I know it is a subsidiary of paypal, not paypal itself, but that is irrelevant.
I know it is a subsidiary of paypal, not paypal itself, but that is irrelevant.
I got into a discussion once about how to properly handle passwords (cause somebody has to do it). There is no right answer, just lots and lots of wrong ones. Don’t encrypt, hash. But not that hash, use another...and not any of those over there; and sure as shit don’t write one yourself. Use an off-the-shelf hash...just not any that you have access to now. Not that one either, we don’t recognize the author by name...and not the other one because we don’t like the owner of the company (who is not a developer).
TL:DR, if you write code that needed security...eventually you are fucked.
> Not that one either, we don’t recognize the author by name...and not the other one because we don’t like the owner of the company (who is not a developer).
This is quite obviously bad rhetoric (outright dumb, I'd say.) But let's say it's remotely true: you think "complete dysfunction, and inability to analyze root problems" -- that it's a reason why we shouldn't crack down these people?
Doctors make mistakes. Everyone knows that. Sometimes it's negligence, sometimes it's tragedy, sometimes it's just random happenstance or Friday the 13th or whatever. But for some reason, we don't interpret this as a blank cheque to let any jackass on the street legally operate on people, risking their lives, and then -- when they hurt someone -- we all throw up our hands, sigh, and say -- "well dang, at least Frito Pendejo, he tried really hard, tried his best and doctors, y'know, medicine is crazy and uncertain!!! there are no right answers!!!"
If a company decides to collect, store and profit off of my personal data and they lose it, I really don't care about "best practices". They profited from my data, they have to pay if they lose it. The company always has the choice of not storing the data in the first place, if they can't bear the risk of a substantial fine in case my data is disclosed.
Perfect security is impossible, but let's not forget 1) who is harmed, or 2) who is getting rich and who will in a worst case will cut their losses, go bankrupt, then start another company with the accumulated weath.
So the real issue should be: When and how will a new secure form of identity be created, used, and made available. Social security numbers were never intended to be used in the manner in which they are.
I'm allowed access to the information, and can request that it be updated. They can't keep the information longer then is necessary, they can't use it for anything other than the original collection purposes, they have to take reasonable measures to secure it, they can't disclose it etc.
I won't harp on about the details, but it's relatively well thought out (apart from some limitations regarding the reporting of breaches, but there are changes in the pipeline to patch that up).