There's a solution: personal liability for the executives and managers at the company, and for the investors.
For example, every person who has ever worked for IDScan at any level of management should have all lifetime compensation clawed back and then pay a further 2x of that in fines. All VCs in the company should face personal liability up to 10% of their net worth. (Fines should be based on net worth; see e.g., https://www.nytimes.com/2018/03/15/opinion/flat-fines-wealth...)
> All VCs in the company should face personal liability up to 10% of their net worth
Unless you have a requirement to also use domestic ID-verification services, this just means you shut that sector down in the U.S. and all our scans go to a country that doesn't extradite.
The solution is simpler: you're not allowed to hold certain special categories of data. ID scans, until we get proper identity verification in America, being one of them.
There is no legal basis for this for taking the salaries of everyone who worked at the company in any level of management at any time.
No large undertaking could ever function with such broad exposure to liability, anyways.
This is a little harsh. What about requiring companies to carry management liability insurance? Or to list individual managers on cybersecurity insurance policies? Premiums will rise when a company employs managers with claims history. Eventually, it becomes difficult to employ them in key positions if they have a bad track record.
Or maybe something bigger should change
like why your driver license or even id should enable someone to do damage to your life?
especially that it isnt difficult to lose it and even needs to be shared with someone (e.g hotel)?
Fines exceeding 100% of lifetime compensation might actually do something. As it stands, clawbacks are ineffective — for example, Carrie Tolstedt of the Wells Fargo scandal wound up money ahead to the tune of tens of millions of dollars:
https://en.wikipedia.org/wiki/Carrie_Tolstedt
> In response to the report, Wells Fargo retroactively fired Tolstedt for cause and revoked $47.3 million that they had previously paid her. This brought the total amount of money she had given up to $67 million, or about 54% of her $125 million pay package she initially received when she retired.
No, this is a NOW problem, not a future one and it will take months if not years to fully understand the impact. We need a NOW solution not prevention. Training AI on all the images and data here will facilitate a class of identity theft we may not have ever seen. This cannot just be abut prevention.
You do realize the limited liability corporation was a key innovation that unlocked the Industrial Revolution, right?
Companies definitely respond to fines or liability. They just need to be big enough.
For example, I recently heard an interview from an environmentalist who expected to be outraged touring a Chevron drilling location but was surprised by how much precaution is taken these days. Basically, liability for oil spills is massive. We could just make data leak liability massive too.
This is so unrealistic but I do agree personal liability should come into play more for people who knowingly act inappropriately.
Including investors is a bit much unless they encouraged or mandated some decisons that enabled this.
It's cleaner to hold some of a corp's money in escrow if they're handling IDs, to ensure they can't avoid fines via bankruptcy.
If you add in personal liability for mistakes, nobody competent will ever bother working in the industry again. It's not worth the personal risk. You'll get stuck with bottom of the barrel staff who don't have much to lose and get a steady paycheck for a few years.
Great way to incentivize everyone to do nothing. Most middle managers don’t know shit.
> personal liability for the executives and managers at the company
How cute, you think the engineers who failed to properly develop and maintain a system that can securely store sensitive information flawlessly won't (or shouldn't) be held accountable.
Every time this topic comes up it makes me wonder how many people on here who go "wow how in this day and age is it possible to have a data breach???" aren't just extraordinarily lucky that no one is really trying to attack the service they created or are fortunate enough to work in the few places that can legitimately say they're nigh-impenetrable.
Liability doesn't fix the damage that is already done. We can punish all the people involved in this, and it will still be the case that your drivers license is available for purchase and identity theft against anyone is now much easier. They don't have enough enough to repair the damage they've caused, even if we take everything from them.