Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

71–80 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#71
post #2

Prison time for this is madness.

No it’s not. People should be jailed for messing with other people’s lives. Don’t gather data if you can’t protect it.

The part that scares me that management could held legally accountable for a mistake of a developer.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#72
post #6
post #2

Prison time for this is madness.

I think there are states in America where you can go to prison for stealing a pack of bubble gum. So I won't really cry for the targets here.

Would you if developers start going to jail for leaks?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#73
post #55
post #42

Earlier quoted context omitted.

Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?

I smell a blockchain pitch… :P

That would end up using money against law enforcement or prosecution as a proxy for lack of fairness/effectiveness, and we already know that money is a bad proxy for morality. That’s why this law has prison time.

If the blockchain could send people to prison, then we’d probably have other problems.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#74

My pet theory is this is firing a shell across the bow of BigCorp. Telling them change is coming. Maybe this won’t pass, but be prepared to be held more accountable.

The FTC already has quite a lot of authority over privacy regulations (in the financial sector at least) and does next to nothing with that authority. They spend zero time affirmatively looking into regulatory compliance and only take (very limited) action after receiving numerous reports about egregious violations. I suspect this far more of a "look at how much we're helping consumers" that will add some teeth to the few enforcement actions they do pursue but won't do much by way of removing their head-in-the-sand approach to consumer privacy.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#75

Earlier quoted context omitted.

Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s

Europe does not have anything comparable to Silicon Valley, and heavy regulations are often cited as making it hard to do business there.

Yet they still seem to find a way. That tells me the regulations aren't as onerous as some businesses would have you believe.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#76
post #3
post #2

Prison time for this is madness.

It reads to me like the prison time in this bill is reserved for the crime of knowingly mis-certifying annual reports to the FTC on data protection (ie, for defrauding the government) --- those reports are also only required from businesses with $1B+ of revenue. The rest of the penalties in the bill seem to take the form of liability under FTC's "Unfair Trade Practices" authority.

Thanks for clarifying; I completely misunderstood that. If only journalists were half as good as you at reporting information...

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#77
post #26

This is going to make it impossible to start a startup. We need to organize a movement against this.

No, it means you shouldn't create a startup if you're not qualified to handle the data correctly. Way too many bootcamps grads running around saving unencrypted PIA in databases and with root AWS keys because of the "move fast and break things" mentality. (obviously most startups wouldn't be affected by this law, but the principles still apply)

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#78
post #14

Earlier quoted context omitted.

I disagree. The current standard is that privacy and security are only so important as to prevent law suits unless there is law that says otherwise. That is a pretty low bar. With this privacy and security must be taken seriously from the start. I am of the opinion that wanton neglect that results in massive consumer harm (think Equifax hack) should warrant prison time.

This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly

If management asks you to cut corners to ship the app, ask them to put it in writing.

There's nothing wrong with iterating quickly, but developers are responsible for making sure their systems are secure and resisting shipping applications that aren't. It is a developer's responsibility to push back on shipping broken software. If they're forced to, they need to make sure there's a paper trail that shows that. Otherwise it's indistinguishable from a developer just having done a bad job of their own accord.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#79
post #42

Earlier quoted context omitted.

Maybe there needs to be consequences for selective law enforcement and/or selective prosecution?

That sounds somewhat naive, but on the other hand it also might help in getting all these unenforced, legacy laws of the book that result in anyone at all times being with one foot in prison if someone decided to enforce every law.

I agree with it sounding naïve. The thing is, we’ve tried a lot more things that attempt to pragmatic and reasonable with limited success: innocent people get hurt, while bad actors weasel out. I know the standard is supposed to be to allow a hundred guilty people go free rather than allow one innocent person be imprisoned, but given how many people are in prison, there might be more innocent people in there than we’d like to admit.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#80

Earlier quoted context omitted.

Of course, Europe has had no startups at all since the Data Protection Directive (95/46/EC) was passed in 1995. /s

Europe does not have anything comparable to Silicon Valley, and heavy regulations are often cited as making it hard to do business there.

I'd be A-ok if it had been impossible for Google, Facebook, etc to build advertising empires.
Post reply on HN