4 ms·
Or … and hear me out on this one … care?
by louthy 13d ago
Or … and hear me out on this one … care?
- augment_me 13d agoSounds like something that costs money, if a university doesn't care I don't think most companies will.
- louthy 13d agoYes, being competent requires effort. It certainly feels much better being an proactive member of society rather than a self-serving arsehole though. So, there is that.
- nostrademons 13d agoIt feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling. Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
- louthy 13d ago> It feels better only as long as everybody else cares too. Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional. I did it because: * it’s the right thing to do * for professional pride * and so I could sleep at night And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection, by the industry as a whole, made it seem like a breach would be survivable, but luckily we never tested that theory. I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks. [1] https://www.meddbase.com/ https://www.meddbase.com/
- rpdillon 13d agoPeople don't think caring about your customers leads to failure, but it's a lot harder than not caring, and it does seem to be the case that it is mandatory to not care if you're going to be chasing massive valuations. We're moving from a high trust society to a low trust society, I fear. It's a tough transition.
- louthy 13d agoI realise I’m a sample size of 1, but for me caring was good for business: caring means you can empathise, if you can empathise you can understand, if you can understand you can build a better product.
- rpdillon 13d agoWe're having two different conversations. You're advocating for good citizenship, which is great. I try to do that, too. But I also know that's not scaleable, and folks are lazy.
- zelphirkalt 13d agoA university which doesn't care to protect its students, deserves to get its whatever-license/accredited status checked/audited.
- pluc 13d agoEvery single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
- toomuchtodo 13d agoCaring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky. To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context. (cyber consultant and practitioner)
- x3n0ph3n3 13d agoThat's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.
- toomuchtodo 13d agoYou can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s). I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives. TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
- bluGill 13d agoThere is a lot more than regulations. Reputation is important as well. While you can give up a reputation fairly quickly, it is very hard to get/keep. Many companies are well aware of the value of their reputation - they call it the value of the brand.
- my-huge-pony 13d ago
- AIiscoming 13d agoLets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it. I might suggest a construct like this too. What do you think how much it cost to do it perfect?
- louthy 13d agoPerfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net. It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
- augment_me 13d agoAgain this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional". There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.
- louthy 13d ago4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data. One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.
- augment_me 13d agoSo we get to a very easy formula for companies to do in the EU and UK: If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) { Roll your own security solution } Else { Outsource to 3rd party }
- m132 13d agoSome hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.
- SoftTalker 13d agoFollowed by deleting data once you've used it for its stated purpose. Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
- gregglain 13d agoNot collect data? Heresy!
- fn-mote 13d agoIn the abstract, yes. In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.
- markhahn 13d agothat's the odd thing: we simply don't ask whether there's an alternative. for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
- rTX5CMRXIfFG 13d agoFunny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.
- ortusdux 13d agoThat's more expensive.
- carefree-bob 13d agoProblem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this. They can try: * various education campaigns * force users/customers to adopt passkeys or other phishing resistant mfa * add various alarms and alerts for unusual activity, resulting in lockout The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
- novok 13d agoHow much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard? Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.
- asp_hornet 13d ago> to have leaked the personal data of 10 million or more people through intent or gross negligence But to your point, the article doesn’t define what that means.
- someguynamedq 13d agoWoosh
- louthy 12d agoPlease take a look at the posting guidelines [1] and consider using more respectful and constructive responses. [1] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html