4 ms·
"Let's Stop Giving Retailers a Free Pass on Data Breaches"? What a joke; the very headline conveys a sentiment that frames the debate around how out of touch co
by Digital-Citizen 9y ago
"Let's Stop Giving Retailers a Free Pass on Data Breaches"? What a joke; the very headline conveys a sentiment that frames the debate around how out of touch corporate media (and thus any blind repeater site) is.
Corporate media has been giving passes with one-off coverage that often neglects to mention any proposals for remedying long-term public ramifications. But the public's interest isn't well served by corporate media nor is public interest properly evaluated by corporate media.
Let's also stop thinking the stock market is a proper means of evaluating something applicable to most people's interests, because that's never been true. The stock market has more to do with wealthy people than most people.
The corporate death penalty seems right and proper for very egregious offenses like credit rating agencies because the public will suffer the most and for the longest time (possibly the rest of their lives) when these records are insecure. Organizations will continue to lazily make evaluations based on these records but the records could have been tampered with. And judging by Equifax's successful lobbying, the ratings agencies get away with scarce punishment and therefore have little reason to care about fixing what they broke. Relatedly, it's time we stopped trusting so few organizations with something so precious. The market just isn't designed to handle truly important things, so we should stop trusting it to do so.
No, let's not give them or any other organization passes, but let's also realize that most of these organizations use proprietary software (untrustworthy by default) to keep that data secure where nobody (including the organization) simply can't do effective audits. How proprietary software works is a secret, so such software is structurally incapable of ever being reasonably considered a sound choice for data safety. And organization's choices affect user's data safety, so users have an interest in this but not enough control over how their data is stored.
- jiveturkey 9y agodon’t agree with proprietary software being structurally unfit for purpose but otherwise you hit the nail on the head.
- midev 9y ago> let's also realize that most of these organizations use proprietary software (untrustworthy by default) This is completely incorrect. The only example of a data breach you gave was a result of open source software (Apache Struts for Equifax). Open source software has contributed to plenty of data breaches, and I seriously doubt you've ever audited the millions of open source packages and dependencies you're using. This is bad corporate security, by believing this type of nonsense. Then you'd inadequately assign risk, and fail to protect against real threats, instead focusing on 1990's "M$" risk. > How proprietary software works is a secret I don't need to know how exactly software works to make calculated decisions about risk. We sign vendor service agreements with other companies, that give us assurances about their data handling practices, their audit/compliance history, etc. I can look at how vendors manage their PSA process, how transparent they are with security disclosures, things like that.
- touristtam 9y agoNo the market in it purest form is designed to allocate resources. However the market isn't pure & personal data shouldn't be considered first as a resource. At least you can take comfort in the knowledge that the GDPR is coming into force this year for any company doing business in the EU..