3 ms·
I think this is key. All the conversations we're hearing are about data breaches. In my opinion, that's merely a predictable and unavoidable symptom of data hoa
by vec 9y ago
I think this is key. All the conversations we're hearing are about data breaches. In my opinion, that's merely a predictable and unavoidable symptom of data hoarding.
We need to move toward a recognition that collecting PII is inherently dangerous. Holding on to PII forever is inherently dangerous. And that's before the not insubstantial privacy risks these databases incur. I worry that any policy that solely concentrates on breaches is just going to lead companies to gamble that they won't be in the relatively small minority of companies that actually get hacked.
What can we do to incentivize a CTO not to have a customer database, or failing that to keep her company's database as minimalist as possible, even if she is 100% certain that database will never be stolen?