10 ms·
To me, what's missing from that set of recommendations is some method to increase the liability of companies who mishandle user data. It is insane to me that I
by srndsnd 2y ago
To me, what's missing from that set of recommendations is some method to increase the liability of companies who mishandle user data.
It is insane to me that I can be notified via physical mail of months old data breaches, some of which contained my Social Security number, and that my only recourse is to set credit freezes from multiple credit bureaus.
- alsetmusic 2y agoRegulation is key, but I don’t see it as likely when our society is poisoned by culture war bs. Once we put that behind us (currently unlikely), we can pass sane laws reigning in huge corporations.
- OkeyDokey2 2y ago[flagged]
- zeroonetwothree 2y agoIf you aren’t directly harmed yet what liability would they have? I imagine if your identity is stolen and it can be tied to a breach then they would already be liable.
- drawkward 2y agoSurveillance apologist.
- kibwen 2y agoThe fact that my data can be stolen in the first place is already outrageous, because I neither consented to allowing these companies to have my data, nor benefit from them having my data. It's like if you go to an AirBNB and the owner sneaks in at night and takes photos of you sleeping naked and keeps those photos in a folder on his bookshelf. Would you be okay with that? If you're not directly harmed, what liability would they have? Personal data should be radioactive. Any company retaining it better have a damn good reason, and if not then their company should be burned to the ground and the owners clapped in irons. And before anyone asks, "personalized advertisements" is not a good reason.
- pc86 2y agoI mean it's pretty clear that you are directly harmed if someone takes naked photos of you without your knowledge or consent and then keeps them. It's not a good analogy so if we want to convince people like the GP of the points you're making, you need to make a good case because that is not how the law is currently structured. "I don't like ads" is not a good reason, and comments like this that are seething with rage and hyperbole don't convince anyone of anything.
- drawkward 2y agoWhat is the harm? It is not obvious to me, if the victim is unaware...unless you are alleging simply that there is some ill-defined right to privacy. But if that is so, why does it apply to my crotch and not my personal data?
- simoncion 2y agoThese are exactly my questions. If I never, ever know about those pictures and never, ever have my life affected by those pictures, what is the actual harm to me? If the answer to them ends up being "Well, it's illegal to take non-consensual nudie pictures.", then my follow-up question is "So, why isn't the failure to protect my personal information also illegal?". To be perfectly clear, I do believe that the scenario kibwen describes SHOULD be illegal. But I ALSO believe that it should be SUPER illegal for a company to fail to secure data that it has on me. Regardless of whether they are retaining that information because there is literally no way they could provide me with the service I'm paying them for without it, or if they're only retaining that information in the hopes of making a few pennies off of it by selling it to data brokers or whoever, they should have a VERY SERIOUS legal obligation to keep that information safe and secure.
- lcnPylGDnU4H9OF 2y ago> to fail to secure data that it has on me Just want to point out that the company is usually also doing what it can to get other information about you without your consent based on other information it has about you. It's a lot closer to the "taking non-consensual nudie pictures" than "fail to secure data" makes it sound.
- drawkward 2y agoGo ahead, post your phone number here. It's not directly harmful.
- blondelegs 2y ago1-800-call-FEDS
- drawkward 2y agoBahahaha :)
- idle_zealot 2y agoThat's the whole problem with "liability", isn't it? If the harms you do are diffuse enough then nobody can sue you!
- bunderbunder 2y agoThis is exactly why thinking of it in terms of individual cases of actual harm, as Americans have been conditioned to do by default, is precisely the wrong way to think about it. We're all familiar with the phrase "an ounce of prevention is worth a pound of cure", right? It's better to to think of it in terms of prevention. This fits into a category of things where we know they create a disproportionate risk of harm, and we therefore decide that the behavior just shouldn't be allowed in the first place. This is why there are building codes that don't allow certain ways of doing the plumbing that tend to lead to increased risk of raw sewage flowing into living spaces. The point isn't to punish people for getting poop water all over someone's nice clean carpet; the point is to keep the poop water from soaking the carpet in the first place.
- supertrope 2y agoSafety rules are written in blood. After a disaster there’s a push to regulate. After enough years we only see the costs of the rules and not the prevented injuries and damage. The safety regulations are then considered annoying and burdensome to businesses. Rules are repealed or left unenforced. There is another disaster…
- bunderbunder 2y agoTangentially, there was an internet kerfuffle about someone getting in trouble for having flower planters hanging out the window of their Manhattan high rise apartment a while back, and people's responses really struck me. People from less dense areas generally saw this as draconian nanny state absurdity. People who had spent time living in dense urban areas with high rise residential buildings, on the other hand, were more likely to think, "Yeah, duh, this rule makes perfect sense." Similarly, I've noticed that my fellow data scientists are MUCH less likely to have social media accounts. I'd like to think it's because we are more likely to understand the kinds of harm that are possible with this kind of data collection, and just how irreparable that harm can be. Perhaps Americans are less likely to support Europe-style privacy rules than Europeans are because Americans are less likely than Europeans to know people who saw first-hand some of what was happening in Europe in the 20th century.
- halJordan 2y agoThis is the traditional way of thinking, and a good question, but it is not the only way. An able bodied person can fully make complaints against any business that fails their Americans with Disabilities Act obligation. In fact these complaints by able bodied well-doers is the de facto enforcement mechanism even though these people can never suffer damage from that failure. The answer is simply to legislate the liability into existence.
- squeaky-clean 2y agoThe same way you can get ticketed for speeding in your car despite not actually hitting anyone or anything.
- 2OEH8eoCRo0 2y agoI get a feeling that liability is the missing piece in a lot of these issues. Section 230? Liability. Protection of personal data? Liability. Minors viewing porn? Liability. Lack of liability is screwing up the incentive structure.
- brookst 2y agoI think I agree, but people will have very different views on where liability should fall, and whether there is a malicious / negligent / no-fault model? Section 230? Is it the platform or the originating user that's liable? Protection of personal data? Is there a standard of care beyond which liability lapses (e.g. a nation state supply chain attack exfiltrates encrypted data and keys are broken due to novel quantum attack)? Minors viewing porn? Is it the parents, the ISP, the distributor, or the creator that's liable? I'm not here to argue specific answers, just saying that everyone will agree liability would fix this, and few will agree on who should be liable for what.
- TheOtherHobbes 2y agoIt's not a solvable problem. Like most tech problems it's political, not technical. There is no way to balance the competing demands of privacy, security, legality, and corporate overreach. It might be solvable with some kind of ID escrow, where an independent international agency managed ID as a not-for-profit service. Users would have a unique biometrically-tagged ID, ID confirmation would be handled by the agency, ID and user behaviour tracking would be disallowed by default and only allowed under strictly monitored conditions, and law enforcement requests would go through strict vetting. It's not hard to see why that will never happen in today's world.
- malfist 2y ago> It's not a solvable problem Lawnmower manufacturers said the same thing about making safe lawnmowers. Until government regulations forced them to
- 2y ago
- arminiusreturns 2y agoI agree. Let me tell you about what just happened to me. After a very public burnout and spiral, a friend rescued me and I took a part time gig helping a credit card processing company. About 2 months ago, the owner needed something done while I was out, and got their uber driver to send an email. They emailed the entire customer database, including bank accounts, socials, names, addresses, finance data, to a single customer. When I found out, (was kept hidden from me for 11 days) I said "This is a big deal, here are all the remediations and besides PCI we have 45 days by law to notify affected customers." The owner said "we aren't going to do that", and thus I had to turn in my resignation and am now unemployed again. So me trying to do the right thing, am now scrambling for work, while the offender pretends nothing happened while potentially violating the entire customer base, and will likely suffer no penalty unless I report it to PCI, which I would get no reward for. Why is it everywhere I go management is always doing shady stuff. I just want to do linuxy/datacentery things for someone who's honest... /cry My mega side project isn't close enough to do a premature launch yet. Despite my entire plan being to forgo VC/investors, I'm now considering compromising.
- mikeodds 2y agoAs in.. his actual Uber driver? He just handed his laptop over?
- arminiusreturns 2y agoYes. The owner is old, and going blind, but refuses to sell or hand over day to day ops to someone else, and thus must ask for help on almost everything. I even pulled on my network to find a big processor with a good reputation to buy the company, but after constant delays and excuses for not engaging with them, I realized to the owner the business is both their "baby" and their social life, neither of which they want to lose.
- TinyRick 2y agoWhy would you resign? You could have reported it yourself and then you would have whistleblower protections - if the company retaliated against you (e.g. fired you), you then would have had a strong lawsuit.
- OkeyDokey2 2y ago[flagged]
- dylan604 2y agoThis does nothing for them being able to continue with shadow profiles and inferences about you based on data they gather from others in your social network. It is well beyond "data you provide". Like waaaaay beyond.
- OkeyDokey2 2y ago[flagged]
- bilekas 2y ago> To me, what's missing from that set of recommendations is some method to increase the liability of companies who mishandle user data. As nice as this is on paper, it will never happen, lobbyist exists. Not to be tinfoil hat but why would any lawmaker slap the hand that feeds them. Until there is an independent governing body which is permitted to regulate over the tech industry as a whole it wont happen. Consider the FDA, they decide which drugs and ingredients are allowed and that's all fine. There could be a regulating body which could determine the risk to people's mental health for example from 'features' of tech companies etc. But getting that body created will require a tragedy. Like why the FDA was created in the first place. [1] That's just my 2cents. 1 : https://www.fda.gov/about-fda/fda-history/milestones-us-food-and-drug-law#:~:text=1900%2D1909%3A%20FDA%20Milestones&text=digestion%20and%20health.-,Dr.,food%20and%20drug%20law%20grows.&text=The%20original%20Food%20and%20Drugs,signed%20by%20President%20Theodore%20Roosevelt https://www.fda.gov/about-fda/fda-history/milestones-us-food....
- Aerroon 2y ago>There could be a regulating body which could determine the risk to people's mental health for example from 'features' of tech companies etc. I think ideas like this is why it's not going to happen. Our understanding of mental health is garbage. Psychiatry used to be full of quackery and very well still might be. Treatment for something like depression boils down to "let's try drug in a random order until one works". It's a field where a coin-flip rivals the accuracy of studies. Therefore any regulating body on that will just be political. It will be all about the regulators "doing something" because somebody wrote enough articles (propaganda). Problems like this are why people aren't interested in supporting such endeavors.
- intended 2y agoThat is not the treatment for depression. this argument reduces mental health to medication, which leaves aside everything from the history of mental health (asylums, witch burnings to today), leaps in medicine (from lobotomies, to SNRIs, bipolar meds and more), to simply better diagnoses. There are certainly tons of people here who have benefited from mental health professionals - overextending the flaws in psych simply to dismiss the idea of a watchdog is several unsupported arguments too far.
- layer8 2y agoI’m completely sympathetic to making companies more liable for data security. However, until data breaches regularly lead to severe outcomes for subjects whose personal data was leaked, and those outcomes can be causally linked to the breaches in an indisputable manner, it seems unlikely for such legislation to be passed.
- Onavo 2y agoThen instead of regulating the companies, make SSN easily revokable and unique per service. I don't understand why Americans are so oppposed to a national ID despite the fact that every KYC service use SSNs and driver licenses.
- candiddevmike 2y agoBecause they're the mark of the beast or a step towards fascism or something. I don't think it would take much to convert real IDs into a national ID, they are as close to as they can get without "freaking people out".
- Nevermark 2y agoEmphasizing that the number can be changed would really help there. People could even generate their own number (private key), which they never gave out, and appeared differently to each account manager verifying it, and still replace them. When you choose your own number, it's only the Mark of the Beast if you are the Beast! * ** * 666, 13, 69 and 5318008 expressly prohibited. ** Our offices only provide temporary tattoos.
- mapt 2y agoThe expansion of KYC and the hegemonic dominance of our global financial intelligence network is a recent infringement on our privacy that would not necessarily pass popular muster if it became well-known. Most of our population is still living in a headspace where transactions are effectively private and untraceable, from the cash era, and has not considered all the ways that the end of this system makes them potential prey. The fact is that the market is demanding a way to identify you both publicly and privately, and it will use whatever it needs to, including something fragile like a telephone number 2fa where you have no recourse when something goes wrong. It's already got a covert file on you a mile long, far more detailed than anything the intelligence agencies have bothered putting together. The political manifestation of anti-ID libertarians is wildly off base.
- trinsic2 2y agoSounds like a bunch of crap the industry is already trying to sell the public and no its not working and yes we can do with out it.
- bhhaskin 2y agoIf your identity gets stolen, you should be able to sue all the companies that had a leak.
- nimbius 2y agoI think the only reason were seeing this revelation from a federal agency after 20 years is to boost the governments case against tiktok.
- runjake 2y agoYMMV, but it took me 15 minutes start to finish to freeze my credit with the 3 bureaus using the following instructions. https://www.nerdwallet.com/article/finance/how-to-freeze-credit https://www.nerdwallet.com/article/finance/how-to-freeze-cre...
- saagarjha 2y agoOk, but this is something that shouldn't be my problem. And it's not just that; I have to go unfreeze it if someone needs to run a credit check.
- runjake 2y agoRight, but you've got to do what's within your control, unless you're planning a Senate campaign and plan to resist significant and lucrative lobbying operations against you.
- wwmiller3 2y agoUnfortunately, that isn’t enough to mitigate identity theft. Someone leveraging the recent National Public Data breach opened a checking and savings account using my identity (no credit checks are performed in doing so) then committed wire fraud using accounts.
- jamesmotherway 2y agoBanks use various other services such as Early Warning. Still, it's absurd the lengths we need to go to for any level of assurance against fraud.
- tombrossman 2y agoYMMV indeed. Since moving overseas 15 years ago, I tried numerous times and it simply is not possible. All the forms require a U.S. mailing address to register. Same for online access to your Social Security account. There are an estimated 10 million Americans living overseas. Taken together, we are the equivalent of the 11th largest state. All of us completely blind to what is happening with our credit record and Social Security account. At this point I think the only way this gets fixed is massive fraud/exploitation by organized crime, so these organizations finally address the problem.
- closeparen 2y agoShared secrets are criminally negligent security architecture in 2024. We can authenticate identity and authorize payment without giving the relying party a token to leak or abuse. The energy behind this problem is good, but "everyone try harder to protect the shared secrets entrusted to you" would be a tragic waste of it.
- DoctorOetker 2y ago> [...] would be a tragic waste of it. The first time would have been a tragedy, from then on it has been farce after farce. Imagine a world where companies would have to prove the necessity of storing specific factoids. It would only take 1 security researcher to prove it being unnecessary, invalidating that class of "legitimate interests". Today this value judgement happens in human brains, like the (correct) judgement in your comment. If we want to scale it objectively we would have to switch to formal verification. A whole industry of compliance checking could come to exist where a company wants to get its operations screened for compliance issues, so as not to suffer criminal negligence penalties.
- closeparen 2y agoThe problem here is the payments industry (continuing to issue and accept "credit card numbers") and the voters (refusing to authorize a proper national ID). An individual entity that has to conduct business under these circumstances has no real alternative. You are not being harmed by the storage or leakage of a few bytes, that's ridiculous. You are being harmed by the financial industry and government's insistence that knowledge of these bytes is sufficient to take your property or hold a debt against you.
- pkphilip 2y agoBut reveal any "classified" information about the govt and you will end up in jail. The severe asymmetry between what a citizen can do and what the govt gives itself the right to do is crazy.
- m463 2y agothat, and removing the commercial trackers from this ftc.gov webpage... googletagmanager.com googleapis.com fontawesome.com addtoany.com sigh