Live data from Hacker News

Canada's tax revenue agency tries to ToS itself out of hacking liability

riskybiznews.substack.com

51–60 of 192 posts

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#51
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

> Imagine going to an amusement park and signing a waiver that the park takes no responsibility for your injuries. If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible I don't know Canadian law, just for fun this is my understanding of it under US laws which are likely similar although Canada usually has more co…

> My guess (not a lawyer just guessing) is that if they followed all best practices and someone bruteforced an RSA 2048 key which is currently understood to not be (reasonably) possible - that might be covered? However if they left a S3 bucket open without a password, that would be under negligence?

Not a lawyer either, but to me, since users have no means to protect themselves against a backend breach, it seems like it would inherently be the fault of the business.

My chosen parallel would be owning a dog. Owning a dog has some inherent risk, because even if you take all precautions, there's always a chance it gets off it's leash or breaks out of the yard and bites someone. "I had a fence" shouldn't free you from liability; the fence was insufficient because someone still got bit. The only way to be free of that small risk is to not own a dog.

I view data the same way. Storing sensitive data comes with an inherent risk that it will be compromised. By asking for and keeping that data, companies assume the risk of that data being breached, and any resulting damage. If that risk is unacceptable, don't ask for or keep the data. Or find some way to make it so the data can't cause damage even if it's stolen (e.g. by using some kind of public tax ID).

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#52

[flagged]

What are you talking about?

Here's someone who has clearly never been to Canada. Canada has lots of problems, yes, but this just smacks of a strongly held yet uninformed opinion.

Actually, looking at their comment history they seem to be the champion of edgy one-liner comments. Nothing to see here.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#53
If you pay attention to ToS's, you'll find companies are increasingly trying to pull stunts like this. The CRA's terms are objectionable, yet sadly benign compared to other reprehensible terms I've seen gating the web. Lawyers are copying each other's tactics and propogating dark patterns that I doubt will stand the test of litigation (but will cost some poor sap a lot of money and time to get there). Indemnity clauses are another one (no, I'm not going to reimburse you for damage if my account gets hacked through no fault of my own).

When I encounter clearly dodgy terms like this I often contact the organization and tell them I do not accept the given clause. Sometimes they say 'stop using our service' (rarely enforced) but most often they simply don't respond.

Someone at CRA with authority to fix this might perk up if thousands of Canadians start emailing them about it, report it to MP's, the Privacy Commissioner and other ombudsmen, etc.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#54
post #16
post #8

Earlier quoted context omitted.

[flagged]

Can you please not post like this to HN? It's not what this site is for, and destroys what it is for. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.

no problem, ill stop posting comments.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#56
post #50

Earlier quoted context omitted.

The US has CBP checks on roads, doesn’t it?

Yes, but very limited. They are only allowed to ask "are you a US citizen", and walk a dog around the car. I've never had one take more than 60 seconds in either AZ or CA.

I'm a tall middle aged middle class white man and I had no issue with any police check in my life either.

I think there are demographics that have different experiences than mine, especially when there's a dog involved (who can provide any excuse necessary:)

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#57
post #13
post #6

> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsi…

Legal structures and especially state or state sponsored entities in Canada work much differently than in the US. The ICBC has a literal state sponsored monopoly over car insurance, titling a vehicle and driver licensing, whereas in the US no state handles car insurance, while titling a vehicle and driver licensing are not necessarily the same state organizations. This state sponsored vertical integration enables abu…

> The ICBC has a literal state sponsored monopoly over car insurance

No, this is only true for the most basic plans (called Autoplan). For anything beyond this, eg third-party liability, collision, comprehensive, etc., you can buy private insurance or go with ICBC for those plans too if you want.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#58
post #57
post #13

Earlier quoted context omitted.

Legal structures and especially state or state sponsored entities in Canada work much differently than in the US. The ICBC has a literal state sponsored monopoly over car insurance, titling a vehicle and driver licensing, whereas in the US no state handles car insurance, while titling a vehicle and driver licensing are not necessarily the same state organizations. This state sponsored vertical integration enables abu…

> The ICBC has a literal state sponsored monopoly over car insurance No, this is only true for the most basic plans (called Autoplan). For anything beyond this, eg third-party liability, collision, comprehensive, etc., you can buy private insurance or go with ICBC for those plans too if you want.

But that basic insurance is extremely overpriced compared to similar insurances in other countries, and it is mandatory so you have to pay it.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#59

Earlier quoted context omitted.

> Imagine going to an amusement park and signing a waiver that the park takes no responsibility for your injuries. If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible I don't know Canadian law, just for fun this is my understanding of it under US laws which are likely similar although Canada usually has more co…

> My guess (not a lawyer just guessing) is that if they followed all best practices and someone bruteforced an RSA 2048 key which is currently understood to not be (reasonably) possible - that might be covered? However if they left a S3 bucket open without a password, that would be under negligence? Not a lawyer either, but to me, since users have no means to protect themselves against a backend breach, it seems like…

The standard with dog bites is “reasonable precautions” to prevent them, thus a good fence that failed because it was hit by a meteor could be a perfectly reasonable defense. People don’t build structures with rocks falling from the sky in mind. On the other hand a fence the dog can open or climb over is not, which of course depends on the dog.

I suspect the same would be considered for computer security. Hacker News and a Bank have very different bars for what’s reasonable.

Re: Canada's tax revenue agency tries to ToS itself out of hacking liability

#60
post #58
post #57

Earlier quoted context omitted.

> The ICBC has a literal state sponsored monopoly over car insurance No, this is only true for the most basic plans (called Autoplan). For anything beyond this, eg third-party liability, collision, comprehensive, etc., you can buy private insurance or go with ICBC for those plans too if you want.

But that basic insurance is extremely overpriced compared to similar insurances in other countries, and it is mandatory so you have to pay it.

If it's overpriced (relative to payouts) and the funds get returned to the population at large (through public services and mitigation of indirect damage caused by drivers) then that sounds like a very effective way to get drivers to pay for their externalized costs (in a way that other countries' privatized, profit-limited insurance schemes doesn't afford).
Post reply on HN