2 ms·
Hard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that oth
by agar 3y ago
Hard disagree. Many security "breaches" are really the discovery of customer data in an S3 bucket "that no one is using in an out of the way data store that otherwise wouldn't need to be touched."
Forcing companies to track and manage the data in their stewardship is necessary because clearly the economic incentive is not high enough - by your own admission. It's easier (and cheaper) to just leave around. But - when, not if - it's hacked, /I/ bear the cost of their negligence, not them.
This is exactly why consumer protection laws are needed.
- johndhi 3y agoI think we're forcing them to manage the data in their stewardship inefficiently. I'd actually love a law that says if my data gets stolen from a company and a hacker uses that stolen data to harm me, the company must pay for (some portion of) those harms. But today it's setup so even if I don't get harmed they pay some lawyers to make the case go away.