Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

81–90 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#81

Would these rules also apply to NSA/CIA misuse of surveillance?

Those are already criminal, just rarely prosecuted even when known.

But the higherups also refuse to call them abuses or crimes most of the time.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#82

Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.

Given that most (all?) public Wi-Fi's primary function is to collect data & stalk people for advertising, it's not a big loss.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#84

Earlier quoted context omitted.

Prison time for executives is the only thing that gets taken seriously. Fines to executives can just be paid by executive insurance, and unless you crank them up to 4% of global revenue like GDPR, fines to the company will likely simply become cost of doing business. But threaten the executives with prison, and they'll suddenly make sure that the company complies with the law. I bet e.g. SOX would be taken a lot less…

Easily disproven. The 2008 crash is full of executives who did not comply with the law, and did not take the threat of prison seriously. I think to this date you can count the number in prison on two hands, and most of those were more foot soldiers than masterminds.

I hear this a lot and have never had anyone explain what laws were broken by those executives.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#86
post #6

Earlier quoted context omitted.

I think there are states in America where you can go to prison for stealing a pack of bubble gum. So I won't really cry for the targets here.

Would you if developers start going to jail for leaks?

I'm working in a field where there is a slim, but non-zero chance of going to jail if my software fails.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#87
post #82

Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.

Given that most (all?) public Wi-Fi's primary function is to collect data & stalk people for advertising, it's not a big loss.

Regardless of their intended purpose, in a world of costly cell phone data plans, the widespread availability of public wifi has been fantastic when you need it. Would be a real bummer to lose that if nothing takes its place.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#88
post #20

Earlier quoted context omitted.

Say you have a medical office, and you installed a cheap door lock which most burglars can easily crack, then a burglar breaks into your office, steals Ssn and other private info, should the doctor who runs the office go to prison for that?

I think it would be reasonable to have a law that says you need to have X level of security for certain information. Then it would be criminal to provide less than that level of security, especially just to save money. I just think it would have to somehow have exemptions for honest mistakes, and clever attackers.

The problem with that is the devil is in the details and it fails to account for changes properly in technology and excludes far better alternatives.

Say for instance there is a requirement that there must be DES encryption of passwords. That would be a downright terrible law on several levels - first of which is that the best way to secure passwords is not keeping them in the first place but a hash. The encryption standard is as laughable now as requiring banks lock their vaults with a simple warded lock - the kind where skeleton keys work because shaving the teeth from the key means it no longer has anything to catch on while it turns the lock.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#89
post #2

Prison time for this is madness.

Indeed. Most people have absolutely no idea what prison is, how it works, who actually suffers, the lasting secondary effects, and how little it changes anything.

Throwing around prison lightly is dangerous. For some reason data privacy gets people emotionally charged instead of thinking clearly, and it's easy to say "lock them up", but that's exactly the same attitude that led to such heavy criminalization of other things that now takes up resources, fills up courts, wastes lives, and accomplishes almost nothing.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#90

Unintended consequences: This could make running a public Wifi hotspot a losing proposition for many businesses that operate one today.

Nope.

The bill defines covered entities in Sec. 2.(5)(A) and 2.(5)(B). In particular, companies with less than $50,000,000 in gross receipts and information on fewer than 1,000,000 customers are not covered by this legislation.

And even if those apply to your local coffee shop or whatever, Sec. 2(5)(B)(iii) further limits the definition of covered entity so that businesses that do not provide 3rd party access to information are not covered.

So Starbucks and other huge coffee chains/retail shops are the only organizations that would have to re-evaluate data collection from their public Wifi hotspots, and even then might be exempt depending on what they are collecting and how they are using that information. And, I should point out, these companies will need privacy experts on staff anyways, so this provision is highly unlikely to cause them to shutter their in-store Wifi networks...

Additionally, some of the more onerous requirements only apply to a subset of covered entities with yet larger gross receipts and yet larger numbers of tracked consumers.

But, unequivocally, your locally owned mom & pop coffee shop is excluded from consideration under this provision multiple times over.

Post reply on HN