8 ms·
As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothi
by _Codemonkeyism 9y ago
As long as the CEO of an company (RNC) that gives data to an outsourcer (Deep Root Analytics) is not going to jail to give data to an unqualified company, nothing will change.
If the CEO goes to jail, things will change very rapidly (CEO will manage his CMO much tighter who will first want to see an security audit not older than 6 months).
At least CEOs I have reported to as CTO were very sensitive for implemention issues in areas that could land them in jail.
Same for every other hacking (e.g. Sony) or IT failure (e.g. British Airlines crashed DC).
- strictnein 9y agoWhat law did they break, exactly? These aren't medical or financial records. A careless programmer makes a bad choice and the CEO has to go to jail? Come on.
- djtriptych 9y agoCareless programmers can also mishandle health/credit card/minor information. We have laws protecting all of that data in particular. I'm not sure the expansion of data privacy laws to include all PII is so farfetched.
- 794CD01 9y agoIt's a slippery slope. Analysis of writing style, patterns of use, etc can deanonymize data to the point where basically everything becomes PII.
- Frondo 9y agoLet's slide a little more down that slope, then. Where personal data and privacy is concerned, I'd rather err on the side of caution, than the world we live in now.
- InitialLastName 9y agoDunno about anybody else, but I'd like to find a convenient canyon.
- urethrafranklin 9y agoLiterally everyone wants that, the problem is there isn't one, at least that anyone's been able to identify as of yet.
- djtriptych 9y agoThere certainly is one, if you only take into account public opinion. We're dealing with conflicting interests of people who generate data and corporations that collect and traffic data.
- dsmithatx 9y agoTreat everything as PII and we are good. The constitution has an amendment to protect our rights. That seems important. I know of no guaranteed right of corporations to infringe on our privacy and to provide access our data. Forty years ago we didn't have this issue because there wasn't so much data for them to try to get their grubby greedy hands on. They don't need our data (ANY OF IT)!
- jtuente 9y agoThe US constitution forbids the US government from acting in certain ways, it in no way impedes upon private organizations. Tort law and the like is what holds private organizations accountable. i.e. The fourth amendment does not protect you from a private entity or individual; laws covering trespassing, theft, breaking and entering do. Please don't drag the constitution into an argument it does not have a place in.
- anigbrowl 9y agoI'd like to argue (not for the first time either) that the Constitution is seriously deficient in its failure to enshrine privacy as a personal right. Great as it has been for the last couple of centuries, I think it's obsolete and should be replaced rather than merely amended.
- gozur88 9y agoThere's no reason that can't be done as an amendment.
- anigbrowl 9y agoIt's not the only thing I'd like to change. Besides which, there is already a movement in progress to bring about another article V convention and I'm guessing the goal of the proponents is drastic rather than minimal alteration. Here's a recent summary article on developments: https://www.washingtonpost.com/opinions/were-surprisingly-close-to-a-new-constitutional-convention-bad-idea/2017/04/06/f6d5b76a-197d-11e7-855e-4824bbb5d748_story.html https://www.washingtonpost.com/opinions/were-surprisingly-cl...
- deleted 9y ago[deleted]
- kevindqc 9y agoIt's not about the careless programmer IMO. It's that there was nothing in place to make sure the data was secure. Or if there was, it wasn't effective.
- angersock 9y agoCareless programmers don't compile dossiers on over 200M American citizens just for funsies.
- Godel_unicode 9y agoYou might be interested in visiting : Facebook.com Lexisnexis.com Twitter.com Plus.google.com LinkedIn.com Etc...
- nemothekid 9y agoNot sure I understand your response. I wouldn't describe Facebook's security processes as "careless", nor would I describe their vast and complete data collection as "for funsies"
- bduerst 9y agoI think their point is that there are thousands of programmers who handle this data on a daily basis as part of their job - intentionally limiting the scope to "funsies" is ignoring that.
- fnovd 9y agoYou can't blame a "careless programmer" when the real problem is organizations simply not committing any resources to security. It's like a hospital only employing 1 nurse and blaming her when patients inevitably die. The organization has a clear responsibility to employee a sufficient number of experts to protect their data. DRA is not unique here but does demonstrate a pattern of companies playing fast and loose with sensitive data with minimal repercussions. We'll keep seeing things like this until our laws are such that stewards of data like these have some sort of incentive to protect them.
- ksk 9y ago>You can't blame a "careless programmer" when the real problem is organizations simply not committing any resources to security. How have you established that they didn't have a sufficient number of experts? What if they purchased a product or service and it simply didn't work? Its rather harsh to point fingers without having all of the information. >We'll keep seeing things like this until our laws are such that stewards of data like these have some sort of incentive to protect them. I think we need to give companies appliance-like products with a simple set of instructions that anyone can follow. Even a simple change where the data is stored in a 'vault' that requires the use of special tools with built in access controls and auditing would prevent a lot of data breaches. This means you cant email files around or share them on google docs or whatever. I'm convinced that people will do the right thing if you make it easy enough for them.
- anigbrowl 9y agoI'm really impressed at the lengths people will go to defend those whose malfeasance or ineptitude unarguably worsen the lives of up to two hundred million people. You seem like a smart person, please tell me how you think it's OK that these folks' contact details and potentially very detailed psychological and political profile information are now likely available on the dark web? Given that this data was collected for explicitly political purposes with the specific goal of shaping voting behavior - one of the few things in American life where privacy is considered sacrosanct - surely you don't need me to point out the potential for manipulation, exploitation, and intimidation that become available to bad actors in possession of this data. Are you familiar with the concept of 'strict liability'? Do you have any policy reason why such a standard shouldn't apply in cases like this?
- maxerickson 9y agoI dunno about the jail part, but the being ultimately responsible for the actions of the people working for you sort of goes with the title. Like, why is the organization set up so that 1 programmer can make a catastrophic mistake? The CEO is responsible for that.
- bb88 9y agoSo if the system is set up so that one programmer can make a catastrophic mistake, then the system is broken. If the system is set up so that one general can launch a nuclear warhead, then the system is broken. If the system is set up so that one politician can kill people without a trial, then the system is broken. If the system is set up so that one nurse can release data on 1 million patients, then the system is broken. It's not "what happens when a careless programmer does X." but rather "why do we have a system where a careless programmer can do X."
- ethan_g 9y agoWhile I generally agree with your point, it's hard to make this into law. Do you think it should be illegal to have a company with only 1 programmer? If not, how do you prevent them from making catastrophic mistakes?
- dragonwriter 9y agoLaw generally doesn't prevent catastrophic mistakes, it creates consequences for them which incentivizes those in a position to make them to find ways of preventing them.
- Allower 9y agoGross negligence. Yes, there has to be REAL consequences, even if its incredibly easy to do. Same goes for setting fires..
- frisco 9y ago> What law did they break, exactly? That's not how laws work. Laws can be whatever we write them to be. Losing medical and financial records was once not illegal too.
- sgift 9y agoNot retroactively, that would be a disaster.
- gozur88 9y agoAnd specifically mentioned in the constitution (twice!) as something the government can't do.
- dragonwriter 9y agoIt absolutely is how criminal laws work under the Constitutional prohibition of ex post facto laws; while we can write forward looking criminal laws however we want (within other Constitutional limits), we can't apply those new laws to past conduct.
- Retra 9y agoYou can apply them to discussions about hypothetical solutions to current problems, though.
- stale2002 9y agoSo, what, it should be illegal to leak your data on public Facebook scraping? None of the info they had was private info. If you don't want your info to be leaked then don't make it public.
- gozur88 9y agoNo, that's not how laws work. The law comes first. Then its application to behavior. If they didn't break any existing laws then there's nothing to do but propose a new law.
- draw_down 9y agoWell, that's the whole game. Either we care and there are consequences, or we don't care and there aren't consequences. We decided we don't care.
- holaboyperu 9y agoWhere does the buck stop then?
- anigbrowl 9y agoThe point is that we need laws to govern the management of personally sensitive data like this. Privacy laws in the USA are appallingly weak.
- rayiner 9y agoOP is clearly suggesting creating a law to avoid this sort of outcome. And while these aren't medical or financial records, they did include: "names, dates of birth, home addresses, phone numbers, and voter registration details, as well as data described as 'modeled' voter ethnicities and religions." Say on average people would pay $5 for this stuff not to be leaked. You're talking about a $1 billion fuckup resulting from a choice that is, as far as I can tell, gross negligence on the part of the programmer.
- criley2 9y ago>?A careless programmer makes a bad choice and the CEO has to go to jail? Come on An institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely? Come on. A CEO is responsible for his organization. If you ruin lives, you have to pay the price. Can't handle the heat? Don't take the job. I hate how CEO's get hundred million dollar parachutes because, the risk and danger and difficulty of such a position warrants such extravagant pay. But, then, we ask them to be responsible, bear responsibility for the organization which paid them a hundred million dollars to be responsible,and we say "come on?" Utterly ridiculous. CEO's bear responsibility for their organizations, or the organization should not exist. There must be responsibility for private organizations, lest the concept of private organization be nothing more than a cheap trick to remove criminal and civil liability from wrong doing.
- iamdave 9y agoAn institutional failure of review, testing and security that will lead to tens of billions of dollars of identity theft goes unpunished completely? I'm going to agree with you in wanting to see someone punished for this, I'm not sure if I'm on the side of jail time in the absence of malicious intent.
- grovegames 9y agoBut what law specifically was broken? Should we have a law that punishes the CEO for data breeches? Is a CEO responsible if his experts recommended the practice? Is the CEO responsible if their staff went around and did this without conscent? That seems rife for abuse. Don't like your CEO, leak some data and have him go to jail.
- karmelapple 9y agoI think data that has to do with voting records, or suspected voting records, would be very reasonable to be under the purview of being treated as sensitive data that, if breached, should have consequences to a company.
- 9y ago
- deleted 9y ago[deleted]
- eof 9y agoA careless programmer making a bad choice should simply not be able to leak 200M personal details. I am not sure that jail time is really the thing here, but there are institutional problems if this is something that happens.
- michaelbuckbee 9y agoAs of right now there is not a Federal law describing exactly what is PII data (which would be a prerequisite for this). There are many (48) different state laws that do define what PII is and how organizations (commercial and governmental) are to handle data breach notifications. If you want to see what a crazy patchwork map of laws this is checkout: https://blog.varonis.com/us-state-data-breach-definitions/ https://blog.varonis.com/us-state-data-breach-definitions/ These only come into play if a certain minimum number of state residents have had their data compromised and if that data is of a certain class. Typical classes are: - Account info - Financial info - Health Info - Health Insurance info - DNA - SSN - Biometrics, etc. And I'm not a lawyer, and we likely don't have all the facts, but at first glance the data released in this breach doesn't meet any of those classifications. It looks pretty much like the data you'd get out of a phone book (name, address, phone number) with a few data points like geocoding and their guess as to your religion and politics. Which isn't to say that it's great, or that it's not a problem that this was all released, but it is pretty much public data.
- rmc 9y ago> What law did they break, exactly? These aren't medical or financial records. I know this is USA, but FYI in the EU, all personal data is protected.
- remline 9y agoIf this data has private information on non-republicans then jail them for having it, not for leaking it. There is no special purpose in these two groups of colluding Americans that grants them special rights to gather data on their non-associates any differently than any other member of the public.
- ganoushoreilly 9y agoIf they are gathering data through any means it's no different than other marketing firms. I think the real debate needs to be about what any companies can share.
- remline 9y agoBut it is not about what they can share, it is about what they or anyone can collect, store and use. What you can share lets companies store and make decisions based on data they shouldn't have and couldn't share as long as their inputs and outputs look clean. I,e. Facebook or Google could help you intentionally run a race biased campaign across all their assets as long as they don't tell you any specifics and include a little noise so you can't be sure of any one user's race. All thanks to what they can collect, use, but refuse to share.
- erikpukinskis 9y agoThis is a losing battle. The cost of rebuilding this kind of database, even from scratch, is only going to go down.
- stale2002 9y agoWhy do you think any of this data is private? They seem like they were doing reddit scraping/Facebook scraping. Nothing illegal about that.
- ganoushoreilly 9y agoIf they are gathering data through any means it's no different than other marketing firms. I think the real debate needs to be about what any companies can share.
- gr3yh47 9y ago> (e.g. Sony, Sony, Sony, Sony, Sony, Sony, Sony, Sony) ftfy
- dude01 9y agoI agree. As an example, over a decade ago I was on a team deploying an app to Switzerland. They took privacy really seriously, because they told me that employees get fined/imprisoned for privacy breaches, not just corporate fines.
- lr4444lr 9y agoVoter records are public data. What would they be penalized for?
- dredmorbius 9y agoThere's more than voter data here. The size and scope of the data are larger than most voter record data. The data appear to include proprietary data from various sources who may not agree with the terms of disclosure here. Scale matters.
- lr4444lr 9y agoMaybe, but that's a violation of the company's TOS, not the public's right to privacy.
- political_tech 9y agoThrowaway account because of involvement in this field. Even though the RNC is a private organization, it doesn't operate like a normal company. The partnerships that it makes with companies that it awards contracts to are largely relationship-driven, not actually driven by objective analysis of value propositions. Those decisions tend to be made at the COO/CoS (Chief of Staff) level.