Live data from Hacker News

The privacy wars are about to get a whole lot worse

locusmag.com

141–150 of 170 posts

Re: The privacy wars are about to get a whole lot worse

#141

Earlier quoted context omitted.

> How do we decide when it is negligence, and when there was nothing that could be done? This isn't an insoluble issue: courts deal with similar decisions in car crashes, medical malpractice, and many other scenarios. A plaintiff could argue that the respondent should have been aware of certain vulnerabilities because they were widely disseminated, or that certain practices are explicitly warned against in common tra…

Very true, but courts arent known for being up to date with tech.

Courts aren't up to date on medicine either, but they manage to preside over malpractice cases somehow. I'm sure if technical malpractice graced their courtrooms regularly they would manage somehow. Probably by relying on expert witnesses and learn the bits and pieces of jargon they need to know.

Re: The privacy wars are about to get a whole lot worse

#142

Earlier quoted context omitted.

Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.

The reality is that today nobody is responsible for data security. Developers foist the risk onto consumers, who don't have any real choice in the matter, and don't even know what the real risk profile is that they (we) are agreeing to. If you accept that somebody, somewhere needs to be held responsible for data breaches, the most sensible party is us. We have all the domain knowledge and we're the only ones who can…

So -- national building codes for software? Government instpectors who audit code? Building permits required to even write code, or modify existing code?

Doesn't seem to line up very well with "Move fast and break things"

Re: The privacy wars are about to get a whole lot worse

#143
post #21

Why doesn't Firefox ship with third-party cookies disabled? What would it break that isn't user-hostile? ( edit Chrome, IE, Safari, I understand, but privacy is one of Firefox's main differentiators.)

> What would it break that isn't user-hostile?

The Facebook "Like" button for starters.

Is that user-hostile? Is that important?

It's in the eye of the beholder, but if Firefox "doesn't work" for a large tranche of non-technical users, that's a big problem.

It's also not clear how much it would achieve. It's not that difficult to turn a 3rd party cookie into a 1st party one.

Re: The privacy wars are about to get a whole lot worse

#144

Earlier quoted context omitted.

> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…

How do architects get away with vague details when lives can be on the line? If they design the building correctly, they should be pushing to make things as explicit as possible so that when contractors make a mistake it is clear where the fault is. It seems unprofessional that they'd be pushing in the other direction.

For context, the majority of lawsuits in construction involve defects that are far from life threatening. Waterproofing, insulation, or, say, windows not working quite right are more common. There could be millions of dollars at stake because a defective building is worth less as an asset, but there are rarely lives on the line.

I don't think many architects would be comfortable taking risks with critical structural details. Also, even if a firm isn't found technically liable for a deadly building failure it can still be very bad for business.

That said I'm sure some architects still put people's lives at risk to avoid liability. I suspect it's similar any other industry where, sometimes, collectively people in a company put the public at risk for the sake of financial gain - pharmaceutical companies, manufacturers, mining companies, etc. No individual feels personally responsible.

Re: The privacy wars are about to get a whole lot worse

#145

Earlier quoted context omitted.

> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…

Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.

It certainly would a huge change. I'm not suggesting it should happen, just imagining that it _could_.

There are pros and cons to it. It might lead to higher salaries for engineers - liability bringing licensing requirements which could restrict supply.

Re: The privacy wars are about to get a whole lot worse

#146

Earlier quoted context omitted.

The reality is that today nobody is responsible for data security. Developers foist the risk onto consumers, who don't have any real choice in the matter, and don't even know what the real risk profile is that they (we) are agreeing to. If you accept that somebody, somewhere needs to be held responsible for data breaches, the most sensible party is us. We have all the domain knowledge and we're the only ones who can…

So -- national building codes for software? Government instpectors who audit code? Building permits required to even write code, or modify existing code? Doesn't seem to line up very well with "Move fast and break things"

> Doesn't seem to line up very well with "Move fast and break things"

When it comes to security around my personal data, I don't want anyone to move fast or break things. Businesses should either not bulk collect identifiable data or treat it with the care and diligence it deserves.

And while we're at it if 20 year old self taught rockstar programmers don't have the skills to do that, maybe they should learn. If you're making web software which stores personal information and you can't name 5 of the OWASP top 10 without looking them up, you're a privacy time bomb. I want my personal data far far away from your product.

When it comes to security, move slowly and fix your shit.

Re: The privacy wars are about to get a whole lot worse

#147

Earlier quoted context omitted.

> How do we decide when it is negligence, and when there was nothing that could be done? As others have pointed out, that question is one that courts deal with every day in other industries. IANAL but I have some familiarity with the architecture and construction industry, where there are lots of lawsuits around negligence. My understanding is that the question is generally framed as "what would a reasonable professi…

Would a reasonable engineer allow a SQL injection vulnerability to persist in 2016 You are suggesting that a software engineer should be personally liable for the code he writes, just as a civil engineer is liable when he stamps a blueprint. That would be quite a change for our profession.

If you want to bandy around words like "engineer", then that's exactly what should happen.

Re: The privacy wars are about to get a whole lot worse

#148
post #116

Earlier quoted context omitted.

In the specific hacks I was thinking of, they didnt hoard and store any info. Equipment was installed that siphoned credit card info from their payment systems. I cant think of a way to run a store without passing credit card info through your payment processing system to the banks.

Agreed, credit cards are a ridiculous necessity. I think in this case the credit card companies should be liable. I am continually amazed by the simple solution bitcoin provides to this problem: instead of me giving you an account number that you (or anyone who gets the number) pull(s) money from, you give me a number that I push money to. It's going to be a long time before that kind of change in our payment systems…

Perhaps the hack becomes tricking the consumer into pushing to the wrong address. Is that the consumer's fault? I agree that the current system is vulnerable, but perhaps we just get different hacks, not no hacks.

Re: The privacy wars are about to get a whole lot worse

#149
post #82

Earlier quoted context omitted.

No way. The largest threats to your privacy by several orders of magnitude over the stuff we complain about: - Electric, gas, sewer, water, trash utilities that you basically can't live without. - Thinking of going rustic? Better not own the land in your own name. Most places, parcels are easy to find online. - Property management companies - Sites that facilitate rental applications - Your 100+ year old bank - Credi…

What? Why would Verizon want to connect anything to your mom's car? That's very strange. Could it be that they want to monitor cellphone coverage maybe? Or even monitor their competitors' coverage? It just creeps me the hell out thinking that my telecom would like to connect something to unrelated stuff...

I believe this (https://www.hum.com/) is the device in question. Seems like just another horribly insecure IOT device.

Re: The privacy wars are about to get a whole lot worse

#150
post #18

Earlier quoted context omitted.

In theory the European Union has a bit better law than the US in this area. I write in theory - because in practice the USA does not need to abide by it - and it is mostly US companies that keep our data. As to the awareness group - I guess this will be controversial - but there are the Pirate Parties with privacy in the core of their ideology. Personally I think that we'll have to give up strict privacy - it is inev…

This is only an inevitability because we do not control our software and hardware. It is entirely possible to replace most of these privacy-destroying technologies and services with privacy-respecting free software solutions. Check out this list of alternatives, for example: https://degooglisons-internet.org/liste?l=en

I am all for control of our devices (even though I can see some problems with for example cars) - but it is only a part of the problem. First of all we will never control other people devices - and they will know more and more about us. Second there will be more and more services that will require the devices we control to expose more and more data about us.
Post reply on HN