5 ms·
Instead of a data tax, I like the idea of mandatory data insurance, with payouts to users whose data is leaked/stolen. If your company has shitty security, or a
by drspacemonkey 9y ago
Instead of a data tax, I like the idea of mandatory data insurance, with payouts to users whose data is leaked/stolen. If your company has shitty security, or a history of leaks, your data insurance provider will charge out the ass.
The financial math has to clearly be on the side of it being more profitable to practice proactive security.
- QAPereo 9y agoJust set a value on the data, a monetary value, and the rest will naturally emerge through insurance and due diligence by insurers.
- RcouF1uZ4gsC 9y agoWithout data provenance (ie a data chain of custody) corporations will just "subcontract" it out to the lowest bidder. There needs to be consequences all the way up the chain to everybody that provided the data. This way, the people will bad security won't even get the data in the first place because no one will risk their data with them.
- PeterisP 9y agoRegulations like EU GDPR require such provenance - you can subcontract if you wish, but you're still liable if your subcontractor fails in some way.
- JumpCrisscross 9y ago> I like the idea of mandatory data insurance Why not just liability for lost data? Companies could then choose to hold the risk themselves or field it out to insurers.
- sidlls 9y agoSeems to me substantial liability will create a market for insurance of this sort anyway.
- RevHaze 9y agoIf it doesn't need to be insured, you could just spin off a smaller entity responsible for holding the data for you, and shut the company down if the data leaks. You can do the same if insurance is required of course, but any brand new 'personal data holding' company would likely have very high insurance premiums to offset the risk.
- extrapickles 9y agoIts fairly common in the temp employee industry that if a temp worker gets injured the temp agency folds and restarts to avoid the penalties. It would be nice to require insurance or a bond to hold personal data so a company can't just disappear when data is lost. [0]: http://projects.thestar.com/temp-employment-agencies/ http://projects.thestar.com/temp-employment-agencies/
- ticviking 9y agoAnd people wonder why I am so hostile to the our way of creating and governing corporations, and our way of divorcing business from the lives and reputations of of those who run it.
- unclebucknasty 9y agoWhile simultaneously championing corporate personhood.
- TeMPOraL 9y agoHoly shit. This is exactly what I mean when I say that, if you want to see real corruption, just take a look at regular small businesses around you. https://news.ycombinator.com/item?id=15950934 https://news.ycombinator.com/item?id=15950934
- JumpCrisscross 9y ago> If it doesn't need to be insured, you could just spin off a smaller entity responsible for holding the data for you, and shut the company down if the data leaks If this is possible without insurance then it’s possible with, and every insurance company will mandate the structure to limit payouts. Mandating insurance simple entrenches the insurers. Why, for instance, would you want to require Apple purchase insurance against its users’ data? Side note: beneficial ownership [1] and affiliate definitions [2] are useful for such cases. [1] https://www.investopedia.com/terms/b/beneficialowner.asp https://www.investopedia.com/terms/b/beneficialowner.asp [2] http://rule144opinion.blogspot.com/2014/02/rule-144-are-you-affiliate.html?m=1 http://rule144opinion.blogspot.com/2014/02/rule-144-are-you-...
- collingreene 9y agoThis exists and companies purchase it, ex: https://www.thehartford.com/data-breach-insurance https://www.thehartford.com/data-breach-insurance Risks (all kinds, not just technical) can be accepted, ignored, transferred and mitigated so it is important to have this option. Its still not a great option for anyone involved as it is hard to price and last I checked had pretty low ceiling on payouts.
- rhizome 9y agopayouts to users whose data is leaked/stolen What would the actuarial standards be for something like that?
- ateesdalejr 9y agoI'm assuming the strength of your password. The security practices of the company storing data. e.g. Company only uses SHA-1 for storing passwords premiums skyrocket.
- Spooky23 9y agoSounds like the offspring of FIPS 140-2 and PCI. Have fun with that.
- ateesdalejr 9y agoYeah. I wouldn't advocate a for a law like that at all. Too much governmental control over business practices.
- deleted 9y ago[deleted]
- partycoder 9y agoAnd since no insurance provider enjoys compensating millions of people, it would be very likely they would fiercely fight those responsible for the leak.