Live data from Hacker News

The privacy wars are about to get a whole lot worse

locusmag.com

111–120 of 170 posts

Re: The privacy wars are about to get a whole lot worse

#111
post #100

Earlier quoted context omitted.

I mostly agree, though I think that California's massive amount of readily available tech venture capital, as compared to anywhere else on Earth, is a far more important factor in its abundance of startups, rather than its obscure law banning non-compete agreements.

The law isn't obscure at all, it's a fundamental part of employment law that separates California from many other states. And saying it's due to tech VC is saying there's a lot of tech success due to the overabundance of tech success. People who work at a company can quit and start a startup, even in the same industry, carrying with them their hard-won expertise. Without a legal cloud over their heads which will scar…

"Obscure" does not mean "unimportant." It means few people know about it. I've lived in San Francisco and worked in the tech industry here for 10 years, during which time I've discussed this exact law with numerous people in many different roles. I can count on one hand the number of people who had heard of it before I told them.

Since almost nobody (here or elsewhere) knows that this law even exists, it's reasonable to conclude that it is not a significant factor in the development of the local tech industry.

Moreover, all of the large tech concerns whose profits fund those VC firms would be much better off without this law and are openly against it. See, for example, the anti-employee poaching ring that Steve Jobs set up.

Re: The privacy wars are about to get a whole lot worse

#112
post #7

I like Cory Doctorow. I really do, and I agree that this is a problem. But as I argue, the genie is already out of the bottle, the cat is out of the bag and the barn door is open. What we should focus on instead is mechanisms for mitigating and punishing malicious use of data, AS WELL AS putting the surveillance to good use, eg body cameras for on-duty police officers: http://magarshak.com/blog/?p=169

With parallel construction and such, it might be hard to punish malicious use...

Punish parallel construction, perhaps?

Re: The privacy wars are about to get a whole lot worse

#113

Earlier quoted context omitted.

"They're portraying the negligent company as the victim!" While I agree that things like sql injection are negligent, there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Saying "dont hire bad people" is easy, but how do you do that? And the standard for best practices is constantly moving in our industry, how do we decide when it is negligence, and when there was no…

Do you regularly hire contractors and then never look over the work they do? Because I don't, and frankly, that's kind of idiotic. The data is your responsibility, not theirs. They also have no interest in the longevity of your company, why would you trust them without checking what they are doing? As a customer, I don't care how Home-Depot handed out my CC info, I care that they did. Sure some hacks happened despite…

"Do you regularly hire contractors and then never look over the work they do?"

I dont when it comes to software. For say legal services, I dont have many options, as I am not an expert. The point I was trying to make is that sometimes people hire contractors because they dont have the expertise. How are they supposed to review something they dont understand? Saying every organization should have top notch IT on staff so this doesnt happen is hand-waving as well.

Re: The privacy wars are about to get a whole lot worse

#114
post #108

Earlier quoted context omitted.

"They're portraying the negligent company as the victim!" While I agree that things like sql injection are negligent, there were also credit card hacks/leaks(and an nsa leak) that were the result of malicious contractors. Saying "dont hire bad people" is easy, but how do you do that? And the standard for best practices is constantly moving in our industry, how do we decide when it is negligence, and when there was no…

I think I'm with Cory on this. It's negligence if you leak it. Period. Nobody is obligated to hoard and store a bunch of sensitive personal data from their customers.

In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.

Re: The privacy wars are about to get a whole lot worse

#115

Earlier quoted context omitted.

Do you regularly hire contractors and then never look over the work they do? Because I don't, and frankly, that's kind of idiotic. The data is your responsibility, not theirs. They also have no interest in the longevity of your company, why would you trust them without checking what they are doing? As a customer, I don't care how Home-Depot handed out my CC info, I care that they did. Sure some hacks happened despite…

"Do you regularly hire contractors and then never look over the work they do?" I dont when it comes to software. For say legal services, I dont have many options, as I am not an expert. The point I was trying to make is that sometimes people hire contractors because they dont have the expertise. How are they supposed to review something they dont understand? Saying every organization should have top notch IT on staff…

There's a famous saying along the lines of "If you are rich, hire two accountants. One to keep track of your books, and another to keep track of the first guy"

If you provide sensitive information to anyone that you don't have legal recourse against, then I don't really have any sympathy for you. If you make a bad business decision and it leaks my info, I'm not upset because someone took it without your approval, I'm upset because it was leaked.

There's a cost/benefit risk to everything. If you want to take the route of working with contractors, you have to weight the risks for that as well.

Re: The privacy wars are about to get a whole lot worse

#116
post #108

Earlier quoted context omitted.

I think I'm with Cory on this. It's negligence if you leak it. Period. Nobody is obligated to hoard and store a bunch of sensitive personal data from their customers.

In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.

Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable.

I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems (from pull to push, whether with bitcoin or some other system) can be widely implemented.

Re: The privacy wars are about to get a whole lot worse

#117

Earlier quoted context omitted.

"Do you regularly hire contractors and then never look over the work they do?" I dont when it comes to software. For say legal services, I dont have many options, as I am not an expert. The point I was trying to make is that sometimes people hire contractors because they dont have the expertise. How are they supposed to review something they dont understand? Saying every organization should have top notch IT on staff…

There's a famous saying along the lines of "If you are rich, hire two accountants. One to keep track of your books, and another to keep track of the first guy" If you provide sensitive information to anyone that you don't have legal recourse against, then I don't really have any sympathy for you. If you make a bad business decision and it leaks my info, I'm not upset because someone took it without your approval, I'm…

"If you are rich, hire two accountants. One to keep track of your books, and another to keep track of the first guy"

Brilliant, I hadnt heard of/thought of that.

"There's a cost/benefit risk to everything. If you want to take the route of working with contractors, you have to weight the risks for that as well."

True, I would just like to point out that hiring your own staff might no work out either...

Re: The privacy wars are about to get a whole lot worse

#118

Earlier quoted context omitted.

> Companies can still track me, my data's still out there. I don' think this is right. When you were being a "luddite" you probably had less data collected about you, but you couldn't see that. All you can see is the cool tech stuff you are missing out on, so you feel that keenly. I think the reason a lot of people give up their privacy is that they feel like they have lost it already, so they might as well "Get what…

No way. The largest threats to your privacy by several orders of magnitude over the stuff we complain about: - Electric, gas, sewer, water, trash utilities that you basically can't live without. - Thinking of going rustic? Better not own the land in your own name. Most places, parcels are easy to find online. - Property management companies - Sites that facilitate rental applications - Your 100+ year old bank - Credi…

This? http://www.computerworld.com/article/2868475/verizon-unveils...

It's the only thing I can think of. I sure as hell wouldn't be a part of it though.

Re: The privacy wars are about to get a whole lot worse

#119
post #116

Earlier quoted context omitted.

In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.

Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable. I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems…

"I think in this case the credit card companies should be liable."

Maybe? I didnt see anything about home depot suing the contractors? Really, they should be held financially and criminally liable.(if they werent)

The public ledger part of bitcoin is great also. You can see where the stolen money went. Maybe if they added a way to flag money, so spending stolen bitcoin would trigger an alert at the merchant, the same way canceled credit cards do now.

Re: The privacy wars are about to get a whole lot worse

#120
post #116

Earlier quoted context omitted.

Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable. I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems…

"I think in this case the credit card companies should be liable." Maybe? I didnt see anything about home depot suing the contractors? Really, they should be held financially and criminally liable.(if they werent) The public ledger part of bitcoin is great also. You can see where the stolen money went. Maybe if they added a way to flag money, so spending stolen bitcoin would trigger an alert at the merchant, the same…

re: the contractors being liable, currently the way things work is, when my credit card is used fraudulently the credit card company owns that and pays me back, which is the least they could do. I don't even know if they attempt to work with law enforcement to catch the actual fraudsters, but I sure hope they do. Maybe I should be more proactive about that? I don't know.

EDIT: I should point out I don't know any details about the Home Depot "hack" and I might not be addressing all the pertinent points of that particular incident. Bottom line is still the same, it shouldn't be the customers who suffer when this happens. The people that made it so easy for my personal information to leak, the ones who necessitated that my personal information even be required as part of the transaction, should be the ones feeling the pain.

Post reply on HN