Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

59% Positive

Analyzed from 1550 words in the discussion.

Trending Topics

#data#business#care#system#companies#fines#security#company#don#breaches

Discussion (68 Comments)Read Original on HackerNews

hn_submit4 minutes ago
This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets.

Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.

augment_meabout 2 hours ago
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

Minimizes money usage and does not require any security investments

louthyabout 2 hours ago
Or … and hear me out on this one … care?
m132about 1 hour ago
Some hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.
SoftTalker17 minutes ago
Followed by deleting data once you've used it for its stated purpose.

Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.

AIiscomingabout 2 hours ago
Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it.

I might suggest a construct like this too.

What do you think how much it cost to do it perfect?

louthyabout 2 hours ago
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.

It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).

plucabout 2 hours ago
Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.
ortusdux34 minutes ago
That's more expensive.
augment_meabout 2 hours ago
Sounds like something that costs money, if a university doesn't care I don't think most companies will.
louthyabout 2 hours ago
Yes, being competent requires effort.

It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.

So, there is that.

zelphirkaltabout 1 hour ago
A university which doesn't care to protect its students, deserves to get its whatever-license/accredited status checked/audited.
toomuchtodoabout 2 hours ago
Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.

To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.

(cyber consultant and practitioner)

my-huge-ponyabout 2 hours ago
Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?

I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.

x3n0ph3n3about 2 hours ago
That's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.
ameliusabout 2 hours ago
That's like blaming Seagate when your harddisk fails.

No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

augment_meabout 2 hours ago
Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.

Seagate will not in a million years sign anything like this when you buy a HDD.

louthyabout 1 hour ago
That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too.
xboxnolifesabout 1 hour ago
You can't just absolve yourself of responsibility by saying "I hired a contractor". You are still responsible for doing your due diligence in picking your contractor.
SoftTalkerabout 2 hours ago
It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
dmos62about 2 hours ago
That's legal?
miohtama5 minutes ago
It’s Hollywood accounting
EA-3167about 2 hours ago
Sure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?"

Sort of like EULA's a lot of the "value" is incredibly theoretical.

micromacrofootabout 2 hours ago
similarly, most AI datacenters aren't directly owned by the frontier labs

guess who holds the bag if capacity needs collapse

ranger_dangerabout 2 hours ago
imnotr0b0tabout 2 hours ago
That sounds risky
bdangubic44 minutes ago
Anyone that hires such a company deserves the treatment you are proposing
prologicabout 2 hours ago
Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
SoftTalkerabout 2 hours ago
"through intent or gross negligence"

I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.

bluGillabout 2 hours ago
The hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place.

(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)

roundup32 minutes ago
Assuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company.
xp8428 minutes ago
I'm assuming the intent is to protect customers.

Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.

I'm thinking:

(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)

- Name and address or name and phone number leak: $100 per customer affected.

- Email: $50 per customer affected, or $100 if tied to any other data.

- Social Security numbers: $2000 per customer affected

- Unsalted or plaintext passwords: $500 per customer affected.

- Cap is the greater of 200% of annual EBITDA, or 20% of revenue

Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.

This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.

My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.

aucisson_masque17 minutes ago
GDPR in Europe puts it at 4%, and yet we are seeing leaks every week.

10% maximum mean nothing if it’s not enforced, you got to make examples.

__natty__about 1 hour ago
Huge fines but reasonable. Especially now with all the people doing blind vibe coding
ggarnhartabout 2 hours ago
This feels like a really odd way to incentivize data breaches and/or not reporting data breaches.
Retro_Devabout 2 hours ago
Um, I think it does the opposite of what you are suggesting - this aims to reduce data breaches and incentivize people to prevent these breaches.
jmclnxabout 2 hours ago
Sounds great if all the following is true.

* Before Tax Revenue

* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.

* Includes Worldwide Revenue

* Includes companies based in all other Countries.

I would have went for 20%, but if he above applies I wish the US would do the same.

zelphirkalt28 minutes ago
The US is probably among the countries, where the lobbying against such a law or policy would be very severe, because multiple of their tech giants are built on the foundation of abusing people and considering fines to be cost of business.
quickthrowmanabout 2 hours ago
I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
Retro_Devabout 2 hours ago
> there’s no such thing as a secure computer system

Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.

Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.

aucisson_masque12 minutes ago
> Where is your source for this? It is entirely possible to make a secure computer system

You can’t. You don’t need source for that, just common sense.

Exploits are discovered every day, bugs happen, bad actors.

You can do the best system, shit still happen.

BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?

If the cia couldn’t prevent it, I bet you can’t.

buellerbuellerabout 2 hours ago
Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.
google234123about 2 hours ago
You legally have to hold transactions for years yk as a business
josephg30 minutes ago
Then secure your database? This stuff isn’t rocket science. You don’t even have to hold historical transactions online. It’s quite difficult for hackers to access a hard drive sitting in a drawer.
google234123about 2 hours ago
Probably a law targeted at foreign companies
Retro_Devabout 2 hours ago
I especially hope this holds true, because I don't want my information being leaked by anyone.
Advertisement
rectangabout 2 hours ago
It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.
esafakabout 2 hours ago
The EU AI Act already levies 7% global annual turnover penalties for prohibited AI practices.
happytoexplainabout 2 hours ago
Higher.
nosmokewhereiamabout 1 hour ago
Imagine 10% of Samsung!

Edit: "That'll be $23B. Cash or card?"