Anyway, just want to say that there's a special place in Hell reserved for people who do that kind of thing, and to minors, even...
Anyway, just want to say that there's a special place in Hell reserved for people who do that kind of thing, and to minors, even...
ou are arguing for behavior without providing any suggestions on how to achieve it. "Wouldn't it be better to simply do the right thing." is not a solution.
What I propose is a set of policies and incentives that archive what you want.
Each individual company might try to motivate slightly better behavior in their own clients but overall they want their administrative percentage of a growth industry so they drive up absurd costs like the US health care industry.
The goal is to remove value so there's no expectations of ransom and therefore no thefts. If a company has to pay X for the loss off data, they would be fools not to pay x/100 to someone who breaks in, steals the data and promises not to report it.
What keeps that from being too much of a concern? What similar factors apply in the data breach ransom scenario? What's different?
(Just for clarification: if a bad actor poisons a few jars, the producer in question is probably not legally responsible; but they still face a significant cost in lower sales. So blackmail is just as possible.)
Naturally, if free marketeers had created a market for food tampering that encouraged industry collusion with criminals instead of law enforcement, they would tell us it was an inevitable development and they are getting us the best outcome of many bad new realities.
If you have some time, listen to this podcast episode https://www.econtalk.org/anja-shortland-on-kidnap/
> Anja Shortland of King's College London talks about her book Kidnap with EconTalk host Russ Roberts. Kidnapping is relatively common in parts of the world where government authority is weak. Shortland explores this strange, frightening, but surprisingly orderly world. She shows how the interaction between kidnappers, victims, and insurance companies creates a somewhat predictable set of prices for ransom and creates a relatively high chance of the safe return of those who are kidnapped.
The broad incentives in kidnapping cases are comparable to what we discussed. As far as I can tell the market for kidnapping insurance doesn't have any special regulation, so perhaps a good proxy for how a free market might operate.
One of the main takeaways for me was that when eg an oil or mining concern buys kidnapping insurance for their employees, the insurance company strictly insists that employees not be told that there is insurance.
> the insurance company strictly insists that employees not be told that there is insurance.
The stated inference:
>> Each individual company might try to motivate slightly better behavior in their own clients but overall they want their administrative percentage of a growth industry so they drive up absurd costs like the US health care industry
The background concept that applies irregardless of whether a parasite is "criminal" or standard practice (of course every parasite can claim something symbiotic, maybe kidnapping is just freelance private security testing with post pricing):
https://en.wikipedia.org/wiki/Parasite_load
The insurance parasite/symbiote load as percentage of GDP, compare the 1980s to now:
https://data.oecd.org/insurance/insurance-spending.htm
The percentage of GDP lost in ransom? 0%? Terrorist ransom was also popular in the 1980s but government interfered directly, preventing most private payments and that response was primarily with force.
So, would a government demanding €10k for every kidnap of your employees they hear of fix a problem?
No, it would make kidnapping more attractive. It would threaten to involve a larger parasite (clearly this is too late in the case of kidnapping in this century!) And you would have a permanent problem with a powerful parasitic market deriving more profit than the primary market of criminals.
Luckily, for food conglomerates their stock price is uninsurable.
Unluckily for humans, government hasn't stepped in to prevent a market and much more profitable secondary markets for kidnapping in this decade.
Unluckily for private data most governments haven't come down on the use of laundered stolen private data (i.e. outlawing the sloppy US credit market, any unique pricing of insurance to a group, etc.) Luckily, they have not gone so incompetent as to add an incentive that makes all private data valuable.
Apropos government and ransom payments: in some countries, like Switzerland, _paying_ ransom is generally illegal. That's meant to make blackmailing Swiss people and companies less attractive. Not many countries follow the Swiss lead here, though.
> Luckily, for food conglomerates their stock price is uninsurable.
What do you mean? Falling stock prices are one of the easiest thing to insure against. Just buy some puts. https://en.wikipedia.org/wiki/Put_option
> Unluckily for humans, government hasn't stepped in to prevent a market and much more profitable secondary markets for kidnapping in this decade.
Sorry, which governments and which markets are you talking about? Especially which secondary market? (Do you mean the insurance market? If yes, that's probably better described as a derivatives market.
A secondary market is a rather different beast. See eg https://en.wikipedia.org/wiki/Secondary_market
In the case of kidnapping, a secondary market would be one where you'd sell on kidnapped people. Not one where you make insurance 'bets'.)
Yes, I did. I provided you with this solution: "simply invest that money in better security to begin with"
> "Wouldn't it be better to simply do the right thing." is not a solution.
I never said that. But what I did say is indeed a solution.
> What I propose is a set of policies and incentives that archive what you want.
Well, it certainly makes incentives, but probably not the ones you had in mind. For instance it incentivizes middlemen to scrape off valuable resources that could have been used to secure the actual data. At best this lowers the profit margin left over for the hospital to improve the security, but it's way worse than that. Instead the middleman actually incentivizes hackers to crack into the very system the middleman "insures," exactly because huge insurance payouts are involved.
Perhaps the hackers could fake a mental disorder and get committed at the hospital, which would make it far easier to get insight into how the data security system works, and then plant a backdoor or leak that way. This means the hacker would both get money from blackmail and money from insurance payouts (win-win for him), making the incentives from the insurance scam absurdly bad. But perhaps that was the goal all along?
Meanwhile the owner is already disincentivized from securing the system further, because he can claim that he already did enough to secure it, while what he actually means is that he insured it... Whatever he paid for, was certainly not free! The only one incentivized to look into the matter, is the insurance company itself, because they're the ones who stand to lose the most money if the system fails. And even they don't want to waste money on a matter they might not even understand themselves. Meanwile their biggest incentive isn't to secure the data, but to not pay money to the patients. And perhaps the easiest way to avoid that, is to hire a PR consultant instead of fixing the data system.
Certainly the least of their worries are the patients, who are the real losers here, from being trapped in a game of exploitation for profit, and who quite possibly have to pay a much higher fee for the services of said institution because of it. Luckily, Finland is a welfare state, so that extra cost probably won't be billed individual patients (depending on how this privately owned hospital operates), but instead it will most likely be forwarded to the taxpayers, which – while spreading the cost on more hands – is still extremely bad.
Overall, introducing an insurance scheme only adds another problem, without fixing the initial one, because how would you rate the probability of the system failing? That's what sets the insurance fee, after all. Thus, for the insurance companys part, it's far better to overbill, which would just result in increasing cost, without much benefit to anyone.
As you can imagine, for the legislator, this is quite a headache. The insurance idea is appealing because it lets the market price the risk, and introduces a mechanism that can adapt to changing conditions. What mechanism do you propose to induce companies to fix their security?
Does that seem like a good idea to you?
> Or should we require compliance with an ISO standard? Or just put companies on the hook for all breach-related costs?
Companies are already doing a combination of the two.
> As you can imagine, for the legislator, this is quite a headache.
Why? Legislators don't need to get involved at all, outside making sure that justice is served to the criminals, and that injured parties are duly compensated.
> The insurance idea is appealing because it lets the market price the risk, and introduces a mechanism that can adapt to changing conditions.
Sure, if the advantage of it defeats the severe problems already stated, and then only if it costs less than to simply invest in better security (or in the least that it doesn't lower the margin enough to hamper such improvements).
> To what standard should security be increased? (...) What mechanism do you propose to induce companies to fix their security?
That's up to the company. None of them wish the bad reputation of causing their own patients harm, immaterial or otherwise. Even so, most countries also have data security laws in place. For instance, where I'm from, patient data is regulated to avoid data loss that injures patients, for example by requiring certain forms of encryption, and (strictly) limiting who is allowed to handle certain data. On top of that are personal privacy laws, and patient safety laws, also particulary pertaining to patient data. Failure to follow these rules incurrs fines or at worst jail, especially if it's due to lacking security, too many open attack vectors, public or easy access to areas that should otherwise have been locked, etc.