3 ms·
I've now received "your personal information has been breached, here's some free credit monitoring" letters three times. Once from a major health insurer, once
by GabrielF00 12y ago
I've now received "your personal information has been breached, here's some free credit monitoring" letters three times. Once from a major health insurer, once from a major retailer, and once from a large regional hospital. I've also been a member of several large websites that have had their systems breached. Given the sheer number of breaches, and the variety of organizations that have been breached, I suspect that most Americans have had their information compromised by hackers at least once.
We're also regularly seeing breaches of major companies for the purposes of economic espionage, and disruption of service as a political or economic tactic. We regularly hear about breaches of government systems, including sensitive systems.
Given that very sophisticated companies and government agencies are regularly suffering from breaches, I think we have to conclude that we are really struggling to build systems that provide adequate protection for our personal data.
All of the comments in this thread have addressed the risks of government overreach, but none of them have looked at the costs of these breaches. At what point do we conclude that our technological tools are inadequate, and we also need additional legal tools to deter potential hackers who are overseas and out of reach of the US legal system?
- c22 12y agoSomewhat agreed, but couldn't our legal tools instead/also be focused on the organizations that take responsibility for storing our data? Fines for allowing user data to be breached may stimulate development of tools and methodologies better able to protect private data and rules that limit sharing of user data can protect us from even the well-financed malevolent actors. Focusing on this side of the coin may allow us to realize systems that actually do protect our data from being compromised as opposed to spending our resources tracking down individuals and attempting to apply legal tools which the most successful criminals will soon adapt to evade anyway.
- GabrielF00 12y agoI think the problem with this thinking is that even without explicit fines, the costs of a data breach are already incredibly high for companies. There's the potential loss of sales for a customer-facing business, as well as costs of class action lawsuits, system cleanup, etc. Sony Pictures was crippled by a cyberattack. Target's CEO was forced to resign. So, maybe fines would make this situation better, but CEO's should already be up at night worrying about cybersecurity. My inclination would be to pursue better security, but also to go after the really sophisticated cybercriminals that are currently outside the reach of our legal system.