11 ms·
To me, the main issue is accountability. A citizen's data can be collected, badly secured, stolen, and used by criminals without the user ever being aware of s
by nathan_long 9y ago
To me, the main issue is accountability.
A citizen's data can be collected, badly secured, stolen, and used by criminals without the user ever being aware of step 1. Just like a citizen can get ill from swimming in a river without ever being aware of the factories upstream.
The solution is not to force citizens to constantly be on the lookout. It's to severely punish polluters and leakers.
When a CTO says "let's collect geolocations", the CEO should should have legal and business reasons to say "no way, it's not worth the financial risk of losing them; it could destroy our company."
---
Update: I do not think the government should mandate specific practices; it's too complicated, too fast-changing, and too hard to police.
It should be entirely results-based. You lose people's data, you pay big bucks. Figuring out how not to lose it is your problem. The government sets the rules, and the market plays the game.
- jenscow 9y agoAgreed. However, the punishment shouldn't just be financial, otherwise it will just be risk-assessed. How about a ban on the data collection for a period, or lose the ability to use it.
- nathan_long 9y agoI disagree. "You can't use the collected data anymore" is a million times harder to enforce than "pay us ten billion dollars." > otherwise it will just be risk-assessed. The key is to make the cost so large that the risk isn't worth it. What's my geolocation history worth to Google? $20? $200? Make them pay $2,000 if they lose or misuse it. Sure, maybe they'll buy "data loss insurance". But even then, there will be motivation to do things better. Eg, the insurer will refuse to cover claims where proper encryption wasn't used, will prorate policies based on data collected, etc.
- tankenmate 9y agoFrom May 2018 in the EU the maximum fine for a data breach is €20m or 4% of global annual revenue. This is due to the GDPR.[0] [0] https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- isostatic 9y agoSo after a certain point, the bigger the company the lower the fine? 20 million is 0.01% of Apple's turnover.
- patmcc 9y ago>>>I disagree. "You can't use the collected data anymore" is a million times harder to enforce than "pay us ten billion dollars." Not especially hard; you send in auditors to delete the collected data from all servers. Oh, that kills the company? Too bad.
- nathan_long 9y agoIt wouldn't fly. And the data may have been "laundered" intentionally or not - used to send emails, get new customers and social media contacts, etc. It may be hard to even trace anymore.
- overhang 9y agoDefine 'misuse'. If they sell ad space based on your geolocation, is that a misuse? If they sell your geolocation, ip address, and search history together, is that a misuse?
- Roodgorf 9y agoDoesn't that still end up being financial? If someone is banned from collecting data and is later found to have been doing so anyway, the most likely recourse is fines, right? Or are you suggesting this would imply criminal consequences (i.e. jail)?
- wbl 9y agoWhat's wrong with that? You get the socially optimal amount of data collection.
- pbhjpbhj 9y agoHow about financial plus the CEO, and any management lower provably found negligent, can't work in a role where they have responsibility for data handling (which includes not being superior to anyone who is data handling).
- mtgx 9y agoWell put and a great analogy. I hope Troy uses it. Politicians pay attention to soundbites like that because they realize how those soundbites could be used against them if more people hear about them, too, and then find out their representatives did nothing to stop the companies from "harming the data environment."
- DannyB2 9y agoThe financial penalty needs to be in two parts. 1. a cost for losing personal data. 2. a cost per person's data that was stolen. That ensures there is a minimum penalty. Enough to make it CHEAPER to take a lot of security measures, even if you don't have many people's data yet. But also a gigantic penalty for the next Equifax.
- ars 9y agoBe careful of not setting the fine high enough to motivate companies to cover up breaches instead. No one would have known about Equifax if they had not self disclosed. It doesn't even have to be the CEO - if I am the employee who is about to cost my company $$$$, I might just quietly fix it and say nothing.
- jakelazaroff 9y agoCovering up data breaches should be straight-up illegal, as in prison time. If I am the employee who is about to cost my company $$$$, I'd much rather report it than risk going away.
- deleted 9y ago[deleted]
- ars 9y ago> Covering up data breaches should be straight-up illegal, as in prison time. Is it also illegal to cause a breach? Do you understand the backwards motivations you are giving people? He can disclose the breach, cause himself (or his co-workers) to risk prison, and cost his company $$$$, which is likely to get people fired. Or, Cover the whole thing up (i.e. quietly fix the bug), and no one will ever know. And if they do find out, he can say "I didn't know anything about a breach, I proactively fixed a bug, I didn't realize someone had taken advantage of the bug" - i.e. he's safe either way.
- jakelazaroff 9y agoThere are two separate infractions here that shouldn't be conflated: allowing a data breach to occur, and failing to disclose a breach. As far as I can tell, the perverse incentive you're describing is that the if the penalty for a breach occurring is too harsh, it could lead companies to cover up a breach rather than disclose it. A penalty for failing to disclose a breach would be meant to discourage that, and I don't see how that penalty is itself a perverse incentive. The penalty for a data breach must be harsh enough that it would cost a company more than it would to guard against it. I don't believe that there exists a penalty that satisfies that condition yet is also light enough that a company wouldn't cover up any breaches that occurred.
- mratzloff 9y agoI had a non-technical friend whose fatalistic impression was that "these things happen and there's nothing that can be done given a determined attacker." Well, look, I said, these hackers aren't going in like Mission: Impossible. Equifax was incompetent, and there's zero penalty for utter incompetence. There must be. The Equifax hack was the equivalent of data malpractice. It's like a hospital mixing up the labels on saline and hydrogen cyanide and then saying, "Whoops. Sorry about that." The cavalier attitude that companies have about data security infuriates me. Americans will be dealing with the repercussions of this for the rest of their lives. Meanwhile, Equifax keeps making money. Equifax's entire business was trading off of our data, but protecting that data was evidently not a priority for them. They should be fined into oblivion.
- RachelF 9y agoMy opinion is that information about you should belong to you. Other entities should not be allowed to keep or trade information about individuals without paying them directly. That way people will realise that their personal info is worth something.
- mjevans 9y agoThe problem is this is effectively a reputation score; only you have very limited rights to see it* (once a year, per agency; and only if you ask... Oh and BTW, I pulled /all/ of mine just before it came out that the breach happened; :( ) Also a problem; they use simple knowledge of a single magic number as authentication ('identification'). The three current companies in the US could have gotten together and worked around the lack of a national ID and created a private SIN cryptographic... but that would cut in to their profits. Though I hear other countries that have done this also have issues with 'business individuals' being contacted and scam attempts rampantly abusing their data...
- will_hughes 9y ago> Other entities should not be allowed to keep or trade information about individuals without paying them directly. To be the devils advocate for a moment, what about the other side of that? Should businesses not be able to keep and share records saying "This person owes us money but refuses to pay"?
- jakelazaroff 9y agoMandating specific practices with regard to technologies is probably not possible, but we can certainly come up with a general framework for deciding the degree of recklessness. For example, the penalty for allowing data to be stolen via an exploit for which a security fix was issued months prior should be more severe than via a zero-day.
- nodesocket 9y agoStaying with accountability. The source of the vast majority of these attacks are from China, Russia, and Eastern European countries. Why shouldn't the people commiting the crimes be punished? Currently those governments and crimals almost always get away with it. There is no punishment for bad behavior. As most of us being technical engineers on HN know it is nearly impossible to completely prevent a breach or attack if a savvy group wants to put in the effort and time. I'm not saying that Equifax and equivalent companies were not grossly inept and incompetent, but eventually we have to start putting pressure on the criminals and reduce the incentives. Cyber crime currently does pay. Extremely well.
- will_hughes 9y agoThere are already enough laws covering the unauthorised use of computer systems. The US Congress (and for that matter European Parliament) are limited to acting upon companies and people within their borders. Who should you go after? The people that keep stealing drugs from the pharmacy, or the pharmacist who keeps the keys to the drug locker on a chain beside the door.
- mschuster91 9y ago> Currently those governments and crimals almost always get away with it. > but eventually we have to start putting pressure on the criminals Hmm. On the one hand you are certainly right - but on the other hand I'm sick of the consequences of decades of US interventions in foreign countries. To make stuff worse, China, Russia and Eastern Europe is, basically, one block. If the US were to intervene in ANY of the countries, and if only with economic sanctions, I can easily see either a hot war or more stealthy "counter interventions" like the Russian support for Trump on the horizon. Pressure and (military?) intervention only really works against tiny/poor-ish countries in Africa and Southern America. The rest can do whatever they want and are accountable to no one.
- JohnLocke1632 9y agoWhile I agree that accountability matters, I believe you are stripping blame from U.S. actors when there is blame on the U.S. front as well. To think our country doesn't do these exact same things to other nations is blatantly ignorant. It has been proven that U.S. agencies hold flaw information so that they may use it against foreign or domestic actors rather than informing the entities responsible for these vulnerabilities or the greater public. This is truly a global issue and it is a mistake to focus blame on any singular nation states. You must not let the U.S. propeganda machine cloud your judgement.
- prawn 9y agoPenalties would need to be based on the size of the company or breach, otherwise this would result in smaller companies being unable to risk competing, right? If effective features or revenue require user data collection, but smaller companies are terrified of data loss, they're less likely to compete. Admittedly, smaller companies will have minuscule teams and probably an increased risk of slipping up, but also smaller databases to lose or target. But I don't like the idea of only the largest companies having the ability/confidence to power on. If Uber is getting a $20k fine, I doubt that's a deterrence for them, but it would be for a tiny startup.
- kevin_thibedeau 9y agoPenalties need to impact CEO compensation. Punish them with a $200K max cash salary and no options or security instruments to get around the penalty.
- rjmunro 9y agoNo, just make them pay the fine directly, lose their jobs and right to be company directors, and bad cases, where they turned a blind eye, actually go to jail.
- overhang 9y agoLet's say that Party A collected private data as in your step 1. Then Party B stole that data as in your step 3. Do you punish at step 3? Party A's step 3 is Party B's step 1. I don't much see the difference between them. What if Party A willfully gave the data to Party B? No punishment? Equifax is a good example of Party B in this case. Can't we punish all the Parties A?
- ekianjo 9y agonot just big bucks. Jail time for those responsible of oversight in terms of data security sounds very appropriate. Call it jail or something else, but it needs to impact individuals and not just company money, and it should have dire consequences on their future job prospects in that field.
- pishpash 9y agoAccountability is a petty side show. Who, in the first place, gave the providers consent for all this, and who appointed them owners of PII? There is a gross lack of information and consent, and a violation of the proper ownership of PII, which should be with the user. Right now data is collected under the cover of overly broad user agreements that are never read, if even that, and data is dispersed among third parties without further user knowledge. The user is completely in the dark. They did not really agree with the collection of data, and cannot really see what was collected, where it ended up, and how it was used, not even at an aggregate level. Furthermore the user finds it very difficult to withdraw, even if they had actually given informed consent, since it's so hard to delete anything off of premises you do not own. It's a distraction to talk about how to punish people for not safekeeping something they stole from you in the first place. After all, a so-called "breach" is just one thief stealing from another -- would you expect a thief to care that much on your behalf?
- CuriousSkeptic 9y agoFully agree! This is the important point to stress here in my opinion. Was a bit surprised to not see more comments about this aspect of the problem here.
- voidmain 9y agoI'm not a big fan of contracts of adhesion. I think that to give up important rights by contract should require a correspondingly conspicuous degree of solemnity, not a link at the bottom of a web page to terms of service that state they can be changed at any time by one party. But the reality is that no matter how much contractual solemnity you require to let other people trade in your personal information, most people will do it in order to get credit. If to get a home loan you had to copy down a contract giving the bank the right to do credit monitoring in longhand with a fountain pen and sign it sixteen times in your own blood, my guess is that people would still be doing it, because credit monitoring really does make loans cheaper. So as a practical matter, I don't think the Equifaxes of the world would go away if the problem you point to was solved. Whereas there's no reason they shouldn't at least internalize the cost of losing your information through incompetence.
- specialist 9y ago"I do not think the government should mandate specific practices; it's too complicated, too fast-changing, and too hard to police." I disagree. Breeches are inevitable. "when", not "if". Today, for interop, all demographic data must be stored as plaintext, because we don't have national identifiers. The only fix is to issue globally unique identifiers. Then we can encrypt demographic data at rest. Greatly mitigating the damage of breeches. That's why we need a federal level solution.
- icebraining 9y agoThe only fix is to issue globally unique identifiers. Then we can encrypt demographic data at rest. Greatly mitigating the damage of breeches. How does that follow? I work in a country with such identifiers, and I don't see the connection. By the way, just because such identifiers exist, doesn't mean people are keen on giving them out to every company, and in fact, asking and storing it is frowned upon by our national data protection commission, unless you have a good reason to do so (just like any other personal data).
- specialist 9y agoJust like passwords, you don't store the identifiers as-is, which is a rule that is easy to explain, enforce. Translucent Databases: Confusion, Misdirection, Randomness, Sharing, Authentication And Steganography To Defend Privacy http://a.co/hTfRPP9 http://a.co/hTfRPP9 http://www.wayner.org/node/39 http://www.wayner.org/node/39
- otakucode 9y agoThere is no need for a single centralized identifier. Each need for an identifier has its own requirements, things like ensuring a person has been served only once, ensuring every person has been served at least once, ensuring every participant meets some criteria, etc. There is no need for, for example, the social security administration to be able to cross-reference with the drivers license registry. It makes no sense, and would be pretty dangerous, to create a single identifier that invites cross-relation of a persons entire existence into an easily-profileable bundle.
- caconym_ 9y ago+1. The debate needs to be reframed. Right now we implicitly accept that corporations have a right to scrape and store our sensitive personal data with zero regard for security best practices, and we hem and haw over what the penalty should be, if any, when the leaks inevitably happen. We need to look at it from the other direction. Leaking personal data harms consumers. If you do it and are shown to have been negligent, there should be a meaningful penalty. The legal/financial calculus needs to force corporations to take this stuff seriously, or not at all. Corporation X does not have a right to exist in the future just because its business works in the present.
- voidmain 9y agoYou have the key points: Some significant (edit: strict, not negligence-based) liability for data breaches is the key. And regulation of security practices is the worst idea ever; it will ossify current architectural mistakes at best and turn into a complete regulatory capture nightmare at worst. Ideally the liability would actually go to compensate victims (for example, via class action). But even if the government keeps it it might be better than nothing. A potential improvement would be to require companies to carry insurance (or be able to solvently self-insure) for the maximum possible liability if all the personal data they store was disclosed. That way a company like Equifax has to price the full risk of the data they store even if it is larger than their whole market cap. And the insurance industry might learn to do some due diligence, and be a source of "regulation" with much better incentives to be optimal than a government regulator has.
- kakarot 9y agoIf we were to implement some form of insurance, I worry that executives who make bad decisions about user privacy won't ever see jail time. This needs to be something you can go to prison for.
- voidmain 9y agoCriminal law is a very blunt instrument, and for good reason is usually reserved for deliberate actions, not mistakes. If you want to make willfully concealing a data breach (to avoid liability or just bad publicity) a crime, that would be pretty reasonable.
- otakucode 9y agoWe have laws for criminal negligence. If a company is building a bridge and the CEO ignores warnings from one of their engineers, or deprives them of the tools necessary to do their job, or hires inexperienced engineers because they are cheaper - that CEO goes to prison. This should be the case for any company which deals with the public. White collar crime causes more economic damage and kills more people every year than street crime does, but we punish it as if it doesn't matter and such crime has become utterly normalized and it needs to be stopped.
- WalterBright 9y agoPerhaps a more pragmatic solution would be like truth in labeling laws on food cans. I.e. the company collecting your data must explicitly say what it is collecting, in a standardized format specified by the government. Like if an app is going to transmit your email address book back to headquarters, it must specifically disclose it is doing so, otherwise the app maker is subject to enforcement action.
- voidmain 9y agoThat won't solve the problem, because there are plenty of good reasons for people to share information with companies that they don't want to share with everyone. In the case of the Equifax breach, people shared personal information with their lenders; do you think they're going to stop doing that if they're informed? See also my reply to @pishpash below.
- deleted 9y ago[deleted]
- scoot 9y agoThat's effectively what the European General Data Protection Regulation covers. The good news for European citizens is that global organizations are accountable for safeguarding their data. The good news for global citizens is that European organizations are accountable for protecting their data too. The gap? Non EU custodians of non EU citizens' personal data. That's a big gap! We need a Global Data Protection Accord.
- ewjordan 9y agoDo you really think China and/or Russia would ever get in line with something like that, given that they're responsible for (or at least turning a blind eye to, in the cases where it's not government-sanctioned) almost all of this crap?
- tremon 9y agogiven that they're responsible for almost all of this crap Where'd you get that impression? Almost all data public data breaches concern Western companies and Western hackers. And people have been warnings against the lax security standards and worse coding practices for decades. Your trying to shift the blame to the russkies is just another example of denialism.
- ewjordan 9y agoI see millions of hack attempts coming from Russia and China every day even on sites that see a tenth of that traffic, and have to deflect them constantly. Who do you work for?
- jackpirate 9y agoA potential downside to "entirely results-based" enforcement is that companies now have a negative incentive to monitor for and report data breaches. Why install an intrusion detection system if it could potentially cost the company millions when it triggers? Better just to not know that data was exfiltrated. You don't even have to cover anything up if you never learn there was a problem to begin with.
- saulrh 9y agoTwelve months ago I'd have called that a solved problem - c.f. entities like the EPA, OSHA, or NHTSA that conduct results-based inspections and investigations ("how much crap is actually in the water coming out of your pipes?", "was this injury/crash/accident a result of a violation") and come down on violators like a ton of bricks - but the suicide party is doing an excellent job of sabotaging our civilization's guardrails and sawing away at its fall-arrest lines.
- reacweb 9y agoYes and hiding a leak should also be more severely punished.
- Cthulhu_ 9y agoIn the Netherlands we've had a err, meldplicht / reporting obligation for data leaks for a while now. We also have laws about how user data should be protected, and an agency actively checking whether businesses uphold said laws. It's not complicated for government rulings; the law just states what information is considered private (and this doesn't change too often), and make it obligatory to protect it. Which it already is I'm sure.
- nathan_long 9y agoFolks seem to like my "polluting a river" analogy in the parent comment. I thought of a related point. People have said that if there are consequences for losing customer data, companies will be motivated to cover up their mistakes. Part of the solution there would be "whistleblower" laws similar to what we have for OSHA violations. But another part would be legitimizing white hat hacking. Suppose my apartment has some hazardous problem, like exposed wires. It's perfectly legal for me to notice that and tell my landlord. I can take pictures for proof, and if necessary I can report it to the government. The landlord will not be allowed to ignore me. If, however, I notice a glaring security problem on a web site I use, there's no government agency to tell. If I tell the site owners, there's a good chance that they can ignore me or even punish me for noticing. Now, going along with my "results-based" argument, unlike building codes, we don't want our laws to specify security practices. But if an outsider can demonstrate that they can obtain personally identifiable information from a computer system, the owners of that system should be fined and required to fix it, and the person who found the problem should be legally protected. Imagine the mess a landlord would be in if somebody died because of a hazardous condition that they'd been notified of six month earlier. Now imagine that web sites were held to the same standard. "You had a massive data breach, and this security researcher has proof of notifying you six months earlier of the vulnerability. You're in big trouble."
- DyslexicAtheist 9y agoI love the polluted river analogy. You often hear today that "Data isn't oil" but from a breach perspective it is a good analogy when considering its toxicity.
- MaxBarraclough 9y ago> Folks seem to like my "polluting a river" analogy in the parent comment. Yes, definitely! Eben Moglen makes exactly this point in his lecture, Snowden and the Future Part III. He puts it as privacy being 'ecological not transactional', and uses 'pollution' as you have. I can't resist an extended quote; Moglen puts it very eloquently: > Those who wish to earn off you want to define privacy as a thing you transact about with them, just the two of you. They offer you free email service, in response to which you let them read all the mail, and that's that. It's just a transaction between two parties. They offer you free web hosting for your social communications, in return for watching everybody look at everything. They assert that's a transaction in which only the parties themselves are engaged. > This is a convenient fraudulence. Another misdirection, misleading, and plain lying proposition. Because — as I suggested in the analytic definition of the components of privacy — privacy is always a relation among people. It is not transactional, an agreement between a listener or a spy or a peephole keeper and the person being spied on. > If you accept this supposedly bilateral offer, to provide email service for you for free as long as it can all be read, then everybody who corresponds with you has been subjected to the bargain, which was supposedly bilateral in nature. Full transcript+video+audio at http://snowdenandthefuture.info/PartIII.html http://snowdenandthefuture.info/PartIII.html
- qrbLPHiKpiux 9y ago“Seems like the only winning move is not to play.” - WOPR
- shadowtree 9y agoYou just summarized the principle of GDPR legislation across the EU, coming into effect May 2018. Fines of up to 4% of global revenue of the offender. Looking forward to massive lawsuits against Facebook, Google, Uber, etc.
- rmc 9y ago> When a CTO says "let's collect geolocations", the CEO should should have legal and business reasons to say "no way, it's not worth the financial risk of losing them; it could destroy our company." Sounds like the EU Data Protection law, which says you need a legitimate reason to store & process personal data.
- snarfy 9y agoThe government shouldn't mandate any specific practice, but they could create a regulation. You lose people's data that you use for identification, that data can no longer be used for identification. If it is used, you are liable for any damages caused by a false identification.