Bogus digital signatures, Re: OT: utility account transfer frauds

Dave Howe DaveHowe at gmx.co.uk
Sat, 12 Oct 2002 10:17:25 +0100


Ian Brown wrote:
> Charles Lindsey wrote:
>> Which seems to me like a good argument why the law should assume that
>> anyone who does not keep his key secure should be made to abide by
>> the content of anything signed with it.
>
> Then you think it's wrong that UK credit card companies generally
> bear the risk of transactions made by stolen cards (which are much
> easier for the average user to protect than a software-held private
> key) after the first ?50?
I assume that is for cardholder-present transactions then - because for mail
order (or web order) they are damned quick to deduct the amount of the
forged payment from our next month's transactions - even for a £5-50 data
lead....