‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. louthy · · focus · HN ↗
      Or … and hear me out on this one … care?
      1. carefree-bob · · focus · HN ↗
        Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this.

        They can try:

        * various education campaigns

        * force users/customers to adopt passkeys or other phishing resistant mfa

        * add various alarms and alerts for unusual activity, resulting in lockout

        The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.