Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've been long arguing that there should be severe legal consequences for companies who leak data. Right now there's almost no legal repercussions for this sort of thing. I expect better from Microsoft, but I really don't expect any better from the thousands of tiny startups out there. Unless the people involved suffer any serious consequences for leaking their customer's data, they won't bother spending the time and money to do a good job and these breaches will continue to be commonplace.

As much as I love the free market, we're completely failing to protect consumers. I think we need the government to step in and align incentives. I don't know if we need engineers to be personally liable in the case of data breaches, but I'm serious enough about this that I wouldn't take it off the table. Medicine has malpractice suits. Engineers have a professional duty of care. Builders have building codes. We need an equivalent for software engineering.

Its not the wild west anymore when we didn't know how to do this right. For almost all modern software, best practices are out there and well known. The way you secure a password database hasn't changed much in the last decade. Apparently people just don't care enough to learn and apply those techniques. Bootcamps don't even bother to teach any security practices. Given how much the world relies on our industry's ability and knowledge, that needs to change in a hurry.



>As much as I love the free market, we're completely failing to protect consumers. I think we need the government to step in and align incentives.

>Medicine has malpractice suits. Engineers have a professional duty of care. Builders have building codes. We need an equivalent for software engineering.

The key difference is that when a doctor or engineer screws up, people die. The burden is on the people calling for regulation to show the tangible, measurable harm to peoples' health or finances resulting from these data breaches, otherwise the average person won't take them seriously.

It's also the case that doctors and engineers aren't dealing with adversarial input. If somebody blows up a bridge nobody blames the engineer, and if a patient deliberately harms themselves nobody blames the doctor. Yet web infrastructure is constantly dealing with adversaries across the world trying to breach it.


Nobody would blame the coders if the customers were willingly exposing all their private info, would be the comparison. Nobody would blame the coders if an APT socially engineered their way into a well-programmed secure system. Everyone rightfully blames the coders if they keep building projects that aren't up to modern standards (and if their company asked them and allowed them the time and resources to build something secure. Otherwise, it's on management.)


>Right now there's almost no legal repercussions for this sort of thing. //

Except in the EU, you mean? Where the fine is what, up to 4% of global annual turnover.

So there are ways to do it, but occasionally you have to click a couple of dialogs on a website so they've been widely slated.


Also most of the dialogs have been lying from the start, implying that they need permission for the cookies "required to run the site", which are in fact session cookies, which do not require the dialog. It seems they've become stricter about what the dialogs should say (probably the GDPR? which is predated by the cookie dialog law), but in the beginning there was a lot of misinformation (not always deliberate, some frontend devs were also just misinformed). And this, at least in part, caused the wrong reaction from the public: That the cookie dialogs are stupid and annoying, instead of informing them that certain sites would really like to use cookies for purposes of 3rd party advertising and tracking networks. Maybe if there had been more websites proudly displaying a (non annoying) banner "our site's cookies are fine; they do not require a cookie dialog!". I don't know.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: