Prevalent themes in the discussion
- Private companies routinely leak data because security is weak and penalties are trivial
- max__dev: “Private healthcare is much worse, seemingly they have an open access policy. New breaches occur in the order of millions per week.”
-
libcat99: “And it will remain this was as long as the consequences of not protecting our data remain trivial.”
-
Personal liability for executives, managers (and investors) would force better security practices
- jsrozner: “personal liability for the executives and managers at the company, and for the investors… every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines.”
-
p_l: “In EU, NIS2 regulations already hold top management personally liable both financially and in worst case criminally.”
-
Much of the leaked data (SSN, driver’s license, etc.) is already public; the real problem is broken identity verification
- nullc: “The breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis.”
-
terr: “Maybe better than ‘enter your name and SSN’… we’d have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.”
-
Security is viewed as a cost; firms spend only when fines/liability exceed the expense of protection
- sandeepkd: “Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security.”
- firebeyond (on credit‑monitoring profit): “How many people actually sign up for your 'free credit monitoring for a year' following a breach?… it automatically converts to a paid subscription.”