143 points throw7 1 hour ago 41 comments
quickthrowman 41 minutes ago | parent
google234123 38 minutes ago | parent
Retro_Dev 5 minutes ago | parent
Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
prologic 38 minutes ago | parent
augment_me 34 minutes ago | parent
jmclnx 37 minutes ago | parent
* Before Tax Revenue
* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.
* Includes Worldwide Revenue
* Includes companies based in all other Countries.
I would have went for 20%, but if he above applies I wish the US would do the same.
augment_me 36 minutes ago | parent
Minimizes money usage and does not require any security investments
louthy 34 minutes ago | parent
augment_me 33 minutes ago | parent
louthy 31 minutes ago | parent
It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.
So, there is that.
nostrademons 24 minutes ago | parent
Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.
louthy 13 minutes ago | parent
Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.
I did it because:
* it’s the right thing to do
* for professional pride
* and so I could sleep at night
And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection by the industry as a whole made it seem like it would be survivable.
I still walked away from it a wealthy man. Being competent and caring about your customers (and being able to sleep at night) doesn’t have to mean failure like it seems everyone here thinks.
pluc 30 minutes ago | parent
toomuchtodo 27 minutes ago | parent
To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.
(cyber consultant and practitioner)
x3n0ph3n3 25 minutes ago | parent
toomuchtodo 25 minutes ago | parent
I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.
TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.
bluGill 10 minutes ago | parent
my-huge-pony 11 minutes ago | parent
I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.
SoftTalker 5 minutes ago | parent
augment_me 5 minutes ago | parent
If this is not possible no cloud storage would ever be possible to be liable for anything. Your Google drive got hacked? Your responsibility.
AIiscoming 9 minutes ago | parent
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
ranger_danger 27 minutes ago | parent
dmos62 26 minutes ago | parent
micromacrofoot 18 minutes ago | parent
guess who holds the bag if capacity needs collapse
EA-3167 11 minutes ago | parent
Sort of like EULA's a lot of the "value" is incredibly theoretical.
amelius 13 minutes ago | parent
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
augment_me 7 minutes ago | parent
Seagate will not in a million years sign anything like this when you buy a HDD.
imnotr0b0t 8 minutes ago | parent
SoftTalker 35 minutes ago | parent
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
bluGill 7 minutes ago | parent
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
rectang 31 minutes ago | parent
esafak 11 minutes ago | parent
ggarnhart 14 minutes ago | parent
Retro_Dev 9 minutes ago | parent
happytoexplain 12 minutes ago | parent