Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

21–30 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#21
post #2

Prison time for this is madness.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business.

But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less seriously without those teeth.

Besides that, I don't see a reason why wilful privacy violations should not be met with prison terms. Don't want to go to prison? Don't collect/share data that you're not allowed to collect/share.

Even for negligence, there is precedent to send people to prison, although that usually requires the negligence to result in death. But the scale at which software mistakes can cause damage is often higher than the scale at which mechanical/structural engineering does: A collapsing building kills hundreds of people. A collapsing Equifax database doesn't kill anyone directly, but affects over a hundred million people, and has the potential to ruin their lives (imagine e.g. private Facebook profiles outing people in intolerant areas - would probably lead to a larger number of deaths than most modern-day building collapses).

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#22
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

That's not equivalent. The equivalent would be the database or S3 bucket having a low quality password like "password".

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#23
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

[deleted]

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#24
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

are you saying leaving open filesystems and databases is the same as using a cheap lock?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#25
post #2

Prison time for this is madness.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

Easily disproven.

The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#27
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

I think it would be reasonable to have a law that says you need to have X level of security for certain information. Then it would be criminal to provide less than that level of security, especially just to save money. I just think it would have to somehow have exemptions for honest mistakes, and clever attackers.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#28

Earlier quoted context omitted.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

well that's because it wasn't enforced properly. we need prison time and to enforce it.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#29
post #26

This is going to make it impossible to start a startup. We need to organize a movement against this.

Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#30

Earlier quoted context omitted.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

Huh? Doesn't this prove the point? None of the people went to prison in the end, and the message remained clear: you won't go to prison.

That's why it's not taken seriously.

Post reply on HN