Which means nothing gets done because it's pretty hard to prove where any one misusing your information got it from. My identity was stolen after breach but when I took it up with entity that lost my information, they were like "Prove it" which of course I couldn't because people who did it to me were never caught.
And many mail hosting services let you assign a catch-all, which allows you to simply use anything@mydomain.com to get the same result.
Big companies do this. I have signed up for things using a +filter email address, only to receive the emails from that company that is signed up to get at my plane address, without the +filter part.
Even if you can enter it, various backends in the same company might not handle it correctly and you enter up with an half-working account that their customer support (if they even have that...) cannot solve. Been there, tried that...
Personally I have - as the separator (not on gmail or similar). If you have to give you email on the phone it can cause lengthy discussions why their company name appears in my email address..
I haven't had issues with it in many years.
Okay. So now you, individually, may be able to attribute some sort of responsibility in some sort of civil action.
Penalties that companies care about aren’t going to be built around some very non-standard individual’s ability to maybe, sometimes, attribute blame.
Plus, the real damaging stuff wont have anything to do with your email addresses.
Who decides what a "severe" outcome is? The companies themselves? Why don't we hold them to a higher standard?
a) everyone is impacted by climate change, not just the customers who gave their data
b) climate change has very real consequences for people
Read up on the SSN leak from last week, I didn't give them my data. And it can have real consequences.
but this is the correct justification. If the customer is the one buying these products that cause climate impact, why is it the sole responsibility of the company to pay the cost of rectification?
In such situations, where externality is problematic, it is up to the gov't to push regulations to prevent it. A carbon capture tax, for example, is one such way.
> Why don't we hold them to a higher standard?
why should companies be held to a higher standard than a person?
It isn't - it's the company's responsibility to pass the cost to the customer.
It's similar with climate change. It's just a fact of the matter that people at scale only react as actual consequences become palpable.
1% of users in a data leak having their identities stolen or 1% of the cities in the world becoming uninhabitable due to heat isn't enough to demand action, what about 10%? Is 25% where we draw the line?
That's what imposing a 'severe' outcome would mean. You're using circular logic to be against a statement of facts.
Weird.
So I disagree, we don't need to wait until the data breaches lead to any particular outcomes, we need laws that make it clear that data breaches alone constitute damages to the people whose data was released. More people should be protected by GDPR-style laws, and more companies need to recognise that data security is something they need to take deeply seriously.
GDPR has been with us since 2018, and it if was the deterrent that everyone claimed it to be, we wouldn't be having this discussion today.