top | item 32868179

(no title)

delaynomore | 3 years ago

>I had full expectation that a non-tech company like U-Hual would be fully incompetent to properly store such a trove of identity information,

Why would a tech company be any better at handling data securely? More engineers doesn't mean better security.

discuss

order

toss1|3 years ago

>>Why would a tech company be any better at handling data securely? More engineers doesn't mean better security.

True, it is not a necessary relationship.

My assumption is that a company with technological founders and strong engineering contingent has at least a FEW people who have at least encountered issues of digital and network security before - someone who might raise a flag here and there. So, a slightly greater likelihood of some responsible decisions.

But for non-tech companies, the general attitude I've seen is hostility to whatever IT they have, whether outsourced or insourced, as it is a cost center and generally seen as the scapegoat for whatever inconvenience happens related to any tech, and either wholesale ignorance or active misunderstanding of tech issues.

So, when a responsible and knowledgeable engineer brings up the idea of "maybe it isn't a good idea to store all this info, or at least we should get expertise on how to handle it..." it seems that the likelihood of getting an actively hostile response is higher.

That said, there are plenty of sociopathic execs flocking to run tech companies who will even more actively seek to harvest maximum customer data and 'screw 'em if we leak or sell their stuff'.

So, maybe a minimally effective assumption.