Live data from Hacker News

Canada's tax revenue agency tries to ToS itself out of hacking liability

riskybiznews.substack.com

71–80 of 192 posts

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#71

Earlier quoted context omitted.

"Wild" meaning, the police can still impound your car at their discretion if you blow below not just the legal limit of 0.08, but below the warning limit of 0.05, or even 0!

No shortage of drugs that can make someone a terrible driver. Many drivers are worse alcohol-free than a legally drunk good driver. Focussing on one cause of bad driving (lots of alcohol) is a weak approach to road safety.

This is a weak argument against checkstops. If you're a worse driver without alchohol or other relevant impairments then you shouldn't be driving either. I can't see road signs very-well without corrective lenses, so I don't, and I wouldn't pass a test without them. If you need alchohol to be a good enough driver, you probably won't pass the test sober, or we should have better tests. Moving cars are killing machines unless you're driving them well. I've been stopped at checkpoints and support them. They're scary, but driving is a priviledge and you shouldn't fuck around with it.

They're also not a solution to road safety, they just address one category. Overall road safety comes from a complete reversal of car-dependance along with improvements to road design.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#72
post #36
post #10

Earlier quoted context omitted.

CRA is almost a separate entity from other federal departments, so it behaves like a private business than a government department. They aren’t even at the behest of the treasury board.

The CRA is its own department, like any other department. It is structured and operates just like any other government department as opposed to a private business. They are not at the behest of the Treasury Board because the Treasury Board is a committee, not an administration or agency. The board has no executive authority whatsoever and exists to give advice to Cabinet rather than to perform or execute a duty. Howe…

I recommend you look up the purpose of Treasury Board. They are the corporate treasurer of GoC. All expenditure requests go through them and if insufficiently justified then Treasury rejects them. And the requesting department/division/establishment must resubmit. It even applies to CF/DND too.

(In some countries/companies this function is called the comptroller or the controller.)

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#73
post #17

This government is so shoddily ran (leaving individual party politics aside) - Canadians aren't holding their government accountable. They're too busy trying to survive inflation and the knock-on effects it continues to cause, while distracting themselves with media that tells them "it's okay" and "it's not that bad" Other boondoggled IT projects brought to you by the Canadian government include the Phoenix federal g…

you should consider donating to the Canadian constitution foundation ( https://www.youtube.com/@theCCF ) then or something like them because our constitution actually does have a decent protections for separation of power between provinces and the federal government and getting that back to what is actually in the constitutional documents (as opposed to what has been twisted by decades of bad decisions to favor the f…

I would argue that a lot of our constitutional separation of powers between provincial and federal governments is antiquated and causes more harm than good today (this is particularly true in education and healthcare).

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#74

Earlier quoted context omitted.

What happens if you don't agree to the TOS? Pretty sure that means you can't do your taxes, and you'd get in pretty hot water as a result. To me, that implies that the Canadian government is forcing you to agree to this TOS, which further reduces its legal defensibility.

You can still mail in paper forms.

And the bad boys and girls can still hack CRA and if they defraud you using the data they stole is CRA still liable in spite of your paper-based filing?

You will have to prove a lot of "facts" to win that lawsuit. Especially since your social number(s), email, phone, whatsapp, etc are all public info already.

Recall a few years ago an uneducated hacker ("script kiddie") got part way into a CRA website and they took the whole website down for a week. (The attacker was caught, and prosecuted iirc.)

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#75
Fortunately, contracts in Quebec are dependent of the Civil Code. Terms of service match the definition of a contract. I am eager to see if such practices by any level of government will pass the test of tribunals and current jurisprudence.

Excerpts : 1458 Every person has a duty to honour his contractual undertakings. Where he fails in this duty, he is liable for any bodily, moral or material injury he causes to the other contracting party and is bound to make reparation for the injury; neither he nor the other party may in such a case avoid the rules governing contractual liability by opting for rules that would be more favourable to them.

https://www.legisquebec.gouv.qc.ca/en/document/cs/CCQ-1991?l...

1474 A person may not exclude or limit his liability for material injury caused to another through an intentional or gross fault; a gross fault is a fault which shows gross recklessness, gross carelessness or gross negligence. He may not in any way exclude or limit his liability for bodily or moral injury caused to another.

1475 A notice, whether posted or not, stipulating the exclusion or limitation of the obligation to make reparation for injury resulting from the nonperformance of a contractual obligation has effect, with respect to the creditor, only if the party who invokes the notice proves that the other party was aware of its existence at the time the contract was formed.

1476 A person may not by way of a notice exclude or limit his obligation to make reparation with respect to third persons; such a notice may, however, constitute disclosure of a danger

1477 The assumption of risk by the victim, although it may be considered imprudent having regard to the circumstances, does not entail renunciation of his remedy against the author of the injury.

https://www.legisquebec.gouv.qc.ca/en/document/cs/CCQ-1991?l...

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#76

If you pay attention to ToS's, you'll find companies are increasingly trying to pull stunts like this. The CRA's terms are objectionable, yet sadly benign compared to other reprehensible terms I've seen gating the web. Lawyers are copying each other's tactics and propogating dark patterns that I doubt will stand the test of litigation (but will cost some poor sap a lot of money and time to get there). Indemnity claus…

Yeah like you say this isn’t a new phenomenon. In some cases they even try to shield themselves with legislation.

For example let’s look at Ireland.

[0] Ireland tries to exclude itself from GDPR https://www.thejournal.ie/data-protection-bill-2018-3853647-...

[1] Entire health system compromised and possibly majority of PHI data exfiltrated https://www.hse.ie/eng/services/publications/conti-cyber-att...

[2] Irish health service only begins notifications to confirmed affected individuals a year later https://www.hse.ie/eng/services/news/media/pressrel/hse-begi...

[3] selective punishment of companies whose data is breached eg google https://techcrunch.com/2022/03/14/dpc-sued-google-rtb-compla... vs meta https://www.dataprotection.ie/en/news-media/data-protection-...

Laws unevenly applied make a mockery of justice.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#77

Fortunately, contracts in Quebec are dependent of the Civil Code. Terms of service match the definition of a contract. I am eager to see if such practices by any level of government will pass the test of tribunals and current jurisprudence. Excerpts : 1458 Every person has a duty to honour his contractual undertakings. Where he fails in this duty, he is liable for any bodily, moral or material injury he causes to the…

IANAL... but...

I don't think that the CRA is subject to Quebec law, and believe that the CRA may exercise sovereign immunity, though I'm not sure that it has done so in the past.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#78
Certainly having a government agency able to force you to accept ToS like you'd see in the private sector is absurd since it lets the government skirt its own laws.

Feels like a "could the government do that" standard would be a good one to apply to any ToS when figuring out whether it's enforceable. Or maybe this is just more evidence that ToS should be generally and universally ruled unenforceable.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#79
post #59

Earlier quoted context omitted.

The standard with dog bites is “reasonable precautions” to prevent them, thus a good fence that failed because it was hit by a meteor could be a perfectly reasonable defense. People don’t build structures with rocks falling from the sky in mind. On the other hand a fence the dog can open or climb over is not, which of course depends on the dog. I suspect the same would be considered for computer security. Hacker News…

Genuine question, would you not be held responsible in the US if a meteor hit your fence allowing your dog to get out and bite someone? I know that it was unpreventable but isn’t it still your dog and your responsibility?

You can be sued for anything but I suspect in this case the “Act of God” clause would come into pay and insurance would (or wouldn’t) cover it.

Eg if you had a known dangerous dog that had bitten twelve babies before but you didn’t destroy it, you’re up the creek even if it got out because of the meteor.

But if the dog only but because it’s tail got singed by the meteor, you’d probably be ok.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#80
post #30
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

What's interesting to me is that they provide assertions about themselves in the TOS. How is any user going to verify those statements?

And what if those statements are proven false in a breach!
Post reply on HN