10 ms·
This issue can be solved with mandatory insurance and compensation structure. For this sensitive private health information compensation should be at least 5 fi
by INGELRII 6y ago
This issue can be solved with mandatory insurance and compensation structure. For this sensitive private health information compensation should be at least 5 figures per person, no excuses. A data breach involving 10,000 people could cost 100s of millions.
Companies would have to take mandatory insurance against massive data leaks. In order to keep insurance fees reasonable, they would have to implement good security. Insurance companies would do audits because they don't want to lose money. They would promote secure data vaults, require hardware authentication devices from their customers in exchange of insuring them.
Car manufacturers must be prepared to do massive recalls in case there is a fault in the car. Automotive recall insurance is a big business. Same thing. Regulatory structures protecting consumers.
- OpticalWindows 6y agoI think we need to make it at minimum 6 figures per person for adequate protection. Once information is out there is no taking it back. Banks, jobs will use all information against you. Electronic survalence is just another form of "Public HR" sure someone could intentionally post shit online to fuck with these systems but the creators have no remorse for such "people" as they are "degenrate" to try to destroy such "high minded" systems.
- seibelj 6y agoIt should be 7 figures. How can we put a price on knowing how often you go to the doctor?
- baobabKoodaa 6y agoSure, and while we're at it, why don't we make it a gazillion euros. After all, you can't put a price on privacy.
- contravariant 6y agoActually it should be free, after all you can't put a price on privacy.
- fogihujy 6y agoI suspect this is going to end up as one of the most expensive GDPR fines ever (edit: as a max-fine case, not neccesarily in sheer numbers). Furthermore, many individuals have had extremely sensitive data leaked publicly, and they could sue individually for damages. In other words: It could end up being insanely expensive.
- Hamuko 6y ago>I suspect this is going to end up as one of the most expensive GDPR fines ever. I suspect that this isn't. Vastaamo Oy has about 14 million euros in annual revenue. >they could sue individually for damages. I'm guessing you're American if you think that it's gonna result in "insanely expensive" damage payouts.
- fogihujy 6y agoJag äger en segelbåt. ;) Yes, and the maximum fine is 20M€. It'll probably be quite enough to take them down. The individual payouts of any lawsuits would probably end up as five-figure numbers, so if the hacker is telling the truth about then we'd end up with at least 400M€, which in my opinion is quite insane by Finnish standards. The number of victims here is quite insane after all.
- OpticalWindows 6y agoMake it 8 so you can knock it over and have it be infinity
- Hamuko 6y agoYou're not going to get seven figure payouts in Finland at any point. This isn't America.
- baobabKoodaa 6y agoIf this leak would have cost "6 figures" per person, as you advocate, that would total somewhere around 4 billion euros. If the insurance company has to pay out billions of euros for a single leak, it's going to have to charge pretty hefty premiums for their client. In order to stay profitable, the client has to raise prices for their mental health services. If the end user was previously paying 100 euros to talk to someone about their mental health issues, maybe now they would have to pay 100 euros to talk + 200 euros to cover the insurance premium. Doesn't sound too good, does it? Now let's imagine what the insurance company does when it's about to get hit for 4 billion euros. Instead of paying out, it's going to hire an army of lawyers who are going to make a convincing argument that, actually, this was not a data leak at all, this was [something else not covered by the insurance agreement]. We've already seen this with all the "cybersecurity insurance" products, which are basically scams.
- OpticalWindows 6y agoYes, good. Change your systems or get rid of it. Make it uninsurable and replace it with something of actual value.
- erdos4d 6y agoWhy should a private insurance company be allowed to skim a profit off this? The government should be on the hook directly, with careers ended when the taxpayer has to compensate these people for their injury.
- eru 6y agoSame reason we have private insurance companies in general. See also https://en.wikipedia.org/wiki/Reinsurance https://en.wikipedia.org/wiki/Reinsurance
- michaelt 6y agoIf you want fire insurance for a factory, the insurers will inspect what you're doing, the safety precautions you have in place, your testing regimes and so on - and charge you more (or refuse to insure you at all) if they don't like what they see. And as there are multiple insurers you get a competitive market - meaning the insurers who are best at spotting real problems prosper, while the insurers who miss problems or worry about non-problems are less profitable. And if a company can't get insurance at all it's not because one guy was being a hardass - they've had a bunch of chances to convince different insurers, all of whom have refused, rather than blame for them going out of business falling on some government agency. This is appealing to people who love free markets and small government, as there are multiple competing insurers, and all the inspections, monitoring and even the payouts happen at no cost to the government.
- nabla9 6y ago> Banks, jobs will use all information against you In the EU and Finland there are laws regulating what private data banks or companies can use or collect. For example, companies are forbidden from googling job applicant without their permission or looking at their social media. They also can't by data from data collectors like they do in the US.
- OpticalWindows 6y agoagain you're making the mistake that nobody would even try to break these laws as these are very hard to enforce. they probably have loopholes the size of trucks where they could hire outside sources to do such things but hide their sources.
- fogihujy 6y agoThat's the point with GDPR; you can't just start using personal data unless the person has given explicit permission for that data being used for that specific purpose. That applies to data from outside sources as well.
- OpticalWindows 6y agoAgain you're not going to catch everyone or even a large fraction of people who do it.
- nabla9 6y agoIn the US company can buy your information from data brokers. It contains your social networks, opinions etc. In EU doing that would be huge risk and it's not generally done. Just because there are loopholes and regulations can be violated does not make regulation pointless. It directs behaviour and what is considered acceptable.
- OpticalWindows 6y agoI think there are two ways to manage these types of issues. 1. Bring it fully legal and have a large impact on how it is done in cooperation with government. It could be beneficial to allow government insight so that it can prepare the general public about what is going on or how society might reflect on it. In general I believe we should be aware of all of the things this data can do. If during full disclosure people want this data regulated so be it. 2. Criminalize it (hard mode). It looks like with GDPR it will be criminalized and it will rely on companies using good faith on acquiring data like this. It will be regularly impossible to defeat all criminal actions but there will be no question who has the athority on such measures. With regards to both methods i see huge problems in the public understanding who is using and how the information is used. So it seems for now there is a few options left. One of which is to restrict knowledge and keep good people in power with the opportunity to use this data. Even with that we fail daily. everything is a struggle but perhaps this issue might shape how humans interact with eachother in the future the most.
- throwaway894345 6y agoI don't think it would be feasible to start at 6 figures--I think we would have to start lower and raise over time. If you start at 6 figures, a single breach can land a company well into the billions, and insurance premiums would be way too high for corporations to stay in business. I know there are a lot of "well good, fuck the corporations" sentiments out there, but these are corporations which can be economically viable and securely protect consumer data if they are given some time to improve their security. We absolutely should walk the price up over time, but let's give people some time to develop and implement a security competency within their organization (not to mention growing a security auditing competency sufficient to handle the scale of all businesses) before imposing ruinous insurance premiums.
- OpticalWindows 6y agoSure but you could consider the cost to the actual individual in the price of depressed wages, deteriorated personal relationships ect. They wont get a penny of it unless outlined by law.
- throwaway894345 6y agoOf course. My point was that we must also consider feasibility--we should absolutely get to a state in which corporations should bear the full cost for their security decisions; however, we probably won't be able to get there overnight.
- kebman 6y agoWouldn't it be better to simply invest that money in better security to begin with? An insurance scheme looks to me like a great incentive to hack insured servers, in order to cause insurance payouts on top of blackmail. Anyway, just want to say that there's a special place in Hell reserved for people who do that kind of thing, and to minors, even...
- adkadskhj 6y agoBetter? Probably, but everything in life is about incentives. If they have no incentive to protect the data to begin with then the "best" thing for them to do is invest most of the money.
- INGELRII 6y ago>Wouldn't it be better to simply invest that money in better security to begin with ou are arguing for behavior without providing any suggestions on how to achieve it. "Wouldn't it be better to simply do the right thing." is not a solution. What I propose is a set of policies and incentives that archive what you want.
- foolmeonce 6y agoI don't think a giant new source of income for insurance companies and slip and fall con artists will fix anything.. Each individual company might try to motivate slightly better behavior in their own clients but overall they want their administrative percentage of a growth industry so they drive up absurd costs like the US health care industry.
- eru 6y agoYou make an interesting point that with enough bad regulation, you can destroy any good and sensible idea.
- foolmeonce 6y agoAdding high value to stolen personal data is a sufficient bad regulation alone. The goal is to remove value so there's no expectations of ransom and therefore no thefts. If a company has to pay X for the loss off data, they would be fools not to pay x/100 to someone who breaks in, steals the data and promises not to report it.
- TedDoesntTalk 6y agoNo insurance company is going to take that deal because infosec audits are not perfect and they can not audit every possible software release. So your plan means governments will have to provide this insurance (there is precendent for governments providing insurance; eg Medicare in the US) That means taxpayers will fund the payouts. This is not a good solution. I don’t have an alternative, but I dont like this one.
- WhompingWindows 6y agoRegulations could encourage/entice/require big insurance companies to take on infosec contracts.
- INGELRII 6y agoInsurance business is risk management in imperfect world. Quantifying the risk and pricing it is their business.
- beefield 6y agoInsurance companies like risks that are diversified over their customer base, with regular enough occurrence in the customer population that the cost of payments over time is relatively stable. Insurance companies absolutely abhor risks that are affecting large portion of their customer base at the same time but only rarely. Re-insurers offer some help, you can talk about some special investment vehicles where insurance companies can offload those kind of risks off their books, but in the whole, I think it is quite safe to assume that insurnace market for those kind of risks would be seriously broken.
- tupputuppu 6y agoYour opinion is invalidated by the fact that cyber breach insurance is a thing that insurance companies sell already today.
- beefield 6y ago
- zepto 6y agoBye bye startups.
- ptaipale 6y agoYou get downvotes, but I do think you are right: at least in health industry, this event is a perfect stickhorse to push startups out of business i Finland. The current left-wing government has had that on the agenda, and they now have lots of fuel for it. They will also attack the "pörriäinen" class (Mehiläinen Oyj and similar larger health care providers) but those will withstand the storm; the small ones will be wiped out - Vastaamo for sure, but possibly also others.
- candiodari 6y agoOr you could solve this issue by not having this data in the first place. This data is so private and the violation of trust by the system so complete that the trust of most of these people will never be repaired. You don't need secure data vaults, you need LESS DATA. And anything you can't deal with seeing published, think VERY long and hard if it is absolutely necessary to have it. Even when it is necessary, is there any reason at all for not having it on a unpowered hard drive in a bank vault that requires approval from at least 2 directors to temporarily connect it to a machine that has never been connected to the internet. Most security breaches (including ransomware events) are insider attacks. Secure data vaults that only allow "authorized persons" access to patient data are therefore never secure. Secure data vaults are
- Hamuko 6y agoI don't see how any patient data can exists in this world under these conditions.
- candiodari 6y agoOn a notebook (the paper kind), locked, in a specific doctor's office is not a problem at all.
- Hamuko 6y agoHow do patient referrals work?
- aspenmayer 6y agoSame way they worked before computers? Fax machines still exist.
- Hamuko 6y agoWell now the patient data is not really locked away in a specific office.
- deleted 6y ago[deleted]
- vmception 6y ago> This issue can be solved with mandatory insurance and compensation structure. For this sensitive private health information compensation should be at least 5 figures per person, no excuses. A data breach involving 10,000 people could cost 100s of millions. Cheaper to not worry about that and just pay the hackers occasionally then. In market based economies, the state is not serious about fines and convictions of corporations because the state doesn't want to be responsible for making monopolies of the remaining companies in the country. You can read more about this in the book "The Chickenshit Club"
- newcomputer 6y agoNah, the solution to people getting hacked is not to punish the people who got hacked. Nice try though.