Earlier quoted context omitted.
You contribute to campaigns of politicians (aka bribe) and write legislation for them to pass.
I don't have enough time left on this Earth to explain the concept in a way that politicians could implement, I'm in my 40s. In my preferred alternate universe, Keybase was sold to a benevolent billionaire. Or more realistically, a normal billionaire who intended to run it at a loss until he could leverage it to effect world domination, but managed to mess it up somehow and get it nationalized. Or something. I can dr…
Data leak contains 26B records from numerous previous breaches
91–100 of 150 posts
Re: Data leak contains 26B records from numerous previous breaches
#92Earlier quoted context omitted.
It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…
I'm very open to government solutions, but at the same time I'm not sure they have a good track record. Despite that, this service should come from the government because anyone else has misaligned incentives. I specifically would want a privacy and security maximalist approach. What we have right now is completely unacceptable, especially given our current technology level. Though of course, the downside is also tha…
They issue me a single identification number that can be used anywhere at anytime without any verification or notification that it has been used, and it's next to impossible to get a new one issued.
This is madness. A state funded "insurance" system to backstop this mistake is an unworkable hack that seeks to ignore the fundamental problem.
Re: Data leak contains 26B records from numerous previous breaches
#93I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
Who will lobby for it because /you/ don’t count? Too poor to matter to law makers.
Re: Data leak contains 26B records from numerous previous breaches
#94I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
They do win, unfortunately because they're right. Why spend much on designing security when the inevitable breach costs nothing other than bad press for a few days and then all is forgotten.
The only possible solution is to have significant fines for every data item breached.
Ideally I'd ratchet up the fines for each occurrence. First breach should hurt the company financially a bit but not be too disruptive, offering a learning opportunity.
Subsequent breaches the fines go up, by the fifth breach or so the fines would wipe away the company entirely, since they clearly didn't learn.
Anything short of something like this, companies will never care and leak all your data to the wind every year.
Re: Data leak contains 26B records from numerous previous breaches
#95I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
> I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. They do win, unfortunately because they're right. Why spend much on designing security when the inevitable breach costs nothing other than bad press for a few days and then all is forgotten. The only possible solution is to have significant fines for every data…
Like 3 check chess, but in Delaware.
Re: Data leak contains 26B records from numerous previous breaches
#96I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. I have gone from feeling outraged to completely numb to these kind of disclosures and have pretty much just assumed that my information will inevitably be leaked somewhere by someone. Does anyone else feel this way? I just keep a close eye on my financial statemen…
> I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. They do win, unfortunately because they're right. Why spend much on designing security when the inevitable breach costs nothing other than bad press for a few days and then all is forgotten. The only possible solution is to have significant fines for every data…
Re: Data leak contains 26B records from numerous previous breaches
#97Re: Data leak contains 26B records from numerous previous breaches
#98Earlier quoted context omitted.
It’s time for attorney generals to hold permanent identity monitoring pots and funds. The idea that someone can lose all your data and then pay for two years of identity monitoring is absurd. The people with the data can see that and can just wait two years to sell it. Social security numbers don’t reset after two years. If you lose data, you pay a data breach tax forever. Over time, your competitors will be able to…
> It’s time for attorney generals Attorneys general They are attorneys, so that is the word to pluralize. What type of attorney are they? General
Re: Data leak contains 26B records from numerous previous breaches
#99Earlier quoted context omitted.
> I feel like the people who calculate that it's more cost effective to deal with the hit from a security breach vs spending money on good security have won. They do win, unfortunately because they're right. Why spend much on designing security when the inevitable breach costs nothing other than bad press for a few days and then all is forgotten. The only possible solution is to have significant fines for every data…
This would be create an incentive to attack a competing company until you breach it 5x, causing its destruction. Competitors would be attacking each other nonstop. Like 3 check chess, but in Delaware.
Well-funded attackers and competing nations are already attacking these companies, so adding their competitors to the mix doesn't change a lot.
Re: Data leak contains 26B records from numerous previous breaches
#100Earlier quoted context omitted.
I just went through a call with my credit card company. 4 transfers later the only verification I've been asked is the last 4 of my social, my name, and when I was at the "highest level" of security they took the amazing step to... call me back. All because my credit card, which is travel focused, got flagged because I bought a You are not alone. It is an __absolute joke__ that my github account is more secure than a…
USAA actually does push passcodes using their app. The banks' understanding of security is so poor that they push people to use voice or fingerprint authentication. My wife constantly fights Wells Fargo about it every time she calls them because they want to helpfully sign her up for their voiceprint service so she doesn't have to use her PIN anymore. She used to work in a retail cellphone store so has heard tons of…