Earlier quoted context omitted.
Yes, I am suggesting that. I don't necessarily think jail time is the right thing, but I do think something like meaningful fines are more than reasonable for major software bugs that cause these kinds of breaches of privacy. It will make larger companies like this be much more careful when money is on the table for them to lose. To me, if we can criminalize something like a major oil spill such as BP/Deepwater Horiz…
Canada recently passed a law that adds fines to data breach incidents iirc. A professor mentioned it and its why I'm researching auth on my winter break. Come to think of it, does anyone know of good auth resources for a mean stack that isn't a copy paste blog? I'm trying the udacity auth course as a starting point (uses oauth2)
The relevant rfc and drafts perhaps? https://tools.ietf.org/wg/oauth/
Also checkout OWASP https://www.owasp.org/
If your implementing openid connect, use a certified lib https://openid.net/developers/certified/