4 ms·
Designing a system to resist law enforcement is not the only way to make a system that resists insider attacks. In fact, it's a terrible way. Banks have figur
by codex 13y ago
Designing a system to resist law enforcement is not the only way to make a system that resists insider attacks. In fact, it's a terrible way. Banks have figured out how to comply with the law, allowing law enforcement to seize bank assets, without letting employees abscond with deposits; it's not difficult. The two problems are not the same.
- jlgreco 13y agoJust because one can be done without the other does not mean that doing one without the other is preferable to doing both.
- AnthonyMouse 13y ago>Banks have figured out how to comply with the law, allowing law enforcement to seize bank assets, without letting employees abscond with deposits; it's not difficult. Are you sure? It seems that all banks have done is to be able to resist attacks from adversaries up to a certain size. Typical criminals are smaller than this, typical governments are larger. But when the reverse is true the banks fold to the criminals (as in various high-corruption countries), or the government folds to the banks and let them out of well-deserved hot water when the banks are the ones thieving and cheating. I don't like either of those things if I'm a depositor who is trying not to have deposits stolen by criminals, bankers or corrupt governments.
- kevinpet 13y agoThat's not true. The financial system does not primarily rest on technical safeguards. It rests on legal safeguards and risk management (i.e. it puts the onus to strike the balance between security and convenience on the company in the best position to decide what's a legitimate request). If I have read-only access to your bank, or to Mint, or if I can steal your mail, and I've ever received a check from you, I can set up an ACH relationship with my broker. I could probably even pull money out of your account. The transfer would be quickly reversed, and I'd be easily caught.
- PeterisP 13y agoInsider attacks are definitely not a solved problem for banks, insider attacks or cooperation with insiders are a major part of realized fraud losses. For banks (unlike data companies) the most effective anti-fraud tools are actually not about prevention, but detection and mitigation. Well, also insurance and prosecution.