- Companies should suffer massive fines / damages / criminal charges when they leak the personal data of millions of customers.
- I think EULAs are a ridiculous run-around the law. They should be non-enforceable. Its far from perfect, but case law is pretty clear that people and companies are liable for damages due to foreseeable harm that they cause. (Except EULAs dodge this.) (I am not a lawyer, this is not legal advice.)
Software engineers & security engineers can make just about anything secure. But we can only do so if we're given time and money to hire the expertise when needed. We need to make it incredibly expensive for companies to lose personal data like this. Management teams should be clamoring to hire the best security engineers. But they'll only do so if they're sufficiently motivated.
The risk of massive liability is the right incentive to convince companies to invest in getting information security right. The current status quo is ridiculous.