3 ms·
What if a data breach happens due to an 0 day exploit with a 3rd party library? Do people from the company where the data breach happened still go to jail then?
by Cyclone_ 8y ago
What if a data breach happens due to an 0 day exploit with a 3rd party library? Do people from the company where the data breach happened still go to jail then?
- foolrush 8y agoIn law, the term “negligence” usually plays an important role. “What ifs” have already been played out historically, which is case law.
- sigfubar 8y agoDouble the term: once for the breach, and again for poor security review & architecture.
- currymj 8y agoas far as I can tell, this bill would only allow jail time if there was a serious breach, at a large company, and higher-ups left it out of an official report they would be required to make to the government. in other words, all they have to do is fulfill their obligation disclose that they were hit by this 0-day, in order to at least be protected from jail time.
- pm90 8y agoWhich seems like a reasonable policy IMO. Its encouraging companies to be forthcoming with their data breaches .... or else.
- spydum 8y agoMy guess is prudent man principal applies - did they have a reasonable plan to remediate once the 0-day was known? How would peers in the industry have been affected? If it’s truly a 0-day, and they followed reporting the breach, I don’t see it being likely. You could argue a single 0-day should not result in a breach (security is best as a layered defense), but that’s probably far less likely to find. https://en.wikipedia.org/wiki/Prudent_man_rule https://en.wikipedia.org/wiki/Prudent_man_rule