3 ms·
We need a regulatory rulebook codified in law by congress that fines companies that make these "mistakes". Enough of a fine will force companies to take these "
by propman 8y ago
We need a regulatory rulebook codified in law by congress that fines companies that make these "mistakes". Enough of a fine will force companies to take these "mistakes" seriously.
In Yahoo's case, that might have forced Marissa to actually keep a cybersecurity team and not cut them when she knew the systems were in danger of being compromised. We aren't getting any jail time, but hefty fines that don't stifle growth, just punish negligence and carelessness that are codified and don't need long court hearings to pass are a must.
- zerostar07 8y ago"Technology by legislation" - that's the new trend it seems. How about replacing passwords with something technologically superior instead?
- cpburns2009 8y agoSuperior technologies such as...?
- Jach 8y agoThe obvious one is public-private keys. Servers only ever get your public key.
- cpburns2009 8y agoThat's a solution I do like. I was expecting to hear biometrics, email login tokens, or social account logins.
- maltalex 8y agoReplacing passwords won’t suddenly alight large companies interests with yours.
- zerostar07 8y ago... because twitter has an interest in leaking passwords?
- maltalex 8y ago... because Yahoo had an interest in leaking passwords? Security is expensive, breaches have to be made more expensive. That's the difference between a company's management thinking about security as a checkbox they have to fill as opposed to an ongoing investment meant to reduce risk.
- aaronbrethorst 8y agoIt isn't a new trend. Section 508 of the Rehabilitation Act legislated that the government purchase accessible software. HIPAA legislated that your medical data be kept secure. Minnesota, Nevada, and Washington have enshrined some or all of PCI DSS into law: https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard#Mandated_compliance https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Sec... A little farther afield, seat belt technology has been legally mandated to be included in most automobiles sold in the United States since 1968: https://en.wikipedia.org/wiki/Seat_belt_laws_in_the_United_States https://en.wikipedia.org/wiki/Seat_belt_laws_in_the_United_S...
- deleted 8y ago[deleted]
- zerostar07 8y agoThose are great examples of regulations that actually benefit the user. When the regulation however addresses the wrong problem, then it becomes burdensome and dumb. If the user uses a simplistic password, his account will be hacked even if it's never leaked. Studies show that bad passwords and phishing are more destructive than leaks.
- quadrature 8y agoI agree. But i'm not sure this sentiment applies here, twitter probably has an amazing security team and its clear that they were using good practices. they found a bug and disclosed the issue to their users.
- deleted 8y ago[deleted]
- curiousgal 8y agoNo one forced you to create a Twitter account.
- robinhood 8y agoWhy? I have a small app with a few thousand users that generate almost no money but contain sensitive data - if I were to be fine because of a leak, I would be dead financially. Where do you draw the line between the companies that should be fine and those which don't? No matter how advance our technology is or the security measures we take, any system connected to internet somehow will have a leak or an intrusion or something that compromise security.
- plopz 8y agoAre you arguing that you should be allowed to be reckless because you cannot afford the cost of being careful?
- xur17 8y agoHe's arguing that there is a risk no matter how careful you are, which would prevent a lot of smaller developers from building anything at all.
- always_good 8y agoWell, we need to be realistic about risk, security, and responsibility. And how legislation can have unintended consequences that work against our higher goals. For example, a common refrain on HN is how centralized the internet is becoming. Do punitive damages for mistakes prevent mistakes? How likely is it to create an environment where the only organizations that exist are those that can afford mistakes? Is that worth it, especially in the context of some Twitter passwords that were logged internally? Also, one of the most important awakenings that need to happen in light of recent events is the personal responsibility of who you share your information with. It's just as important as the question of what an organization does with your information. If there were no trade-offs, then we could fix everything with legislation.
- SahAssar 8y agoI'm not arguing for a fine, but companies should be legally obligated to tell their users when the personal data of their users might have been compromised.
- always_good 8y agoSeems like a kneejerk reaction. For example, I can imagine kneejerk legislation that would simply ensure that next time this happens, Twitter just keeps their lips zipped. Not exactly an improvement. Can you pitch an example of what this legislation would actually look like? And how it would differentiate between something like the Experian leak and some (oh no) Twitter passwords getting logged internally.