing a USB Key containing patient data: https://www.thestar.com/news/gta/2012/05/28/durham_region_he... The expectation is that the government protect your privacy or pay if they fail to do so.. as with any private data.

But the government is financed by taxpayers, so the taxpayers will end up being the payers of any fines the government is liable for. It's circular.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#15
post #7

Also noteworthy is that compared to leading commercial websites (Amazon, Facebook, etc.), the Canada Revenue Agency website: Responds an order of magnitude slower (like 3000 ms vs. 300 ms), and has maintenance downtime hours (instead of being up 24/7). > However, the Internet is a public network and there is the remote possibility of data security violations. They conveniently ignore the fact that HTTPS is pervasive…

In first few the years following the 2000/2001 dotcom crash the Swedish Tax Agency realized they had a golden opportunity to move away from expensive and fickle consultants to a competent in-house team of long-term employed developers. They pulled it off really well. The effect is still visible - web services are well designed in a simple and efficient way and generally just work.

I think now (and the next year or two) might be a suitable time to pull a similar move.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#16
post #8
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

[flagged]

Can you please not post like this to HN? It's not what this site is for, and destroys what it is for.

If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#17
This government is so shoddily ran (leaving individual party politics aside) - Canadians aren't holding their government accountable. They're too busy trying to survive inflation and the knock-on effects it continues to cause, while distracting themselves with media that tells them "it's okay" and "it's not that bad"

Other boondoggled IT projects brought to you by the Canadian government include the Phoenix federal government paysystem - which coming up on a decade now, some federal employees _still_ aren't getting paid correctly, and the ArriveCan app - which is their hastily created, bug-filled app for pre-entry customs processing checklists that had accessibility problems for the disabled which have likely still been ignored, among other issues.

Between this and the very dodgy reactions from government officials (or lack thereof) to the recent news of foreign influence in our politics and elections processes from China, I would say this country has had its core emptied out and replaced with a nougat center of tasty corporate corruption and money laundering goodness.

The attitude seems to be "Not enough money to create and maintain a system that respects the privacy of our citizens, but we'll just legalese our responsibility away because we can and we're the government so _there_! We're like a silicon valley company, just try to sue us!"

At least we know that tax companies in the states are lobbying to make it harder to file taxes with the US government - the Canadian government just makes it more difficult by themselves!

I for one would like our government to be as responsible as possible when it comes to handling our data - ideally having as little of it as possible, only the required amounts to interact with me as minimally as possible - instead of having it all available in a portal that can be easily compromised and hacked judging from previous leaks/breaches in the linked article.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#18
post #7

Also noteworthy is that compared to leading commercial websites (Amazon, Facebook, etc.), the Canada Revenue Agency website: Responds an order of magnitude slower (like 3000 ms vs. 300 ms), and has maintenance downtime hours (instead of being up 24/7). > However, the Internet is a public network and there is the remote possibility of data security violations. They conveniently ignore the fact that HTTPS is pervasive…

Revenue Canada's website is slow and often down for maintenance, but at least I find it much easier to find what I'm looking for than on Amazon. It's actually one of the better user experiences I have online, and much easier than tax filing was in the US. But that response time ensures I'll never get addicted to doom-scrolling my tax records, to be sure.

By comparison with the province of BC's web services, anything provided by the federal government looks straight out of science fiction. For example: https://www.corporateonline.gov.bc.ca/ ... have fun!

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#19
post #13
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

Legal structures and especially state or state sponsored entities in Canada work much differently than in the US. The ICBC has a literal state sponsored monopoly over car insurance, titling a vehicle and driver licensing, whereas in the US no state handles car insurance, while titling a vehicle and driver licensing are not necessarily the same state organizations. This state sponsored vertical integration enables abu…

I clicked

> https://www.reddit.com/r/nottheonion/comments/xa9j3x/church_

to get

> Sorry, this post has been removed by the moderators of r/nottheonion.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#20
post #5
post #2

Do government agencies generally have that kind of liability in the first place?

I am not a lawyer, but if it's provable that your data was stolen, why wouldn't a citizen be able to take an entity to court for what would be reason precautions and protections around their data? If you can show that they didn't have audits, protections against their DB, etc. then I can imagine they'd be as liable as a private entity. But as is mentioned, this is all but demanded of Canadians to use this service, an…

Due to the principle of sovereign immunity. A government can only be sued if it explicitly has granted permission, otherwise the government is immune from civil action.
Post reply on HN