Companies behind major negligent data leaks can now face fines of up to 10 percent of annual revenue under revised privacy rules.
115 comments
Minimizes money usage and does not require any security investments
Courts are run by people, not AI, so judges can easily ignore the corporate entity once these laws are passed.
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down because most businesses cannot survive that? We have to remember who is the original criminal here.
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
Seagate will not in a million years sign anything like this when you buy a HDD.
Sort of like EULA's a lot of the "value" is incredibly theoretical.
guess who holds the bag if capacity needs collapse
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
You can’t. You don’t need source for that, just common sense.
Exploits are discovered every day, bugs happen, bad actors.
You can do the best system, shit still happen.
BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?
If the cia couldn’t prevent it, I bet you can’t.
You can make a system "more" secure than other systems, but you cannot make it truly secure.
For one, the lack of any secure computing systems.
Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
Read the full thread on Hacker News →
Related stories
- Hacker News · 6 points · about 9 hours ago
- Hacker News · 1 points · about 10 hours ago
- Hacker News · 68 points · 9 days ago
- Hacker News · 377 points · 16 days ago
- Data Breach at Health Insurer Anthem Could Impact Millionskrebsonsecurity.comLobsters · 3 points · over 11 years ago
- 2015 Office of Personnel Management data breachen.wikipedia.orgHacker News · 1 points · 8 days ago