5 ms·
we can start by repealing laws that give corporate entities immunity when data is leaked. Make them liable for lawsuits with set minimum damage amounts for exp
by ep103 5y ago
we can start by repealing laws that give corporate entities immunity when data is leaked. Make them liable for lawsuits with set minimum damage amounts for exposed data, and one would be able to watch the money flow into better tech security on a society-wide scale.
- ClumsyPilot 5y agoWe can also add a prohibition on three-letter agencies installing purposeful backdoors which are later exploited by criminals. Maybe it's time they actually were helping regular citizen protect themselves and their privacy, instead of playing chicken with their counterparts abroad.
- acdha 5y agoI support that but … how often has that happened? That Juniper incident didn’t seem to be widespread and it certainly doesn’t appear that a notable percentage of breaches are due that kind of thing.
- fragmede 5y agoExcept we don't know most of the hacks going on, so we definitely don't know how they happened. Eg we'll never know how many hacks were due to Debian's SSH fiasco but I bet you it's far from zero.
- acdha 5y agoWe don’t know everything but think about how many we do get details about showing nothing of the sort. It seems conspiratorial to assume that this happens often but is always hushed up.
- willcipriano 5y agoSimpler and more effective solution: Do as JFK suggested and "splinter the CIA into a thousand pieces and scatter it into the winds".
- arminiusreturns 5y ago...and we saw what happened to him. JFK and RFK's death together were a foreign and domestic policy coup. Ask yourself, by whom? Coincidence theorists are the real crazies.
- AmericanChopper 5y agoWhat laws do you imagine grant corporate entities immunity? The companies are victims of the crime in this case, along with their customers. There is no special law that grants corporations criminal immunity from falling victim to a crime, because that’s not illegal. If you look at how this sort of thing is regulated, there’s two general approaches. The first is creating a category of data that requires special protections, and defining a standard for protecting it. Either through legislation (like HIPAA), or self-regulation (like PCI). The other is to specify a requirement to protect all PII, but not define any specific standard for protecting it, only prescribing penalties for failing to do so (when seems to be what the EUs regulatory approach is). Both of these approaches are problematic. Is it self-evident that any breached data was not sufficiently protected? I don’t think any experienced professional would agree. It is impossible to build a system that is completely protected from being potentially compromised, and it’s possible for a largely unprotected system to last its entire lifespan without being compromised. So the simple fact that a system has been compromised doesn’t necessarily reveal any information about how adequately protected it was. On the other hand, is there a single security standard that’s widely regarded as being good? I don’t think there is. The ones that are generally regarded as the best I would personally consider to be not bad, but not great. One size fits all solutions tend to find a lot of not fit for purpose use cases as well. It’s also not apparent to me at all that spending more money on security achieves better security outcomes. I’ve worked in numerous large enterprises that spend enormous sums of money on security budgets, and manage to achieve very little with it. So I don’t think you’re going to get much consensus on that being a suitable metric for how adequate a company’s security systems are either. You could easily devise a system that punishes companies for falling victims to these attacks. But that’s the only outcome it’s going to achieve. A punishment for being the victim of a crime.