I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
This could be a voluntary insurance that companies purchase on behalf of their users. If the company suffers a breach, they will be bound to pay X amount to their users depending on the data lost. Dress it up with a fancy badge to slap on the front of their site. Maybe a silver badge means user data is insured up to $10 each; a gold badge is up to $100; platinum up to $1000.
Yahoo Triples Estimate of Breached Accounts to 3B
121–130 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#122I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#123Earlier quoted context omitted.
They can, but in practice, they don't.
> They can, but in practice, they don't. And you're confident of this how? I'm not actually convinced this is true. It's definitely a widespread belief though.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#124I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
On my small business we ask only for an email address, password and confirm password. Everything else is excessive.
Tax obligations can be another problem which may require an address, but often have a simpler way to resolve them by simply picking the appropriate country and state off a list or even with just a checkbox for "are you in X jurisdiction which I am required to tax?". I believe Tarsnap handles it that way.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#125I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.
> Anyone who has my data for any purpose owes me my cut.
It's well established in the US that you do not in fact own your data. You don't own your school records or employment records. You don't own your medical records or your credit records. In general the best you have is a right to view those records and that's only in certain cases.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#126Earlier quoted context omitted.
> You really do need user accounts to run an email service Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible. Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting c…
>> User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service > Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to gi…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#127Earlier quoted context omitted.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#128I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#129Re: Yahoo Triples Estimate of Breached Accounts to 3B
#130> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse
Does anyone have insight on how this works? Do you just sue the pants off of the execs, or the lawyers who did due diligence, or the SREs maybe? Do the clawback the difference in goodwill + legal costs from the selling investors? Is there recourse at all? It'll probably the some poor schmuck SRE getting the blame, like always, right?