5 ms·
Only true if the punishment for both is the same. If they come forward they should be punished more lightly, but if not at all it only encourage "we'll just ap
by OptionX 2y ago
Only true if the punishment for both is the same.
If they come forward they should be punished more lightly, but if not at all it only encourage "we'll just apologize latter" sort of thinking.
- im3w1l 2y agoThere is also no real benefit to storing passwords in plaintext so I don't think your fear is realistic at all. If you are going to fine this at all, then 10k-100k would be an appropriate amount.
- Timon3 2y agoWhy 10k-100k, how did you arrive at that amount? Meta put their customers at risk through negligent actions. A fine in the range you propose would be lower than any investment required to improve security (e.g. by hiring a single additional person). What company in their right mind would do anything to improve security in that case?
- im3w1l 2y agoThat's close to how I arrived at the number - I used programmer wages. Reading about best practices around password storage and implementing it is fairly quick and easy, so a fine of that size will still be sufficient incentive.
- Timon3 2y agoBut why would that be an appropriate amount? By having the fine around the lowest possible investment to tackle the issue, you're literally incentivizing companies not to take security seriously. After all, you can save money early into development, and just fix it whenever you have time - you'll still save money compared to doing things right immediately. So again, why would this make sense?
- rsynnott 2y agoThat seems like pretty much a license to have practices as poor as you want. For a company of that size, a fine that size would just not be material at all.
- rsynnott 2y agoThey would have been punished more lightly if they’d come forward within 72 hours; as it is it appears to have taken two months.