Earlier quoted context omitted.
I'd rather see the hammer applied to the companies that allow the data to be stolen.
From what I read in the complaint, it wasn't as blatantly bone headed as other breaches. Seemed to be an IAM permission issue related to AWS WAF. This argument is constantly made on HN and it is analogous to; you left your back door open at your house, and instead of arresting and prosecuting the robber, we are going to arrest you. Sure, I made a mistake and left my back door open, but that doesn't give the robber th…
I admit the Equifax situation was worse. The people whose data was lost by Capitol One probably at least have some sort of business relationship with that company (for example, they may have applied for a credit card). I had no business relationship with Equifax at all, yet apparently information about me was leaked. I don't buy anything on credit, so I don't give a tinker's damn what my credit score is. Equifax provides no value to me whatsoever, yet I now have to worry about information they collected about me with no authorization from me. I'd like that company to be sued into bankruptcy.