upvote
> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want

Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.

That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

reply
> I think it's usually not malice, it's incompetence.

Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

reply
why not both?
reply
[flagged]
reply
It's really not a hot take.
reply
> Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.

I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.

reply
One could say that simply incentives are wrong so people turn negligent and/or are out of their breadth on a topic.

But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?

reply
> Intent matters a great deal,

The road to hell is paved with good intentions.

reply
In the context of a company doing something like this, intent does not matter in the slightest.
reply
deleted
reply
> Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.

The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.

reply
In China, CEOs go to prison or are executed. Not all the time, but enough. In the US, they are given a golden parachute and make more money at their next posting. There is mostly only failing upwards.
reply
Will the CEO suffer consequences? It seems the worst they face is being fired with a golden parachute.
reply
It's malice. Compliance tends to not "maximize the shareholder value". Why pay millions/year to maintain a compliance team when you can get away with paying a small fine from time to time?
reply
It's probably both, vis a vis negligence. I just wish it was treated as criminal negligence. This will continue as long as CEO's face no real punishment for mishandling PII.
reply
Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!

At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!

reply
Uhh. I think you misread my comment pretty badly here. I am not making excuses for anyone.

I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.

Both are inexcusable, but one is more common/likely than the other.

You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?

reply
> I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.

Not being held accountable for negligence or incompetence is the evil machination.

reply
Everything you say should be true on any level playing field. Not in the British public sector where shambolic incompetence is the norm.
reply
Replit was asking for my license to change email address. Jeez
reply
Same here when they find out I’ve never had an FB/IG/X etc account. As though having that crap in your life is somehow mandatory.

People who make poor choices love to pretend that they had no choice at all.

reply
1. Interaction with Meta is virtually mandatory in many places in the world. Try opting out of Meta when your kid's daycare or your building's group chat is on whatsapp.

2. It doesn't really matter if you opt out, because _other people around you don't_: they take pictures in which you show, they tag you, they talk about you, they send you links, etc. Which means they (Meta) build a shadow profile of you anyway.

The "personal responsibility angle" is pure fiction.

reply
My building’s group is on FB. I’ve managed without access for over a decade.

I live a somewhat normal adult life and manage without having anything to do with Meta ¯\_(ツ)_/¯ I probably miss out on some things, but I don’t notice.

All my friends just contact me through other sources.

If you have kids, it’s more difficult - I can acknowledge that.

reply
You’re assuming that my primary concern is my privacy rather than my sanity. I don’t understand how anyone can seek out a non-stop feed of the sort of people who routinely post on FB. I’ve seen exactly what the doom scroll does to people without them realizing it.

So yeah if a business requires me to have an account I’ll find a different business to patronize. Frankly if you’re expecting someone other than you to take responsibility for the media you consume, that’s a problem.

reply
When are the victims going to start getting significantly compensated for these breaches?

They will keep happening as long as the consequences are just the cost of doing business.

reply
It becomes tricky fast.

There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".

There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).

Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!

reply
It will be when enough people elect enough politicians who take action against this weaponized incompetence and strip-mining of the peoples' assets.

Or, if that does not happen, when enough people rise up in revolution and take the compensation for themselves.

Or, never.

If enough people vote enough or revolt enough, they cannot be stopped. But the incentives for too few people rising up are too costly. They work hard to keep the equilibrium in that balance.

reply