Prison time for this is madness.
No it’s not. People should be jailed for messing with other people’s lives. Don’t gather data if you can’t protect it.
Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
71–80 of 285 posts
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#72Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#73Earlier quoted context omitted.
Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?
I smell a blockchain pitch… :P
If the blockchain could send people to prison, then we’d probably have other problems.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#74My pet theory is this is firing a shell across the bow of BigCorp. Telling them change is coming. Maybe this won’t pass, but be prepared to be held more accountable.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#75Earlier quoted context omitted.
Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s
Europe does not have anything comparable to Silicon Valley, and heavy regulations are often cited as making it hard to do business there.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#76Prison time for this is madness.
It reads to me like the prison time in this bill is reserved for the crime of knowingly mis-certifying annual reports to the FTC on data protection (ie, for defrauding the government) --- those reports are also only required from businesses with $1B+ of revenue. The rest of the penalties in the bill seem to take the form of liability under FTC's "Unfair Trade Practices" authority.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#77This is going to make it impossible to start a startup. We need to organize a movement against this.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#78Earlier quoted context omitted.
I disagree. The current standard is that privacy and security are only so important as to prevent law suits unless there is law that says otherwise. That is a pretty low bar. With this privacy and security must be taken seriously from the start. I am of the opinion that wanton neglect that results in massive consumer harm (think Equifax hack) should warrant prison time.
This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly
There's nothing wrong with iterating quickly, but developers are responsible for making sure their systems are secure and resisting shipping applications that aren't. It is a developer's responsibility to push back on shipping broken software. If they're forced to, they need to make sure there's a paper trail that shows that. Otherwise it's indistinguishable from a developer just having done a bad job of their own accord.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#79Earlier quoted context omitted.
Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?
That sounds somewhat naive, but on the other hand it also might help in getting all these unenforced, legacy laws of the book that result in anyone at all times being with one foot in prison if someone decided to enforce every law.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#80Earlier quoted context omitted.
Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s
Europe does not have anything comparable to Silicon Valley, and heavy regulations are often cited as making it hard to do business there.