<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fipr]]></title>
    <link>http://securityratty.com/tag/fipr</link>
    <description></description>
    <pubDate>Wed, 23 Jan 2008 12:14:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Financial Ombudsman losing it?]]></title>
      <link>http://securityratty.com/article/74e08152850c21aa924133108ad1f3fd</link>
      <guid>http://securityratty.com/article/74e08152850c21aa924133108ad1f3fd</guid>
      <description><![CDATA[I appeared on You and Yours (Radio 4) today at 12.35 with an official from the Financial Ombudsman Service, after I coauthored a FIPR submission to a review of the service which is currently being...]]></description>
      <content:encoded><![CDATA[<p>I appeared on &#8220;You and Yours&#8221; (Radio 4) today at 12.35 with an official from the Financial Ombudsman Service, after I coauthored a <a href="http://www.fipr.org/080116huntreview.pdf">FIPR submission</a> to a review of the service which is currently being conducted by <a href="http://www.thehuntreview.org.uk/">Lord Hunt</a>.</p>
<p>Our <a href="http://www.fipr.org/080116huntreview.pdf">submission</a> looks at three cases in particular in which the ombudsman decided in favour of the banks and against bank customers over disputed ATM transactions. We found that the adjidicators employed by the ombudsman made numerous errors both of law and of technology, and concluded that their decisions were an affront to reason and to justice.</p>
<p>One of the cases has already <a href="http://www.lightbluetouchpaper.org/2007/02/08/financial-ombudsman-on-chip-pin-infallibility/">appeared here</a> on lightbluetouchpaper; the other two cardholders appeared on an investigation into card fraud on &#8220;Tonight with Trevor MacDonald&#8221;, and their case papers are included, with their permission, as <a href="http://www.fipr.org/080116huntreview.pdf">appendices to our submission</a>. These papers are damning, but the Hunt review&#8217;s staff declined to publish them on the somewhat surprising grounds that the information in them might be used to commit identity theft against the customers in question. Eventually they <a href="http://www.thehuntreview.org.uk/submissions/submissions.html">published</a> our submission minuss the two appendices of case papers. (If knowing someone&#8217;s residential address and the account number to a now-defunct bank account is enough for a criminal to steal money from you, then the regulatory failures afflicting the British banking system are even deeper than I thought.)</p>
<p>The Financial Ombudsman Service, and its predecessor the Banking Ombudsman, have for many years found against bank customers and in favour of the banks. In the early-to-mid 1990s, they upheld the banks&#8217; outrageous claim that mag-stripe ATM cards were invulnerable to cloning; this led to the court cases described <a href="http://www.cl.cam.ac.uk/~rja14/Papers/wcf.html">here</a> and <a href="http://www.cl.cam.ac.uk/~rja14/Papers/liability.pdf">here</a>. That position collapsed when ATM criminals started being sent to prison. Now we have another wave of ATM card cloning, which we&#8217;ve discussed several times: we&#8217;ve shown you a <a href="http://www.lightbluetouchpaper.org/2006/12/24/chip-pin-terminal-playing-tetris/">chip and PIN terminal playing Tetris</a> and described <a href="http://www.lightbluetouchpaper.org/2007/08/08/chip-and-pin-relay-attack-paper-wins-best-student-paper-at-usenix-security-2007/">relay attacks</a>. There&#8217;s much more to come.</p>
<p>The radio program is not yet available online; I&#8217;ll put in a link here when it appears. We clearly have them rattled; the ombudsman was patronising and abusive, and made a number of misleading statements. He also said that the &#8220;independent&#8221; Hunt review was commissioned by his board of directors. I hope it turns out to be a bit more independent than that. If it doesn&#8217;t, then consumer advocates should campaign for the FOS to be abolished and for customers to be empowered to take disputes to the courts, as we argue in section 31-32 of our <a href="http://www.fipr.org/080116huntreview.pdf">submission</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 23 Jan 2008 12:14:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ombudsman">ombudsman</category>
      <category domain="http://securityratty.com/tag/financial ombudsman service">financial ombudsman service</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/submission">submission</category>
      <category domain="http://securityratty.com/tag/submission minuss">submission minuss</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/bank customers">bank customers</category>
      <category domain="http://securityratty.com/tag/independent hunt review">independent hunt review</category>
      <category domain="http://securityratty.com/tag/fipr submission">fipr submission</category>
      <source url="http://www.lightbluetouchpaper.org/2008/01/23/financial-ombudsman-losing-it/">Financial Ombudsman losing it?</source>
    </item>
  </channel>
</rss>
