5 ms·
There's a solution: personal liability for the executives and managers at the company, and for the investors. For example, every person who has ever worked for
by jsrozner 18d ago
There's a solution: personal liability for the executives and managers at the company, and for the investors.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealthy-poor.html https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
- schainks 18d agoThis.
- mccauley 18d ago100%
- mahboi 18d agoIt's cleaner to hold some of a corp's money in escrow if they're handling IDs, to ensure they can't avoid fines via bankruptcy.
- jm4 18d agoThis is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
- dylan604 18d agoWho receives the payouts of those insurance benefits and how would one go about making a claim?
- jm4 18d agoThe company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy. What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
- toss1 18d agoAnd when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then? Insurance is not a solution for everything. More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly. It is really simple: If they can not handle properly the risks of their business, they should be in another business.
- nicce 18d agoIncluding investors is a bit much unless they encouraged or mandated some decisons that enabled this.
- vjvjvjvjghv 18d agoInvestors benefit from company gains despite not having encouraged or mandated some decisions that enabled the gains. So it makes sense that they also get exposure to the downside.
- nicce 18d agoThey already get downsides if company gets fines or even goes to bankruptcy. You never know whether they invested based on information that was not true at all. Which is unfortunately too common.
- shimman 18d agoIt sounds like they need additional exposure then as they aren't assessing the real risks and seem to have completely ignored them. Why should society care that some group of investors didn't do their homework? Is that the excuse we use to avoid prison sentences now?
- solidsnack9000 17d agoThere are many, many cases where investors are misled by companies -- this falls under the (very broad) heading of securities fraud and it's easy to find documented cases of it. It's not a question of doing their homework. There is literally no way to have the broad base of investment in markets by members of the public that we see today if investors incur personal liability. It was and remains one of cornerstones of any commercial society.
- Dylan16807 17d agoThey said VC, not all investors. Let's say the investor part doesn't apply to public companies, to make it simple.
- dyauspitr 18d agoGreat way to incentivize everyone to do nothing. Most middle managers don’t know shit.
- bix6 18d agoThis is so unrealistic but I do agree personal liability should come into play more for people who knowingly act inappropriately.
- rectang 18d agoIt's perfectly reasonable, and if something perfectly reasonable is "unrealistic", then the system is corrupt.
- bix6 18d agoBankrupting everyone who does business by making them repay 300% of earnings is unreasonable. The liability shield is too strong though so I do agree it’s causing problems.
- rectang 18d agoThe socialized losses vastly exceed 300% of earnings - they're analogous to a company mishandling toxic waste and ruining everyone around them. The way they are running their business is catastrophically irresponsible, and if they can't afford the consequences, they shouldn't have gone into this business.
- p_l 17d agoIt's already a rh>ng for critical infrastructure companies in EU.
- ndsipa_pomu 17d agoUnfortunately "knowingly act inappropriately" is going to be tough to prove. I think it's better to pin the responsibility onto the top executives unless they can prove that it was a specific bad actor despite systems put in place to prevent that. Otherwise, it's too easy for execs to ignore privacy and security concerns just because they are not familiar with that side of things. We should also make it much easier for company employees to whistle-blow or even initiate stringent audits of security and privacy.
- rectang 18d agoFines exceeding 100% of lifetime compensation might actually do something. As it stands, clawbacks are ineffective — for example, Carrie Tolstedt of the Wells Fargo scandal wound up money ahead to the tune of tens of millions of dollars: https://en.wikipedia.org/wiki/Carrie_Tolstedt https://en.wikipedia.org/wiki/Carrie_Tolstedt > In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
- xienze 18d ago> personal liability for the executives and managers at the company How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable. Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
- triceratops 18d agoDoes IDScan need to store the IDs after they've verified them? If they deleted the IDs within a week of getting them surely the leak would be much smaller.
- matwood 18d agoMaking holding data like this a liability that has to be insured, etc... is part of a good solution IMO.
- arionhardison 18d agoNo, this is a NOW problem, not a future one and it will take months if not years to fully understand the impact. We need a NOW solution not prevention. Training AI on all the images and data here will facilitate a class of identity theft we may not have ever seen. This cannot just be abut prevention.
- bpodgursky 18d agoIf you add in personal liability for mistakes, nobody competent will ever bother working in the industry again. It's not worth the personal risk. You'll get stuck with bottom of the barrel staff who don't have much to lose and get a steady paycheck for a few years.
- biggc 18d agoI believe that many "professionals" have personal liability and carry insurance. Lawyers, doctors, and engineers to name a few.
- bpodgursky 18d agoThe liability the OP describes is clownish and nobody would ever insure against it.
- pesus 18d agoThat still prevents it from happening again, no? Still seems like a success.
- bpodgursky 18d agoNo, it guarantees it will happen because only terrible people will work on the systems.
- deleted 18d ago[deleted]
- tester756 18d agoOr maybe something bigger should change like why your driver license or even id should enable someone to do damage to your life? especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
- seizethecheese 18d agoYou do realize the limited liability corporation was a key innovation that unlocked the Industrial Revolution, right? Companies definitely respond to fines or liability. They just need to be big enough. For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
- porkshoe 17d agoThat works for Chevron because they have enormous assets to lose. In the ID company case, there simply aren't enormous assets available, despite enormous damage being possible. As such, we really need to re-think just how much we limit liability. Perhaps it's time to stop allowing degenerate gamblers to freeroll their risks... perhaps it's time to start zeroing out investors, so that they have to start behaving responsibly.
- solidsnack9000 18d agoThere is no legal basis for this for taking the salaries of everyone who worked at the company in any level of management at any time. No large undertaking could ever function with such broad exposure to liability, anyways.
- SlavikCA 18d agoThat's right: no legal basis exists now. The proposal is to create such legal basis. And if "No large undertaking could ever function with such broad exposure to liability" - that would be great, i think we would prefer that such firms doesn't exists.
- Ajedi32 18d ago"such firms" being any and all IT companies? They would still exist, just not in any country insane enough to pass a ridiculous law like this.
- JumpCrisscross 18d ago> that would be great, i think we would prefer that such firms doesn't exists They stop existing within your jurisdiction. Also, the idea that the public would go along with any of this for this issue is silly. Let's start with crimes that actually cost lives.
- rectang 17d ago> Let's start with crimes that actually cost lives. https://spectrumlocalnews.com/tx/south-texas-el-paso/news/2024/02/22/financial-and-psychological-effects-of-identity-theft https://spectrumlocalnews.com/tx/south-texas-el-paso/news/20... "According to the Identity Theft Resource Center’s 2023 Consumer Impact Report, 16% of identity theft victims are experiencing suicidal thoughts."
- rectang 18d agoThen such businesses should not exist. What right do they have to gamble with the wealth of 150 million people unrelated to their enterprise?
- ball_of_lint 18d agoLiability doesn't fix the damage that is already done. We can punish all the people involved in this, and it will still be the case that your drivers license is available for purchase and identity theft against anyone is now much easier. They don't have enough enough to repair the damage they've caused, even if we take everything from them.
- sigmoid10 18d agoThe damage can't be undone, but you can learn from it and prevent these things from happening again and again. If every CEO truly believes that his personal wealth and freedom is at stake with the safety of his customers' personal data, they will see that ITsec becomes a cornerstone of the company instead of an annoying compliance sheet checkbox.
- onemoresoop 18d agoLiability can be a strong incentive to improve the system in the future.
- stronglikedan 18d ago> Liability doesn't fix the damage that is already done. Neither does imprisoning murderers for life, but it's one heck of a deterrent.
- noosphr 18d agoThe only time it's worked is in El Salvador and it was because they arrested the 2% of the population who had the potential to be murderers and have so far thrown away they key. I imagine before too long they will also have a final solution to the problem of feeding them for the next 50 years.
- deleted 17d ago[deleted]
- jmcqk6 17d agoThere are quite a few people who murder despite the risk of incarceration. I would love a system that approaches it more like: "you've lost trust of this civilization to act in good faith, and now you will be contained in a way that can rebuild that trust, and you will not be allowed to re-enter this civilization until you have indeed rebuilt that trust." We'll probably never get there.
- JumpCrisscross 18d ago> All VCs in the company should face personal liability up to 10% of their net worth Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite. The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
- redorb 17d agoI've always found it absurdly awkward to give companies personhood AND have them unable to be put into prison. I prefer how director level in EU seems to have some big responsibility.
- faster 17d ago"personal liability for the executives and managers" at which company? What's stopping IDScan from "delegating" the storage to another company so they're no longer liable for stolen data? If Company A uses IDScan and the storage of the ID info is handled by Company B, do I have standing to demand compensation for damages from Company B when my data is stolen after I agree to let Company A verify my ID? BTW this is how accountability is being avoided today.
- josh_p 17d agoI think IDScan is still responsible for. You don’t typically go after hosting providers for failures like this, right? Or are you referring to the practice of using shell companies to obfuscate responsibility? In that case, I think there’s history that says IDScan would still be responsible, questionable legal business nonsense be damned.
- crm9125 17d agoPotentially, all of them. If someone steals my identity, and puts me in a position where "I" owe money that I didn't borrow, NONE of that money paid back will come from my pocket. The government can figure out who should owe it, but it sure as hell isn't me. I think in the same way part of our paycheck goes to federal taxes, part of our paycheck should go towards funding an insurance for the financial impacts these sorts of events, commensurate with the total compensation of a person, and adjusted each year for the growth of any stocks granted to that person. I'm sure there are edge cases and operational details that need to be figured out with that idea, but at the end of the day if a company is directly or indirectly responsible for awful things, the executive and senior leadership should feel the impact more than others, financially and/or criminally.
- mitxela 17d agoIt's not identity theft - it's bank robbery, and the bank is trying to pin it on you: https://www.youtube.com/watch?v=CS9ptA3Ya9E https://www.youtube.com/watch?v=CS9ptA3Ya9E
- paimapi 17d ago
- 0xbadcafebee 17d agoOr, we could introduce a software building code, the way we have codes for every other kind of safety-impacting product. But apparently software is never unsafe, we never need to protect people from software systems, and definitely shouldn't pass a law requiring those systems be protected adequately, with legal consequences for not doing so.
- mitxela 17d agoEven though software has been around for a while now, it does still seem to be evolving rapidly enough that a fixed code is a bad idea. Remember password change requirements that were terrible, but stuck around for 20 years before being removed from the relevant voluntary code (I think something from NIST)?
- 0xbadcafebee 17d agoYou're describing a compliance success story. NIST creates the standards that businesses must follow when doing business with the Federal Government. Without those standards, the government's operations would be even more unreliable and haphazard than they are today. A long time ago they mandated a single password policy, because having thousands of agencies all with different password policies was crazy. At the time, they (and the industry) thought it was a good policy. Some people suspected otherwise, but there was no proof to show that a change was necessary. So academic research was undertaken to find whether the policy was helping. The research showed that it was more harmful than helpful. Academia proposed a solution, NIST considered it, and then adopted it, in 2017. The language they used in 2017 was "flexible", so nobody really had to change. Finally in 2025 they made the language mandatory. Now the affected companies will be forced to abandon their crappy password policies, specifically because they aren't allowed to keep them anymore, if they want those lucrative contracts. This should not just apply to the Federal Government. The same reasons FedGov needs these standards applies to every single one of us. The tech lobby has successfully fought this for years, and politicians are scared of introducing something that might negatively impact public citizens (and thus risk the politician's job). But they can't deny that FedGov needs these standards. This is a pretty normal process. The electrical code, building code, fire code, etc, all take time to change. But the changes do happen, and we all reap the benefits. With no code at all, we would be experiencing a lot more death, injury, financial loss, and inconvenience. And btw, there is a lot of technology that has not evolved much in 40 years. We don't need to make everything absolutely perfect, and every aspect 100% set in stone, in order to have a code. Every other code is updated regularly. Software code can change too. (Or are software people too incompetent to figure it out? I might agree with that...)
- ip26 17d agoI've got bad news for you jsrozner, John down in accounting at <your employer> did something very unethical last week. So you, jsrozner, a first level manager in customer support who has never even met John, are going to jail for a decade and all lifetime compensation will be clawed back.
- bradleyjg 17d agoPerhaps you’re right but how about starting with anything at all meaningful against the company itself? They end up pay some class action lawyers $8 million dollars and we get a letter offering FREE CREDIT MONITORING!!1!
- closeparen 17d agoPeople need to stop believing insane, delusional things like the existence of a human being with a certain name, address, phone number, birthday, SSN being secret or private information. Downstream of that, people need to stop accepting knowledge of the basic public metadata fields or possession of images containing them as evidence of identity verification. Do actual public key cryptography on the internet or check biometrics and the document’s physical security measures in person.
- xlayn 17d agojsrozner for president. Again... just imagine the cost of say replacing the SSN and each and every one of the licence drivers in the US... JUST IMAGINE THAT COST PAID FROM THE TAXES YOU PAID, and again by you because it's not free... so it's leaked all over again in 1 month because there is no way "to incentivize these guys to jail" fast enough. It's done and works that way because the deterrents are 1% of the income of the company.
- crote 16d agoDon't forget jailing the idiot politicians who okayed handing over all those driver's licenses to a private company.
- hulitu 12d ago> personal liability for the executives and managers at the company, and for the investors. That is not how capitalism works. See Microsoft, Google, Facebook for examples.