At scale $50K still adds up to a lot, and we'd probably have to cap it some other way too because at-scale breaches don't add up that far, because the system does in fact react to them. This particular breach would be a seven trillion dollar payout if we don't cap it, and the simple reality is that this breach, no matter how much pain it may eventually cause us, is not going to cause anywhere near seven trillion dollar's worth of damage to consumers, or the economy, or anything else. But $50K makes sense for isolated cases that don't get a coordinated response.
I mean, really, once you get past the amount of assets that Apple holds, it's all the same penalty anyhow: Instant corporate bankruptcy. Arguing about whether we penalize a company trillions of dollars or quadrillions of dollars is not really an argument.
If you get it to work, we can then proceed to get rid of police departments.
Too bad the current party in power has only one mandate: tear down everything the last guy accomplished.
I can imagine at least some companies would stop worrying about security since they are insured if something goes wrong.
However, on the blockchain...well that might just happen, but it won't be a government running the identity system.
Summarize what you think this law is preventing in your words and we can compare it to what the law actually says.
[1]: But unfortunately they may be constrained by the aforementioned Privacy Act of 1974.
wouldn't disclosure of hacks (by Equifax) be strongly disincentivized with this scheme?
wouldn't Equifax just lie to the public if they discovered a hack so that their insurance premiums stayed low?
worse yet, would Equifax just eliminate security audits and stop looking for hacks altogether so they could plausibly claim their data was secure?
Maybe this would lead to a rise in secure storage firms that actually do their job with this so small outfits like employers could continue to identify employees without having to actually have a SSN in the database.
is the government going to do those? it doesn't seem to be able to do that sort of thing now. how will the government gain the resources, the capability?
i don't see the government doing a good job of regulation enforcement.
sometimes it's corrupt (e.g. building inspection approvals in Los Angeles, where I live, have sometimes required side payments to the inspectors).
sometimes it's underfunded. one source estimates that only 2% of imported food is inspected: http://www.nbcnews.com/id/44701433/ns/health-food_safety/t/f...
In fact, it's the best case scenario for the company, to make even more money by selling insurance for protecting the data you just gave them.