6 ms·
Andrew Yang should campaign on making Equifax pay for data pollution. In fact, every one of these "data breaches" should be treated like the BP Oil spill. If t
by dznodes 7y ago
Andrew Yang should campaign on making Equifax pay for data pollution. In fact, every one of these "data breaches" should be treated like the BP Oil spill. If these companies can't be held accountable for protecting our data then they shouldn't be allowed to collect it in the first place.
If it cost them as much to clean up each spill as it cost BP, you better believe they would take better care not to let it happen again.
- boring_twenties 7y ago> If these companies can't be held accountable for protecting our data then they shouldn't be allowed to collect it in the first place. It's so sad that this is even remotely controversial. Equifax should have gotten the same treatment as Arthur Andersen.
- thephyber 7y agoFrom my reactive, emotional side, I would argue yes. From my rational, informed side, I would argue no. Here's my rationale. The data stolen from Equifax has not shown up on the black market and hasn't been actively used, which suggests this was a nation-state using the data for something other than profiting from fraud. This also suggests that the hack could easily be considered an "act of war", so given enough time+effort+resources, no company would likely be able to resist that breach (although I know Equifax could have done FAR better than they did). Technically I don't "own" the data that Equifax has about me. Equifax owns the collection of it, their reporters (ex retailers, landlords, bank/mortgage companies) each own a shard, and other data aggregators who contract with any one of these actors can own part/all of it. I am not Equifax's customer. They are required to deal with me based on a few rules defined in the Fair Credit Reporting Act, but the FCRA also provides some protections for credit reporting agencies who don't violate those rules. I'm sure they minimize the effort/resources they devote to helping credit consumers because that is the profit motive of every company. I'm sure Equifax has a ridiculous EULA/ToS that I probably implicitly agreed to when I used the AnnualCreditReport website, and probably additionally when I deal with any retailer that pulled credit reports from Equifax (including the IRS after the breach was revealed). It likely involved me signing away my rights to a class action litigation or my rights to a trial by jury, because that is par for large contemporary corporations. The standard for "protecting consumer data" is remarkably low except in a few sectors (ex. healthcare, retailers storing credit card data), and even in those it's still disheartening. The problem here is that companies can easily argue to {regulators, judges/juries, their BoD, cybersecurity vendors} that they can't be expected to spend more than the industry average because that hurts them more than the competitors. This just becomes a Prisoner's Dilemma where our data's security becomes the victim to corporate (in this case credit reporting bureau) self-interested decision making.
- ddsea 7y ago> The data stolen from Equifax has not shown up on the black market Yet - and also the absence of evidence doesn't mean the evidence of absence. Not all criminals are stupid, a smart one would wait till vigilance dies down.
- nerdponx 7y agoOr it's already been distributed/used/sold, albeit not as a single large leak of data.
- pishpash 7y agoI dispute that the data doesn't belong to you, even if it was collected by someone else. That's the crux of the matter, isn't it? If the information shares entropy with me or my various states, because it physically came from my body or my actions, then there's a strong argument to say it belongs to me, its origin, no matter how far it has been transmitted.
- boring_twenties 7y agoI'm skeptical of the claim that only a nation-state could have done this. Too lazy to look it up now, but I could swear that it was publicized that they were pwned using vulnerabilities that had been publicly known and patched for months? That would be extreme negligence no matter how you slice it. > Technically I don't "own" the data that Equifax has about me. This itself is a big part of the problem. It should absolutely be illegal for companies to hold sensitive info like my SS# without my permission.
- pretendscholar 7y agoWhat do you think a Warren or Sanders position would look like on this issue because that sounds it would be exactly their stance.
- nerdponx 7y agoTheir donors might balk, however.