Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

51–60 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#51

Would these rules also apply to NSA/CIA misuse of surveillance?

There have been a handful of prosecutions (and many hundreds of firings) for misuse of the FBI's NCIC database by law enforcement officials. For instance, ex-NYPD Sergeant Joseph Dwyer was convicted of conspiracy in federal court in 2016 for selling information from NCIC to private defense investigators.

Personally, I believe this kind of breach-of-trust should be prosecuted much more vigorously. But besides the fear of embarrassment, I suspect federal agencies are unwilling to compromise intelligence methods to prosecute misbehavior.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#53
post #30

Earlier quoted context omitted.

Huh? Doesn't this prove the point? None of the people went to prison in the end, and the message remained clear: you won't go to prison. That's why it's not taken seriously.

So why pass a law if it can't or won't be enforced? And do you realize how political prosecutors offices are? Also, laws like this become patronage to the drafters when they're out of office. "Well you REALLY should hire our compliance services." Laws only work when cultural norms already do 99% of the heavy lifting.

> Laws only work when cultural norms already do 99% of the heavy lifting.

And this is the aspect where a lot remains to be done in the USA. Many people who buy, sell or plain steal personal data don't perceive it as something negative. Some of these people are high-level executives and get praise as "disrupting the industry", some do their job quietly, and very often their victims don't even realize the extent of the harm done to them.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#54
post #45

so they admit, that the war on drugs is not working anymore. a new paper dragon is needed.

This is a very strange comparison to me, given the enormous disparity in the targets. But can you expand on your line of thought?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#55
post #42

Earlier quoted context omitted.

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?

I smell a blockchain pitch… :P

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#56
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

You’d have to walk back from who owns the medical office. If it’s the doctor who owns the office, then that would be the where responsibility ends.

Doctors already have a responsibility to safeguard the privacy of their patient e.g. interviewing minors-turned-young-adults on their own and asking if they have permission to share the patient’s health information with their parents or guardians.

If the doctor installed the lock manually and there was a reasonable expectation to install a lock of a certain strength, then yes the doctor would be responsible.

If the doctor hired someone else e.g. a locksmith or the property management, then the people who were hired would be responsible so long as they were informed that they needed a particular kind of lock, they were certified to perform the installation, and there were laws on the books for the each of those kinds of responsibilities.

It definitely seems onerous, burdensome, and expensive, but the costs of these kinds of security breaches have been severely discounted by those who have the power to otherwise act.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#57
post #31

Earlier quoted context omitted.

Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s

Exactly.

There are plenty of startups in Europe.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#58
post #20
post #14

Earlier quoted context omitted.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

The question isn't whether the door lock was great, but instead was there a door lock in the first place and if it was locked. If not do you continue to operate with an unlocked door or do you lock the damn door?

You cannot stop all criminals, but you can take reasonable actions (due diligence) to ensure a reasonable effort, according to industry, and timely corrective actions once a breach is known.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#59
post #14

Earlier quoted context omitted.

I disagree. The current standard is that privacy and security are only so important as to prevent law suits unless there is law that says otherwise. That is a pretty low bar. With this privacy and security must be taken seriously from the start. I am of the opinion that wanton neglect that results in massive consumer harm (think Equifax hack) should warrant prison time.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

> It needs punishment for the management who doesnt allow time to set things up properly

Hard to show it was management's fault, and not the result of a developer who really didn't have the AWS skills (though that's probably still the fault of management, for not verifying skillsets before hiring or giving AWS keys)

Everything we know about iteration cycles, quick access to devops resources, etc, will change when prison time becomes an option.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#60
post #20

Earlier quoted context omitted.

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

The question isn't whether the door lock was great, but instead was there a door lock in the first place and if it was locked. If not do you continue to operate with an unlocked door or do you lock the damn door? You cannot stop all criminals, but you can take reasonable actions (due diligence) to ensure a reasonable effort, according to industry, and timely corrective actions once a breach is known.

The problem is there's way too many developers being given AWS keys who don't even know what a lock looks like.
Post reply on HN