"This could go really wrong if we let non-tech savvy regulators dictate tech stacks, specific hashing/encryption tools. Could work well, but just has a lot of potential to go very wrong."
Engineers, capitalism, private business have utterly, completely, fully and in totality failed.
This is not a little failure. Not a medium one. Not a large one.
This is a foundational, cataclysmic failure of the most epic proportion.
I think the time for voluntary private action has passed.
If developers, their managers, their stakeholders, and their shareholders took security and privacy remotely seriously, we would not be here.
We are here.
It is time to admit the full and complete failure of private software companies to protect data and privacy, and time for government to create a criminal schedule for management and developers who perpetuate criminal negligence.
I believe only 2 things will solve this:
1) Massive financial loss for shareholders -- they speak 1 language, US Dollars. If we say a US Citizens data is worth $100,000, then the fines would be large enough to literally destroy any firm who dared play loose with security. If there is no existential risk, there is zero motivation for compliancy. Only existential risk matters to shareholders. The rest is Cost of Doing Business.
2) Criminal liability for management and developers of products which violate security and privacy due to criminal negligence
Without this, you can all but guarantee that your full identity is kept in plain-text and has already been stolen.