A massive cache of law enforcement personnel data has leaked
zdnet.com
zdnet.com
A hallmark of negligence right there. Hard to grasp why the protocols weren't followed in this specific instance by Texas State University (which was hosting the database) given the extreme sensitivity of the information content and adverse fallout that could result -- public exposure of personally identifiable information of thousands of law enforcement personnel across the country.
A perfect example of what happens when data security and integrity protocols are taken for granted.
My ignorant guess, someone who could have made an active decision instead vaguely thought "we're not that interesting, who would even know we exist, it would take time and money to learn how or find someone who knows ... squirrel!"
Passwords can at least be changed, but data leaks are basically entropic; there's no way to reverse the damage. I don't want to stop holding leak sources accountable for what they lose, but from a personal viewpoint I'm now more interested in mitigation than prevention...
Where is this happening? I'm not aware of any company being prosecuted (or even penalized in any significant way) for releasing data.
Legally, or even on a consumer level, I don't see any kind of meaningful consequence. And the rate of data loss probably won't go down until that changes.
I think it's still keyed on email address though.
Feels like this is serious crime. If caught, any idea what would be penalty for such abuse? 20 years Feds club?
I don't know why you're getting down-voted. Crimes that in even the most trivial way victimize cops get prosecuted super aggressively.