4 ms·
You have the key points: Some significant (edit: strict, not negligence-based) liability for data breaches is the key. And regulation of security practices is t
by voidmain 9y ago
You have the key points: Some significant (edit: strict, not negligence-based) liability for data breaches is the key. And regulation of security practices is the worst idea ever; it will ossify current architectural mistakes at best and turn into a complete regulatory capture nightmare at worst.
Ideally the liability would actually go to compensate victims (for example, via class action). But even if the government keeps it it might be better than nothing.
A potential improvement would be to require companies to carry insurance (or be able to solvently self-insure) for the maximum possible liability if all the personal data they store was disclosed. That way a company like Equifax has to price the full risk of the data they store even if it is larger than their whole market cap. And the insurance industry might learn to do some due diligence, and be a source of "regulation" with much better incentives to be optimal than a government regulator has.
- kakarot 9y agoIf we were to implement some form of insurance, I worry that executives who make bad decisions about user privacy won't ever see jail time. This needs to be something you can go to prison for.
- voidmain 9y agoCriminal law is a very blunt instrument, and for good reason is usually reserved for deliberate actions, not mistakes. If you want to make willfully concealing a data breach (to avoid liability or just bad publicity) a crime, that would be pretty reasonable.
- otakucode 9y agoWe have laws for criminal negligence. If a company is building a bridge and the CEO ignores warnings from one of their engineers, or deprives them of the tools necessary to do their job, or hires inexperienced engineers because they are cheaper - that CEO goes to prison. This should be the case for any company which deals with the public. White collar crime causes more economic damage and kills more people every year than street crime does, but we punish it as if it doesn't matter and such crime has become utterly normalized and it needs to be stopped.
- voidmain 9y agoSorry, I just don't agree. Strict liability is where it's at, because the reality is that standard practice in these matters is very risky, so you're never going to be able to pin negligence on anyone even in a civil case. Making companies fully internalize the expected cost of data breaches will actually solve the problem, even if it doesn't make you feel as good. What you propose will most likely be totally ineffective, and even if it does anything it will just be to create some kind of wasteful butt covering behavior totally orthogonal to actually solving the problem.