4 ms·
Pass a law that says every lost user account is an X dollar fine based on data "richness" that can't be discharged in bankruptcy. For simplicity, let's say $10
by Thriptic 7y ago
Pass a law that says every lost user account is an X dollar fine based on data "richness" that can't be discharged in bankruptcy. For simplicity, let's say $10 in this case. 160 million lost accounts is now a 1.6 billion dollar fine. That is enough to cripple a lot of companies. It would make people think long and hard about what data they wanted to keep and how they wanted to secure it.
Alternatively, create a situation where companies are responsible in perpetuity for damages related to identity theft if a victim's credentials are lost. If company X loses my SSN and then someone opens up a fake account in my name, they are automatically responsible for any costs I incur and I don't have to prove attribution.
The purpose should be to heavily, heavily disincentivize any storage of basic data or PII unless absolutely necessary.
- umvi 7y agoYes, that would also make it really easy for individuals/corporations/state actors/etc. to destroy companies: secretly employ security researchers that compromise your target's database and bam, you've just crippled/ruined them. China tired of US putting pressure on Huawei? Bam, start targeting American companies and totally financially ruin them using their own privacy laws/fines against them! Disgruntled suicidal employee has a grudge? Take down the whole company on your way out with that backdoor time bomb you planted and let the $1.6B fine do the rest!
- Jweb_Guru 7y agoYou know that there are other industries that have heavy regulatory fines like this, right? The existence of a software culture where a single rogue employee can easily destroy the privacy of hundreds of millions of people is itself a huge part of the security problem. If there were actual consequences for this kind of thing there would be a lot of changes to software development practices. I'm not saying that culture alone will make code perfectly secure, but I do think caring about the code being secure (in the sense that the company will face deep financial and legal trouble if it isn't) is a necessary prerequisite. Arguably, it's the only thing that works. You may argue that you can't just buy absence of security bugs with money and a different culture, but there are plenty of formal verification tools out there, and they are not all toys. True, verified code is expensive compared to writing "normal" software, which is developed using the same best practices" that lead to a data breach being announced seemingly every other day. But it is quite cost-competitive with "high assurance" software (i.e. software developed when people face real consequences for the existence of bugs) and the techniques have been used to secure a number of nontrivial real systems by now. I have absolutely no doubt (as someone who's in the field) that we would see a huge boost to the state of the art in that field if there were actual money in it, especially considering how much of the current difficulty with using formal verification comes down to the lack of user-friendly tooling. But, to reiterate, my larger argument isn't really about formal verification; I'm mostly bringing it up to refute the argument that the existence of bugs is something totally outside of any company's control. Ultimately companies are currently choosing not to pay to make their code secure, and it's not hard to see why given the current legal climate of "there are no consequences whatsoever." Ideally, the first step towards fixing this would be for the software development community at large to acknowledge that it is, actually, a choice, but frankly I don't see things happening that way. If a move towards not just safer, but genuinely bug-free (or at least, bug-free outside of hitherto undiscovered exotic side channels) software is going to happen at all, it'll be because a large government drags its country's unwilling programmers and CEOs in that direction.
- jonknee 7y agoThat assumes the company is worth something, this company is worthless, fining them a billion dollars is useless.
- EpicEng 7y agoThere has to be a finding of gross negligence. Shit is going to happen even if a company does it's best and follows all of the best practices. Under your rules and OS zero day, which the company has zero control over, could ruin them. A single employee fooled by an email could do the same. It's far too simplistic and heavy handed. Also, not all data is equal. For example, if someone gets my HN creds I really don't care. My bank on the other hand...