5 ms·
IMO there should be expensive data breach bond/insurance requirements for any company storing data about people, scaled by how much and possibly which kinds of
by ashark 9y ago
IMO there should be expensive data breach bond/insurance requirements for any company storing data about people, scaled by how much and possibly which kinds of data are stored. Discourage holding a bunch of stuff "just in case".
And FFS, at least outlaw the required arbitration BS for data breaches. Let the bond or insurer pay out when it happens, then jack up their prices on the breached company until they cry.
- pc86 9y agoBy "until they cry" I assume you mean "until they can no longer continue passing the costs directly to the consumer, at which point they simply go into bankruptcy and reincorporate 6 months later at the lower insurance rate?"
- ashark 9y ago1) if they have competitors, they can't do much "passing along to consumers" to begin with, and 2) I thought insurance companies were supposed to be really good at assessing risk, and markets are magically efficient and all that, so shouldn't the better insurers unravel such schemes? Plus it's not like losing, you know, brand recognition and such is nothing. Point is it should hurt a lot to leak personal data, and it's this or directly regulate (this sort of thing used to be the right-wing way of doing things, but now doing anything at all about these problems, no matter the mechanism, is "left", at least in the US—see also health care)
- abakker 9y agoIf the data you hold as a business is so valuable that the insurable risk of loss is too expensive for your business, then ask, "do we really need to hold that data?" If your business needs to pass that on to consumers because you can't afford the hit to your margins, then consumers need to ask, "is [service/product] really worth that much to me?" The downside is that the most critical components of information which tie to identity itself, are the ones that businesses most commonly need to hold to verify identity. More challenging is that without a way to modify identity data (i.e. change your SSN), the insurable risk is huge because it needs to include a discounted cost of identity monitoring forever, and the cost of the individual losses that someone might encounter for the loss of that data. Then of course, if a person's identity is compromised more than once, how do you discount the responsibility across multiple careless parties? IMO it all comes down to never using immutable information (Name, DOB, etc) to firmly define identity online. That information should be for display purposes only. At the backend, we need an identity that is tolerant of change, and can easily be updated if it is ever lost. In reality this will probably mean that instead of an ID, we have ID probability, which would include photos, addresses, ID numbers, Credit card account access, and companies that needed to verify it would be able to evaluate how certain they were the identity was real, and to insure against mishandling of the individual components of information.
- ashark 9y ago> The downside is that the most critical components of information which tie to identity itself, are the ones that businesses most commonly need to hold to verify identity. More challenging is that without a way to modify identity data (i.e. change your SSN), the insurable risk is huge because it needs to include a discounted cost of identity monitoring forever, and the cost of the individual losses that someone might encounter for the loss of that data. Then of course, if a person's identity is compromised more than once, how do you discount the responsibility across multiple careless parties? If it gets expensive enough, maybe banks and CC companies and such will finally get off their asses and fix the whole "identity theft" issue. That's a feature, not a bug. I think the US is too allergic to anything with even a whiff of "secure national ID" for us to let the government fix it, so this is the next best (or, better, depending on your perspective) option. I frankly don't care how we do it, but it's really stupid this is still a thing people have to worry about, and making it cheaper for the banks to fix it than not to fix it seems like the most politically viable solution.
- abakker 9y agoAgree completely. Personally, I was hoping that Visa, MC, and Amex together could just create a new standard "financial ID number" or "Credit ID Number" that they could collectively agree on and we could all just kind of ignore the government. CC numbers themselves are almost good enough in the first place, they just need to get a little more self-referential. Hell, maybe they could even use a distributed ledger to do it and bring in the credit reporting agencies too.
- gizmo686 9y ago>we could all just kind of ignore the government. You mean the government that spent 26 years printing "NOT FOR IDENTIFICATION" on the bottom of every social security card.
- arca_vorago 9y agoWhat you haven't addressed is the fact that so much of SV, yc included, is now based off a business model of selling that data to third parties such as but not limited to advertisers. The same applies to the tech around banking and credit, with data selling and sharing going on all over the place. This is the elephant in the room I don't see anyone addressing, but be warned, we can see the effect caving to this model had on the journalism industry. If tech doesn't free itself from this, it will likely have similar consequences.
- curun1r 9y agoOne would hope that insurers would start proactively setting the rates for their policies based on several factors and not just in response to breaches and payouts. For instance, an insurers exposure would be greatly affected by the types of information collected, so they could offer a lower costs to a business that was only collecting email addresses than to one that collected many more types of PII. You'd also hope that insurers would start to give preferential rates to companies that complete (and resolve) periodic security audits from trusted auditors. The benefits of insurers getting involved is that they can de facto mandate these kinds of security audits and practices by making insurance policies unaffordable without them. And, unlike government regulation, the requirements from insurers can evolve rapidly over time in a way that's difficult for laws to evolve. Insurers will hire security experts to advise on best practices and each have their own ideas of what security means. If a business finds a single security practice onerous, they can shop for an insurer that doesn't require it.
- deleted 9y ago[deleted]
- sbov 9y agoWhat data about people would apply? What about public records? Note that if you own property, your name and address are already public.
- syshum 9y ago"Public Records" is part of the maximization problem The Government is more guilty than any business on collecting, hoarding, and making public all kinds of personal information about you. If the government wants to curb data breaches it needs to start cleaning its own house. 90% of "public data" should not be public at all