logoalt Hacker News

lrvicktoday at 6:52 AM2 repliesview on HN

I say this as a fan of a lot of what Framework is doing.

Lets not pretend we do not all -know- virtually every SaaS sucks ass at security because it slows down sales.

Companies that use these easy button services anyway are knowingly putting PII at risk and any liability should fall on those decision makers.

If you do not have the security and infra staff to take user data in house securely, in highly auditable secure enclaves, then you should not store it at all.


Replies

orwintoday at 8:31 AM

I created an account more than two years ago, and never connected to it since. EU rgpd is very clear about data retention delays. I won't report it, but to be clear I am very cross with Framework, when even Chinese companies respect my privacy more.

vladvasiliutoday at 7:18 AM

Let's not pretend we do not all -know- virtually every company looks at security as a cover your ass exercise. The SaaS is able to provide some fort of "certification", so companies are happy to move responsibility to them.

They don't actually care about protecting PII or anything.

show 1 reply