This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong.
Given that risk, as much as I don't want to live in an overly litigious society, letting the risk of lawsuits drive good security may be preferable to putting security in the hands of a few faceless government officials who themselves face no repercussions for getting the regs wrong.
Engineers, capitalism, private business have utterly, completely, fully and in totality failed.
This is not a little failure. Not a medium one. Not a large one.
This is a foundational, cataclysmic failure of the most epic proportion.
I think the time for voluntary private action has passed.
If developers, their managers, their stakeholders, and their shareholders took security and privacy remotely seriously, we would not be here.
We are here.
It is time to admit the full and complete failure of private software companies to protect data and privacy, and time for government to create a criminal schedule for management and developers who perpetuate criminal negligence.
I believe only 2 things will solve this:
1) Massive financial loss for shareholders -- they speak 1 language, US Dollars. If we say a US Citizens data is worth $100,000, then the fines would be large enough to literally destroy any firm who dared play loose with security. If there is no existential risk, there is zero motivation for compliancy. Only existential risk matters to shareholders. The rest is Cost of Doing Business.
2) Criminal liability for management and developers of products which violate security and privacy due to criminal negligence
Without this, you can all but guarantee that your full identity is kept in plain-text and has already been stolen.
The DNC was hacked. The FBI and CIA have had their web sites hacked. The OPM had >22 million people's personal info stolen by Chinese hackers. The NSA itself has had major incidents where essentially cyber weapons were leaked. Those are just SOME of the ones we know about.
Let's stop pretending like government is any more capable, or even as capable, of protecting data than competent corporations. When was the last time Facebook or Google had massive data breach? It's not about 'the corporations maaan' it's about competency and the limited consequences of screwing up so bad.
There is such a thing as punitive damages but in most civil cases a company or individual is not going to be held liable for more than actual damages.
Banks are usually happy to provide you with a credit line many times your net worth if you have a reasonable credit score.
The threat of lawsuits already existed before this hack. Look at the multi-million payout Target paid after their credit card breach (and they say it cost their company ~200mil). So that was STILL NOT ENOUGH to change Equifax's behavior.
Improved government oversight/regulation of this industry is more than overdue. This is a national security issue and we should not have our data (and the means of protecting it) held hostage by private companies.
Who is banned from using computers? You mean, in prison?
From Wiki:
>Samy Kamkar, the author of the worm, was raided by the United States Secret Service and Electronic Crimes Task Force in 2006 for releasing the worm.[4] He entered a plea agreement on January 31, 2007 to a felony charge.[5] The action resulted in Kamkar being sentenced to three years probation with only one computer and no use of internet,[6] 90 days community service, and $15,000-$20,000 USD in restitution, as directly reported by Samy Kamkar himself on "Greatest Moments in Hacking History" by Vice Media's video website, Motherboard.
There have been cases of people being banned from using any personal computer.
http://www.loc.gov/pictures/resource/fsa.8b15572/
Context:
> Bouk, Dan. How Our Days Became Numbered: Risk and the Rise of the Statistical Individual (pp. 232-233). University of Chicago Press. Kindle Edition.
> In the case of Lange’s unemployed lumber worker, we find a man who might have opted for a tattoo because it could identify him in the case of an accident. After all, he did dangerous work. Or, as he paid money into the Social Security system, he may have wanted to ensure he’d one day be able to redeem his annuity, that he would not forget his number. Neither explanation, however, encompasses his evident pride in his number, his willingness to show off for Lange (who undoubtedly encouraged him, maybe posed him).
> Was he proud to have been, as the New York Times had put it, a “holder” of a Social Security number? Possessing such a number meant a promise of future income, protection for himself, and— after the just-completed 1939 amendments that included expanded support for families— protection for his wife and future children against his old age or death. 76 Maybe he felt pride in the New Deal, in a government committed to him and his family, and advertised that pride on his bicep. Or perhaps, his tattoo displayed a workingman’s pride in his gender and class identities. Possessing such a number signaled his status as an industrial worker. Such status mattered in a bean-picking camp where most pickers had been excluded from eligibility for Social Security. Possessing an account set this unemployed lumber worker apart, probably even from his bean-picking wife.
This is some Mr. Robot / Fight Club shit. Get it over with.
This whole mess could be trivially fixed by credit bureaus introducing a PIN for every person and require it for opening a new credit line (issue is whether they could keep it safe, but at least it would resolve this problem).
They even already have such mechanism in place, which is done through freezing the file. The problem is that for some crazy reason we are charged when we are trying to protect ourselves.
819