[FYI] Did Encryption Empower These Terrorists?
Bill Frantz
frantz at pwpconsult.com
Mon Sep 24 17:31:47 EDT 2001
At 10:11 AM -0700 9/24/01, lynn.wheeler at firstdata.com wrote:
>as mentioned in the various previous references ... what is at risk ...
>effectively proportional to the aggregate of the account credit limits ...
>for all accounts that happened to have been stored in any account master
>file ... is significantly larger than any particular merchant may have
>directly at risk because of a security breach. in the "security
>proportional to risk" theory .... the entity that has the risk should have
>control over the security measures, those security measures should be
>proportional to what they have at risk, and the cost of those security
>measures should also be proportional to the risk.
It seems to me that because of the $50 liability limit under US law, most
of the risk is carried by the credit card issuers. They are also in a
position to require proper security by contract with the merchant.
Cheers - Bill
-------------------------------------------------------------------------
Bill Frantz | The principal effect of| Periwinkle -- Consulting
(408)356-8506 | DMCA/SDMI is to prevent| 16345 Englewood Ave.
frantz at pwpconsult.com | fair use. | Los Gatos, CA 95032, USA
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at wasabisystems.com
More information about the cryptography
mailing list