this post was submitted on 23 Jan 2024
255 points (92.9% liked)

Technology

59402 readers
2667 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] demesisx@infosec.pub 202 points 9 months ago* (last edited 9 months ago) (51 children)

I have a solution:

governments should heavily fine companies that are subject to data breaches.

If it cost them real money (proportional to their market cap, the amount of customers affected, and/or the severity of the breach) to allow a data breach, I’m betting they’d shore up those holes REALLLLLLLLLL QUICK.

[–] Sanctus@lemmy.world 108 points 9 months ago (11 children)

This is always the answer. "How do we solve x in y industry?" Make the fucking corpos responsible for their own asses and it will get fixed. If it costs them more money to be breached they will do everything they can to not allow that.

[–] eltimablo@kbin.social 3 points 9 months ago (1 children)

It'll also screw over anyone trying to break into the market, ensuring that the big tech companies remain unchallenged indefinitely.

[–] demesisx@infosec.pub 8 points 9 months ago (1 children)

Disagree if you add the three different factors that I added to account for this in my original comment:

As I wrote in my edit, I think the size of fine should be dependent on:

  • size of company

  • the reasonable expectation of security (which would partially attempt to decrease fines for unfixable breaches)

  • the number of unique users affected

[–] theneverfox@pawb.social 2 points 9 months ago (1 children)

I think that's a great starting point for effective legislation.

I also think this could easily be twisted to become yet another artificial barrier to entry.

I don't know what to do with that knowledge...I think you're correct, but I also think there's no way to pass such a law with its spirit intact today

[–] demesisx@infosec.pub 1 points 9 months ago

I’ll put the ball in your court.

I’ve completely and irreparably broken up with electoral politics in the United States ever since my tax money started being spent solely on austerity and genocide. It’s about as likely for this to be introduced as a bill as it is for a third party to win a presidential election…ie IMPOSSIBLE.

load more comments (9 replies)
load more comments (48 replies)