331 points by throw7 1 day ago | 109 comments | View on ycombinator
augment_me 1 day ago |
prologic 1 day ago |
SoftTalker 1 day ago |
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
hn_submit 1 day ago |
Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
_the_inflator 1 day ago |
So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass.
If the Berlin incident remotely had happened to any private company - hell would have been loose.
Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.
roundup 1 day ago |
markhahn 1 day ago |
Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.
xp84 1 day ago |
Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.
I'm thinking:
(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)
- Name and address or name and phone number leak: $100 per customer affected.
- Email: $50 per customer affected, or $100 if tied to any other data.
- Social Security numbers: $2000 per customer affected
- Unsalted or plaintext passwords: $500 per customer affected.
- Cap is the greater of 200% of annual EBITDA, or 20% of revenue
Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.
This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.
My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
ggarnhart 1 day ago |
guillybarres 1 day ago |
__natty__ 1 day ago |
pstoll 1 day ago |
jmclnx 1 day ago |
* Before Tax Revenue
* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.
* Includes Worldwide Revenue
* Includes companies based in all other Countries.
I would have went for 20%, but if he above applies I wish the US would do the same.
quickthrowman 1 day ago |
aucisson_masque 1 day ago |
10% maximum mean nothing if it’s not enforced, you got to make examples.
happytoexplain 1 day ago |
rectang 1 day ago |
nosmokewhereiam 1 day ago |
Edit: "That'll be $23B. Cash or card?"
Minimizes money usage and does not require any security investments