This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.
Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked
Despite decades of hacking attacks, companies leave sensitive data unprotected
21–30 of 45 posts
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#22Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...
> I have done what the law or insurance company wants to see and I have consultants as black sheep. You hit a great point. The law and insurance companies have a major impact on what companies do. If it's illegal (and they'll get caught) or the insurance companies say "do this to get insurance or if you don't do it the insurance doesn't cover you" people will make change. That right there is a way to bring change. Ca…
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#23Why treat anything serious if it doesn't impact the board? I wouldn't either if I'm in that position. For sure I'm going to hire consultants with coats made of certificates and then sleep tight. I have done what the law or insurance company wants to see and I have consultants as black sheep. What on earth do you expect me to do more? Better processes? Sure let me hire more consultants wearing suits...
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#24If we wanted to fix that, we would either vote with wallets (we aren’t, so this doesn’t work) OR we could assign higher penalties for breaches.
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#25Earlier quoted context omitted.
> I have done what the law or insurance company wants to see and I have consultants as black sheep. You hit a great point. The law and insurance companies have a major impact on what companies do. If it's illegal (and they'll get caught) or the insurance companies say "do this to get insurance or if you don't do it the insurance doesn't cover you" people will make change. That right there is a way to bring change. Ca…
The problem is always the same: to do things right, you need people who know what they are doing. Redundantly . Yet, most of us don't know what we are doing, so in practice we end up creating proxies for "the people who know what they are doing according to their certificates certify that I know what I'm doing". Because otherwise you wouldn't be accepted in a cool position, and we all want to be in a cool position. A…
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#26Earlier quoted context omitted.
> I have done what the law or insurance company wants to see and I have consultants as black sheep. You hit a great point. The law and insurance companies have a major impact on what companies do. If it's illegal (and they'll get caught) or the insurance companies say "do this to get insurance or if you don't do it the insurance doesn't cover you" people will make change. That right there is a way to bring change. Ca…
One thing I'm a bit pessimistic is that insurance policies usually bring a lot of paper work and eventually it's just certificates over certificates. But again, maybe (a big maybe) this is still better than what things are going on right now. The best solution is for board members to have respect to their best techincal people and let them create processes best for individual companies. Sadly this is too personal and…
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#27As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…
> Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why established card companies can have very reasonable processes to cancel transactions, mark some as fraudulent, and probably why they have reversible transactions. Do they do that of their own volition, or because there's some legal requirement forcing them to?
If someone steals from your credit card, that's not your money, it's the bank's money - the bank was trying to give you a loan and gave it to the wrong person. That's their problem.
If we didn't have this rule, there would be unlimited rampant fraud - you don't just loose all you have, you loose what you haven't. We would suddenly find out that we are a million dollars in debt for no reason.
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#28This is what happens when there are zero legal repercussions for companies with sloppy data security. Regulatory capture strikes again.
Literally the only reason any company invests actual time into data security is HIPAA, GDPR and SOX. I keep wondering why people haven't demanded more regulation after all their SSNs got leaked
HIPAA passed when people expected Clinton to push for health insurance improvements. The HITECH accompaniment passed in 2009 when health care was a huge issue in the wake of the 2008 disaster, and people expected the govt to crack down on big company malfeasance. Subjectively, I think 'keeping your health information secret because it should be secret' seems more viscerally compelling. SOX passed in the wake of Enron and WorldCom during the .com bust. The EU, broadly, seems less regulation averse than the US, but I'm no expert. That the US hasn't followed suit, despite the current backlash against social media and data tracking in general, is telling.
Most folks think someone getting ahold of their CC# is the worst-case scenario and they or someone they know has probably experienced it. It was probably resolved with a 5-minute phone call, and they probably blamed the last in-person retail transaction they executed before the fraudulent charges rather than some online company they bought a potholder from 18 months prior. They likely don't even consider the implications of someone using their SSN to open a mortgage, lease a boat, claim unemployment benefits, or work a year claiming total tax exemption on their W4.
Even many people who understand the privacy implications might not understand how frequently breaches happen, the practical steps to mitigate them, and whether they're proportional to the risk. Few could factually evaluate the inevitable industry FUD. I think it'd get way more pushback than the right to repair did in Massachusetts, and industry flung some pretty outrageous fear-mongering BS over that one— they implied non-proprietary car computer interfaces would result in women being stalked and raped. In a television commercial.
I think it's doable and very important that we do, but I completely understand why there hasn't been any popular grassroots uprising about it.
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#29Won't happen.
Re: Despite decades of hacking attacks, companies leave sensitive data unprotected
#30As I see it there's two things at play here that feed into one another: 1. The re-framing by financial institutions of them being defrauded as "identity theft" and pushing this responsibility onto their customers. 2. Because of the above, the data can be valuable, incentivizing the compromise. Re 1: Note that credit card companies have had this problem for ages and treated it as fraud for decades, which is why establ…
as with so many other things, elite impunity is the fundamental problem.
for the banks to be putting their own failures of due diligence on consumers’ heads is as an outrage and an absurdity. it shouldn’t even be possible.
if they screw up, they should face the consequences of their incompetence. but they don’t. after the Equifax breach, the CEO retired with $90M.
$90M for presiding over a corporation whose entire business model is an exemption from defamation law, screwing it up, blaming someone else down the line, and exposing millions to so-called “identity theft” —- in other words, millions of people now have an uncompensated permanent commitment to doing due diligence for countless banks, car dealerships, and even Walmarts throughout the country.
> collectively not treating it seriously and essentially letting it happen
the modus operandi for the whole problem space