5 ms·
Korea raises data breach fines to 10% of revenue
- aucisson_masque 15d agoGDPR in Europe puts it at 4%, and yet we are seeing leaks every week. 10% maximum mean nothing if it’s not enforced, you got to make examples.
- quickthrowman 15d agoI would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
- draw_down 15d ago[dead]
- buellerbueller 15d agoMaybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.
- google234123 15d agoYou legally have to hold transactions for years yk as a business
- josephg 15d agoThen secure your database? This stuff isn’t rocket science. You don’t even have to hold historical transactions online. It’s quite difficult for hackers to access a hard drive sitting in a drawer.
- someguynamedq 15d agoBut not impossible
- google234123 15d agoProbably a law targeted at foreign companies
- Retro_Dev 15d agoI especially hope this holds true, because I don't want my information being leaked by anyone.
- Retro_Dev 15d ago> there’s no such thing as a secure computer system Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens. Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
- deleted 15d ago[deleted]
- aucisson_masque 15d ago> Where is your source for this? It is entirely possible to make a secure computer system You can’t. You don’t need source for that, just common sense. Exploits are discovered every day, bugs happen, bad actors. You can do the best system, shit still happen. BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ? If the cia couldn’t prevent it, I bet you can’t.
- askonomm 15d agoSeeing the sheer level of incompetence in the U.S government, I don't think citing CIA has the intended effect you think it has.
- aucisson_masque 13d agoCIA in 2000’s wasn’t yet under trump government and even then, they are still one of the most secure organizations. Trump or not, everyone think of them as highly secure.
- bigfatkitten 15d agoThe South Korean privacy regulator is the most diligent that I’ve ever seen in terms of slapping companies with fines when they screw up.
- prologic 15d agoWow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
- deleted 15d ago[deleted]
- jmclnx 15d agoSounds great if all the following is true. * Before Tax Revenue * If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent. * Includes Worldwide Revenue * Includes companies based in all other Countries. I would have went for 20%, but if he above applies I wish the US would do the same.
- zelphirkalt 15d agoThe US is probably among the countries, where the lobbying against such a law or policy would be very severe, because multiple of their tech giants are built on the foundation of abusing people and considering fines to be cost of business.
- someguynamedq 15d agoWhy is mishandling data tax deductible?
- augment_me 15d agoYou can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function. Minimizes money usage and does not require any security investments
- louthy 15d agoOr … and hear me out on this one … care?
- augment_me 15d agoSounds like something that costs money, if a university doesn't care I don't think most companies will.
- louthy 15d agoYes, being competent requires effort. It certainly feels much better being an proactive member of society rather than a self-serving arsehole though. So, there is that.
- nostrademons 15d agoIt feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling. Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
- louthy 15d ago> It feels better only as long as everybody else cares too. Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional. I did it because: * it’s the right thing to do * for professional pride * and so I could sleep at night And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory. I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks. [1] https://www.meddbase.com/ https://www.meddbase.com/
- SoftTalker 15d ago"through intent or gross negligence" I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
- bluGill 15d agoThe hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place. (I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
- someguynamedq 15d agoYeah neither intent nor gross negligence is the reason most data breaches occur
- xtajv 15d agoHopefully, this raises the bar then.
- rectang 15d agoIt's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.
- someguynamedq 15d agoGoes through != Enforced
- esafak 15d agoThe EU AI Act already levies 7% global annual turnover penalties for prohibited AI practices.
- ggarnhart 15d agoThis feels like a really odd way to incentivize data breaches and/or not reporting data breaches.
- Retro_Dev 15d agoUm, I think it does the opposite of what you are suggesting - this aims to reduce data breaches and incentivize people to prevent these breaches.
- amelius 15d agoIf 10% of revenue is still cheaper than building secure systems ... Perhaps what would help is a progressive system, where you'd pay 20% the next time.
- happytoexplain 15d agoHigher.
- nosmokewhereiam 15d agoImagine 10% of Samsung! Edit: "That'll be $23B. Cash or card?"
- __natty__ 15d agoHuge fines but reasonable. Especially now with all the people doing blind vibe coding
- roundup 15d agoAssuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company.
- xp84 15d agoI'm assuming the intent is to protect customers. Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all. I'm thinking: (The following example is in "American" terms, I assume some other countries have similar ideas as SSN though) - Name and address or name and phone number leak: $100 per customer affected. - Email: $50 per customer affected, or $100 if tied to any other data. - Social Security numbers: $2000 per customer affected - Unsalted or plaintext passwords: $500 per customer affected. - Cap is the greater of 200% of annual EBITDA, or 20% of revenue Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users. This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse. My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
- someguynamedq 15d agoSSN should be 1MM+. It is a password to your national identity that can be used to steal your identity and effectively cannot be revoked once leaked. It is a permanent grievous injury to someone to leak it.
- someguynamedq 15d agoThe irony is that corporations get a higher discount the more people they affect. Damaging 10,000,000 people should cost you more than 10,000,000 times the cost of damaging one, not less. It should be ruinous to cause damage at this scale.
- hn_submit 15d agoThis is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets. Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
- tstenner 13d agoThis is exactly what the GDPR does (except it's 4%, not 10%).
- guillybarres 15d agoWill they uphold this law when DPRK threat actors use it as a form of economic sabotage?
- _the_inflator 15d agoAnd what about the governments like Berlin for example? Massive data breach, and guess what happens? Nothing to those who are responsible for the breach. So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass. If the Berlin incident remotely had happened to any private company - hell would have been loose. Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.
- markhahn 15d agoThis is wonderful, though a little low. Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.
- pstoll 15d agoAbout f’ing time a government made this have real consequences.