Live data from Hacker News

Proposed Jail Time for Tech Companies Who Steal Data

trofire.com

151–160 of 203 posts

Re: Proposed Jail Time for Tech Companies Who Steal Data

#151
post #41

Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? How is this different than taking a picture of someone? The image is owned by the photographer, not the subject(s) according to current laws. if I meet someone on the street, and record their name, the conversation we had, and the location where I met them, an…

> How is this different than taking a picture of someone? The image is owned by the photographer

I think there is a good argument that this is often not just. The iconic image of many events may have the victims preferring not to be that iconic representation years later. They may want their life to be known for them, not a moment long past. For the most obvious example, the famous image of a child running during the Vietnam war[1]. She's famous for being terrified of a napalm attack against civilians and allied forces. The photographer gets to decide if it may be reused, and he will, where it's proved to be his meal ticket. There's many less significant examples of where resting with the photographer is inappropriate.

Rights resting with every subject would raise its own, different problems. I'm not sure how to improve the balance without unreasonably restricting the freedom to take perfectly reasonable snaps.

> if I meet someone on the street .. right to demand that I not record that information

They should, unequivocally. I can walk past a person with clip board taking a survey. I prefer unannounced recordings to be left to authorities and journalists.

> Does my perspective or interpretation of that information give me some ownership to that data?

Nope. If it's about me, I care not what you are trying to interpret from my eye colour, location and my presence in a shop. Just whether I have agreed to your monitoring of me, or whether you are one of a limited number of exceptions. Which seems to be the sensible starting point of GDPR.

> What if I use that information for commercial gain

See above. Makes no difference, other than hugely reducing my sympathy for its collection. I don't care if it concerns 10 or 10m if it's without informed consent (no dark patterns etc).

[1] https://en.wikipedia.org/wiki/Phan_Thi_Kim_Phuc

Re: Proposed Jail Time for Tech Companies Who Steal Data

#152
post #150

Earlier quoted context omitted.

If we consider laws around privacy in meatspace, then here's the common dividing line (according to my memory of an information law class I took something like eight years ago): If someone is in a public space (such as a park) and you take a photograph for instance that happens to include them in it, then you're not violating their privacy. If they're in their home and you photograph them through their window, that i…

If you go into a park and take a picture of the park that has a person standing in the distance and then sell that picture then you have committed no crime. If you follow someone around the park constantly taking their picture and then decide to sell the ones that look the best without either the permission of nor compensation for the subject of your photo then they have a legitimate claim against you. People are not…

>The idea that this data collection is not something that can or should be regulated is perverse and thankfully the general public is coming around to this viewpoint.

A while ago I would have agreed, but as I've watched the progress of data legislation, I've come under the impression that it's flawed in at least two significant ways:

1. Companies lobby for laws that favor them. Sooner or later, they win. And then they spend those winnings to ensure they keep winning (some numbers on the top political contributions from electronics/communications companies: https://www.opensecrets.org/industries/indus.php?ind=B).

2. Enforcement is never going to result in jail time. It's going to appear as fines, serving as a mere cost of doing business which results in further entrenching existing companies against newcomers who can't afford the risks.

People right now are excited about greater legislation because they think it will divert us from the cyberpunk dystopia of megacorps owning the world. But the trend I'm picking up from the current legal battles is that they're actually hastening it by pushing for legislation which those same companies will get to shape the details of.

Thus, the solution I see is not greater legislation (which also implies greater centralization, thus more winner-takes-all for companies and governments), but greater decentralization and personal ownership. Legislation sounds good now, but in the long run it's a trap.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#153
post #41

Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? How is this different than taking a picture of someone? The image is owned by the photographer, not the subject(s) according to current laws. if I meet someone on the street, and record their name, the conversation we had, and the location where I met them, an…

First off, I think the proposal is one of those "looks good on the surface but is dumb when the details come to light". Simply put it is too vague and borderline an election campaign trial balloon, meaning we will see similar on someone's platform.

However the real kicker here is, if they hold private companies to this then how do they excuse the government from similar actions and how does a law assigning this level of protection and declaration of personal property not affect law enforcement? In particular in that your phone/email account/etc has no rights even though your data is there.

If this does get somewhere, what if companies choose to encrypt it all and when stolen it is just encrypted. does the government demand the keys at all times?

Re: Proposed Jail Time for Tech Companies Who Steal Data

#154
post #135

Earlier quoted context omitted.

No, that's not what happened with the GDPR. Most small companies rightfully came to the conclusion that they can't afford to not comply, so at least they tried to. Google though they can afford not to, so they didn't. Now Google is starting to get hit with fines (e.g. France), so they'll probably change their minds.

Google can afford to take as long as they want to comply, and cop the fines along the way. The startups that never get off the ground because the cost of compliance is prohibitive will mean less competition for Google etc in the long term.

I think this is nonsense - it’s only true if you believe the businesses should have existed without protecting user privacy. GDPR and such don’t require you to go out and buy any hardware, or pass through any other expensive compliance audits. PCI/DSS didn’t kill e-commerce, it just set a minimum bar for what companies SHOULD have already been doing.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#155

What if a data breach happens due to an 0 day exploit with a 3rd party library? Do people from the company where the data breach happened still go to jail then?

My guess is prudent man principal applies - did they have a reasonable plan to remediate once the 0-day was known? How would peers in the industry have been affected? If it’s truly a 0-day, and they followed reporting the breach, I don’t see it being likely.

You could argue a single 0-day should not result in a breach (security is best as a layered defense), but that’s probably far less likely to find.

https://en.wikipedia.org/wiki/Prudent_man_rule

Re: Proposed Jail Time for Tech Companies Who Steal Data

#156
post #4

Quit expecting governments to save you. The easiest fix for this problem is to stop using these products! No matter how much bad news comes out about Facebook, Apple, Google, and Amazon using your data in bad ways -- people still keep using them. If enough people quit, this will stop or a competitor will rise up who doesn't do this stuff.

This isn't going to happen while the problems are still theoretical. Few people care if companies have their data as long as it isn't used against them.

These companies collect that data specifically to use it against you for their own financial gain.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#157
post #41

Is personal information really a kind of property, that can be stolen? If it is, aren’t we doing this all the time, any time we perceive anything about anyone? How is this different than taking a picture of someone? The image is owned by the photographer, not the subject(s) according to current laws. if I meet someone on the street, and record their name, the conversation we had, and the location where I met them, an…

I'm reasonably comfortable with a company keeping records of its interactions with me, as long as they're taking proper precautions to keep it secure. Where I draw the line is when they start sharing it with third parties, especially without my consent.

Here's the rub though, what is the definition of "reasonable"? How about "record" or critically, "interaction"? Does browsing a web page allow them to build a shadow profile under the guise of recording an interaction?

Funny enough, the thing you object to is usually the one thing explicitly spelled out in ToS that they are allowed to do with your information

Re: Proposed Jail Time for Tech Companies Who Steal Data

#158
post #145
post #57

Earlier quoted context omitted.

Rule of law demands it be clear what is and is not illegal. Make it illegal to film people in public and the guy who made the Rodney King tape is going to jail.

You can’t retroactively apply laws, thankfully.

Depends on the jurisdiction.

https://en.wikipedia.org/wiki/Ex_post_facto_law

Re: Proposed Jail Time for Tech Companies Who Steal Data

#159
post #154

Earlier quoted context omitted.

Google can afford to take as long as they want to comply, and cop the fines along the way. The startups that never get off the ground because the cost of compliance is prohibitive will mean less competition for Google etc in the long term.

I think this is nonsense - it’s only true if you believe the businesses should have existed without protecting user privacy. GDPR and such don’t require you to go out and buy any hardware, or pass through any other expensive compliance audits. PCI/DSS didn’t kill e-commerce, it just set a minimum bar for what companies SHOULD have already been doing.

Any company effected by GDPR is at risk of being fined a (relatively) large sum. Even if the compliance cost of GDPR appears low, the regulatory risk is large enough that companies have to bear the cost of legal staff to deal with that possibility. Big companies are in a much better position to pay for such things than small companies.

Moreover, startups seeking capital must convince potential investors that the chance of being wiped out by a GDPR complaint is low -- on top of convincing those investors that their business model is viable, that they are entering the market at the right time, etc. Plenty of startups with great ideas never get off the ground because they cannot get the initial capital they need, or they fail to get enough capital to survive a rare negative event.

There is not much doubt that regulations raise the cost of entry to a market. The real question is whether or not it is worth it for society -- if we are willing to sacrifice a few small companies for the sake of the regulatory goal. User privacy is a fine goal, but the EU is losing the leadership it once had in the tech industry to the US and China. Where is the European answer to Google, Facebook, Tencent, or Alibaba? Where is the Europe in the AI race? It is not just GDPR; the right to be forgotten, the draconian copyright rules, and so forth have all contributed to a stifling regulatory environment in Europe and a stagnant tech industry.

Re: Proposed Jail Time for Tech Companies Who Steal Data

#160

Earlier quoted context omitted.

The inherent nature of regulations mean there is always going to be a 'winner' and a 'loser'. For example I have no doubts that regulations removing lead from gasoline resulted in lost profits and hurt businesses, but we can also believe that the societal gains were far greater than the losses. Similarly regulations in favor of privacy for citizens is going to naturally result in some companies, somewhere, having to…

I completely agree. I was referring to the GP's framing of the situation as Big Bad Regulation squashing Mom & Pop tech startups- a bogeyman of dubious existence.

How willing are you to invest in an early-stage startup whose founders could be arrested over a data breach? How much of your own money would you be willing to risk? Would you be willing to work as a founder of such a company and take on the risk of jail time? If this "bogeyman" is of "dubious existence" then your answer should not be impacted at all by the nature of the regulation or the punishment for non-compliance.
Post reply on HN