Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

151–160 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#151
post #139

On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.

Isn't that kind of the point? I'm not anti-google/facebook in the least, and like to think that I'm knowingly trading some privacy in return for ad-supported services that have value to me. But it's tough to think of any compelling arguments for why companies making billions shouldn't be required to a) provide some minimal level of care over the data they collect, and b) disclose what they're doing with all that data. How will that bring about a tech winter?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#152
"Wyden would also create a national “Do Not Track” system to stop companies from tracking internet users by sharing or selling data and targeting advertisements based on their personal information."

Why not just reform EULAs so that people have more power over what they're often blindly agreeing to? If people could easily see the details and to what they're agreeing to and have more power over certain clauses, I think market forces would take the industry into a different direction, and there'd be more transparency. I don't always believe a market-solution is optimal, but in this case, it seems right.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#153

Earlier quoted context omitted.

So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.

I am not an expert bill reader but seems like this loophole is covered as there is another point that says : "(ii) is not substantially owned, oper ated, or controlled by a person, partner ship, or corporation that does not meet the 6 requirements under clause"

Contracting it out still seems to bypass the regulation

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#154
post #139

On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.

> [spyware] technology winter

Mission accomplished?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#155
post #139

On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.

In order for society to function properly it must be informed, if informing the public about the level of spying and data collection large corporations do in order to "subsidize" their products brings about "technology winter" then I welcome the cold...

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#156

Would these rules also apply to NSA/CIA misuse of surveillance?

There have been a handful of prosecutions (and many hundreds of firings) for misuse of the FBI's NCIC database by law enforcement officials. For instance, ex-NYPD Sergeant Joseph Dwyer was convicted of conspiracy in federal court in 2016 for selling information from NCIC to private defense investigators. Personally, I believe this kind of breach-of-trust should be prosecuted much more vigorously. But besides the fear…

The key here is Misuse under the FBI's guidelines which are no where near as strict as they should be under a properly enforced 4th amendment, most of what the FBI collects in the first place should be unconstitutional for them to have if we had a properly enforced constitution, unfortunately we do not.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#157
post #139

On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.

Isn't that kind of the point? I'm not anti-google/facebook in the least, and like to think that I'm knowingly trading some privacy in return for ad-supported services that have value to me. But it's tough to think of any compelling arguments for why companies making billions shouldn't be required to a) provide some minimal level of care over the data they collect, and b) disclose what they're doing with all that data…

What I mean is that it's become a major part of the US's economy. Globally, this industry probably generates 100s of billions of dollars, and those companies mostly spend their revenue on more software, more hardware, more research, more computer scientists, more computer engineers, etc. Indirectly, probably almost all of us here are partially paid from the ad-network-value-chain. And, what about all of the open source products that have been funded by these companies.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#158
post #157

Earlier quoted context omitted.

Isn't that kind of the point? I'm not anti-google/facebook in the least, and like to think that I'm knowingly trading some privacy in return for ad-supported services that have value to me. But it's tough to think of any compelling arguments for why companies making billions shouldn't be required to a) provide some minimal level of care over the data they collect, and b) disclose what they're doing with all that data…

What I mean is that it's become a major part of the US's economy. Globally, this industry probably generates 100s of billions of dollars, and those companies mostly spend their revenue on more software, more hardware, more research, more computer scientists, more computer engineers, etc. Indirectly, probably almost all of us here are partially paid from the ad-network-value-chain. And, what about all of the open sour…

Sounds like a labor mis-allocation bubble.

Bubbles burst. Furthermore bubbles should burst, for the health of the economy.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#159

I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…

IIRC from my brief skim this morning, it's $50MM over three years, so it might make more sense to think about it in terms of $16MM/yr.

edit: I misread this

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#160

Earlier quoted context omitted.

> Hard to show it was management's fault, and not the result of a developer... No. A leader is ultimately responsible for everything that happens or fails to happen under his or her leadership. Full stop. The people in charge of your hypothetical developer are the only ones with the ability to put processes in place to prevent it from happening. They are the least-cost avoider. Therefore, the power and the responsibi…

As a member of upper management, how would you address this then? More QA? More management of development practices? Move way from "devops" and back toward a world where there's a clear isolation between ops and development? Over the past few years, developers have seen more and more autonomy and power. I can't imagine there's a way to avoid walking some of that back (if it can be)

> As a member of upper management, how would you address this then?

By specifying what is and what isn't allowed wrt. user data in products. By ensuring it gets included in new employee training, and communicating that exposing the company to data-related risks is a serious, fireable offense. By having internal checks and audits that monitor data risk and keep it low. I.e. basically the same things you'd address risk of financial malfeasance.

> Move way from "devops" and back toward a world where there's a clear isolation between ops and development?

It's not really about "devops" vs. dev/ops separation - it's about not moving fast and breaking other people's things. You can solve that with good professional practices, but there needs to be an incentive to adopt them (as opposed to the existing incentives to ignore them, in pursue of short-term profit).

Post reply on HN