Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Somewhat agreed, but couldn't our legal tools instead/also be focused on the organizations that take responsibility for storing our data? Fines for allowing user data to be breached may stimulate development of tools and methodologies better able to protect private data and rules that limit sharing of user data can protect us from even the well-financed malevolent actors.

Focusing on this side of the coin may allow us to realize systems that actually do protect our data from being compromised as opposed to spending our resources tracking down individuals and attempting to apply legal tools which the most successful criminals will soon adapt to evade anyway.



I think the problem with this thinking is that even without explicit fines, the costs of a data breach are already incredibly high for companies. There's the potential loss of sales for a customer-facing business, as well as costs of class action lawsuits, system cleanup, etc. Sony Pictures was crippled by a cyberattack. Target's CEO was forced to resign. So, maybe fines would make this situation better, but CEO's should already be up at night worrying about cybersecurity.

My inclination would be to pursue better security, but also to go after the really sophisticated cybercriminals that are currently outside the reach of our legal system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: