Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> This is how we should view optional services that require us to give our PII data in exchange for hours of attention-grabbing content.

This is a nice fantasy, but realistically it means you shouldn't use probably 90% of services out there, which isn't reasonable for most people. Plus, there are plenty of companies with treasure troves full of data on you that have equally questionable data security/privacy practices that you've never even directly interacted with.

We need regulation. There is no other alternative. And we need to stop blaming victims of data breaches for companies not putting basic security measures in place. I don't think it's unreasonable to expect every company you interact with to securely store your sensitive data. If a place was physically making people ill like in your thought experiment, they wouldn't be around for very long; I think we should demand the same for our data.



No one is blaming the victims. Please read my comment again. What I'm saying is that regulation puts in guardrails that don't actually do anything to protect your data.


>What I'm saying is that regulation puts in guardrails that don't actually do anything to protect your data.

Right, and when you go to the grocery store you catch listeria every time? Oh wait, food handling is rather safe because of well enforced regulation.

The problem with libertarians is they don't think of the wide spread public effects of their behaviors. Trash piles up outside their house and suddenly bears are eating the neighbors.


Food regulations work. Data security regulations don't. Why? Because food safety is a pretty static practice. It doesn't change that often. But software is dynamic. New vulnerabilities and breach techniques come out faster than the speed at which politicians can regulate them. Its a cat and mouse game and government is a really slow and fat cat.


Yea, I hear this all the time. The problem is the things I see attacked are not cutting edge new exploit types invented in the last week, it's the same damned things that we've been fighting the last few decades.


That's the main reason to not use these services. Regulations are in place but companies ignore them. How, exactly, are regulations protecting you when companies refuse to implement any security measures?

You don't find out they've ignored the regulations until its too late.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: