You really just have to make it enough of a hassle for thieves that they pick the next easier thing to do. Not create Ft. Knox.
You really just have to make it enough of a hassle for thieves that they pick the next easier thing to do. Not create Ft. Knox.
It's not my fault if my house gets broken in. I have no obligation to meticulously lock all my doors and windows when I leave.
But if I get hacked, it's my fault. The onus is on the individual / company to maintain law and order themselves when online.
That feels wrong to me.
I know I might get robbed at any time, maybe I don't lock my door, thats why I put my money in a bank.
The bank has one job - to keep my money safe. If they have no guards andleave the door open, yes, it is their fault.
If you are not prepared to keep armed guards money safe, then you shouldn't be taking other people's money.
Similarly, companies that cannot keep data safe shouldn't be storing my data in the first place.
If a bank has zero physical security measures and leaves the money out in the open, that is negligent.
But, even if a bank has all the state of the art, "best practices" physical security measures, they can still be robbed. No bank is going to stop a nation-state army attacking them, for example.
I think the same is true of cyber security. Nothing will ever be 100% secure. The question is whether the company has followed reasonable best practices and due diligence. Everything else is up to the government to maintain law and order.
> companies that cannot keep data safe shouldn't be storing my data in the first place.
If you're expecting absolute safety, either physically or electronically, there is nowhere in the universe you could deposit your money. Otherwise, the FDIC already has regulations in place to make sure banks are reasonably secure.
On the old 'net, people had to take personal responsibility for their own data-house because neither law nor enforcement had caught up yet to the notion of having a system intruded upon. Remember, we had to pass laws to make "unauthorized access" illegal in the same sense trespassing is; before that, it was just "some signals a stranger beeps at your machine could cause it to malfunction or to send signals back they could interpret as your bank account number. If you don't want that, harden your system against malfunction."
Nowadays, society has caught up but some people with an old-guard mindset still see someone get their stuff stolen and go "Well, should have locked your doors; only way to guarantee your stuff is safe."
“Our research suggests that friendly fraud will represent 61% of all chargebacks by 2023.”
But using weak and/or compromised passwords is a bad idea in exactly the same way that it's a bad idea to leave your front door unlocked.
Legally, we do assign fault for negligence. If absentmindedly leave your kitchen tap open with the drain stopped and then go on vacation, your flood insurance is probably not going to pay for repairs, even if you didn't deserve to have your house destroyed.
From a policy perspective, I think the most appropriate thing would be a middle ground. It is good for everyone's peace of mind to be sure that your entire bank balance won't vanish without recourse, but if you leave your banking "front door" unlocked, the bank covers 90% of the actual unrecoverable loss, but you're on the hook for the other 10%. That eliminates perverse incentives to use weak passwords without being cruel to victims.
I'd argue it's not quite the same... using weak passwords is more like using a lock that can be 'raked'; your security is just lax.
Re-using passwords is like using the same key for your front door, back door, garage, car... If someone finds it and makes a copy of it, they have full access.
Compromised passwords, it's when you know a key is lost or stolen and you don't re-key.
> From a policy perspective, I think the most appropriate thing would be a middle ground. It is good for everyone's peace of mind to be sure that your entire bank balance won't vanish without recourse, but if you leave your banking "front door" unlocked, the bank covers 90% of the actual unrecoverable loss, but you're on the hook for the other 10%. That eliminates perverse incentives to use weak passwords without being cruel to victims.
Both of my main financial institutions have 'pretty dang good' security measures on one level or another. One, has forced password changes at 6 month intervals (not as good as 90 days, but better than many!) The other does not have forced password changes but I know their internal security is... pretty crazy. Losing your badge 3 times is enough to get you fired, and any contractors who do work must be under a very specific specification of video surveillance while working with their clients.
Forcing password changes reduces overall security, especially for infrequently accessed services. It only normalizes the reset workflow, and enables easier social engineering.
The NIST standard (800-53?) was updated to reflect this reality, and it no longer requires periodic password rotation.
This is not generally true. Insurers are forbidden to pay out claims for intentional bad acts, or fraud, but ordinary negligence is usually covered:
> The good thing is your homeowner's policy usually covers you and your family's negligent behavior no matter where it happens.
https://www.nolo.com/legal-encyclopedia/does-my-homeowners-i...
Sure it isn't your fault if your house gets broken in, but you should still lock your door. The more risk you are of your house being broken in the more precaution you should take.
Right now odds are very high that someone will attempt some form of cyber crime against you. As such you should be taking precautions to prevent it. It won't be your fault if it happens, but it will still ruin you day, and may cost you a lot anyway.
If everyone could wormhole between countries, first world houses would be ransacked pretty damn quickly.
That’s why people steal catalytic converters etc.
IMO the cheapening of technology has made a difference with this. When my (then not yet) ex-wife was burglarized, Just her laptop and a camera gave the criminal 900$ at a pawn shop [0].
[0] - which BTW, fun thing about this, if your insurance covers 'replacement cost' you are better off not finding your items at a pawn shop. Most state laws are written such that as long as the pawn shop collects fingerprints/ID, the person who was stolen from can get their items back, but must pay the pawn shop back what they paid the thief for it. Insurance will happily pay that instead but still take your deductible out. (It worked out OK for me, the wedding ring was among the stolen items, never got pawned and that covered the deductible and then some... eventually helped pay for the lawyer lol)
This needs to be a full time job to make the $500/day though. Some houses are as you say now worth the bother, but others have things that can be sold. The key is you need to know what you can sell and for how much before you take it.
As the other poster said, the hard part is not getting caught. The easy places to sell these things (pawn shops, scrap yards) tend to ask for id - and the ones that accept a fake id will only take so much before they have to recognize you.
Without someone to take the risk and a sizable cut your best bet might be a few fake ID’s and a multi city spree of pawn shops. Though if you have access to high quality fake ID’s banks are probably a much better option.