4 ms·
Is bad security ok for, say, a bank or a nuclear power plant?
by pps43 6y ago
Is bad security ok for, say, a bank or a nuclear power plant?
- SahAssar 6y agoNo, and that's why we (basically all nations that have banks or nuclear power plants) have specific laws governing them. Look, if you want to pass a law saying all internet business having X personal data needs to prove Y security, then I'd probably be for it (depending on X and Y). We already have PCI-DSS and similar today for payment providers. I'm just saying that there is nothing like that today, and if there was we'd have a lot more irresponsible people in prison.
- pps43 6y agoIn "2020 Commission Report" by Jeffrey Lewis, North Korea nukes the US because of one twit. This looks very plausible to me.
- SahAssar 6y agoAre you arguing against something I've said? Because if so I don't understand what or how.
- pps43 6y agoI'm arguing that Twitter is now critical infrastructure, like banking or power grid, and needs to take security seriously. If they don't do it themselves, they'll get regulation like HIPAA.
- SahAssar 6y agoThen you need to find someone else to argue with. All I said was that bad security is not criminal currently.
- 6dEOWVt4WN 6y agoA nuclear power plant, no. Because, its most likely public property and so govt should have a say in its security. Even if it was a privately owned nuclear power plant, a breach would catastrophically and directly affect people who are not just its customers. But, a bank, which is a privately owned entity. I think yes. If I own a bank and have bad security practices, and a breach impacts only my customers. I think the customers have the right to sue the bank but its up to me to decide what security I use, and if its not good the customers are free to choose to do business with another bank. But I don't think the govt should decide what level of security is sufficient? Think of it this way, does this imply if my house is robbed I could be held liable because I chose to use locks on my house that were non compliant to govt regulation?
- pps43 6y agoLarge banks are designated as SIFI (systemically important financial institutions, aka "too big to fail"). When they screw up, the government steps in and props them up with taxpayer's money. To those banks losses from lax security are externality. In that sense they are not very different from nuclear power plants. Indian Point is owned by Entergy and it gets the money when everything works fine, but the risks are covered by the government through Price-Anderson Nuclear Industries Indemnity Act. If your house is robbed, it's your problem. But if you store personally identifiable information for everyone and it gets stolen, now it's everyone's problem.