6 ms·
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we sw
by augment_me 15d ago
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.
Minimizes money usage and does not require any security investments
- louthy 15d agoOr … and hear me out on this one … care?
- augment_me 15d agoSounds like something that costs money, if a university doesn't care I don't think most companies will.
- louthy 15d agoYes, being competent requires effort. It certainly feels much better being an proactive member of society rather than a self-serving arsehole though. So, there is that.
- nostrademons 15d agoIt feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling. Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
- louthy 15d ago> It feels better only as long as everybody else cares too. Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional. I did it because: * it’s the right thing to do * for professional pride * and so I could sleep at night And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory. I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks. [1] https://www.meddbase.com/ https://www.meddbase.com/
- rpdillon 14d agoPeople don't think caring about your customers leads to failure, but it's a lot harder than not caring, and it does seem to be the case that it is mandatory to not care if you're going to be chasing massive valuations. We're moving from a high trust society to a low trust society, I fear. It's a tough transition.
- louthy 14d agoI realise I’m a sample size of 1, but for me caring was good for business: caring means you can empathise, if you can empathise you can understand, if you can understand you can build a better product.
- rpdillon 14d agoWe're having two different conversations. You're advocating for good citizenship, which is great. I try to do that, too. But I also know that's not scaleable, and folks are lazy.
- zelphirkalt 15d agoA university which doesn't care to protect its students, deserves to get its whatever-license/accredited status checked/audited.
- pluc 15d agoEvery single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
- toomuchtodo 15d agoCaring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky. To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context. (cyber consultant and practitioner)
- x3n0ph3n3 15d agoThat's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.
- toomuchtodo 15d agoYou can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s). I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives. TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
- bluGill 15d agoThere is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand.
- my-huge-pony 15d ago
- AIiscoming 15d agoLets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it. I might suggest a construct like this too. What do you think how much it cost to do it perfect?
- louthy 15d agoPerfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net. It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
- augment_me 15d agoAgain this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional". There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
- louthy 15d ago4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data. One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
- augment_me 15d agoSo we get to a very easy formula for companies to do in the EU and UK: If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) { Roll your own security solution } Else { Outsource to 3rd party }
- m132 15d agoSome hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.
- SoftTalker 14d agoFollowed by deleting data once you've used it for its stated purpose. Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
- gregglain 14d agoNot collect data? Heresy!
- fn-mote 14d agoIn the abstract, yes. In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.
- markhahn 14d agothat's the odd thing: we simply don't ask whether there's an alternative. for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
- rTX5CMRXIfFG 14d agoFunny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.
- ortusdux 14d agoThat's more expensive.
- carefree-bob 14d agoProblem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this. They can try: * various education campaigns * force users/customers to adopt passkeys or other phishing resistant mfa * add various alarms and alerts for unusual activity, resulting in lockout The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
- novok 14d agoHow much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard? Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.
- asp_hornet 14d ago> to have leaked the personal data of 10 million or more people through intent or gross negligence But to your point, the article doesn’t define what that means.
- someguynamedq 14d agoWoosh
- louthy 13d agoPlease take a look at the posting guidelines [1] and consider using more respectful and constructive responses. [1] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- ranger_danger 15d agoPerhaps they should read https://en.wikipedia.org/wiki/Piercing_the_corporate_veil https://en.wikipedia.org/wiki/Piercing_the_corporate_veil
- makeitdouble 14d agoParent isn't talking about shareholders or ownership, but full delegation of a process to a contracting company. Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.
- dmos62 15d agoThat's legal?
- micromacrofoot 15d agosimilarly, most AI datacenters aren't directly owned by the frontier labs guess who holds the bag if capacity needs collapse
- EA-3167 15d agoSure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?" Sort of like EULA's a lot of the "value" is incredibly theoretical.
- miohtama 14d agoIt’s Hollywood accounting
- m463 14d ago[dead]
- amelius 15d agoThat's like blaming Seagate when your harddisk fails. No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
- augment_me 15d agoNot really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point. Seagate will not in a million years sign anything like this when you buy a HDD.
- SoftTalker 15d agoIt's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
- louthy 15d agoThat’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too.
- augment_me 15d agoMaybe it's different in the US, but in the EU you can get certified to be able to handle certain data securely, for example getting SOC/ISO/ESC certifications. When you then are looking for storage solutions you can in practice absolve yourself from liability/gross negligence if you choose a provider that has these certifications. So when an org needs cheap solutions, they find the cheapest compliant provider and hands are clean.
- 15d ago
- imnotr0b0t 15d agoThat sounds risky
- bdangubic 15d agoAnyone that hires such a company deserves the treatment you are proposing
- killingtime74 14d agoThere are specific laws called Piercing the Veil that can easily be passed to close this type of loophole. Courts are run by people, not AI, so judges can easily ignore the corporate entity once these laws are passed.
- rat9988 14d agoDoesn't seem out of reach of AI. Not sure why you think so.
- laughing_man 14d agoPiercing the corporate veil is difficult to do in practice unless they've gotten very sloppy.
- killingtime74 14d agoIf they see people doing exactly what was described to avoid fines I think they will amend the law to explicitly allow piercing the veil. Just like for directors
- dubeye 14d agoSounds good in theory, what's the practical reality in your experience?
- killingtime74 13d agohttps://www.holdingredlich.com/federal-court-decision-pierces-the-corporate-veil-for-breach-of-director-duties https://www.holdingredlich.com/federal-court-decision-pierce... This is an example (I have nothing to do with this case)
- Barrin92 14d ago>You can just do what my university did, hire a small shell firm with 3 employees to hold all your data except you can't in South Korea because PIPA (their data privacy/compliance framework) is as strict if not stricter than GDPR and comes with criminal liability in case you violate consent rules, so you can't just send other people's data to some third party shell company either why do people always make these completely generic comments as if they've just on the toilet figured out the one simple trick every data framework covered over a decade ago