Live data from Hacker News

Ring LLC home security company ransomed by ALPHV ransomware

web.archive.org

71–80 of 124 posts

Re: Ring LLC home security company ransomed by ALPHV ransomware

#71
post #68
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

I kinda agree with you but it’s a tough one because what you’re describing is fining the victims of a crime. We don’t fine homeowners who fit cheap locks and get burgled do we. Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up ag…

We don't fine them, but homeowners usually don't have million of records of private data at home.

Wouldn't you want your bank get fined if they aren't secure enough and loose your money? Or your local government if they loose your tax records because they think they don't need to lock their door?

The hard part will be determining whether the company could have done something about it (like locking the doors or the windows). If they could, they for sure should get a fine if they didn't.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#72

My personal trust of devices like this is low - and since it is capturing public side recordings (outside my front door) I'm less worried about the vidoes. I just prefer to treat them as untrusted devices and put them on my guest network isolated from the rest of my network.

Apparently quite a few people have Ring cameras inside their homes as well. And another point. You might not think video outside your home matters, but it could be invaluable to burglars who want to know when you're not home. I could imagine it being used to deanonymize location data as well because it would provide known locations and timestamps to filter data against.

You think he's so stupid he goes out his own front door? /butchered sg-1 reference

Re: Ring LLC home security company ransomed by ALPHV ransomware

#73
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

> companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers This is zealous. If consumers don't care, and nobody can show tangible damages, "massive fines" and "criminal charges" are closer to moral outrage than prudent lawmaking.

What's your basis for assuming customers don't care?

I think there are those who don't care, and those who care but don't know better in the face of misleading marketing.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#74
post #68
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

I kinda agree with you but it’s a tough one because what you’re describing is fining the victims of a crime. We don’t fine homeowners who fit cheap locks and get burgled do we. Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up ag…

It would be like fining the victim of home burglary who stores data about their neighbors for profit. Mandatory business data leak should be exempt but everything else should be a liability. If they save cc info by default (opt-out) that should be a major liability.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#75
post #22

Earlier quoted context omitted.

[flagged]

Twitter used to be controlled by the blue tribe. Now it’s been bought by a (perceived) member of the red tribe. It’s a simple as that. People feel the need to signal their tribal affiliation and attack those from other tribes. Been part of human behaviour since humans began.

No.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#77

Earlier quoted context omitted.

>company is closed permanently in the interest of public security. So there goes a janitors job, secretaries etc. Local cafes, bars, transport lose out. The dependents of all the company are now involved. There's a long chain of consequences after this. Why not just target the guilty: maybe any punishment should make them suffer.

Sounds like a good incentive for the janitors to not leave doors open at night for their own convenience, creating massive security risks. Regardless, plenty of places need janitors and the likes. They'll find other jobs.

They'll find jobs with companies that fill the void but with improved security measures.

If anything, there will be more jobs created by the demand to shore up security. They'll be high quality jobs too, as management will be reluctant to outsource potential criminal liability to incompetent contractors in India.

Re: Ring LLC home security company ransomed by ALPHV ransomware

#80
post #68
post #12

I've said it before and I'll say it again: - Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers. - I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge thi…

I kinda agree with you but it’s a tough one because what you’re describing is fining the victims of a crime. We don’t fine homeowners who fit cheap locks and get burgled do we. Pragmatically, it might be the right thing to do, but it feels wrong. Would you consider a due diligence to security threshold? That would certainly make it easier the well resourced to weasel out of fines, but when a small startup comes up ag…

We absolutely do fine/convict homeowners if, in a burglary, their improperly secured gun is stolen. The fines aren't for being hacked, they're for not adequately securing user data; ownership of which is a conscious decision.
Post reply on HN