For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
What's stopping IDScan from "delegating" the storage to another company so they're no longer liable for stolen data? If Company A uses IDScan and the storage of the ID info is handled by Company B, do I have standing to demand compensation for damages from Company B when my data is stolen after I agree to let Company A verify my ID?
BTW this is how accountability is being avoided today.
Or are you referring to the practice of using shell companies to obfuscate responsibility? In that case, I think there’s history that says IDScan would still be responsible, questionable legal business nonsense be damned.
Snark aside, I agree with you, it’s messed up and there is a better a way.
Neither does imprisoning murderers for life, but it's one heck of a deterrent.
We'll probably never get there.
I hate to think how many people would kill if it were not illegal. Think about that. Then tell me its not a deterrent.
Holding actual humans liable (with appropriate levels of harshness) would make actual humans more likely to take preventative steps. Holding shareholders somewhat liable (maybe extra taxes on sales of a companies stock) might be useful also.
Does wonders for how c-level treats compliance work, now if only middle management followed...
And why the hell would anyone want a job where a mistake results in personal ruin? Sure, there are a lot of shitty companies and people running them, but mistakes also happen when people are trying to do a good job. It’s not possible to completely prevent a data breach even with an unlimited budget.
I think the best solution is to weed out the people who behave irresponsibly and have an environment where we learn from the ones who are responsible and fail anyway.
We are talking about the sort of job where you are paid ludicrous amounts of money. The sort of jobs that usually come with massive golden parachutes
People earning more money in a year than most people earn their whole lives should be accepting a much higher burden of risk
People will do nearly anything if the price is right.
This sort of personal liability OP is proposing would just ensure the security industry is dominated by highly compensated compulsive gamblers because nobody else is insane enough to take the risk. It's an absolutely ridiculous idea.
Corporations evolved the liability structure they have today so that large undertakings, where many people have to work together and where the bad deeds of a small number of those people could sink the undertaking, were something that regular -- people who can't self insure -- could be a part of, as investors, managers, staff, &c, &c.
Limited liability may make accountability too narrow; but blanket personal liability makes it far too broad. It's not a solution for running a large, complex economy in a more accountable way.
what's the point of liability insurance if youll never be held liable?
It's why you can't legally drive without insurance. It's not for you or your car, nobody cares about that. It's for the other people and their property.
We're talking about assurances that you're going to be able to cover damages if you rear-end a sedan and cause $8,000 in repairs. That's why you're required to drive with insurance coverage.
What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.
Insurance is not a solution for everything.
More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.
It is really simple:
If they can not handle properly the risks of their business, they should be in another business.
Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.
Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.
Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.
We need people to stop internalizing that the government and the rich somehow deserve access to private data just because they want to use it. Seeing a way to make money using enough to make you entitled to it.
Force businesses to add value if they want to exist instead of extraction or rent seeking.
I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.
The same way it is handled in any other business or trade with risk.
Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.
If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.
Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.
It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.
Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.
What amount per person is acceptable for a thing that simply should never happen?
I don't think "this will ruin my and my bosses life"-levels are over the top at all. Don't wanna risk it, then don't store the data. Usually for most purposes it would be e ough to store that yes, someone has a legit drivers license, which types of vehicles it is for and how long it is valid (if there is a limit).
We don't get to this kind of data reduction if people don't see data as the liability it sometimes is for their customers.
like why your driver license or even id should enable someone to do damage to your life?
especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
No large undertaking could ever function with such broad exposure to liability, anyways.
And if "No large undertaking could ever function with such broad exposure to liability" - that would be great, i think we would prefer that such firms doesn't exists.
They would still exist, just not in any country insane enough to pass a ridiculous law like this.
They stop existing within your jurisdiction. Also, the idea that the public would go along with any of this for this issue is silly. Let's start with crimes that actually cost lives.
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
https://en.wikipedia.org/wiki/Carrie_Tolstedt
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
The liability shield is too strong though so I do agree it’s causing problems.
Companies definitely respond to fines or liability. They just need to be big enough.
For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
Lawyers, doctors, and engineers to name a few.
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
If they deleted the IDs within a week of getting them surely the leak would be much smaller.
It's time for us to stop pretending that YC checks do anything except provide an illusion of security while putting people's living in danger.
AI makes it trivial to generate fake documents, so most KYC checks can't actually be trusted to verify your identity. As an example of how ridiculous things have gotten, Anthropic launched their verification program for granting access to their Mythos models. North Korea are experts at bypassing KYC checks and were granted early access while the rest of us were locked out.
These leaks are constant and largely unavoidable. Even the largest, most trusted companies in the world get regularly hacked. My passport was leaked and I've received multiple blackmail attempts from people demanding I pay a ransom. There have been multiple kidnappings that have been related to home addresses and private information being leaked.
The situation is really bad, and there are no easy solutions. The correct answer is probably a new government ID system based on public key encryption with some sort of multi-sig between the individual, the government, and your parents (until you're 18). This won't be easy to roll out, but our current system is broken beyond repair. Unfortunately, things probably need to get way worse before anyone cares enough to fix it.
Check out Estonia
The system is only as strong as its weakest link. ID cards can be faked and mobile devices can be stolen. Biometrics can't be easily faked, but they're horrible to have leaked because you can't change your fingerprints or eyeballs if compromised.
[0] https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
outside of english class "secure" is relative and context-dependent, not binary.
It also requires actually caring about security and putting effort into it. These data breaches are usually systems where little attention was paid to security in the first place, and e.g. getting ahold of one user's password is enough to lose the game. Getting companies to care about security is really hard, but it does happen.
My point was that computers are as secure as human(s) who programmed them were careful and competent. Computer security is ultimately human knowledge and reasoning competence (plus time/money tradeoffs, if made willingly)
Who do you think employs the top-level criminals?
That's overhead that businesses really hate paying as it's diverts software devs away from making new features.
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag... was a National Security Disaster and I'm not sure we saw useful concrete changes.
I’m not sure how we start over but this data plus LLMs is gonna make it a full time job to keep your parents from sending every penny to a scammer.
I don't know if it even matters. I always assumed every bit of my information was available somewhere. Just curious.
I think IDScan should set something up so we can check if our data was compromised, at the least.
There are a number of companies (e.g. Delete Me) that offer that service. They wouldn't have caught the subject of this post since it was a breach.
The problem here arose from ID verification where you need to show your ID to an entity that then has the opportunity to store it.
Ironically in case of breach they just sell you another of their product where you put your personal information again
How many people actually sign up for your "free credit monitoring for a year" following a breach?
When you do, you typically do so by signing up for the highest tier (sometimes $30 or even $50 a month) product with a redemption code for one year free. You have to enter a credit card to do so, and to no-one's surprise, if you don't cancel in time, it automatically converts to a paid subscription "for your convenience".
There are many consumer protection farces in the US, but right up there has to be the notion that "identity theft" is the consumer's responsibility/obligation to prevent or resolve, not the entity that actually had the data stolen. You're considered liable until you prove innocence, even though you did nothing wrong.
This very nearly burned me when buying my home - having been an AT&T customer in the PNW for nearly two decades, "I" apparently decided to hit up a Walmart on the outskirts of El Paso, sign up for a Verizon service, run up two months of international calls and bail out.
Despite a police report, my utility statements, AT&T bills, etc. (all of which were, to be blunt, none of VZWs business), VZW stood by it initially, "On review of your documentation, we remain satisfied that this debt belongs to you based on the documents used to open your account".
I asked to see them, since they were, in VZW's own words, "mine". "We can't, for customer privacy reasons." Oh, so "mine when the bill needs paid, may not be mine for privacy purposes".
Somehow a few hours before our court hearing they by some miracle decided to settle the debt with no fee to me.
You may enjoy/find-useful this Mitchell & Webb radio-skit [0] of a conversation between a banker and a visiting customer.
I suspect the reason for that (nothing other than a "gut feeling" that I get, seeing the story pushed off the front page so quickly, every time), is that the breach was through a backdoor that was deliberately coded into the system, for TLA use, and what happened, is exactly what people keep warning about; it got breached, and is now a "front door," and The Powers That Be don't want that examined too closely.
Many people pretend this isn't happening because of the "The Drivers Privacy Protection Act" but the DPPA is paper thin protection at best as it has a long list of permitted uses which anyone can just lie about (and are you worried about threats from parties so honest they're unable to lie?). Not that they usually have to lie given that the permitted uses include "For use by licensed private investigation agencies" and "For the bulk distribution of surveys, marketing materials, or solicitations"... In practice this just means accessing the information costs a little money and requires someone check a "this is for a permitted purpose" checkbox. The biggest impact is that it causes abusers of the information to be circumspect about their sources, which helps maintain the data-harvesting status quo.
(Guess what: the same databases also have ALPR gathered pictures of your car at whatever locations its been in public view... stores, your home, your mistresses home... Makes flock (YC S17) look pretty mild by comparison. The fundamental sin is requiring ID without also making it a crime for anyone but the owner and issuer to posses someone elses ID information.)
In some sense the IDScan breach may (ultimately) improve our privacy and security because it will break people out of the FALSE belief that this information is private, or that it can be protected by anything short of restricting its collection in the first place.
- license number
- license class
- license issue date
- license expiration date (birth day and month in my state)
- birth date
- eye color
- sex
- height
Are any of these very difficult to find?My ex had access to Lexis Nexis and I was always shocked how much information about people they have.
The 2nd factor is the phone number on file, which offloads liability for errors in that mechanism to the phone company.
The goal is to reduce the amount of decisions the teller makes, so as to reduce the amount of errors they can make, which also reduces the amount of training they need, all of which reduces costs.
It’s really interesting how the lack of US federal government stepping in to provide an official electronic identity verification API has resulted in the mobile phone networks becoming the de facto arbiters of identity. Even for government services.
I don’t even think I could trust having my phone number on someone else’s mobile phone plan, as I would want to ensure I have as much control over it as possible.
With the benefit of hindsight, we'd have all been better off if SSNs had been so obviously flagrantly public that nobody would ever consider them a trust-factor.
"I know! We'll use this number that its issuing agency says is most definitely not to be used for identification purposes for identification purposes!" is real PHB thinking.