Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

64% Positive

Analyzed from 2259 words in the discussion.

Trending Topics

#data#information#security#insurance#don#company#breach#https#liability#should

Discussion (67 Comments)Read Original on HackerNews

O3marchnativeless than a minute ago
I'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised up to and including their fingerprints.

[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

jsroznerabout 1 hour ago
There's a solution: personal liability for the executives and managers at the company, and for the investors.

For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)

rectang27 minutes ago
Fines exceeding 100% of lifetime compensation might actually do something. As it stands, clawbacks are ineffective — for example, Carrie Tolstedt of the Wells Fargo scandal wound up money ahead to the tune of tens of millions of dollars:

https://en.wikipedia.org/wiki/Carrie_Tolstedt

> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.

jm4about 1 hour ago
This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
tocs325 minutes ago
Holding actual people liable sounds like a more effective option. The insurance would just be included into the cost of doing business and make everything more expensive. Insurance makes everything worse.

Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.

jm41 minute ago
Are we talking hypothetical utopia or something that could actually happen? Insurance probably isn’t the most perfect solution but it’s the most feasible. These exact policies and insurers already exist.

And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.

I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.

AngryData16 minutes ago
Could we not keep the same "harsh" plan, and then let others provide and purchase such insurance on their own? Why does the insurance have to be mandated?
dylan604about 1 hour ago
Who receives the payouts of those insurance benefits and how would one go about making a claim?
jm4about 1 hour ago
The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.

What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.

atoav34 minutes ago
This is data that will be relevant for every single victim for decades to come and they will pay for this regularly, and it cannot be undone.

What amount per person is acceptable for a thing that simply should never happen?

I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).

We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.

bix634 minutes ago
This is so unrealistic but I do agree personal liability should come into play more for people who knowingly act inappropriately.
rectang20 minutes ago
It's perfectly reasonable, and if something perfectly reasonable is "unrealistic", then the system is corrupt.
nicceabout 1 hour ago
Including investors is a bit much unless they encouraged or mandated some decisons that enabled this.
vjvjvjvjghv26 minutes ago
Investors benefit from company gains despite not having encouraged or mandated some decisions that enabled the gains. So it makes sense that they also get exposure to the downside.
xienze15 minutes ago
> personal liability for the executives and managers at the company

How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.

Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.

triceratops5 minutes ago
Does IDScan need to store the IDs after they've verified them?

If they deleted the IDs within a week of getting them surely the leak would be much smaller.

mahboiabout 1 hour ago
It's cleaner to hold some of a corp's money in escrow if they're handling IDs, to ensure they can't avoid fines via bankruptcy.
rectang33 minutes ago
Fines on the scale that it might be reasonable to reserve escrow funds for are just "cost of doing business" fines.
jm4about 1 hour ago
Companies typically have insurance policies to cover this kind of stuff.
schainksabout 1 hour ago
This.
mccauleyabout 1 hour ago
100%
dyauspitr42 minutes ago
Great way to incentivize everyone to do nothing. Most middle managers don’t know shit.
0xmattf35 minutes ago
Is there any way to check if your ID was compromised without going on some onion site?

I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.

I think IDScan should set something up so we can check if our data was compromised, at the least.

abirch27 minutes ago
What I would love to know is who is selling my info. I get texts from all kinds of politicians but I didn't know who sold them my number. Seems like selling someone's property without their approval should be illegal. It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)
curuinorabout 3 hours ago
Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.
UltraSane29 minutes ago
Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.
FLeXMurphy5 minutes ago
> You don't hear about bank mainframes getting hacked often.

Who do you think employs the top-level criminals?

pyrale1 minute ago
Sure, but not in the IT service.
cogman106 minutes ago
It makes systems harder to work with and new features slower to deploy and it requires you to make sure you stay on top of CVEs.

That's overhead that businesses really hate paying as it's diverts software devs away from making new features.

drdaemanabout 2 hours ago
Human security. Computers are fine, they usually do exactly as they’re programmed.
curuinorabout 1 hour ago
We don't care about the computers, humans are what society is for
iAMkenoughabout 1 hour ago
getting the idea lately that society hates humans
er4hnabout 2 hours ago
Will anything be different _this time around_?

https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.

selectodude15 minutes ago
Elon fucking Musk has literally every single piece of personal information of every person in the country. It’s so far past too late for any of this to matter.

I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.

flerchinabout 1 hour ago
Equifax's stock price went up when they were hacked.
jmclnxabout 1 hour ago
Joking right :)
robinsoncrusue9 minutes ago
American national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
sandeepkdabout 2 hours ago
Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security.

Ironically in case of breach they just sell you another of their product where you put your personal information again

FireBeyondabout 1 hour ago
The CRAs compete for breach business, because it's absolutely a profitable enterprise for them:

How many people actually sign up for your "free credit monitoring for a year" following a breach?

When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".

There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.

This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.

Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".

I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".

sidewndr46about 1 hour ago
Was ran through the same gauntlet by a medical provider billing me for services. Insurance wouldn't pay them due to "insufficient documentation". Wouldn't disclose what documentation they had received or what documentation they needed. Just that is was inadequate. Service provider wouldn't tell me what they had sent.

Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.

Terr_about 1 hour ago
> the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen.

You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.

[0] https://www.youtube.com/watch?v=CS9ptA3Ya9E

shireboyabout 2 hours ago
When this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be.
iugtmkbdfil834about 2 hours ago
And then, in real life, one discovers that institutions route around in creative ways for all sorts of different reasons ( recently had to 2fa a transaction at a god damn teller window; you just took my DL ).
AnimalMuppetabout 1 hour ago
Isn't the DL (which has a picture) and your face the two factors? Isn't that the whole point of having a picture on a DL?
Terr_about 1 hour ago
> IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN”

With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.

AngryData14 minutes ago
To be fair many SS cards were printed stating right on them they aren't for ID usage.
mahboiabout 1 hour ago
Passports seem a lot better. You scan it with NFC, and the chip inside proves authenticity via asymmetric crypto.
exabrialabout 3 hours ago
I really want these people handling my healthcare and other details about my life.
max__devabout 2 hours ago
Private healthcare is much worse, seemingly they have an open access policy. New breaches occur in the order of millions per week. Not remotely newsworthy anymore. (last time this was mainstream worthy was 200M leaked records in 2024). Last week https://www.securityweek.com/4-1-million-impacted-by-adapthe... Week before that https://www.yahoo.com/news/us/articles/more-9-5-million-pati... 2 weeks before that: https://www.msn.com/en-us/health/general/carecloud-confirms-...
Libcat99about 2 hours ago
And it will remain this was as long as the consequences of not protecting our data remain trivial.
paimapiabout 2 hours ago
if only we prosecuted corporations as people instead of just giving them the civil liberties of one
dlcarrierabout 1 hour ago
In my experience, any industry following a security standard halts all effort at security once they're compliant with the standard. HIPAA sets a minimum but seems to also guarantee you will get exactly that minimum and nothing better.
sidewndr46about 1 hour ago
The only thing HIPAA guarantees is that when your data is handed out, there was a policy around it.
triceratops2 minutes ago
You want an ID verification company handling healthcare? Even if you're a staunch believer in free enterprise this seems like a capability mismatch.
valleyerabout 2 hours ago
Which people? This leak was caused completely by private businesses.
protimewaster21 minutes ago
I'm confused about the read on this too. It reads like a "I don't want the government involved in my healthcare" type of statement, but it's posted in the discussion section of an article about private companies mishandling data.
charcircuitabout 1 hour ago
Hundreds of millions of American's names, addresses, social security numbers, etc were in the NPD leak which has been publicly downloadable. The idea that any of this information should be considered private, only knowable by the person themself is wrong.
anxmanabout 2 hours ago
Glad to see someone talking about this
Advertisement
nullcabout 1 hour ago
The breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis. Practically all states sell DL and registration information to information brokers, and the remaining ones require you to obtain auto insurance, and the insurers all sell the information.

Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.

(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)

In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.

vjvjvjvjghv24 minutes ago
"but this information was already readily available to bad actors e.g. via Lexis Nexis."

My ex had access to Lexis Nexis and I was always shocked how much information about people they have.

maxrev17about 2 hours ago
Slackers are always behind this shit