2 ms·
There are lots of companies that take security seriously and don’t lose their customers data. Which is good, because there are companies that need to hold custo
by tomComb 2y ago
There are lots of companies that take security seriously and don’t lose their customers data. Which is good, because there are companies that need to hold customer data.
Companies that don’t take security seriously and lose peoples data should be punished accordingly.
Companies that sell customers data should be identified.
But if we treat them all the same, then we let the bad companies off the hook, and punish the responsible companies unfairly.
- kragen 2y agothere are companies that have already had their customers' data exfiltrated and will have it exfiltrated in the future, companies that will only have it exfiltrated in the future, and companies that are about to be dissolved. there is no fourth category. computer security is not currently achievable; the best we can hope for is to contain the damage from the inevitable breaches and reduce their frequency new security holes get introduced faster than old ones get patched, and that will remain true for the foreseeable future