6 ms·
I really hope that's the outcome here. I also think this should pave the way for real legal consequences for moronic data security. Individuals are banned from
by kmix27 9y ago
I really hope that's the outcome here. I also think this should pave the way for real legal consequences for moronic data security. Individuals are banned from using computers when prosecuted, what about "no internet for companies who've proven they can't use it responsibly"
- creatonez 9y ago> Individuals are banned from using computers when prosecuted Who is banned from using computers? You mean, in prison?
- Kroniker 9y agoIt can be a punishment for certain crimes- or as an extended punishment after jail. Things like stalking where a computer was a primary method, valid threats made on a computer, etc.
- kodt 9y agoSome convicted hackers have been banned from the internet, if ever caught using it they go back to prison. There have been cases of people being banned from using any personal computer.
- gipp 9y agoKevin Mitnick, famously, ages ago. Not sure if anyone else has ever had that.
- astura 9y agoSamy Kamkar too for writing the Samy MySpace worm. From Wiki: >Samy Kamkar, the author of the worm, was raided by the United States Secret Service and Electronic Crimes Task Force in 2006 for releasing the worm.[4] He entered a plea agreement on January 31, 2007 to a felony charge.[5] The action resulted in Kamkar being sentenced to three years probation with only one computer and no use of internet,[6] 90 days community service, and $15,000-$20,000 USD in restitution, as directly reported by Samy Kamkar himself on "Greatest Moments in Hacking History" by Vice Media's video website, Motherboard.
- marksomnian 9y agoSamy. He was banned for a while IIRC
- sp332 9y agoJust last month, http://www.bbc.com/news/technology-40833951 http://www.bbc.com/news/technology-40833951 "The conditions of his bail include him not being allowed to access the internet"
- ballenf 9y ago> real legal consequences for moronic data security This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong. Given that risk, as much as I don't want to live in an overly litigious society, letting the risk of lawsuits drive good security may be preferable to putting security in the hands of a few faceless government officials who themselves face no repercussions for getting the regs wrong.
- criley2 9y ago"This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong." Engineers, capitalism, private business have utterly, completely, fully and in totality failed. This is not a little failure. Not a medium one. Not a large one. This is a foundational, cataclysmic failure of the most epic proportion. I think the time for voluntary private action has passed. If developers, their managers, their stakeholders, and their shareholders took security and privacy remotely seriously, we would not be here. We are here. It is time to admit the full and complete failure of private software companies to protect data and privacy, and time for government to create a criminal schedule for management and developers who perpetuate criminal negligence. I believe only 2 things will solve this: 1) Massive financial loss for shareholders -- they speak 1 language, US Dollars. If we say a US Citizens data is worth $100,000, then the fines would be large enough to literally destroy any firm who dared play loose with security. If there is no existential risk, there is zero motivation for compliancy. Only existential risk matters to shareholders. The rest is Cost of Doing Business. 2) Criminal liability for management and developers of products which violate security and privacy due to criminal negligence Without this, you can all but guarantee that your full identity is kept in plain-text and has already been stolen.
- rm_-rf_ 9y agoI agree that we should work to determine if there was criminal negligence and prosecute to the highest degree possible, but I find it laughable that you talk about how engineers, capitalism, and private business have completely failed. The DNC was hacked. The FBI and CIA have had their web sites hacked. The OPM had >22 million people's personal info stolen by Chinese hackers. The NSA itself has had major incidents where essentially cyber weapons were leaked. Those are just SOME of the ones we know about. Let's stop pretending like government is any more capable, or even as capable, of protecting data than competent corporations. When was the last time Facebook or Google had massive data breach? It's not about 'the corporations maaan' it's about competency and the limited consequences of screwing up so bad.