Live data from Hacker News

Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

reuters.com

221–230 of 285 posts

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#221
post #182

Earlier quoted context omitted.

Currently the price we all collectively pay for these “free” services is a decrease in the sanity of public discourse. Is that really a better option?

How would subscription fees improve the discourse on social media sites?

Given "the discourse" currently includes inflammatory crap by bots pulling people's strings, even a small monetary barrier to entry might slow that down.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#222

Earlier quoted context omitted.

Fraud. The ratings agencies lied about the credit worthiness of the mortgages that they bundled.

> The ratings agencies lied They published opinions about the future performance of certain securities. Those opinions were incorrect. Lying would mean misrepresenting the present state of those securities, which they didn’t do. Everyone know they were buying subprime mortgages. They just expected them to trade like prime mortgages.

So is the only difference between lying and knowingly misleading the point in time of the subject in question?

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#223

Earlier quoted context omitted.

At this point, we've scaled back the argument from "this bill would kill startups" to " any bill would kill startups". That's a coherent position, but not one we can reasonably hope to debate about between each other.

Not any bill, just bills with breathtaking fines and possible imprisonment.

This is a frustrating thread.

It starts with the claim that this law could put Flappy Bird on the hook for decades of prison time. I rebut, and you say (paraphrased) "no, read the law, anyone with 1MM users could be sent to prison for failure to comply". This is obviously not true.

Then the claim becomes that pp26-33 of the statute has so many burdensome requirements that it would be impracticable for many startups to comply. I ask for specifics; none emerge. Instead, a new claim appears: every startup would be on the hook for "a couple hundred hours" of legal to verify their compliance.

But the proposal as stated doesn't require formal compliance reviews, making it hard to support an argument that this proposal would somehow cost more than many other regulations that do have that requirement, and for which my firm has done significant engineering and compliance work without spending a hundred hours talking to legal.

But, no, it turns out that's not the argument. The real argument is that the proposal requires auditors, for which legal will have to be deployed prophylactically. Now, the proposal does not in fact have an auditor requirement, but also, the clause that discusses auditors goes out of its way to make it clear that the types of third parties they're referring to are technical experts, which startups already use.

So the argument changes again. Now the argument is that regardless of the specific construction in the proposal (again, these specifics were all brought to the discussion by you!), it would be prohibitively expensive for startups because a lawyer would have to take time to verify the meaning of the law for the startup.

I point out that this is an argument that applies equally to pretty much any privacy or security law, and you respond that this is one is a special case because of the prison time and fines (the "breathtaking" fines are part of the same clauses as the prison liability) --- thus resurrecting the original false claim.

This doesn't read to me like a good-faith argument.

It's of course fine to make the argument that any new regulation would impede startups and would therefore not be worth the trouble (there are other arguments against this proposal you could just as easily make; for instance, that the field isn't mature enough for us to have the FTC use rulemaking authority to establish cybersecurity requirements for startups).

But if those are the kinds of arguments, you're making, make them. Don't move the goalposts.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#224

Earlier quoted context omitted.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I’m having trouble thinking of any other type of work that manages to escape all liability.

So the app developer has to be able to demonstrate they followed some form of best practice with regard to user data. I think you're downplaying the requirements of this law. You should read it, it's pretty onerous and carries decades in prison with it - even GDPR didn't go that far. One interesting caveat, however, is that at least as written, I can't find anything imposing penalties for simply not filing the report…

draft legislation

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#225

Earlier quoted context omitted.

Companies will have a Chief Privacy Officer whose job is basically to provide oversight and, of course, absorb the risk. That person will probably be paid well. I'm actually OK with that. We're always complaining that companies don't take security/privacy seriously because there's no incentive to do so. See e.g. the Equifax HN threads. Having a person in the C suite who'll end up in jail if the company seriously fuck…

I just hope it’s crafted such that it won’t inhibit small businesses or hobbyists.

That's exactly my hope. Only large companies benefit from such laws (including, potentially GDPR), other smaller ones get slowed down. With gdpr, many newspaper outlets stopped access from outside of the US.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#226

Earlier quoted context omitted.

They have to knowingly and intentionally lie to the federal government in an annual report So it's a nonstarter, since the people being prosecuted for these things will have lawyers adept at whittling down intent to only the most brazen and malicious behavior. Not only that, but Sarbanes-Oxley showed us how effective "annual report" red lines are.

Perhaps. But that's not a compelling argument against this bill. Perfect enemy of better and all that.

I agree that the nirvana fallacy is implicated, but there were zero convictions under SarbOx, zero prosecutions even.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#227
post #176
post #15

Earlier quoted context omitted.

> I strongly suspect the only people criminally prosecuted under such a bill will be patsies The only people that can be prosecuted under it are the chief executive officer, the chief privacy officer, and the chief information security officer. The thing that is criminal under this bill and thus can subject them to prosecution is, despite what most news stories imply, not violating privacy. The bill requires the comp…

> are the chief executive officer, the chief privacy officer, and the chief information security officer. So what you are saying is companies should make sure not to have the latter two positions? A CEO gets paid enough they can handle the risk, but the other two positions don't make nearly enough to exist in the face of risk like this.

Is it really a big risk?

The annual report has to describe in detail whether the company complied with the regulations in accordance with subparagraphs (A) and (B) of section 7(b)(1), and to the extent that the company did not list which regulations were violated and how many consumer's personal information was impacted.

7(b)(1)(A) requires the company "to establish and implement reasonable cyber security and privacy policies, practices, and procedures to protect personal information used, stored, or shared by the covered entity from improper access, disclosure, exposure, or use".

7(b)(1)(B) requires the company "to implement reasonable physical, technical, and organizational measures to ensure that technologies or products used, produced, sold, offered, or leased by the covered entity that the covered entity knows or has reason to believe store, process, or otherwise interact with personal information are built and function consistently with reasonable data protection practices".

To be criminally liable the officer has to certify the report "knowing that the annual report accompanying the statement does not comport with all the requirements set forth in this section".

In other words, to be criminally liable the officer has to lie to the FTC.

The main risk it seems to me is that the officers might be given false information from underlings, leading the officers to believe the report is accurate when it is not. If the FTC discovers this, their initial suspicion will be that the officers were the ones that lied. If the officers keep good records of where they got the information they relied on when certifying the report, they should be OK, although it will certainly be something of a hassle.

This only applies at companies with $1 billion or more in annual revenue that deals with personal information on more then 1 million consumers or consumer devices, or that deals with personal information on more them 50 million consumers or devices.

I'd expect a CPO or CISO at such a place is paid well enough to handle this.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#228
post #210

Earlier quoted context omitted.

That's a non-sequitur response; all of these are VC-funded startups that could easily have paid to comply with this proposal.

There are (I have reason to believe) plenty of non-VC funded social media apps. Easy to make, and people think they’re going to be as big as Facebook. I think that type of app will still get made, as people who can’t sort out funding are people I don’t expect to know the law.

I'm sure there are, but those aren't the examples that were just provided!

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#229

Why are bills like these always drafted after the fact? E.g. Equifax, Google+, Facebook hack, etc. It would be common sense to pass laws before it happened and would of incentivize companies to beef up security.

Or make the bill retroactive ... ?

If it'll retroactively apply criminal penalties you're going to need a companion amendment to the Constitution.

Re: Prison time, hefty fines for data privacy violations: draft U.S. Senate bill

#230

Earlier quoted context omitted.

> The ratings agencies lied They published opinions about the future performance of certain securities. Those opinions were incorrect. Lying would mean misrepresenting the present state of those securities, which they didn’t do. Everyone know they were buying subprime mortgages. They just expected them to trade like prime mortgages.

So is the only difference between lying and knowingly misleading the point in time of the subject in question?

> the only difference between lying and knowingly misleading the point in time of the subject in question?

If I say “this stock will rise in value” and then it doesn’t, that isn’t lying. If I say that while knowing the CEO is committing felonies, it still wouldn’t be lying, but it would be problematic. If I say “this is a share of Apple” when it’s actually Twitter, that’s lying. Bad forecasts aren’t lies, they’re mistakes.

The rating agencies’ role in the crisis is interesting and nuanced, and it is difficult to fault anyone other than the investors who over-relied on (and arguably misinterpreted) their guidance.

If you look at every security the agencies rated AAA, they performed as expected in cash flows. The underlying mortgages were mostly garbage, but some kept paying. That meant the top tranche of those structures, the tranches that got a high rating, kept paying.

If you held to maturity, the securities performed as promised. (Cf: if the government hadn’t bailed out AIG, they may not have.) The problem was they crashed in value in the interim because people began doubting if they would perform. That was a problem for liquidity-constrained investors, which was almost everyone in 2008. Rating agencies don’t say “this bond won’t trade at 50¢ on the dollar.” They say “this bond will probably pay you back.” And in the latter assessment, they were surprisingly accurate. The problem was people took the second to mean the first.

Post reply on HN