There's a solution: personal liability for the executives and managers at the company, and for the investors.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
Liability doesn't fix the damage that is already done. We can punish all the people involved in this, and it will still be the case that your drivers license is available for purchase and identity theft against anyone is now much easier. They don't have enough enough to repair the damage they've caused, even if we take everything from them.
The only time it's worked is in El Salvador and it was because they arrested the 2% of the population who had the potential to be murderers and have so far thrown away they key. I imagine before too long they will also have a final solution to the problem of feeding them for the next 50 years.
The damage can't be undone, but you can learn from it and prevent these things from happening again and again. If every CEO truly believes that his personal wealth and freedom is at stake with the safety of his customers' personal data, they will see that ITsec becomes a cornerstone of the company instead of an annoying compliance sheet checkbox.
> All VCs in the company should face personal liability up to 10% of their net worth
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
That's right: no legal basis exists now. The proposal is to create such legal basis.
And if "No large undertaking could ever function with such broad exposure to liability" - that would be great, i think we would prefer that such firms doesn't exists.
> that would be great, i think we would prefer that such firms doesn't exists
They stop existing within your jurisdiction. Also, the idea that the public would go along with any of this for this issue is silly. Let's start with crimes that actually cost lives.
All the better, I've long suspected that these companies are collecting this data and selling some portion of it. Having this category of business entirely disappear sounds like a solid win to me.
Restitution is the legal basis, let's not act like the rich don't force the poor to pay for their civil violations. What it sounds like is the rich don't like it when the law is applied fairly to them too.
This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
Holding actual people liable sounds like a more effective option. The insurance would just be included into the cost of doing business and make everything more expensive. Insurance makes everything worse.
Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.
Sarbanes-Oxley in the US holds top management personally responsible too, and compliance is taken far more seriously than with other regulations as a result.
Are we talking hypothetical utopia or something that could actually happen? Insurance probably isn’t the most perfect solution but it’s the most feasible. These exact policies and insurers already exist.
And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.
I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.
Very true. If you don't want to be exposed to such rich, you're free to work elsewhere. No one is forcing you to take on these jobs that immiserate society.
Yes, there are some people who thrive on risk and will do things like jump off a mountain in a wing suit just for the thrill of it. That doesn't mean making that sort of personal recklessness legally mandatory for employment is a good idea.
This sort of personal liability OP is proposing would just ensure the security industry is dominated by highly compensated compulsive gamblers because nobody else is insane enough to take the risk. It's an absolutely ridiculous idea.
The most reckless will, of course; but most people won't -- they just won't do it.
Corporations evolved the liability structure they have today so that large undertakings, where many people have to work together and where the bad deeds of a small number of those people could sink the undertaking, were something that regular -- people who can't self insure -- could be a part of, as investors, managers, staff, &c, &c.
Limited liability may make accountability too narrow; but blanket personal liability makes it far too broad. It's not a solution for running a large, complex economy in a more accountable way.
Could we not keep the same "harsh" plan, and then let others provide and purchase such insurance on their own? Why does the insurance have to be mandated?
Because the company will file bankruptcy and nobody will get anything. Requiring insurance up front at least provides some coverage for liabilities.
It's why you can't legally drive without insurance. It's not for you or your car, nobody cares about that. It's for the other people and their property.
Nobody is talking about criminal wreckless driving.
We're talking about assurances that you're going to be able to cover damages if you rear-end a sedan and cause $8,000 in repairs. That's why you're required to drive with insurance coverage.
The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.
What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
And when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then?
Insurance is not a solution for everything.
More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.
It is really simple:
If they can not handle properly the risks of their business, they should be in another business.
Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.
Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.
Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.
They are, by deciding if they are able to handle having their lives certainly ruined if they screw up. The trick to punishment as deterrence to planned actions is 100% identification and enforcement, so that people will avoid the behavior to avoid the punishment. Anything less and some people will decide the potential payoff of success is worth it.
Reality and certainty of consequences, not evasion and insuring of liability
I specified it in the last sentence:
>>If they can not handle properly the risks of their business, they should be in another business.
The same way it is handled in any other business or trade with risk.
Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.
If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.
Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.
It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.
Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.
This is data that will be relevant for every single victim for decades to come and they will pay for this regularly, and it cannot be undone.
What amount per person is acceptable for a thing that simply should never happen?
I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).
We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.
Fines exceeding 100% of lifetime compensation might actually do something. As it stands, clawbacks are ineffective — for example, Carrie Tolstedt of the Wells Fargo scandal wound up money ahead to the tune of tens of millions of dollars:
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
No, this is a NOW problem, not a future one and it will take months if not years to fully understand the impact. We need a NOW solution not prevention. Training AI on all the images and data here will facilitate a class of identity theft we may not have ever seen. This cannot just be abut prevention.
You do realize the limited liability corporation was a key innovation that unlocked the Industrial Revolution, right?
Companies definitely respond to fines or liability. They just need to be big enough.
For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
The socialized losses vastly exceed 300% of earnings - they're analogous to a company mishandling toxic waste and ruining everyone around them. The way they are running their business is catastrophically irresponsible, and if they can't afford the consequences, they shouldn't have gone into this business.
Investors benefit from company gains despite not having encouraged or mandated some decisions that enabled the gains. So it makes sense that they also get exposure to the downside.
They already get downsides if company gets fines or even goes to bankruptcy. You never know whether they invested based on information that was not true at all. Which is unfortunately too common.
It sounds like they need additional exposure then as they aren't assessing the real risks and seem to have completely ignored them. Why should society care that some group of investors didn't do their homework? Is that the excuse we use to avoid prison sentences now?
If you add in personal liability for mistakes, nobody competent will ever bother working in the industry again. It's not worth the personal risk. You'll get stuck with bottom of the barrel staff who don't have much to lose and get a steady paycheck for a few years.
> personal liability for the executives and managers at the company
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
I'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised. In addition, millions of sets of fingerprints were recovered by the entity that carried out the hack.
Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.
That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.
It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.
Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.
Skilled and dedicated people and an organization dedicated to maintaining a consistent level of security. Maintaining both of these long term seems to be the challenge for many companies.
Elon fucking Musk has literally every single piece of personal information of every person in the country. It’s so far past too late for any of this to matter.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
What I would love to know is who is selling my info. I get texts from all kinds of politicians but I didn't know who sold them my number. Seems like selling someone's property without their approval should be illegal. It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)
Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security.
Ironically in case of breach they just sell you another of their product where you put your personal information again
The CRAs compete for breach business, because it's absolutely a profitable enterprise for them:
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
Was ran through the same gauntlet by a medical provider billing me for services. Insurance wouldn't pay them due to "insufficient documentation". Wouldn't disclose what documentation they had received or what documentation they needed. Just that is was inadequate. Service provider wouldn't tell me what they had sent.
Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
> the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen.
You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.
American national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
In my experience, any industry following a security standard halts all effort at security once they're compliant with the standard. HIPAA sets a minimum but seems to also guarantee you will get exactly that minimum and nothing better.
I'm confused about the read on this too. It reads like a "I don't want the government involved in my healthcare" type of statement, but it's posted in the discussion section of an article about private companies mishandling data.
When this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all
Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be.
And then, in real life, one discovers that institutions route around in creative ways for all sorts of different reasons ( recently had to 2fa a transaction at a god damn teller window; you just took my DL ).
Yes, but it is rather pointless to argue with teller who can't even begin to understand policy dictating it, much less, apparently, make exceptions. Machine told me to do it.
No, the teller is not sufficiently qualified to be liable enough to match the picture on the ID to the person in front.
The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company.
The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs.
It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services.
I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible.
> IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN”
With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.
Yep. Social Security numbers are not guaranteed to be unique, and for a very long time, were pretty easy to figure out if you knew roughly when a person was born and where.
"I know! We'll use this number that its issuing agency says is most definitely not to be used for identification purposes for identification purposes!" is real PHB thinking.
But they were! My college student ID from 1980 has my SS number right on it. I have here an employee badge from the Walt Disney Company from 2000 and my SS number is in a bar code right on the bottom. Even in 2000, it would be trivial to take a photo of someone wearing the ID badge and decode the 1D bar code on it.
The breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis. Practically all states sell DL and registration information to information brokers, and the remaining ones require you to obtain auto insurance, and the insurers all sell the information.
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
Right on! It's always frustrating reading articles framed in terms of "security breaches" and "dark web", invariably doing hand waving at unspecified harm, when the real threat actor for pretty much everybody is the "above board" surveillance industry. Random people who buy this info outside the law can't really hurt me - it's not like I'm a witch and my DL# is my "true (system-given) name" and I disappear when they say it or something. Rather the parties who can hurt me are the ones who pretend knowledge of this semi-public information is an authentication system, and then hassle me with legal nastygrams when they get defrauded. Or who keep comprehensive dossiers on my behavior to unaccountably sort me into corporate-defined boxes so they can better extract my wealth and otherwise form anti-competitive arrangements against me. These actual attackers operate mostly according to the (very broken) law, and they are what needs fixing. Not just scaremongering when some bogeyman "wrong people" get a small taste of the exact same information.
Hundreds of millions of American's names, addresses, social security numbers, etc were in the NPD leak which has been publicly downloadable. The idea that any of this information should be considered private, only knowable by the person themself is wrong.
There's a solution: personal liability for the executives and managers at the company, and for the investors.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
Liability doesn't fix the damage that is already done. We can punish all the people involved in this, and it will still be the case that your drivers license is available for purchase and identity theft against anyone is now much easier. They don't have enough enough to repair the damage they've caused, even if we take everything from them.
> Liability doesn't fix the damage that is already done.
Neither does imprisoning murderers for life, but it's one heck of a deterrent.
The only time it's worked is in El Salvador and it was because they arrested the 2% of the population who had the potential to be murderers and have so far thrown away they key. I imagine before too long they will also have a final solution to the problem of feeding them for the next 50 years.
The damage can't be undone, but you can learn from it and prevent these things from happening again and again. If every CEO truly believes that his personal wealth and freedom is at stake with the safety of his customers' personal data, they will see that ITsec becomes a cornerstone of the company instead of an annoying compliance sheet checkbox.
No, but it changes the cost-benefit analysis for managers deciding to cut corners in future.
Liability can be a strong incentive to improve the system in the future.
> All VCs in the company should face personal liability up to 10% of their net worth
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
There is no legal basis for this for taking the salaries of everyone who worked at the company in any level of management at any time.
No large undertaking could ever function with such broad exposure to liability, anyways.
That's right: no legal basis exists now. The proposal is to create such legal basis.
And if "No large undertaking could ever function with such broad exposure to liability" - that would be great, i think we would prefer that such firms doesn't exists.
> that would be great, i think we would prefer that such firms doesn't exists
They stop existing within your jurisdiction. Also, the idea that the public would go along with any of this for this issue is silly. Let's start with crimes that actually cost lives.
"such firms" being any and all IT companies?
They would still exist, just not in any country insane enough to pass a ridiculous law like this.
All the better, I've long suspected that these companies are collecting this data and selling some portion of it. Having this category of business entirely disappear sounds like a solid win to me.
Then such businesses should not exist. What right do they have to gamble with the wealth of 150 million people unrelated to their enterprise?
I see no problem with a rule that effectively says no company can exist if it holds such detailed records on millions of people.
Restitution is the legal basis, let's not act like the rich don't force the poor to pay for their civil violations. What it sounds like is the rich don't like it when the law is applied fairly to them too.
Restitution is an equitable remedy, not a legal basis.
This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
Holding actual people liable sounds like a more effective option. The insurance would just be included into the cost of doing business and make everything more expensive. Insurance makes everything worse.
Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.
In EU, NIS2 regulations already hold top management personally liable both financially and in worst case criminally.
Does wonders for how c-level treats compliance work, now if only middle management followed...
Sarbanes-Oxley in the US holds top management personally responsible too, and compliance is taken far more seriously than with other regulations as a result.
If you think there is never a valid use for insurance policies I can’t take you seriously.
Sure, when you want payout. This is not about payout, but about us not wanting it to happen again.
Are we talking hypothetical utopia or something that could actually happen? Insurance probably isn’t the most perfect solution but it’s the most feasible. These exact policies and insurers already exist.
And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.
I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.
> And why the hell would anyone want a job where a mistake results in personal ruin
We are talking about the sort of job where you are paid ludicrous amounts of money. The sort of jobs that usually come with massive golden parachutes
People earning more money in a year than most people earn their whole lives should be accepting a much higher burden of risk
Very true. If you don't want to be exposed to such rich, you're free to work elsewhere. No one is forcing you to take on these jobs that immiserate society.
> And why the hell would anyone want a job where a mistake results in personal ruin?
People will do nearly anything if the price is right.
Yes, there are some people who thrive on risk and will do things like jump off a mountain in a wing suit just for the thrill of it. That doesn't mean making that sort of personal recklessness legally mandatory for employment is a good idea.
This sort of personal liability OP is proposing would just ensure the security industry is dominated by highly compensated compulsive gamblers because nobody else is insane enough to take the risk. It's an absolutely ridiculous idea.
The most reckless will, of course; but most people won't -- they just won't do it.
Corporations evolved the liability structure they have today so that large undertakings, where many people have to work together and where the bad deeds of a small number of those people could sink the undertaking, were something that regular -- people who can't self insure -- could be a part of, as investors, managers, staff, &c, &c.
Limited liability may make accountability too narrow; but blanket personal liability makes it far too broad. It's not a solution for running a large, complex economy in a more accountable way.
if you hold people liable, then they will want liability insurance.
what's the point of liability insurance if youll never be held liable?
Could we not keep the same "harsh" plan, and then let others provide and purchase such insurance on their own? Why does the insurance have to be mandated?
Because the company will file bankruptcy and nobody will get anything. Requiring insurance up front at least provides some coverage for liabilities.
It's why you can't legally drive without insurance. It's not for you or your car, nobody cares about that. It's for the other people and their property.
Driving badly or dangerously gets you in prison. Insurance is not there to ensure road safety. Road safety is enforced by punishments.
Nobody is talking about criminal wreckless driving.
We're talking about assurances that you're going to be able to cover damages if you rear-end a sedan and cause $8,000 in repairs. That's why you're required to drive with insurance coverage.
Who receives the payouts of those insurance benefits and how would one go about making a claim?
The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.
What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
And when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then?
Insurance is not a solution for everything.
More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.
It is really simple:
If they can not handle properly the risks of their business, they should be in another business.
In that kind of situation you are just fucked regardless.
Ok. How do you propose they prove they can handle the risks? Who is responsible for determining that and what are their qualifications?
That's the secret: no one can.
Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.
Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.
Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.
They are, by deciding if they are able to handle having their lives certainly ruined if they screw up. The trick to punishment as deterrence to planned actions is 100% identification and enforcement, so that people will avoid the behavior to avoid the punishment. Anything less and some people will decide the potential payoff of success is worth it.
Reality and certainty of consequences, not evasion and insuring of liability
I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.
The same way it is handled in any other business or trade with risk.
Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.
If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.
Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.
It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.
Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.
This is data that will be relevant for every single victim for decades to come and they will pay for this regularly, and it cannot be undone.
What amount per person is acceptable for a thing that simply should never happen?
I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).
We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.
Or maybe something bigger should change
like why your driver license or even id should enable someone to do damage to your life?
especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
Fines exceeding 100% of lifetime compensation might actually do something. As it stands, clawbacks are ineffective — for example, Carrie Tolstedt of the Wells Fargo scandal wound up money ahead to the tune of tens of millions of dollars:
https://en.wikipedia.org/wiki/Carrie_Tolstedt
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
No, this is a NOW problem, not a future one and it will take months if not years to fully understand the impact. We need a NOW solution not prevention. Training AI on all the images and data here will facilitate a class of identity theft we may not have ever seen. This cannot just be abut prevention.
You do realize the limited liability corporation was a key innovation that unlocked the Industrial Revolution, right?
Companies definitely respond to fines or liability. They just need to be big enough.
For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
This is so unrealistic but I do agree personal liability should come into play more for people who knowingly act inappropriately.
It's already a rh>ng for critical infrastructure companies in EU.
It's perfectly reasonable, and if something perfectly reasonable is "unrealistic", then the system is corrupt.
Bankrupting everyone who does business by making them repay 300% of earnings is unreasonable.
The liability shield is too strong though so I do agree it’s causing problems.
The socialized losses vastly exceed 300% of earnings - they're analogous to a company mishandling toxic waste and ruining everyone around them. The way they are running their business is catastrophically irresponsible, and if they can't afford the consequences, they shouldn't have gone into this business.
Including investors is a bit much unless they encouraged or mandated some decisons that enabled this.
Investors benefit from company gains despite not having encouraged or mandated some decisions that enabled the gains. So it makes sense that they also get exposure to the downside.
They already get downsides if company gets fines or even goes to bankruptcy. You never know whether they invested based on information that was not true at all. Which is unfortunately too common.
It sounds like they need additional exposure then as they aren't assessing the real risks and seem to have completely ignored them. Why should society care that some group of investors didn't do their homework? Is that the excuse we use to avoid prison sentences now?
It's cleaner to hold some of a corp's money in escrow if they're handling IDs, to ensure they can't avoid fines via bankruptcy.
Fines on the scale that it might be reasonable to reserve escrow funds for are just "cost of doing business" fines.
Companies typically have insurance policies to cover this kind of stuff.
If you add in personal liability for mistakes, nobody competent will ever bother working in the industry again. It's not worth the personal risk. You'll get stuck with bottom of the barrel staff who don't have much to lose and get a steady paycheck for a few years.
I believe that many "professionals" have personal liability and carry insurance.
Lawyers, doctors, and engineers to name a few.
The liability the OP describes is clownish and nobody would ever insure against it.
That still prevents it from happening again, no? Still seems like a success.
No, it guarantees it will happen because only terrible people will work on the systems.
This.
100%
Great way to incentivize everyone to do nothing. Most middle managers don’t know shit.
> personal liability for the executives and managers at the company
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
Does IDScan need to store the IDs after they've verified them?
If they deleted the IDs within a week of getting them surely the leak would be much smaller.
Making holding data like this a liability that has to be insured, etc... is part of a good solution IMO.
KYC = kill your customer
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
I'm reminded of the OPM breach back in 2015 [0]. Practically everyone that even applied for a security clearance was compromised. In addition, millions of sets of fingerprints were recovered by the entity that carried out the hack.
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
Near the beginning of my career, I talked to a greybeard who harrumphed at me discussing something-or-other and said "computer security is an oxymoron". I thought he was being too pessimistic, nowadays I realize he was right.
it's silly to think about computer security as binary secure/insecure.
That's too pessimistic. But it is a spectrum. You can't guarantee 100% success against 100% of potential attackers, but it still matters how easy it is to get into something. There's a pretty big difference between a Windows 95 machine hooked directly to the internet and something like a fully up-to-date iPhone. The iPhone is still hackable, but in practice it's so difficult that you're unlikely to be targeted unless you get the attention of a national government.
It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.
Human security. Computers are fine, they usually do exactly as they’re programmed.
We don't care about the computers, humans are what society is for
getting the idea lately that society hates humans
Caring for humans hurts profits
Real computer security IS possible but takes a lot of effort by very skilled and dedicated people. You don't hear about bank mainframes getting hacked often.
Skilled and dedicated people and an organization dedicated to maintaining a consistent level of security. Maintaining both of these long term seems to be the challenge for many companies.
> You don't hear about bank mainframes getting hacked often.
Who do you think employs the top-level criminals?
Sure, but not in the IT service.
It makes systems harder to work with and new features slower to deploy and it requires you to make sure you stay on top of CVEs.
That's overhead that businesses really hate paying as it's diverts software devs away from making new features.
Will anything be different _this time around_?
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
Equifax's stock price went up when they were hacked.
Joking right :)
Elon fucking Musk has literally every single piece of personal information of every person in the country. It’s so far past too late for any of this to matter.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
Is there any way to check if your ID was compromised without going on some onion site?
I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
What I would love to know is who is selling my info. I get texts from all kinds of politicians but I didn't know who sold them my number. Seems like selling someone's property without their approval should be illegal. It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)
> It'd be great if I could request who sold them my data, then go to that entity tell them to stop selling (rinse and repeat)
There are a number of companies (e.g. Delete Me) that offer that service. They wouldn't have caught the subject of this post since it was a breach.
The problem here arose from ID verification where you need to show your ID to an entity that then has the opportunity to store it.
Its unfortunate that the security requirements are expected from the for-profit businesses when the cost of paying penalties for breach of security is way lower than actually implementing the security.
Ironically in case of breach they just sell you another of their product where you put your personal information again
The CRAs compete for breach business, because it's absolutely a profitable enterprise for them:
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
Was ran through the same gauntlet by a medical provider billing me for services. Insurance wouldn't pay them due to "insufficient documentation". Wouldn't disclose what documentation they had received or what documentation they needed. Just that is was inadequate. Service provider wouldn't tell me what they had sent.
Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
> the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen.
You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.
[0] https://www.youtube.com/watch?v=CS9ptA3Ya9E
American national security apparatus do not care about the actual Americans. They are too worried about foreign entanglements, and protecting a specific foreign country than their own country.
Wow, how could this have happened right before the election? Surely this will not be used as a pretext for anything.
Does anyone know what "disabling advertising identifiers" actually means?
Is there anything comparable going on to the data of Chinese citizens? Or Chinese public servants?
I really want these people handling my healthcare and other details about my life.
Private healthcare is much worse, seemingly they have an open access policy. New breaches occur in the order of millions per week. Not remotely newsworthy anymore. (last time this was mainstream worthy was 200M leaked records in 2024). Last week https://www.securityweek.com/4-1-million-impacted-by-adapthe... Week before that https://www.yahoo.com/news/us/articles/more-9-5-million-pati... 2 weeks before that: https://www.msn.com/en-us/health/general/carecloud-confirms-...
And it will remain this was as long as the consequences of not protecting our data remain trivial.
if only we prosecuted corporations as people instead of just giving them the civil liberties of one
In my experience, any industry following a security standard halts all effort at security once they're compliant with the standard. HIPAA sets a minimum but seems to also guarantee you will get exactly that minimum and nothing better.
The only thing HIPAA guarantees is that when your data is handed out, there was a policy around it.
Not true, it makes investigating medical fraud almost impossible.
Which people? This leak was caused completely by private businesses.
I'm confused about the read on this too. It reads like a "I don't want the government involved in my healthcare" type of statement, but it's posted in the discussion section of an article about private companies mishandling data.
You want an ID verification company handling healthcare? Even if you're a staunch believer in free enterprise this seems like a capability mismatch.
When this first landed I asked what the fix could even be. Everyone needs a new ID at a minimum. But then I got to thinking: 1) is that the point? Conspiratorial thinking I know but “hey all Our ids got hacked I guess we need a national id”. And related 2) the current id system from a security standpoint was a band aid fix for outdated world to be shoehorned into a modern one. IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN” but bottom line, at least in US there is no cryptographically secure identity system that proves you are the citizen you say. And that fact bleeds into all sorts of patchwork solutions, fraud, etc. Moreover there are serious philosophical hurdles to getting to one. I’m not even positive I want one. But unless there is some zero-trust way to do this, I’m not sure what the fix would be.
And then, in real life, one discovers that institutions route around in creative ways for all sorts of different reasons ( recently had to 2fa a transaction at a god damn teller window; you just took my DL ).
Isn't the DL (which has a picture) and your face the two factors? Isn't that the whole point of having a picture on a DL?
Yes, but it is rather pointless to argue with teller who can't even begin to understand policy dictating it, much less, apparently, make exceptions. Machine told me to do it.
No, the teller is not sufficiently qualified to be liable enough to match the picture on the ID to the person in front.
The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company.
The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs.
It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services.
I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible.
> IDscan was never cryptographic proof you were who you said you were. Maybe better than “enter your name and SSN”
With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.
To be fair many SS cards were printed stating right on them they aren't for ID usage.
Yep. Social Security numbers are not guaranteed to be unique, and for a very long time, were pretty easy to figure out if you knew roughly when a person was born and where.
"I know! We'll use this number that its issuing agency says is most definitely not to be used for identification purposes for identification purposes!" is real PHB thinking.
But they were! My college student ID from 1980 has my SS number right on it. I have here an employee badge from the Walt Disney Company from 2000 and my SS number is in a bar code right on the bottom. Even in 2000, it would be trivial to take a photo of someone wearing the ID badge and decode the 1D bar code on it.
Passports seem a lot better. You scan it with NFC, and the chip inside proves authenticity via asymmetric crypto.
Glad to see someone talking about this
The breach is bad no doubt-- but this information was already readily available to bad actors e.g. via Lexis Nexis. Practically all states sell DL and registration information to information brokers, and the remaining ones require you to obtain auto insurance, and the insurers all sell the information.
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
"but this information was already readily available to bad actors e.g. via Lexis Nexis."
My ex had access to Lexis Nexis and I was always shocked how much information about people they have.
Right on! It's always frustrating reading articles framed in terms of "security breaches" and "dark web", invariably doing hand waving at unspecified harm, when the real threat actor for pretty much everybody is the "above board" surveillance industry. Random people who buy this info outside the law can't really hurt me - it's not like I'm a witch and my DL# is my "true (system-given) name" and I disappear when they say it or something. Rather the parties who can hurt me are the ones who pretend knowledge of this semi-public information is an authentication system, and then hassle me with legal nastygrams when they get defrauded. Or who keep comprehensive dossiers on my behavior to unaccountably sort me into corporate-defined boxes so they can better extract my wealth and otherwise form anti-competitive arrangements against me. These actual attackers operate mostly according to the (very broken) law, and they are what needs fixing. Not just scaremongering when some bogeyman "wrong people" get a small taste of the exact same information.
Hundreds of millions of American's names, addresses, social security numbers, etc were in the NPD leak which has been publicly downloadable. The idea that any of this information should be considered private, only knowable by the person themself is wrong.
Slackers are always behind this shit