this post was submitted on 09 May 2024
467 points (99.2% liked)

Technology

59424 readers
2893 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 6 months ago

If a company ruins people's lives, I'm okay with them disappearing and all their investors losing their shirts.

I agree that a company that can't afford to pay for the damage it is causing is doing more harm than help and should go away.

What I think we can both absolutely agree on, is that the current system where companies forcibly collect all kinds of information on people, don't take security seriously, get breached, and the only punishment that happens is a few million dollars fine they can just write a check for and everyone affected gets a year of credit monitoring, is a broken system. In many of these breaches, they happen because the data was stored so poorly one could make a serious argument for gross negligence. When a company does this and the punishment is a wrist slap, I have a problem with that. It becomes a cost of doing business, not something company management is actually afraid of.

Also, as somebody who actually works in IT, I can tell you cyber insurance is a thing. For small businesses it covers this sort of breach. When you sign up for it they send you a whole questionnaire that asks about your security practices. It's all boilerplate bullshit. Real cybersecurity involves an insane amount of complexity and required understanding at every level, and the insurance questionnaire is like do you use multi-factor authentication for your email y/n?. If you check no you get a higher insurance premium.

Perhaps a solution would be a mandatory payment of $250 per person made directly to that person if their information is breached. And if the company fails to report it within 60 days, it triples. If the company intentionally conceals it, it quadruples. And should the company go bankrupt and liquidate, these payments to users will be considered the primary creditor and take priority over all others. So no more of this '$10 discount on your next purchase and a year of credit monitoring' class action settlements, put some real fucking teeth in a law. People would get some real compensation. And personal information would no longer be seen as a $20/person asset but rather as a potentially destroy the company liability.