cross-posted from: https://feddit.org/post/4262252
A combination of good high-speed internet coverage, high digital literacy rates, large rural populations and fast-growing fintech industries had put the Nordic neighbours on a fast track to a future without cash.
[…]
But Russia’s invasion of Ukraine in 2022 and a subsequent rise in cross-border hybrid warfare and cyber-attacks blamed on pro-Russia groups have prompted a rethink.
[…]
The Swedish government has since completely overhauled its defence and preparedness strategy, joining Nato, starting a new form of national service and reactivating its psychological defence agency to combat disinformation from Russia and other adversaries. Norway has tightened controls on its previously porous border with Russia.
[…]
[Norway’s] justice and public security ministry said it “recommends everyone keep some cash on hand due to the vulnerabilities of digital payment solutions to cyber-attacks”. It said the government took preparedness seriously “given the increasing global instability with war, digital threats, and climate change. As a result, they’ve ensured that the right to pay with cash is strengthened”.
[…]
Yeah, considering how bad banks and other financial institutions are at IT security and the fact that there’s no incentive for a capitalist financial institution to fix that problem, it’s not a good idea.
That’s not entirely true. In order to be allowed to keep processing transactions you have to adhere to strict rules which do get regularly audited. And then there’s the whole “customers will switch to another more reliable party in case of outages or security problems”. And trust me, I’ve seen first-hand that they do.
You have to put on a show that you are sticking to those processes, on paper. But the fines for data breaches are generally way less than they save on not having a fully funded IT department and using security products that someone got a kickback for rather than the best product.
“Hacking” isn’t some magical, intensely creative process for geniuses loke on TV. For the most part, it’s usually just finding the really common things that IT departments don’t do because they are underfunded and treat IT people like replaceable cogs. There is software out there to exploit those deficiencies. So they are forced to do things like use default or obvious admin passwords because who knows who is going to be there tomorrow to fix something and without the proper tools to store credentials, there’s no way to properly secure things.
And when a security vulnerability is found, there’s a reason why many don’t bother informing the company before going to the media. Those companies pour tons of money into lawyers to avoid admitting the fault, often getting the innocent person who found the problem arrested, and never fix the actual issue. Just ask any pro whitehat security researcher not hired by the company all the things they have to do to protect themselves from being sued or arrested for “hacking” when they notice a problem.
And government technical auditors are a rarity because the regulators are underfunded. So they might go through some small list of things during regular audits, but they don’t know to check if a DBMS system that contains backups and is stored “in the cloud” is using a default password or other common hacking targets. Hackers don’t go after the primary infrastructure most of the time. It’s not necessary because there are so many sloppy processes or left over insecure projects that “the last guy” was working on or that got defunded before it was completed, but only the primary infrastructure gets audited usually because that’s all there is time and money for.
As for going somewhere else, there often aren’t other places to go and when there are they usually have the same problem because there’s very little reason for any of them to compete with each other. Most industries have consolidated so much that there are only a handful of parent companies left so it’s easy to collude just because their leaders are often all in the same room at conferences and such.
I think you’re being too pessimistic about IT security, particularly in the Financial sector. A lot of the security rules and audits aren’t even government-run, it’s the sector regulating itself. And trust me, they are pretty thorough and quite nitpicky about stuff.
The cost of failing an audit also often isn’t even a fine, it’s direct exclusion from a payment scheme. Basically, do it right or don’t do it at all. Given that that is a strict requirement for staying in business, most of these companies will have sufficiently invested in IT security.
Of course it’s not airtight, no system really is. But particularly in the financial sector most companies really do have their IT security in order.
And then there’s the whole “customers will switch to another more reliable party in case of outages or security problems”.
Outages? Yes. Security problems? LMAO!
Our company has directly profited from a competitor that leaked sensitive data, because some of their large corporate customers decided to switch to us.
Business don’t like being on the receiving end of a data leak either you know.
If it isn’t cash you have to ask permission from someone to use it
Most of us need permission just to get our hands on cash.
Exactly… I am amazed that we all allowed for things to get this bad.
A lot of work to try to undo this idiocy.
Deny money changers profit
Cashless can only work if you adopt a digital cash such as monero, other wise you are taking away privacy, control and possibly small transactions (depending on what fees are common in your country)
In a cashless society banks and credit companies become your rulers as you have no real way to bypass them.
I suspect that any country that tries to go cashless without a real cash alternative, will just find itself with a new form of cash (gold, silver, etc) since eventually there will be enough people trying to avoid fees and taxes
Cryptocurrency has basically many of the same problems as traditional banks, it’s just a matter of who is controlling it. Monero is slightly different from most, because it is much more anonymous, but it’s really only a matter of time before even that advantage is lost.
There is no substitute for physical currency if you want privacy and anonymity.
Do you know how Monero’s advantage could potentially be lost?
From what I understand, which honestly, isn’t a lot - the method used to anonymize transactions and balances is more like obfuscation than anything else. The system uses various techniques to fuzz up the data in such a way that it becomes impossible to trace.
It’s a bit like if you wanted to send a bank transfer for £200 but anonymize it somewhat, you could transfer that money around between a bunch of other bank accounts, before sending it on to the final source. And if multiple people are doing the same thing, it becomes essentially impossible to determine where the money entered and left.
The problem is though that such systems aren’t true encryption in the same way that RSA is, for example - the data isn’t unreadable, and it’s not impossible to reverse, it’s just that there’s so much junk data and it’s such a mess that it makes the true transactions difficult to identify and the end user has extremely strong plausible deniability. However, it’s likely just a matter of time before some state actor finds a vulnerability in the technique that allows them to trace transactions - if they haven’t already done so.
What if it bounced through multiple peers between sender and recipient, encrypted on each hop like Tor? Then they’d need to actually break the encryption, or compromise every hop.
The transaction data itself does need to be publicly readable, because otherwise the whole consensus mechanism that the blockchain relies on wouldn’t work.
Hmm gotcha. Yeah this stuff goes over my head haha but it sounds similar to a Bitcoin mixer/tumbler. I wonder if the anonymity scales with the number of users using the network. I also wonder if you happened to send a transaction at a “bad” time (no-one else is using the network) then it’s easier to trace.
Yeah, totally - I think it’s designed to be hard to understand, both tech stuff and financial stuff is often made intentionally confusing, in my opinion. It’s not dissimilar to the bitcoin mixers, but it’s still much stronger - the system is automated, you can’t mess it up as a user, you’re less reliant on a single-point-of-trust, and so on.
You might be on to something about quiet periods - I don’t really have the knowledge to say either way. There might be a bit of stuff that goes on in the background for wallets even if they’re not actively conducting “real” transactions. But, I don’t know, really.
Sure, but if a cyber attack knocks out your credit card systems in a targeted attack, chances are they’re taking your cash machines down as well.
And who carries enough cash around to be useful any more? I know I don’t. I might have a £20 note tucked in my phone case at a push.
And who carries enough cash around to be useful any more?
I do. Maybe not physically in my pocket, but between my wallet and my home there’s enough cash to buy a tank of gas and a few days of groceries.
Parts of the debit/credit processing system are fragile enough that I’ve seen them down randomly for signifigant portions of a day.
Cash has got me food when other people have been stuck without the ability to pay more than once in the last couple of years.
Proper planning which more people should be doing!
But people also should be using cash as much as possible before regime takes it away.
£20 should still get you a meal of some kind until the credit cards and cash machines are back, hopefully within a few hours or next day at the latest.
Can’t really say I even have that much on me most of the time though - perhaps I should change that, keep a minimum of like €50 that’s only touched in an emergency or something. Swedbank has had several outages in the last few months here in Estonia and it affects many stores’ payment terminals too.
Just having a power outage is enough lol, never mind an attack.
Carrington event and we are fuckarruuh
Yeees! Great! I like cash.
Not to mention total monetary surveillance
The moment you start using this argument you become a tinfoil hat money laundering thug. Being afraid of putin is more socially acceptable.
Can you clarifying. The sarcasm in first sentence doesnt make sense in context of the second.
I refer to comment sections under news about going more cashless, for example. Commenters saying it’s bad for privacy get downvoted a lot because it’s not socially acceptable to say so.
Same in face to face social setting. If you want to take a stand against cashless, it’s good to say something else than the privacy mantra, or people stop listening to you.
It’s because you’re taking a stance against cashless, which sounds paranoid and weird to most people.
Take a stand against VISA and PayPal. Then the bad guy isn’t “our” government, it’s corporations everyone already hates. And it references problems people already experience.
It’s much easier to explain how the situation is already bad than it is to argue how it “could become” bad.
Hmm, I don’t anticipate the government to have many issues with that part… But if they have access, then enemies of the state may also gain access, which is the real problem they care about here.
I hoped for a second they meant moneyless.
Something we can thank the Russians for and hackers everywhere.
Yup, good things can happen for bad reasons.
The netherlands are already looking into it: https://www.ngi.eu/ngi-projects/ngi-taler/
The project could be used via paper trail, as far as I understand it.
Woot! It’s been a while since I looked into Taler, but I’ve long held that we should be using it or something like it for digital transactions. I’d love a browser extension that compensates creators for removing ads, for example, and I think this would be a fantastic way to do it. But having it at a national level is even better!
Yeah, I think so too. It should replace bank transactions completely.
I hope someone posts here when/if they decide to adopt it, because I’d love to hear more details about it.
Taler e-money is issued with a validity period. One month before the expiration date, you wallet should automatically exchange any digital cash that is about to expire for new digital cash with an extended validity period.
Haha no, thanks. I really don’t understand why Stallman stands behind dystopian statist money.
I think the idea was that you can’t hoard anything, and stealing or reusing is harder. But it does make the central management way more powerful than it should be. But it’s normal bank standard.
What do you mean with “dystopian statist money”?
Since when keeping the money you earned is “hoarding” and a bad thing?
I think money with expiration period that exists to prevent people from having savings is very dystopian, I don’t feel like there is something to explain.
For the individual saving is something very good. For the economy, however, a money hoarder is dead weight. It’s why inflation won’t ever completely go away, because it discourages hoarding (investing/bringing it to the bank can counteract this, that’s why I didn’t call it saving the second and third time)
It really depends who the issuer of the certificates (wallets) is. The funds get automatically transferred and won’t be lost, it’s “just” a privacy problem (plus the issuer will probably be able to interfere).
So the idea isn’t that dystopian, but it very much depends on the implementation.
In the conflict of interest of individuals vs. “the economy” I’m on the side of individuals, sorry.
If he doesn’t like hoarding, why doesn’t it just inflate?
I think the reason for this implementation is more the theft prevention. This sounds very mich like certificates to me
I’m more concerned with the threats from the people in charge of the system, but whatever gets them to the conclusion that it’s a bad idea is fine with me.
Money changers in shambles.
The risk of the payment system getting shut down and people being unable to make payments for a while is real. And it is one good reason to be less reliant on digital payments.
But there is also the risk of bad actors, which could also be e.g. Russia, getting access to decades of payment history through a hack, if everything is digital. Having that data for every citizen of a country could enable efficient profiling of people in the country using big data analysis technologies.
The kind of thing you could find out with the transaction data is who are working in the military or security police, who is sympathetic to Russia and at the same time vulnerable to work with foreign governments, and potential blackmailing material relating to people in these or other groups. I’m sure the analysts working for the bad actor can come up with even more useful things to look for in the data.
There are of course a lot of other data sources that bad actors are interested in and that are easier to hack, but the financial history seems more comprehensive source of information than most other ones.
Having that data for every citizen of a country could enable efficient profiling of people in the country using big data analysis technologies.
You don’t need an external actor for that, a government can very well do that to their citizens…
It already happened in Ukraine during the NotPetya attack by Russia in 2017
https://en.m.wikipedia.org/wiki/2017_Ukraine_ransomware_attacks
Yup, I keep a fair amount of cash on hand at home in case there’s some kind of mass outage so I can at least get essentials to last until power is restored. Oh, and I also use it for my kids’ allowance and for baby sitters, but I have larger denominations as well in case of emergencies.
That said, I have been considering using cash more often because I really don’t like all the tracking that already goes on, and I certainly don’t want the government having that data as well. But cash is super inconvenient because of small change, so I haven’t made the switch yet. If we could get rid of the small change and just round prices a bit, I would seriously consider going back to cash.
Just a note, high denominations are not great during emergencies, unless you mean big purchase emergencies. Buying food and gas with high denomination bills may end up in seller not accepting the bill because they have no change. Or happily accepting that bill despite having no change.
For small change, you could take the jar to your bank and make a cash deposit (and see the cashier die inside). In some branches they have machines for counting change.
unless you mean big purchase emergencies
Yup, exactly that. I’m in the US and keep a few hundred in $100 bills, with the rest being smaller denominations. I usually have about $1k in cash in a safe, with lots of small bills. So that should be plenty to handle a couple weeks worth of groceries, or a couple large purchases (e.g. paying someone cash to move a tree or something).
The risk of the payment system getting shut down and people being unable to make payments for a while is real. And it is one good reason to be less reliant on digital payments.
Or entities. The USA had a brief oil crisis recently because one of the major pipeline companies had their billing system hacked. Since the company couldn’t verify whether someone had paid, they just didn’t supply any oil.
Couple that with some misleading news stories and social media panic, and it blew up into a proper shortage from people hoarding all the petrol, and leaving none left.
Do you have any more info about this?
Here’s an article about them turning it off because of being unable to verify the bill: https://edition.cnn.com/2021/05/12/politics/colonial-pipeline-ransomware-payment/index.html
And here’s two attributing the issue, at least in part, to panic buying: https://www.aljazeera.com/economy/2021/5/11/petrol-shortages-sweep-us-as-colonial-pipeline-remains-down
The risk of the payment system getting shut down and people being unable to make payments for a while is real. And it is one good reason to be less reliant on digital payments.
Exactly.
Part of the card processing system goes down often enough due to various technical failures that it should just be good business sense to always be capable of accepting cash.
We have cash?
o_O
Haven’t used it for years.
Guess you don’t like privacy
It’s still legal tender so they have to accept it. They don’t like it, but they do. Last time I visited Norway I held up the line at the grocery store trying to buy candy with cash that had been gifted to me. I’m not sure the cashier knew what to do with it.
Edit: many people telling me they are not required. From what I could find, cash is still “tvunget betalingsmiddel”, but there are some broad exceptions. Ref. So, I don’t think I was out of line expecting to pay cash at the grocery store. However, that was the only time I paid cash when I visited last time, so yeah, it’s basically cashless already.
They do not have to accept it
legal tender
As far as I understood it in the last 20 years, it is only legal tender for debt facing the goverment. No private business has to accept cash. They do not have to accept cards either. If they wish, they could demand payments only in acorns or bottle caps if they wanted to. Only govermental Institutes (eg. for taxes, fines, etc.) have to always accept cash so you can always free yourself from outstanding debits without needing a bank account as bank wiring or credit cards are a private 3rd party business that can not be guaranteed for every citizen (as banks can arbitrary decline service to people).
At least in Germany legal tender means “valid for payment of any obligation”, also private ones. But if a shop says “we don’t accept cash” then they’re not entering a sales contract with you unless you agree to pay in another way, without contract no payment obligation to them so they’re not required to accept anything, and if there is a contract, well, you agreed to the terms.
I don’t think the same would fly for e.g. rental or utility contracts, though. Any contract that isn’t agreed upon and fulfilled while you’re standing in front of the cashier.
Thankfully, Monero denies nobody
I took a bus in Malmö over ten years ago (on the seaside to the railway station), they didn’t accept cash or card, only some mobile payment. Got a free ride.
Happens with all the ferries in Norway too
Shops in Sweden very often state that they don’t accept cash - and it’s perfectly legal for them to make that choice.
My derped eyes and pronked brain read cashless as moneyless. Comon, Nordic countries, you can do it.
They call that type of “no currency” economy bartering. It works well for peer to peer transactions. Not quite so well for larger ones.
In a post-scarcity society, you wouldn’t need money.
We could actually achieve that too. We’d just need to solve food logistics hurdles, homelessness, useless subsidies, bigotry, corruption, greed. Totally doable in our lifetime. /s