‹ BackHN Continuity

Thread

Korea raises data breach fines to 10% of revenue

339 points · 115 comments · throw7

  1. augment_me · · focus · HN ↗
    You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

    1. louthy · · focus · HN ↗
      Or … and hear me out on this one … care?
      1. m132 · · focus · HN ↗
        Some hard to swallow pills for tech companies in 2026: data not collected in the first place cannot leak.
        1. fn-mote · · focus · HN ↗
          In the abstract, yes.

          In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.

          1. markhahn · · focus · HN ↗
            that's the odd thing: we simply don't ask whether there's an alternative.

            for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.