5 ms·
Posted this on the other thread from Facebook, but at what point do we start imposing strict fines on companies that are found to have done this? Granted, I gu
by krisrm 8y ago
Posted this on the other thread from Facebook, but at what point do we start imposing strict fines on companies that are found to have done this?
Granted, I guess we wouldn't be hearing about this instance at all if there was to be some sort of fine attached - it would have just been swept under the rug - so maybe that's not a good idea. I'm just tired of the "oops we stored your passwords in plaintext lol" from companies with engineers that should clearly know better.
- Angostura 8y agoIt's likely to have been a breach of GDPR, so if this situation had existed when GDPR was in force, the answer to your question would be "at this point".
- segmondy 8y agoWhen we can start fining you for your mistakes, when developers can start getting fired for any mistakes immediately. I don't care about Facebook, but storing user passwords is the plain is not "privacy violation" without the password they still have access to all your data. storing user passwords by logging it is stupid amateur security mistake. I can understand if Facebook stored the password and used it to access your other accounts with permissions to invite users then sure fine em. But mistakes are mistakes, they owned up to it.
- krisrm 8y agoStoring passwords in plain text is beyond a simple slap-on-the-wrist mistake, and it has real security implications.
- nbardy 8y agoI wouldn't mind that, more responsibility on the software developer means more leverage to push back. I guarantee you I'm not rushing for a deadline if I think I'm compromising security that may put a black marge on my career.
- bogomipz 8y agoAn internal tool that allowed for logging clear text passwords was a mistake. A culture that allowed said system to exist for 7 years without being surfaced by any type of internal security audit is something else entirely. Financial penalties could/should/would target the latter not the former.
- enraged_camel 8y ago>>When we can start fining you for your mistakes, when developers can start getting fired for any mistakes immediately. Sounds good to me. Plenty of people in other industries get fired all the time for violating best practices, regulations, and so on. Why should software be any different? Are we special?
- chillacy 8y agoMost tech companies have a “blame the process, learn, and fix the process” approach. I’m not sure what industries you’re talking about but manufacturing and aviation seem like they have a similar process.
- NelsonMinar 8y agoI agree, it's time for there to be criminal negligence penalties for these most egregious failures of even basic security practice.
- paulcole 8y agoIf being bad at your job is a crime then lock me up.