• hakim.ali - Thursday, December 20, 2018 8:12 AM

    Of course we should ask any entity that collects our data to be accountable for it, but imho we also need to accept and internalize that:

    1. Our sensitive data will get out into the world. It is just a matter of time. Whether it is because of any given company's lax security policy, or malicious actions by internal/external personnel, or intentional selling of user data without approval (*cough* Facebook *cough*).

    2. We individually need to own some part of keeping our data safe, or implementing processes that won't hurt us too badly when our data gets out. This includes, among other things:
    - Locking our credit reports
    - Not using the same password on more than one site
    - Not using the same credit card number on more than one site (the one I use allows me to create unlimited virtual numbers, so I create a new one for each website I do business with; there are 3rd party providers that will also do this for you), so if one site is hacked you don't have to change it everywhere else.

    Agreed. No amount of regulation will really stop eventual leakage, just as strict laws do not eliminate auto crashes. That's why we have airbags, seatbelts and ambulance services... to reduce the damage when the inevitable happens.

    But things can be done at the user level and the payment level. Outfits like Facebook have no interest in restricting your information, as compared to a normal business which has a commercial interest in NOT sharing their customer list. One thing that would help is the ability to generate a crypto key to lock a credit cart to a single vendor. Hence any theft of the CC information would be useless anywhere else, but still provides the convenience of reorder from the legitimate vendor.

    Also we should NOT be using biological ID (especially over the net) orother not readily changeable information (birth, SS, family etc). All identification should be quickly and effectively cancelable.

    ...

    -- FORTRAN manual for Xerox Computers --