5 ms·
> Is it time for us to simply accept that it's inevitable that, at some point, everything will be hacked, and hacked often? I disagree. I’d take the Economists
by jrue 8y ago
> Is it time for us to simply accept that it's inevitable that, at some point, everything will be hacked, and hacked often?
I disagree. I’d take the Economists route, which is looking for the incentives that drive motivation. If companies were held to a higher standard of accountability, imagine how many would beef up their security. For decades, security researchers have been poking fun at how ridiculous some of these sites are at handling security, and nothing ever happens.
Now, imagine if there was severe economic accountability to a company that was hacked. Perhaps payouts to each person affected (in this case, to all 150m). I imagine you’d see security become a top priority very quickly at most companies.
- nkkollaw 8y agoIn Europe you have GDPR, there are huge fines for stuff like this.
- ams6110 8y agoHave any fines actually been levied and enforced?
- nkkollaw 8y agoDefinitely. Here is an example: https://www.insideprivacy.com/data-privacy/portuguese-hospital-receives-and-contests-400000-e-fine-for-gdpr-infringement/ https://www.insideprivacy.com/data-privacy/portuguese-hospit.... There are also many, many more examples for smaller companies that get fined 5000-20000.
- Choco31415 8y agoYes, there have been some enforcements already: [0] https://www.bleepingcomputer.com/news/security/first-gdpr-sanction-in-germany-fines-flirty-chat-platform-eur-20-000/ https://www.bleepingcomputer.com/news/security/first-gdpr-sa... The Flirty chat app is fined for leaking 808,000 emails to the tune of 20,000 EUR. [1] https://news.ycombinator.com/item?id=18531588 https://news.ycombinator.com/item?id=18531588 The Cuddly chat app is fined for using plaintext password storage to the tune of 20,000 EUR. (No hack known as of yet?) [2] http://fortune.com/2018/11/27/uber-eu-data-hack-fines/ http://fortune.com/2018/11/27/uber-eu-data-hack-fines/ As foreword, this occurred under older privacy laws and not quite GDPR. Many sources agree that GDPR would increase fine sizes in a repeat event. Due to a data breach at Uber exposing 57 million people's records, they were fined 600,000 EUR by the Netherlands and 385,000 GBP by the UK. [3] See nkkollaw's comment below/above.
- Phlarp 8y agoThat's hardly even a speeding ticket for Uber. As long as the fines are this low companies of sufficient size simply treat this as a cost of doing business.
- iagooar 8y agoThey are this low because they have only started fining companies. If Uber breaks the law again, the fine will be a lot higher.
- blacksmith_tb 8y agoIt appears that the maximum fine is 4% of a corporation's global earnings[1] which could be a lot of money, but still "just a cost of doing business" at the same time. 1: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation#Sanctions https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
- isostatic 8y agoGlobal turnover. "Earnings" tends to mean profit. Uber is somewhere around $10b gross revenue, so $400m fine for every breach. Sure it's "just a cost of doing business". It also means that it's better to spend $200m beefing up their security to reduce from 1 data breach every year to one every 5 years. Marriot revenue is $23b, so that's a potential $920m fine. IHG (say), who invest in security and don't have a breach, get to charge less for their hotels, or make more profit.
- nkkollaw 8y agoI thought the same thing, but I was corrected here on HN: if you read the same exact like you posted, it says "a fine up to €20 million or up to 4% of the annual worldwide turnover of the preceding financial year in case of an enterprise, whichever is greater", so the they ARE allowed to fine you EUR 20 million. Much more than "just a cost of doing business" for the majority of companies.
- closeparen 8y agoFining the company does nothing for the user whose data got leaked. Identity theft isn't a matter of degree; deterring future leakage has zero value. Either there's enough information on the black market to impersonate someone, or there isn't.
- nkkollaw 8y agoSo, are you for eliminating prisons? If I kill somebody, that person isn't there anymore, you don't think deterring other from killing other people isn't reasonable?
- closeparen 8y agoI think making it harder to fence stolen goods is a better use of time than increasing the penalties for theft.
- chibg10 8y agoAs a developer, do you really want to live in a world where "security is a top priority" at every company? Does such a world even make economic sense after accounting for the opportunity cost of the time most that developers would otherwise spend actually building new products and features? While companies could probably do better than they are right now, hacks like this are probably never going to be eliminated. There are too many companies and too many developers for nobody to make mistakes, even when they're being mindful not to. Investing in solutions that assume hacks will happen seems reasonable to me.
- philipodonnell 8y agoAs a developer, no. As a consumer, yes.
- rubber_duck 8y agoI doubt it - it would increase the cost and slow down the innovation for questionable gain.
- paulie_a 8y agoAs a developer yes. If that cost can't be baked into building new products, either the developer needs to learn how to emphasize the importance, or that company needs to go out of business.
- groby_b 8y agoAs a developer, yes. I really wish more developers had at least a basic ethical grounding and didn't just go "fuckit, revenue!". (Or, in larger companies, "fuckit, my boss told me") And when you consider opportunity cost - even just double-checking you aren't affected takes a minute of time, as a consumer, that means this hack just wasted close to a thousand years of human life. Where's the accounting for the opportunity cost of that?
- stanleydrew 8y agoOnly a handful of people will actually bother to check whether they were affected.
- closeparen 8y agoEither your information is known to an attacker, or it isn't. Great security "at most companies" in a hypothetical future doesn't help. You need security better than the best attacker, at every company, all the time. That's a pipe dream. Instead we should take advantage of public-key cryptography, so that authenticating to one company does not leave behind infinitely reusable credentials for others.
- bparsons 8y agoAgreed. Statutory, automatic penalties for data mishandling or negligence need to be brought in. Right now, there are few penalties, outside of a brief reputational hit, for large firms that lose control of customer data.
- DanielBMarkham 8y agoThat's wrong for many reasons. Others have covered the simple fact that you couldn't start any app with lots of users and zero capital. The downside is huge. Barriers to entry become more impossible than they already are. But that's not the worst of it. The Economist here is doing a static analysis, oddly enough. They're making the simple observation that if things cost more or have more risk, they get more attention. That's if they have more risk today. Once you collect data, it doesn't go anywhere. Every bit that sits on your servers can easily be copied to another server, today, tomorrow, ten years from now. Do you know what all the bits are on your computers? This isn't copyrighted DRM or porn. You could have a blob hashes and userids. If I put that on your computer, would you know? Could you be expected to find it? Know what it was? As Facebook and the other platforms are demonstrating, this data continues to have value many years after it was collected. And once somebody gives some data to you, it's effectively both invisible and trackless. Over long periods of time, your cost becomes infinity to maintain this risk. Meanwhile, attack vectors get better and people come and go out of your offices all the time. Could you manage that risk? Forever? I can't think of _any_ sensitive data on the web that's stayed safe. Why would attaching any amount of value change that?
- james_s_tayler 8y agoSo far the market has decided that she economics for protecting users and protecting data just isn't there and that's why we see what we see. That's why GDPR happened. "Ok, if you're not going to do anything about it, we'll make you do something about it." So you're not taking the economists point of view at least from the perspective of the free market rather you're thinking about which economic levers you could pull to effect change from a regulators point of view.