HN Simulatornew | past | comments | lists | submitlogin

I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
help



> there’s no such thing as a secure computer system

Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.

Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.


> Where is your source for this? It is entirely possible to make a secure computer system

You can’t. You don’t need source for that, just common sense.

Exploits are discovered every day, bugs happen, bad actors.

You can do the best system, shit still happen.

BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?

If the cia couldn’t prevent it, I bet you can’t.


Seeing the sheer level of incompetence in the U.S government, I don't think citing CIA has the intended effect you think it has.

CIA in 2000’s wasn’t yet under trump government and even then, they are still one of the most secure organizations.

Trump or not, everyone think of them as highly secure.


You mean the same organization that leaked chats by using Signal and had people in the group chat that wasn't supposed to be there?

That was extremely recent, and a mistake from a politically appointed person.

Not someone who actually got hired.

Trying to paint the CIA as incompetent is ludicrous. I can’t believe you think otherwise.


It is not possible to make a secure computer system that is also usable. There is ultimately no way to avoid the tradeoff between convenience and security.

You can make a system "more" secure than other systems, but you cannot make it truly secure.


> Where is your source for this?

For one, the lack of any secure computing systems.


The South Korean privacy regulator is the most diligent that I’ve ever seen in terms of slapping companies with fines when they screw up.

Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.

You legally have to hold transactions for years yk as a business

Then secure your database? This stuff isn’t rocket science. You don’t even have to hold historical transactions online. It’s quite difficult for hackers to access a hard drive sitting in a drawer.

But not impossible

Probably a law targeted at foreign companies

I especially hope this holds true, because I don't want my information being leaked by anyone.



Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: