4 ms·
Around the time of the Equifax breach, there was a discussion here that put it succinctly. "Identity theft" is just a clever name for "fraud" that shifts the re
by matmann2001 7y ago
Around the time of the Equifax breach, there was a discussion here that put it succinctly. "Identity theft" is just a clever name for "fraud" that shifts the responsibility away from the bank.
- vernie 7y agoSimilar to "responsible disclosure"
- october_sky 7y ago> Similar to "responsible disclosure" Huh? How is "responsible disclosure" related at all?
- taviso 7y agoIt's acceptable to cut corners and ship shoddy software to consumers, because if anyone points out the flaws, they're being "irresponsible". The responsibility to protect customers is therefore shifted away from the vendors onto researchers. Pretty sweet deal, because good quality security engineering is expensive!
- SpicyLemonZest 7y agoI have never once seen someone say that it's irresponsible for security engineers to point out flaws in software. Indeed, "responsible disclosure" often includes disclosing bugs even though they haven't yet been fixed when the developer isn't responding. There are problems with the term, but this isn't one of them.
- taviso 7y ago> I have never once seen someone say that it's irresponsible for security engineers to point out flaws in software. I've got news for you, it happens all the time. I can't open my mouth without some Microsoft lackey shouting irresponsible at me.
- deleted 7y ago[deleted]
- dkersten 7y agoThe people that I know that works in security research treat responsible disclosure as "you have X time to fix it before we tell the world", to give them a chance to fix things before everyone, with who knows what intent, gets to learn about the issue. There's always a time limit and then its released regardless.
- romwell 7y ago>"Identity theft" is just a clever name for "fraud" that shifts the responsibility away from the bank. Indeed. Here's an analogy I like using (warning: ethical argument follows, not a legal advice). Say, you give your car keys to a valet to park, along with the fee. You come back to find no car. The valet informs you that they already gave away the vehicle to a homeless person that "kinda looked like you, man" because they asked for it. You never get your car back. Now, I personally think it is very fair to hold the company that employed the valet 100% liable for the damages. The business of operating valet parking comes with certain obligations, one of which is to keep your vehicle safe, and return it to you and only to you. If they can't do that, they shouldn't be in that business. It's not your problem that the valet got high and fulfilled an authorized request. They owe you a vehicle. Same with a bank. Allowing unauthorized (meaning: unauthorized by you) access to your account is the failure of a bank to do its job and fulfill its obligations to you. For that, the bank is fully liable. The damages that the thief thus caused to the bank should not be your concern. ------ TL;DR: a thief is guilty for stealing from the bank. The bank is guilty for letting someone else access your account. Both are 100% liable - for different things.