Subtle but important difference.
Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible?
They wouldn’t even have an RFP drafted in 90 days.
141–150 of 181 posts
Subtle but important difference.
Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible?
They wouldn’t even have an RFP drafted in 90 days.
A good law would be that if a customer's data is leaked, any and all revenue that was made with/through that customer must be returned to the customer. All of a sudden companies will magically remember how to do half-way sober IT again.
Earlier quoted context omitted.
>If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, offer $10 credit monitoring (at best), accept the free press coverage, maybe pinky promise to not lie if you've been particularly egregious in your handling of multiple incidents, and then carry on like normal. (This is tongue-in-cheek, I work in security, but I am frustrated with how often stories like this o…
> As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Honestly, I'm more afraid of reputational loss than government fines. Our customers don't have to use our product. They do because they trust us. Lose that trust and it's awfully hard to get it back.
Yes, the CRWD ticker took a hard hit, dropping about 50% over the course of 2 weeks last July. But... it recently topped its previous high, only 7 months later (which is like 1/2 or 1/3 of an enterprise sales cycle!).
A good law would be that if a customer's data is leaked, any and all revenue that was made with/through that customer must be returned to the customer. All of a sudden companies will magically remember how to do half-way sober IT again.
This would be awesome, few if any companies would be able to take the risk of storing customer info, since they would need very good security, and very good reason for every piece of data they store, and insurance to cover themselves in case they do lose your data. In fact companies would go out of their way to not store any of your data.
As someone with 20+ years experience in IT/DevOps/Cloud/whatever, I disagree.
They would simply need to actually use the security that is already there. Data leaks that happen due to lack of "very good security" are extremely rare. In almost every case, someone was doing something very stupid that everyone already agrees is a very obvious thing to not do.
.
> In fact companies would go out of their way to not store any of your data.
The companies that already use existing IT systems, as they are already designed to be used, have no problem protecting customer data and not leaking it. The companies that can not properly hire our outsource competent IT people shouldn't be storing data in the first place. Commerce is subject to regulation, due to human nature, and different regulation is needed today.
.
> and insurance to cover themselves in case they do lose your data
I would prefer that this kind of insurance not exist.
It's amazing that (approximately) no one cares about stuff like this. GoDaddy was severely breached several times over several years, yet they still rake in billions of revenue from their millions of customers. Now they have to pay someone to fill out a biennial checklist and... promise to not lie. Awesome. If you own a company, why even bother with security? Security is expensive. Wait until a breach is exposed, off…
True story. I worked for a medium sized company. They had a very large commercial e-commerce site for their customers. They used Wordpress sites that were hosted on GoDaddy. I worked there for two years. They never updated any of their passwords for GoDaddy or their Wordpress sites. Its been almost ten years since I've worked there and I occasionally log on just to see if they've updated anything. Nope. Last time I c…
... but.. why?
Why let them live rent-free in your mind? Why admit to that in even a pseudonymous space?
Earlier quoted context omitted.
As SRE, I've heard executives say this "There is no penalty for breaches, why care?" Depends on the industry. I'm in healthcare, and our legal department is always reminding the devs that even a small breach can be financially catastrophic for the company, as they are totaled as $xx,000 per person affected. We get training on it every six months.
Except Change Healthcare got hacked, lost a ton of records and they are still operating. So those fines must be, could be up to xx,000 per person affected but in actuality, those affected will get Arbys coupon and C Suite will lose a week of yacht time.
I got a letter telling me they gave away my information with a link to an “identity monitoring” site that looks like the CEOs nephew built in a weekend and just errors out when I sign up.
I was shocked when I purchased a domain recently on GoDaddy (I normally use Cloudflare or AWS) and noticed that they have an 'upsell' with more security options (MFA and some other features) for something like $10/yr. Why wouldn't they want their customers to be more secure by default? To me it just reeks of money-grabbing for people that are none the wiser.
The FTC action is because GoDaddy claimed to have security when they didn’t - not because they didn’t have security in the first place. Subtle but important difference. Also the remedies include having a complete security program within 90 days IIRC, on what world would anyone think that’s remotely possible? They wouldn’t even have an RFP drafted in 90 days.
Earlier quoted context omitted.
So the answer is to put the same kind of onerous penalties that companies pay for leaking healthcare data and apply them to any PII / user data Then you get people on HN shouting "regulatory capture!" and "stifling innovation!"
> Then you get people on HN shouting "regulatory capture!" and "stifling innovation!" You phrasing it like this is not a substitute for explaining why it wouldn't be those things. Also, the most obvious thing is: if you're a healthcare provider, you would probably hire some hackers to go after your competition, and let heavy-handed fines take them down. Much easier than providing better value.