HI version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
64% Positive
Analyzed from 2259 words in the discussion.
Trending Topics
#data#information#security#insurance#don#company#breach#https#liability#should

Discussion (67 Comments)Read Original on HackerNews
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
https://en.wikipedia.org/wiki/Carrie_Tolstedt
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.
And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.
I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.
What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
What amount per person is acceptable for a thing that simply should never happen?
I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).
We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
If they deleted the IDs within a week of getting them surely the leak would be much smaller.
I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
Who do you think employs the top-level criminals?
That's overhead that businesses really hate paying as it's diverts software devs away from making new features.
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
Ironically in case of breach they just sell you another of their product where you put your personal information again
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.
[0] https://www.youtube.com/watch?v=CS9ptA3Ya9E
With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
My ex had access to Lexis Nexis and I was always shocked how much information about people they have.