Remix.run Logo
analog31 6 hours ago

I believe we need to criminalize possession of the data, with statutory damages per violation.

wolvoleo 17 minutes ago | parent | next [-]

Isn't that the case already? Here in many European countries it already is. They're always warning about that when there's a big breach and people download it to see what's in it about them. Not that they're going to prosecute half the country of course but still.

akshatjiwan 5 hours ago | parent | prev | next [-]

Some laws for protection do exist — eg requirement that sensitive data needs to be kept on systems that have been pen tested. But those laws are hardly ever followed and authorities have no real way to check if the 'protected' status of digital storage is actually maintained. What's worse is there are actually voices inside the government that are calling for an end on encryption stating that it encourages criminal activity.

CamperBob2 4 hours ago | parent | prev | next [-]

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

londons_explore 2 hours ago | parent [-]

Estonia has it's ID cards which can sign things....

That suddenly means a data leak doesn't matter - nobody can make new signatures.

Verifying someone's ID would be as simple as asking them to sign your company name and today's date.

mschuster91 an hour ago | parent [-]

The problem is... being opposed to a national ID card scheme is bipartisan in the US [1]. The Republicans go as far as to yap about "mark of the beast", the Democrats and the ACLU fear them being used as part of a surveillance state.

[1] https://www.nyclu.org/commentary/letter-beware-mark-beast-wa...

alistairSH an hour ago | parent | next [-]

Which is insane. The federal government already knows who we are, via SSN, tax returns, and whatever else. The state already knows via tax returns, driver's license, and whatever else.

If we, collectively, don't want a true national ID, then federal regulations on state-issued IDs should be available (something roughly akin to ReadID, but with the ability to use the ID as a proof of age or other attribute as needed).

We'll get there eventually, but not before we try everything else first.

lotsofpulp 4 minutes ago | parent | prev | next [-]

A national ID card scheme has existed for many decades. It’s called a passport.

There is no reason a digital equivalent can’t be made using the passport system, and it can be left optional, just like passports are optional.

nobodyandproud 34 minutes ago | parent | prev [-]

I grew up in that tradition, so I can shed some light: The fear of a national ID isn’t just about tracking and privacy, but that an individual cannot participate in society or survive if the government decides to revoke the id.

Meaning, I can’t buy food; rent or buy a home; or hold any sort of job and earn and save.

What we have today isn’t better, but until recently I was hard pressed to see how such fears were even warranted.

raverbashing 33 minutes ago | parent | prev | next [-]

It would be fun if the GDPR naysayers end up coming up to the same conclusion

actionfromafar an hour ago | parent | prev | next [-]

But that would be like GDPR and that is EU which is communist which is satanic. QED.

vrganj 4 hours ago | parent | prev | next [-]

Not quite the same, but the GDPR gives you a right to erasure.

OKRainbowKid 3 hours ago | parent | next [-]

And afaik it also quite strictly regulates which data you're allowed to collect and process and for which reasons. But on hackernews I feel it is more often than not represented as a symbol of EU bureaucracy, being to blame for cookie banners, and/or designed to extort money from poor helpless trillion dollar US corporations.

vrganj 3 hours ago | parent [-]

Maybe the bureaucracy is there for a reason some times?

Maybe the poor helpless US corporations shouldn't be collecting 153M+ drivers licenses?

Maybe some of the HN audience is trying to collect 153M drivers licenses themselves and labeling it innovation or monetization model?

Hm.

OKRainbowKid 29 minutes ago | parent [-]

In case it wasn't obvious: I do not at all agree with these complaints about the GDPR or EU.

randunel 2 hours ago | parent | prev [-]

Actually GDPR is exactly what they're asking to. Possession of personal data that is not required for a service's functionality is illegal under GDPR.

wolvoleo 15 minutes ago | parent [-]

Well unless it was stored with freely given permission of course.

But it has to be freely given. "Give permission or you can't use this service" is not ok for data that isn't required to provide the service.

DANmode 6 hours ago | parent | prev [-]

Negligence is already illegal.

Just locate a prosecutor.

DaSHacka 3 hours ago | parent | next [-]

I'll sleep so much better at night when the company that'll leak my Social Security Number on the internet due to hosting a backup of a database that's assessible publicly gets fined $0.30 per SSN leaked.

Hell, the execs may even briefly mention it once in the bi-hourly meeting about tomorrow's meeting's meeting, chuckling before moving onto the next slide.

megagpt5 2 hours ago | parent | prev [-]

[dead]