Remix.run Logo
xp84 a day ago

I'm assuming the intent is to protect customers.

Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.

I'm thinking:

(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)

- Name and address or name and phone number leak: $100 per customer affected.

- Email: $50 per customer affected, or $100 if tied to any other data.

- Social Security numbers: $2000 per customer affected

- Unsalted or plaintext passwords: $500 per customer affected.

- Cap is the greater of 200% of annual EBITDA, or 20% of revenue

Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.

This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.

My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.

someguynamedq 17 hours ago | parent | next [-]

The irony is that corporations get a higher discount the more people they affect. Damaging 10,000,000 people should cost you more than 10,000,000 times the cost of damaging one, not less. It should be ruinous to cause damage at this scale.

someguynamedq 17 hours ago | parent | prev [-]

SSN should be 1MM+. It is a password to your national identity that can be used to steal your identity and effectively cannot be revoked once leaked. It is a permanent grievous injury to someone to leak it.