4 ms·
>Wouldn't it be better to simply invest that money in better security to begin with ou are arguing for behavior without providing any suggestions on how to ach
by INGELRII 6y ago
>Wouldn't it be better to simply invest that money in better security to begin with
ou are arguing for behavior without providing any suggestions on how to achieve it. "Wouldn't it be better to simply do the right thing." is not a solution.
What I propose is a set of policies and incentives that archive what you want.
- foolmeonce 6y agoI don't think a giant new source of income for insurance companies and slip and fall con artists will fix anything.. Each individual company might try to motivate slightly better behavior in their own clients but overall they want their administrative percentage of a growth industry so they drive up absurd costs like the US health care industry.
- eru 6y agoYou make an interesting point that with enough bad regulation, you can destroy any good and sensible idea.
- foolmeonce 6y agoAdding high value to stolen personal data is a sufficient bad regulation alone. The goal is to remove value so there's no expectations of ransom and therefore no thefts. If a company has to pay X for the loss off data, they would be fools not to pay x/100 to someone who breaks in, steals the data and promises not to report it.
- eru 6y agoWe have similar situation and incentives for eg poisoning a few jars in a food factory. (And I have read of some rare cases where that was actually a problem.) What keeps that from being too much of a concern? What similar factors apply in the data breach ransom scenario? What's different? (Just for clarification: if a bad actor poisons a few jars, the producer in question is probably not legally responsible; but they still face a significant cost in lower sales. So blackmail is just as possible.)
- foolmeonce 6y agoThat's the example I was thinking of, I'm quite happy with government concerning itself with regulations on options, etc, working closely with the food industry, and perhaps I'm alive only since no free marketeer was around to introduce an unconditional $10k fine per malicious tampering as a way to improve security during the painkiller scandals. Naturally, if free marketeers had created a market for food tampering that encouraged industry collusion with criminals instead of law enforcement, they would tell us it was an inevitable development and they are getting us the best outcome of many bad new realities.
- eru 6y agoYour strawman seems a bit stupid. Real life companies are more long term greedy and ingenious. (Even if only because competition forces them to.) So even if there's an incentive to cooperate with a blackmail attempt that's already happening, there's also a strong incentive to get a reputation that prevents further blackmailing. If you have some time, listen to this podcast episode https://www.econtalk.org/anja-shortland-on-kidnap/ https://www.econtalk.org/anja-shortland-on-kidnap/ > Anja Shortland of King's College London talks about her book Kidnap with EconTalk host Russ Roberts. Kidnapping is relatively common in parts of the world where government authority is weak. Shortland explores this strange, frightening, but surprisingly orderly world. She shows how the interaction between kidnappers, victims, and insurance companies creates a somewhat predictable set of prices for ransom and creates a relatively high chance of the safe return of those who are kidnapped. The broad incentives in kidnapping cases are comparable to what we discussed. As far as I can tell the market for kidnapping insurance doesn't have any special regulation, so perhaps a good proxy for how a free market might operate. One of the main takeaways for me was that when eg an oil or mining concern buys kidnapping insurance for their employees, the insurance company strictly insists that employees not be told that there is insurance.
- foolmeonce 6y agoHere you seem to understand the basis for inference: > the insurance company strictly insists that employees not be told that there is insurance. The stated inference: >> Each individual company might try to motivate slightly better behavior in their own clients but overall they want their administrative percentage of a growth industry so they drive up absurd costs like the US health care industry The background concept that applies irregardless of whether a parasite is "criminal" or standard practice (of course every parasite can claim something symbiotic, maybe kidnapping is just freelance private security testing with post pricing): https://en.wikipedia.org/wiki/Parasite_load https://en.wikipedia.org/wiki/Parasite_load The insurance parasite/symbiote load as percentage of GDP, compare the 1980s to now: https://data.oecd.org/insurance/insurance-spending.htm https://data.oecd.org/insurance/insurance-spending.htm The percentage of GDP lost in ransom? 0%? Terrorist ransom was also popular in the 1980s but government interfered directly, preventing most private payments and that response was primarily with force. So, would a government demanding €10k for every kidnap of your employees they hear of fix a problem? No, it would make kidnapping more attractive. It would threaten to involve a larger parasite (clearly this is too late in the case of kidnapping in this century!) And you would have a permanent problem with a powerful parasitic market deriving more profit than the primary market of criminals. Luckily, for food conglomerates their stock price is uninsurable. Unluckily for humans, government hasn't stepped in to prevent a market and much more profitable secondary markets for kidnapping in this decade. Unluckily for private data most governments haven't come down on the use of laundered stolen private data (i.e. outlawing the sloppy US credit market, any unique pricing of insurance to a group, etc.) Luckily, they have not gone so incompetent as to add an incentive that makes all private data valuable.
- kebman 6y ago> ou are arguing for behavior without providing any suggestions on how to achieve it. (sic.) Yes, I did. I provided you with this solution: "simply invest that money in better security to begin with" > "Wouldn't it be better to simply do the right thing." is not a solution. I never said that. But what I did say is indeed a solution. > What I propose is a set of policies and incentives that archive what you want. Well, it certainly makes incentives, but probably not the ones you had in mind. For instance it incentivizes middlemen to scrape off valuable resources that could have been used to secure the actual data. At best this lowers the profit margin left over for the hospital to improve the security, but it's way worse than that. Instead the middleman actually incentivizes hackers to crack into the very system the middleman "insures," exactly because huge insurance payouts are involved. Perhaps the hackers could fake a mental disorder and get committed at the hospital, which would make it far easier to get insight into how the data security system works, and then plant a backdoor or leak that way. This means the hacker would both get money from blackmail and money from insurance payouts (win-win for him), making the incentives from the insurance scam absurdly bad. But perhaps that was the goal all along? Meanwhile the owner is already disincentivized from securing the system further, because he can claim that he already did enough to secure it, while what he actually means is that he insured it... Whatever he paid for, was certainly not free! The only one incentivized to look into the matter, is the insurance company itself, because they're the ones who stand to lose the most money if the system fails. And even they don't want to waste money on a matter they might not even understand themselves. Meanwile their biggest incentive isn't to secure the data, but to not pay money to the patients. And perhaps the easiest way to avoid that, is to hire a PR consultant instead of fixing the data system. Certainly the least of their worries are the patients, who are the real losers here, from being trapped in a game of exploitation for profit, and who quite possibly have to pay a much higher fee for the services of said institution because of it. Luckily, Finland is a welfare state, so that extra cost probably won't be billed individual patients (depending on how this privately owned hospital operates), but instead it will most likely be forwarded to the taxpayers, which – while spreading the cost on more hands – is still extremely bad. Overall, introducing an insurance scheme only adds another problem, without fixing the initial one, because how would you rate the probability of the system failing? That's what sets the insurance fee, after all. Thus, for the insurance companys part, it's far better to overbill, which would just result in increasing cost, without much benefit to anyone.