This is going to make it impossible to start a startup. We need to organize a movement against this.
I'm sure startups/consultants will step in to provide regulator compliance as a service as well, so maybe not even that.
101–110 of 285 posts
This is going to make it impossible to start a startup. We need to organize a movement against this.
I'm sure startups/consultants will step in to provide regulator compliance as a service as well, so maybe not even that.
The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.
That would be a very positive consequence.
I'm fine with fines, but I hope prison time is restricted to intentional and malicious illicit behavior and not anything due to neglect or oversight. I'm not a fan of people being put in cages unless they're violent or have ruined people's lives intentionally.
It is. Read Sec 5.(d). It's not like people will be thrown in prison because their DB wasn't patched quickly enough. They have to knowingly and intentionally lie to the federal government in an annual report.
So it's a nonstarter, since the people being prosecuted for these things will have lawyers adept at whittling down intent to only the most brazen and malicious behavior. Not only that, but Sarbanes-Oxley showed us how effective "annual report" red lines are.
This would probably mean more compensation at executive level for the increased risks!
I'm actually OK with that. We're always complaining that companies don't take security/privacy seriously because there's no incentive to do so. See e.g. the Equifax HN threads. Having a person in the C suite who'll end up in jail if the company seriously fucks up is, IMO, a net positive for the world.
The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.
1) It encourages companies to be silent or remain ignorant.
2) I didn't see anything mentioned about the cyber-sec aspect, but I would imagine this will put a bounty on the heads of the largest companies.
Perhaps I watch too many (bad?) movies but shorting a stock on the cusp of being hacked could be lucrative.
Earlier quoted context omitted.
It is. Read Sec 5.(d). It's not like people will be thrown in prison because their DB wasn't patched quickly enough. They have to knowingly and intentionally lie to the federal government in an annual report.
They have to knowingly and intentionally lie to the federal government in an annual report So it's a nonstarter, since the people being prosecuted for these things will have lawyers adept at whittling down intent to only the most brazen and malicious behavior. Not only that, but Sarbanes-Oxley showed us how effective "annual report" red lines are.
The biggest unintended consequence I see is that more tech businesses will have to charge for their service rather than make money in opaque ways.
Each covered entity that has not less than $1,000,000,000 per year in revenue and stores, shares, or uses personal information on more than 1,000,000 consumers or consumer devices or any covered entity that stores, shares, or uses personal information.."
Putting those two vastly different classes of entities under the same umbrella and exposing them to decades in prison seems like it would have a chilling effect on the startup community. You would just have to hope that your app/website doesn't get to 1 million users, otherwise you're exposed to requirements where the implementation will bankrupt a small team or independent developer.
I guess you could simply stop allowing new registrations at 999,999 people, but it seems like a bad idea to discourage businesses from growing beyond that.
Earlier quoted context omitted.
This. Leaving databases exposed to the net. Leaving S3 buckets open to the public. All of these sorts of things needs to carry punishments not for the people who are told to set the stuff up. It needs punishment for the management who doesnt allow time to set things up properly
> It needs punishment for the management who doesnt allow time to set things up properly Hard to show it was management's fault, and not the result of a developer who really didn't have the AWS skills (though that's probably still the fault of management, for not verifying skillsets before hiring or giving AWS keys) Everything we know about iteration cycles, quick access to devops resources, etc, will change when pri…
No. A leader is ultimately responsible for everything that happens or fails to happen under his or her leadership. Full stop.
The people in charge of your hypothetical developer are the only ones with the ability to put processes in place to prevent it from happening. They are the least-cost avoider. Therefore, the power and the responsibility belong there.
Strict liability for the least-cost avoider is a sound strategy from both a moral perspective and a law & economics perspective. When proving knowledge and proximate cause are difficult, and someone is clearly in charge, and the harm is great - you place the liability on the people in charge whenever something goes wrong, and be done with it.
Earlier quoted context omitted.
That would be a very positive consequence.
Very true in some cases, i.e. unrollme. But I also like free content and am mostly willing to trade a little privacy for access.