7 ms·
My bank used to reject scans but accept faxes... bureaucratic reasons.
by cgrand-net 6y ago
My bank used to reject scans but accept faxes... bureaucratic reasons.
- dd36 6y agoFaxes are considered secure.
- somehnguy 6y agoI'm declaring myself as considered a Triceratops . Doesn't make it true.
- swixmix 6y agoIt depends on the threat model. If I need to prove to a court in the US, then I'm signing paper and faxing it. To do it differently would be more expensive to prove.
- somehnguy 6y agoRight, the legal system considers it secure. I'm talking about the technical sense. Where there is no encryption at all, anyone with a phone line splitter can listen in, and the machines are usually not in a secured area so anyone could just pick up the fax and walk away. Not secure at all.
- monkpit 6y agoI don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. What matters is legal precedent and existing policy in various countries.
- loeg 6y ago> I don’t think you need to argue that fax is not technically secure on HN. Pretty sure we are all on the same page there. dd36 and swixmix seem to be taking the other side of that argument.
- dd36 6y agoIf I were taking that side, I wouldn’t have qualified my statement. Gov’t and courts consider it secure. HIPAA compliant, etc.
- bcoates 6y agoThey're secure in the sense of being low-risk for active content shenanigans and a small surface area for vulnerabilities. Attacking a network through a .tiff of a fax is a lot harder than attacking it through an email, pdf, word doc, http session, etc.
- jkaplowitz 6y agoIt depends on what your threat model is. The attacks you're talking about are real, absolutely. For the threat model of a physically local attacker with either the right timing (for grabbing an incoming fax) or the right knowledge (for the phone system equivalent of tcpdump), you're quite right that fax is insecure. Likewise for state sponsored adversaries or certain organized crime groups. But if you just want to make it hard for people scanning the internet to see what juicy corporate espionage they can find and resell, without specifically targeting you, fax is probably less vulnerable to that threat model than, for example, an undermaintained email server. Likewise if you piss off script kiddies somewhere on the internet with botnets and exploit kits, your website is probably a bigger risk than your fax machine.
- cortesoft 6y agoIf you pass a law stating you are a Triceratops, it would become 'true' in the legal sense... and since we are dealing with legality, it being declared 'secure' does matter
- yourapostasy 6y agoBehold...the power of lobbyists. Fax industry sure got their money's worth that year that passed.
- recursive 6y agoI don't know directly, but I've heard that there are special laws regarding fraud via fax. Even though fax has no technical protection, it may have legal ones, that might give the counterparty some recourse if things went bad.
- Xylakant 6y agoIn Germany, a fax is legally considered an original copy, a scan/print is not, despite a fax often being a scan that’s then transmitted via fax protocols. Law hasn’t caught up with technology yet in that area. You also get a confirmation from the recipient when using fax.
- detaro 6y agoAll the while we actually have a pretty good law about digital signatures since basically forever, but ~nobody supports those. (and they missed the chance of using the new ID cards to establish them more widely, which was really stupid)
- derefr 6y ago> despite a fax often being a scan that’s then transmitted via fax protocols ...what's the alternative to that "often"? What is a fax machine, if not a scanner attached to a modem?
- anonymfus 6y agoConventional fax machine transmits document while it scans it as it has (almost) no memory. Like analog TV camera, just much slower.
- derefr 6y agoSure, but that's still "a scanner attached to a modem." Nothing about a scanner implies that it must buffer the input, just like nothing about a printer implies that it buffers the output. There are/were "line printers" doing "latch a character from the input line, print the character, unlatch" serial output (which were so common that Unix pipes are designed around the foibles of outputting to such devices.) Most POS thermal receipt printers are still line printers! I don't know as much about scanners, but I can't imagine that the original (digital, attached to a computer) scanners weren't also "serial scanners"—i.e., rather than a 1D scan head with a long CCD strip that could latch an entire line at a time into a shift register, they would have had 2D scan-heads that would scan one pixel at a time, in a "read brightness, signal ready, wait for return line to unlatch" serial loop. No memory required, just terribly slow.
- wayoutthere 6y agoSounds like their document management system was tied to a fax line and they didn't want to bother upgrading. IT departments at banks have like, zero budget.
- qubex 6y agoI read on NH yesterday (or perhaps the day before) that in the USA HIPAA (Health Insurance Portability & Accountability Act 1996) carves our a special exemption to consider faxes ‘secure’.
- loeg 6y agoIt does.