You can't make this up.
You can't make this up.
ich arbeite als (externe) CyberCyberCyber Nase in einer Organisation irgendwo in der Sparkassengruppe. Ich kann dir versichern, dass niemand, der auch nur im entferntesten was mit InfoSec in der Bank zu tun hat, von dieser Marketing Idee erfahren hat.
"I work as an (external) CyberCyberCyber nose in an organization somewhere in the Sparkassen-group. I can assure you that no one who is involved even the slightest with infosec at the bank, has heard anything about this marketing idea."
What the hell.
https://t3n.de/news/sparkasse-digital-strategie-cds-per-post...
Since no-one has a CD drive in their computer anymore, the security risk is negligible
"The Sony BMG CD copy protection scandal concerns the copy protection measures included by Sony BMG on compact discs in 2005. When inserted into a computer, the CDs installed one of two pieces of software that provided a form of digital rights management (DRM) by modifying the operating system to interfere with CD copying. Neither program could easily be uninstalled, and they created vulnerabilities that were exploited by unrelated malware. One of the programs would install and "phone home" with reports on the user's private listening habits, even if the user refused its end-user license agreement (EULA), while the other was not mentioned in the EULA at all. Both programs contained code from several pieces of copylefted free software in an apparent infringement of copyright, and configured the operating system to hide the software's existence, leading to both programs being classified as rootkits."
https://en.m.wikipedia.org/wiki/Sony_BMG_copy_protection_roo...
The common way to get USB malware to install automatically those days was to modify the USB drive to appear as a virtual disc drive, which worked.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
https://www.fca.org.uk/firms/durable-medium
https://www.lexology.com/library/detail.aspx?g=788714a1-d7b6...
Why the bank decided to use USB for this purpose, instead of paper, is very strange.
Still, actual write-once (or read/write until hardware fuse is triggered, read-only afterwards) SD cards should be possible to make.
I've definitely encountered read-only SD cards which I couldn't figure out a way to set it back to RW mode.
Do you have a source backing that up?
Aside from the local tax collector, which insists on snailmailing me a copy of all correspondence even though they also sent everything to me digitally, I can't even remember the last time I received any documents on paper, and I'm in the EU.
https://www.fca.org.uk/firms/durable-medium
https://www.lexology.com/library/detail.aspx?g=788714a1-d7b6...
Why did you need a source for this?
"A PDF can therefore meet the definition of a durable medium."
I think that's shown by the post statistics: around 25 letters received per resident, per year.
I can't remember the last letter I received which only contained papers.
Ramble Edit: it's unfortunate IMHO that there is no "read only" medium anymore. Not sure what it would look like now when USB-C is taking over the world, and that ship probably sailed, but it would be really cool and useful to have the option of a "data only" USB.
Maybe computers could have one USB port marked as "ROM". Or a switch or LED symbol indicating "ROM safe" mode.
When using such a ROM port, anything USB inserted there would only look like a DVD reader. A USB drive would get its files "mirrored" into a virtual ISO filesystem. Any other devices, such as keyboards etc would be just ignored and not connected to at all.
Then there are LTO tapes that have WORM version, which is notionally not overwritable, but that is IIRC also only enforced by software (of the drive).
Also, this is only a software solution as the USB protocol would require bidirectional transmission.
But it would bring us back to being as safe as a CD or diskette was.
I was thinking a special chip, talking bidirectionally both ways, pretending to be a PC host to the USB drive, and pretending to a DVD-ROM to the actual PC.
Even the (*-grand)parent never said the law actually says it can't be an email attachment, they said companies seem to interpret it that way. Which would not be surprising in the least. Then someone said they've never heard of any such law, and I pointed out that it exists.
I'm not sure who you're arguing with but it isn't me or in fact any of the people in this thread.
Sheesh, reading comprehension, please. That or stop moving the goalposts
> Durable media should enable the consumer to store the information for as long as it is necessary for him to protect his interests stemming from his relationship with the trader. Such media should include in particular paper, USB sticks, CD-ROMs, DVDs, memory cards or the hard disks of computers as well as e-mails.
USB sticks are on the list, but so is paper and e-mail. This USB stick could have been an e-mail.
Yes, if two people are going to answer with the exact same link and nothing else, I'm going to answer both with the exact same comment.
> Opinion of Advocate General Mengozzi delivered on 6 March 2012.
> [...]
> In the light of the foregoing considerations, I suggest that the Court answer the question referred to it by the Oberlandesgericht as follows:
It is not the court's decision.
> Terms and Conditions, Price and Service List, Conditions.
> Dear customer,
> our price and service list, our terms and conditions, as well as further conditions which will come into effect on May 1, 2024, can be found on the USB stick.
> With kind regards,
> The Sparkasse Bremen AG
This is like buying vegetable & olive oils from BP or Shell because they're oil experts looking for new income streams as we shift away from petroleum.
Just be sure to use the included NOTVIRUS.EXE viewer for best experience.
Hyperbole, but it's like a bank employee calling you from an unknown number and asking for your email password so they can make sure their communications about your mortgage application don't go to the spam folder.
Oh, trust me, it'll absolutely come from the bank where they're doing all the due diligence necessary, and not from a random malicious party!
It'll say FROM THE BANK on the envelope, so you'll know it's legit.
>I am using Linux anyway.. No autorun.exe here.
Oh, you'll have to do a bit more work then. Just follow the instructions included in the envelope, and run
sudo ./notvirus.sh
from the terminal from the root directory of the USB drive once you mount it.