Comment Re:Shooting the messenger (Score 1) 55
There are those of you who think that every breach is preventable and that the companies that got breached should be punished.
Not exactly. I'm of the mind that if you willfully retain information on individuals then you should be legally responsible for properly controlling it. If you lose control of the information then you are liable. This is not a punishment it is a safeguard against chronic under-investment in security. If a company know that losing control of personal information they gathered could ruin them then one of three things will occur:
1. They will no longer retain more information then absolutely necessary.
2. They will do absolutely everything in their power to ensure that information is kept secure.
3. They will eventually go out of business for taking insufficient care of personal information.
The net result of this is that the pipeline of private information being pumped into the black market will be drastically reduced.
There are those of you who think that every business deal that turns out to be a bad deal, could have been foreseen if proper due diligence was followed.
No, I fully understand that it can happen to many businesses and that is a risk. However, when your business is personal information, then that changes things radically. The number of safeguards that are in place need to be radically increased and mandatory security audits should be part of the process.
Maybe one day you'll actually be in a position to be in the wrong end of such a deal, and you'll find out that it's a lot harder than it looks.
It's not harder than it looks, it's more expensive than the alternative which is why it's not done. This is turn is why holding personal information should come with a financial risk.
Right now, security isn't even a high priority to companies and that is why companies are regularly breached.