4 ms·
What's wrong with the idea of having limits on data collection and regulations around their storage? You can't prosecute someone for being the victim of hackers
by dreamfactory2 11y ago
What's wrong with the idea of having limits on data collection and regulations around their storage? You can't prosecute someone for being the victim of hackers but you can (and should) for not applying reasonable efforts in safeguarding data or storing more than they should.
- superuser2 11y agoThere is always someone on HN who thinks whatever data you're collecting is too much, and plenty of hacks were the result of pretty sophisticated 0days in underlying systems despite reasonable precautions being taken in administration processes. There is already negligence on the books.
- dreamfactory2 11y ago'Too much' isn't just some random person's opinion where it's all relative. There are already plenty of examples of data regulation in governmental and commercial contexts - from PII of minors, to PCI, to data residency, to what companies are allowed to do in regions like Europe, Russia, and Asia. All these hacks we are seeing of both public and private data are proving increasingly damaging as more data is being collected and aggregated (whilst as you point out, impossible to fully protect against). This very clearly indicates an urgent need for far greater regulation of what is allowed both in transit and at rest, as well as suitable penalties for negligence. This should be a politically non-partisan issue as it's so wide ranging, covering national security (e.g. Snowden, OPM) as well as comedy gold in the commercial sector like Ashley Madison and more serious cases like Target.
- superuser2 11y agoData regulation has to do with things like retention length, reasonable precautions, the right to have your data deleted, the right to see what they have on file about you, requirement that data be anonymized under certain contexts, etc. There is not a clear bright line about what data is "too much" for your application - that's a judgement call, and a nightmarishly vague and technical concept for a jury to decide.
- dreamfactory2 11y agoIt also has to do with what kind of data is allowed in transit and at rest as per the examples I gave which are all around legal and commercial regulatory compliance. It has never been a free-for-all where operators use their personal judgement. In several territories you need to be registered with the government to collect certain kinds of data for a start. But now we are at the point where there is sufficient data being collected and aggregated (by both public and private orgs) that hacks can damage economic infrastructure and harm wider society i.e. not limited to those who have interacted with a particular entity. This means that light touch regulation is completely untenable (quite apart from the general naivety of looking to the market to solve problems it could not even theoretically be solved in the marketplace when your infrastructure itself is toast).
- coldcode 11y agoIn this case apparently they failed to even encrypt the data. If you open your garage door and leave all your house doors wide open and get robbed I don't think your insurance company will pay you anything.