back

by toddmorey·12y ago·view on hn ↗
It's maddening that their default position offers no real amends for their 38 million impacted customers, save for a free year of credit monitoring. Canceling my card and getting it reissued is not trivial.

It's not so much the breach as it is the lackluster response and lack of ownership of the problem that has me ready to cancel the service. Even the original blog post, which reported only 1/10th of the real information leak, started with: "Cyber attacks are one of the unfortunate realities of doing business today. Given the profile and widespread use of many of our products, Adobe has attracted increasing attention from cyber attackers."

Sure those are valid statements, but they don't really help me feel good about the Adobe platform going forward, and they do more to pass responsibility than to claim ownership.

2 comments
You should not be upset with Adobe. You should be upset with your payment card provider.

This industry has systematically externalized the cost of these data breaches, and the security systems necessary to try to prevent them, to every other business and end-user in the country.

There are many ways to solve this problem. Europe has largely solved this problem, and using your antiquated American credit card in Europe is not only difficult, but even if possible will elicit crazy looks.

What other industry today would you trust that the only security is a 16 digit number that you repeatedly share with the world and your zip code? And to think this is how we secure our money?

Adobe is offering a service that costs at the least tens of dollars to 38 million people. What is your credit card offering?

Abobe is required to offer credit monitoring. That's not an optional altruistic service on Adobe's part. Depending on the details of the hack, the CC processors can also fine Adobe significant amounts.

The credit card company is offering full fraud protection. So if someone does use your CC for fraud, you're inconvenienced, but not liable. That's far more than what Adobe is required to offer.

I'm quite happy with the American system of "it's the CC provider's responsibility to sort out fraud". It allows commerce to flow, and the backend can figure out fraud most of the time. Putting the burden on a consumer via a PIN system now means consumers have to be more careful, which is bad for consumers and could possibly deter them from using the cards as much.

Edit: The one thing I'd agree on is the broken system of "credit" in the US. Any company can ruin your credit rating based on their own internal policies, and successfully fighting is a major ordeal. All a company has to do for proof is show a bill, which they literally can just make up.

Additionally, requiring an SSN for everything is ridiculous. Cable TV and prepaid T-Mobile even demanded one. In Canada, no company is allowed to refuse service if you decline to provide your SIN.

The free monitoring is only available to the subset that they've confirmed had their payments info affected. They currently are claiming this is only 3M of the 38M customers.

Source: They just directed me to protectmyid.com and told me to sign up and pay for it myself. Not a great customer service experience.

> Europe has largely solved this problem, and using your antiquated American credit card in Europe is not only difficult, but even if possible will elicit crazy looks.

Wait what does Europe do? Just genuinely curious, and a cursory google search didn't return anything.

AFAIK, it works the same online as your typical magnetic strip card, however, it's associated with a PIN which likely (hopefully) isn't stored by the merchant. Similar to a card security code (CVV).

Otherwise, offline you place it into a card reader and enter a PIN. The card then authenticates the transaction only if the PIN matches. The card stays within the reader as you enter the PIN.

Further reading,

http://en.wikipedia.org/wiki/Chip_and_PIN

http://en.wikipedia.org/wiki/EMV

Chip and pin cards.

I can confirm, when I first came to the UK four years ago, only major retailers seemed willing to accept my Canadian CC, and even then, the cashier usually had to call the manager to confirm that it's ok.

Another thing I have to credit Europe with is the lack of proprietary debit card systems like Interac or Plus. It's all done via Visa/Mastercard Debit, so you're never forced to do your online shopping on credit.

Coming from Vancouver, I assumed chip & pin cards were widespread across Canada (they are here). I suppose this is not the case?
You won't leave Adobe because you refuse to learn an alternative tool chain. Talk heavy, maybe adobe will listen and forfeit some of the massive power they have over the internet and users.
Whoa, that's completely unfair. In fact, wherever it's possible (like on independent projects), I work with alternative software. Not to protest Adobe, but because I just think there's better software out there. Some of it is open source. All of it is significantly cheaper, loads faster, and has less bugs.

However, design involving collaborators, vendors, and professional output often requires standardizing on Adobe software. I'm not happy about it, but it's where the industry currently happens to be. Don't confuse honest pragmatism with some form of stubborn laziness.