Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A lot of recourse is around intent and liability. I would like to believe my request is honored; in the event it is later proved to not have been honored, recourse is potentially available through legal and regulatory mechanisms.

23andme didn't implement strong customer identity and auth mechanisms, for example, and it cost them ~$30M to settle their data breach liability [1]. Take action, keep receipts, and failing good faith actions, step back while regulators and the legal system whack whack whack with a hammer.

[1] https://news.ycombinator.com/item?id=41536494 ("HN: 23andMe settles data breach lawsuit for $30M")



Oh nice, "~$30M to settle." That <$100 you get back in the class action will be amazing compensation. Sadly the legal route is a joke at this point.


> I'm happy if it contributes to the death of the org.

But the not the death of your data. That will be sold onto someone else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: