3 ms·
At what point do we start imposing strict fines on companies that are found to have done this? Granted, I guess we wouldn't be hearing about this instance at a
by krisrm 8y ago
At what point do we start imposing strict fines on companies that are found to have done this?
Granted, I guess we wouldn't be hearing about this instance at all if there was to be some sort of fine attached - it would have just been swept under the rug - so maybe that's not a good idea. I'm just tired of the "oops we stored your passwords in plaintext lol" from companies with engineers that should clearly know better.
- jdashg 8y agoI agree there should be fines. It's something like negligent endangerment, to me. As for sweeping it under the rug, anonymous whistleblower bounties?
- henvic 8y agoWhat if we stop thinking about fining or promoting sanctions against everything and start helping people do the right thing? * Promote Multi-Factor Authentication * Promote public/private key usage * Speak out against password reuse ...
- krisrm 8y agoThere's no reason why we can't do both at the same time. Companies, especially tech behemoths like Facebook, should be held accountable for egregious security oversights like this.