10 ms·
> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and inc
by stewx 4y ago
> 10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsible for any damages you may experience as a result
I am not a lawyer, but I would be surprised if this holds water, legally speaking. Imagine going to an amusement park and signing a waiver that the park takes no responsibility for your injuries. If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible. Getting someone to sign something that says "we did our due diligence" doesn't make it true.
- bee_rider 4y agoOn top of this, I don’t see how a contract that you are compelled to agree to in order to do your taxes could be seen as one that you’ve willingly entered.
- stewx 4y agoUsing the My Account web site is not required to do your taxes. You can file by mail AND electronically with Netfile without using it at all. Src: https://www.canada.ca/en/revenue-agency/services/e-services/e-services-individuals/netfile-overview/eligibility.html https://www.canada.ca/en/revenue-agency/services/e-services/... That being said, My Account is a useful, albeit very flawed online tool.
- theloco 4y ago[flagged]
- dang 4y agoCan you please not post like this to HN? It's not what this site is for, and destroys what it is for. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
- thewataccount 4y ago> Imagine going to an amusement park and signing a waiver that the park takes no responsibility for your injuries. If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible I don't know Canadian law, just for fun this is my understanding of it under US laws which are likely similar although Canada usually has more consumer protections. You generally can't waive negligence. Those waivers can be useful for things like a trampoline park - someone lands on their ankle wrong and injurs it, the waiver deals with assumption of the risk - landing incorrectly is a reasonable risk due to the nature of the event. However if a net was missing and you hit the concrete floor - that would be under negligence of the premises owner. My guess (not a lawyer just guessing) is that if they followed all best practices and someone bruteforced an RSA 2048 key which is currently understood to not be (reasonably) possible - that might be covered? However if they left a S3 bucket open without a password, that would be under negligence?
- everforward 4y ago> My guess (not a lawyer just guessing) is that if they followed all best practices and someone bruteforced an RSA 2048 key which is currently understood to not be (reasonably) possible - that might be covered? However if they left a S3 bucket open without a password, that would be under negligence? Not a lawyer either, but to me, since users have no means to protect themselves against a backend breach, it seems like it would inherently be the fault of the business. My chosen parallel would be owning a dog. Owning a dog has some inherent risk, because even if you take all precautions, there's always a chance it gets off it's leash or breaks out of the yard and bites someone. "I had a fence" shouldn't free you from liability; the fence was insufficient because someone still got bit. The only way to be free of that small risk is to not own a dog. I view data the same way. Storing sensitive data comes with an inherent risk that it will be compromised. By asking for and keeping that data, companies assume the risk of that data being breached, and any resulting damage. If that risk is unacceptable, don't ask for or keep the data. Or find some way to make it so the data can't cause damage even if it's stolen (e.g. by using some kind of public tax ID).
- 4y ago
- posguy 4y agoLegal structures and especially state or state sponsored entities in Canada work much differently than in the US. The ICBC has a literal state sponsored monopoly over car insurance, titling a vehicle and driver licensing, whereas in the US no state handles car insurance, while titling a vehicle and driver licensing are not necessarily the same state organizations. This state sponsored vertical integration enables abuse of authority in cases like https://www.reddit.com/r/nottheonion/comments/xa9j3x/church_of_the_flying_spaghetti_monsters_icbc/ https://www.reddit.com/r/nottheonion/comments/xa9j3x/church_... Whereas here in the US I know many people that mix and match between different states DOLs and DORs for a variety of reasons, and your not going to get stuck with the same stubborn employee who can control every facet of your ability to identify yourself and also legally drive a vehicle on the road. The DUI checkpoints up in BC are wild too, I'm glad they are banned in Washington and Oregon. Suspicionless stopping of cars en masse followed by interrogation by police seems like an overreach.
- noughtme 4y ago"Wild" meaning, the police can still impound your car at their discretion if you blow below not just the legal limit of 0.08, but below the warning limit of 0.05, or even 0!
- Scoundreller 4y agoNo shortage of drugs that can make someone a terrible driver. Many drivers are worse alcohol-free than a legally drunk good driver. Focussing on one cause of bad driving (lots of alcohol) is a weak approach to road safety.
- lotsofpulp 4y agoOr a mobile device. Any time of day, I would estimate at least 50% of drivers are glancing down and using phones while driving. Even cops.
- InitialLastName 4y ago
- generalizations 4y agoWhat happens if you don't agree to the TOS? Pretty sure that means you can't do your taxes, and you'd get in pretty hot water as a result. To me, that implies that the Canadian government is forcing you to agree to this TOS, which further reduces its legal defensibility.
- greenshackle2 4y agoYou can still mail in paper forms.
- goosedragons 4y agoBut they might still "email" any reassessment or whatever to your account if you setup paperless beforehand..
- mitthrowaway2 4y agoGenerally the CRA will only email a notice that there is a new message waiting for you on their site; you have to log in to their site to access the message. As far as security practices go, I won't complain about that.
- goosedragons 4y agoYeah, thats why I had email in quotes. Could have been more clear I guess. Still a problem that you need to accept their TOS to see if they decided you owe money.
- 1over137 4y agoNo, you don't have to have any electronic account with the CRA, you can file by paper, and they write you back by paper, and you can pay by cheque, or get your refund by cheque.
- j_not_j 4y agoAnd the bad boys and girls can still hack CRA and if they defraud you using the data they stole is CRA still liable in spite of your paper-based filing? You will have to prove a lot of "facts" to win that lawsuit. Especially since your social number(s), email, phone, whatsapp, etc are all public info already. Recall a few years ago an uneducated hacker ("script kiddie") got part way into a CRA website and they took the whole website down for a week. (The attacker was caught, and prosecuted iirc.)
- tremon 4y agoWhat's interesting to me is that they provide assertions about themselves in the TOS. How is any user going to verify those statements?
- bombcar 4y agoAnd what if those statements are proven false in a breach!
- pcthrowaway 4y ago> If you climb aboard a rollercoaster that hasn't seen any maintenance in 20 years and you get decapitated, I'm pretty sure the park is still legally responsible > "any script, robot, spider, Web crawler, screen scraper, automated query program or other automated device or any manual process to monitor or copy the content contained in any online services" But the CRA already anticipated this and explicitly disallowed headless clients
- kmoser 4y ago> ...or any manual process to monitor or copy the content contained in any online services" So, not allowed to use Ctrl+C on their website?
- nottathrowaway3 4y agoNot a Canadian, but this just seems like a chicken running around with its head cut off [1]. A one-legged duck swimming in a circle. Why does a government want to protect itself from hacking liability via ToS in the first place. Couldn't they, you know, just pass a law saying they're not liable? [1] https://en.m.wikipedia.org/wiki/Mike_the_Headless_Chicken https://en.m.wikipedia.org/wiki/Mike_the_Headless_Chicken
- DlSGUSTlNG 4y ago[dead]