8 ms·
I believe we need to criminalize possession of the data, with statutory damages per violation.
by analog31 1mo ago
I believe we need to criminalize possession of the data, with statutory damages per violation.
- DANmode 1mo agoNegligence is already illegal. Just locate a prosecutor.
- DaSHacka 1mo agoI'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked. Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.
- DANmode 1mo agoSounds like you’re not going to sleep well at night regardless, choosing to stick around for more of that.
- megagpt5 1mo agoNegligence isn't a crime in itself. It is an explanation or cause for other crimes. And there is nothing illegal in the US about selling pictures of people's drivers licenses.
- DANmode 1mo ago> there is nothing illegal in the US about selling pictures of people's drivers licenses. 18 U.S.C. § 1028 makes certain transfers involving identification documents criminal. It specifically covers a driver's license or personal identification card and provides enhanced penalties for transferring such documents. 1028 expressly recognizes electronic transfer as satisfying its interstate-commerce requirement. What are you talking about?
- DANmode 1mo ago> Negligence isn't a crime in itself. It is an explanation or cause for other crimes. Correct, like being criminally negligent of a child, if you leak data through long-known vectors (for argument’s sake), one could argue you are criminally negligent in securing the private data. It doesn’t really go that way, often, now. It could, as more e.g. water treatment and energy providing facilities get pwnd.
- akshatjiwan 1mo agoSome laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.
- vrganj 1mo agoNot quite the same, but the GDPR gives you a right to erasure.
- OKRainbowKid 1mo agoAnd afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.
- vrganj 1mo agoMaybe the bureaucracy is there for a reason some times? Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses? Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model? Hm.
- OKRainbowKid 1mo agoIn case it wasn't obvious: I do not at all agree with these complaints about the GDPR or EU.
- randunel 1mo agoActually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR.
- wolvoleo 1mo agoWell unless it was stored with freely given permission of course. But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.
- 1mo ago
- CamperBob2 1mo agoExactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.
- londons_explore 1mo agoEstonia has it's ID cards which can sign things.... That suddenly means a data leak doesn't matter - nobody can make new signatures. Verifying someone's ID would be as simple as asking them to sign your company name and today's date.
- mschuster91 1mo agoThe problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state. [1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wall-street-journal https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...
- alistairSH 1mo agoWhich is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else. If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed). We'll get there eventually, but not before we try everything else first.
- cucumber3732842 1mo ago>Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else. "They can already send a drone to watch you and track your cell location and, and, and, why does it matter if they also slap up a million AI powered cameras?" The comprehensiveness of the system matters.
- actionfromafar 1mo agoBut that would be like GDPR and that is EU which is communist which is satanic. QED.
- raverbashing 1mo agoIt would be fun if the GDPR naysayers end up coming up to the same conclusion
- GJim 1mo agoA significant percentage of HN posters and readership are those working in US AdTech, who's very salaries are dependent on abusing peoples privacy. Hardly surprising a hefty part of the HN demographic slants towards opposing decent privacy laws.
- wolvoleo 1mo agoIsn't that the case already? Here in many European countries it already is. They're always warning about that when there's a big breach and people download it to see what's in it about them. Not that they're going to prosecute half the country of course but still.
- herbst 1mo agoThere are also very very strict rules for companies that use or process this kinda of data and how they need to save and handle it. Hence why it's basically illegal to use US based services for anything with real data these days. I wish it would be more enforced and controlled tho.
- wolvoleo 1mo agoYeah it's not at all. Everyone just gets away with everything. Recently a bit dutch ISP was hacked and it turned out they kept millions of former customers' details way way beyond any normal lifecycle term. People were still in there that hadn't had anything to do with that company for a decade. This is illegal in the EU but even after this practice was exposed by the leak, the personal data authority just let it all slide. They also sent out a press release pooh-poohing the consequences for affected (ex-)customers and all they did in compensation was to give a "free" antimalware subscription that was basically advertising just like the few months of mcafee crap you get with a new computer. But all we get from regulators and politicians alike is crickets.
- analog31 1mo agoCommenting on my own post, I should expand a bit on "statutory damages." I got the idea from the music industry, where there are automatic civil damages for copying recordings. If you're caught, you get to pay X dollars per item. This means the police don't get involved. The only thing you need is a tort lawyer willing to take a share of the damages. Also, a data breach is proof that you possessed the data. A business wouldn't be able to reduce their liability exposure to zero, but to an acceptably low level, for instance by actively erasing the data before a breach can occur.