Hacker News new | ask | show | jobs
by delta_p_delta_x 29 days ago
> Leaking PII should be very, very expensive

It should be criminal to leak PII, and company leadership should face imprisonment.

5 comments

Yes please! Making PII leaks an expense (like rent and cloud costs) means it's paid by the customer.

I strongly believe we should distinguish the price of doing the operation (aka rent) and the price of doing crime (ideally, jail).

Everything is paid for by the customer. If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.
Yep -- and it's good.

Before: customer pays fines for bad security, rolled into the price of the offering.

After: customer pays for actual good security, rolled into the price of the offering.

If the customer doesn't care, no change. If the customer cares (and let's low key assume PII is important) -- they see net gain from this change.

If only! I would much rather the bill go up then my information get leaked. But instead, I get both.
> If you spend an absolute fortune protecting someone's named and address combination, that will be paid for by the customer.

And then you get your lunch eaten by a competitor who understands that the PII is unnecessary for the business relationship.

But only if that externality is actually accounted for in regulation.

So then the customer will just pay more, because the "prevent you from getting fined into oblivion" insurance businesses you just created with the flick of a pen will need to get paid their overhead and won't do it without a profit.
Then over confident, short sighted or shady characters will accept those directorships and/or sign off on the design because they think nothing will happen or don't care for jail.
Every time I send a work email I leak my pii. We should all use government issued uuids on linked in / facebook.
I used to have a book dropped off at my house that had the names, phone numbers, and physical addresses of everyone in my area.
What you didn't have was a computerised database which could spam everyone on that list in milliseconds, or profile everyone's character, purchase history, medical history, and more.

We used to do a lot of worse stuff too, like eat radium hoping for brighter skin.

Are you seriously comparing an analog phonebook to machine-searchable structured data made available in a data breach?
I'm saying allowing distributing books but criminalizing distributing the digital version is an overrotation.

As much as extreme viewpoints play well on the internet.

I shouldn't be able to say your name?

There's always a budding authoritarian ready to trample freedom of expression for the common good.

I shouldn't be able to say your name? What sort of authoritarian regime do people like you want?