On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.
Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
151–160 of 285 posts
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#152Why not just reform EULAs so that people have more power over what they're often blindly agreeing to? If people could easily see the details and to what they're agreeing to and have more power over certain clauses, I think market forces would take the industry into a different direction, and there'd be more transparency. I don't always believe a market-solution is optimal, but in this case, it seems right.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#153Earlier quoted context omitted.
So then big corps do all their customer information risking behavior in spun out small wholly owned subsidiaries or even arms length non owned ones and if successful acquire them for some fixed amount but if they screw up with this law the company just folds and the parent is free from financial damage.
I am not an expert bill reader but seems like this loophole is covered as there is another point that says : "(ii) is not substantially owned, oper ated, or controlled by a person, partner ship, or corporation that does not meet the 6 requirements under clause"
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#154On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.
Mission accomplished?
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#155On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#156Would these rules also apply to NSA/CIA misuse of surveillance?
There have been a handful of prosecutions (and many hundreds of firings) for misuse of the FBI's NCIC database by law enforcement officials. For instance, ex-NYPD Sergeant Joseph Dwyer was convicted of conspiracy in federal court in 2016 for selling information from NCIC to private defense investigators. Personally, I believe this kind of breach-of-trust should be prosecuted much more vigorously. But besides the fear…
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#157On one hand, I think this is a good thing. That is, I certainly would like to have more control over who uses my own data. But, on the other hand, the scope of this bill has some risk of bringing about a technology winter. Most people outside of tech don't realize how much of the software they use has been indirectly subsidized by the ad and data brokering industries.
Isn't that kind of the point? I'm not anti-google/facebook in the least, and like to think that I'm knowingly trading some privacy in return for ad-supported services that have value to me. But it's tough to think of any compelling arguments for why companies making billions shouldn't be required to a) provide some minimal level of care over the data they collect, and b) disclose what they're doing with all that data…
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#158Earlier quoted context omitted.
Isn't that kind of the point? I'm not anti-google/facebook in the least, and like to think that I'm knowingly trading some privacy in return for ad-supported services that have value to me. But it's tough to think of any compelling arguments for why companies making billions shouldn't be required to a) provide some minimal level of care over the data they collect, and b) disclose what they're doing with all that data…
What I mean is that it's become a major part of the US's economy. Globally, this industry probably generates 100s of billions of dollars, and those companies mostly spend their revenue on more software, more hardware, more research, more computer scientists, more computer engineers, etc. Indirectly, probably almost all of us here are partially paid from the ad-network-value-chain. And, what about all of the open sour…
Bubbles burst. Furthermore bubbles should burst, for the health of the economy.
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#159I read this and immediately thought "oh shit, yet another regulation for a small bootstrapped software business where we try to be honest while the big guys will still find a way to circumvent it". Thankfully, I looked into the fine print and was wrong. This bill is only for Corporations that do over $50,000,000 in revenues or higher OR (EDITED from AND) have info on at least 1,000,000 or more customers. Of course, I…
edit: I misread this
Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill
#160Earlier quoted context omitted.
> Hard to show it was management's fault, and not the result of a developer... No. A leader is ultimately responsible for everything that happens or fails to happen under his or her leadership. Full stop. The people in charge of your hypothetical developer are the only ones with the ability to put processes in place to prevent it from happening. They are the least-cost avoider. Therefore, the power and the responsibi…
As a member of upper management, how would you address this then? More QA? More management of development practices? Move way from "devops" and back toward a world where there's a clear isolation between ops and development? Over the past few years, developers have seen more and more autonomy and power. I can't imagine there's a way to avoid walking some of that back (if it can be)
By specifying what is and what isn't allowed wrt. user data in products. By ensuring it gets included in new employee training, and communicating that exposing the company to data-related risks is a serious, fireable offense. By having internal checks and audits that monitor data risk and keep it low. I.e. basically the same things you'd address risk of financial malfeasance.
> Move way from "devops" and back toward a world where there's a clear isolation between ops and development?
It's not really about "devops" vs. dev/ops separation - it's about not moving fast and breaking other people's things. You can solve that with good professional practices, but there needs to be an incentive to adopt them (as opposed to the existing incentives to ignore them, in pursue of short-term profit).