Hacker Newsnew | past | comments | ask | show | jobs | submit | dylan604's commentslogin

There are many many much more crazier ideas floating around. This one, even if made up, is funny and not harmful to anything. I'll allow it.

True, zootopia 2 agartha conspiracies exist.

Who receives the payouts of those insurance benefits and how would one go about making a claim?

The company typically receives the payout to cover losses from whatever incident precipitated the claim. This isn’t hypothetical. Companies already do this. For example, a company could get hacked and extorted for ransom. They can file a claim and use the payout to pay the ransom. Or a manager makes a mistake that results in a lawsuit, settlement, defense costs, etc. The company can file a claim against a management liability policy.

What’s new that I’m proposing is to require companies to carry insurance and list accountable people on the policies so that claim history is associated with their decisions. Many companies already have management liability and/or cybersecurity policies, but it’s typically optional and individual decision makers aren’t listed on the policy. The claim history is associated only with the company and never the people who made the decision. That’s why they can just leave and do the same thing somewhere else.


And when the hacked information is used to cause a national-level disaster, the costs of which are greater than the assets of the insurer, and their re-insurance funds, bankrupting them, what then?

Insurance is not a solution for everything.

More critically, just because a company buys insurance, it should not be a get-out-of-jail-free card for the executives and management to feel free to manage data irresponsibly.

It is really simple:

If they can not handle properly the risks of their business, they should be in another business.


In that kind of situation you are just fucked regardless.

Ok. How do you propose they prove they can handle the risks? Who is responsible for determining that and what are their qualifications?

That's the secret: no one can.

Any data stored anywhere can be exfiltrated through either social engineering, or computer hacking.

Make it illegal to have this data, and if they really want it, then you hit them with jail when it leaks, not fines that can be paid by the board in the form of a golden parachute.

Only those that absolutely need data like this should store it. Like, I dunno, the government? Everyone else can rely on zero knowledge proofs or literally anything else than forever storing a scan of someone's entire fucking identity.


Seriously this

We need people to stop internalizing that the government and the rich somehow deserve access to private data just because they want to use it. Seeing a way to make money using enough to make you entitled to it.

Force businesses to add value if they want to exist instead of extraction or rent seeking.


They are, by deciding if they are able to handle having their lives certainly ruined if they screw up. The trick to punishment as deterrence to planned actions is 100% identification and enforcement, so that people will avoid the behavior to avoid the punishment. Anything less and some people will decide the potential payoff of success is worth it.

Reality and certainty of consequences, not evasion and insuring of liability

I specified it in the last sentence: >>If they can not handle properly the risks of their business, they should be in another business.

The same way it is handled in any other business or trade with risk.

Make sure the risks are also PERSONALLY CONSEQUENTIAL TO THEM.

If they fail to handle the business with state-of-the-art advanced knowledge, intelligence, diligence, and resources, then they will face serious personal consequences. If they do not want to take that risk, they are free to go work in any other business.

Some people are fine taking the risks of subsea welding or windmill maintenance. Others are not, and are free to pursue other work. The risks for fuking-up there include sudden death and life-changing injury.

It should be the same for people risking the livelihoods of every person who's data they handle — if they fuk-up badly enough, their risk should be financial bankruptcy and prison.

Instead, white-collar work is typically organized so those who fckup get a promotion or just find a new higher-paying job, while the people they screwed over are left to deal with the consequences.


This was the site shown to me to prove the separation of style and content. After that it was CSS-Tricks that I found myself frequently reading for answers to the things I was stuck on getting the layout to work.

That's great. Now put yourself in the same situation the cops are working with and not your arbitrarily applied restrictions. The cops clearly do not have these restrictions, so why are you applying something artificial like this?

Since the context here is the U.S., there are plenty of restrictions they are legally bound by. Here's a small sample:

- The fourth amendment (protection against unreasonable search and seizure)

- Mapp v. Ohio, 1961 (evidence gained without adhering to the fourth amendment is inadmissible)

- Wong Sun v. United States, 1963 (conclusions drawn from unlawfully obtained evidence/illegal entry can be challenged or outright discarded)

- Franks v. Delaware, 1978 (the right to challenge evidence collected on the basis of a warrant granted on the basis of a false statement)


Flock records public events. None of these apply. There is no reasonable expectation of privacy in a public space and the courts have been quite clear on this. Actual legislation would need to be passed to restrict what can be recorded in public settings. A redefinition of "public", basically. And what about the public? Would they also be barred from making their own recordings of public events? Would they be barred from sharing them with law enforcement?

Not necessarily. One could argue my cell phone's signal is in the public when I use it (home or otherwise; it is rather omnidirectional), and the records thereof aren't subject to it the same way as say a search of my phone or my home.

However, in Carpenter v. United States, government entities were found to be in violation of the fourth when accessing historical CSLI records containing the physical locations of cellphones without a search warrant (at least over a period of 7 days or more, if I understood it right). Previously, it was considered fair game under the basis of records technically turned over to a 3rd party.

Then there's United States v. Jones (2012), where it was established a GPS tracking device was attached to a car constitutes a search.

It remains to be seen how Flock will ultimately hold up in court. Although a few cases have popped up, I think it's too early to tell.


The police officer is not standing on the street corner, observing public events. They are searching a privately-held database of sensitive information whose use is governed by certain restrictions, which are being violated by the police officer. Whether or not those violations rise to the level of crime does not erase the fact that they unethical, and likely against both Flock's terms of service and the department's policy.

Pardon, but I think that someone who carries a gun (and is allowed to use it) as part of their work uniform requires stronger, not weaker ethical guidelines than someone who pushes code.

I hold myself to all sorts of standards that are not enforced by anyone outside of me. There are plenty of things I choose not do do despite a complete lack of consequence if I do them.

It's a called integrity and morality. Clearly another thing cops and their sycophants don't have.


I mean, if the field is required and is open text with no requirement that the text be useful, why would you bother? How many of use put stupid text into fields just to get to the download? Yeah yeah, cops are supposed to be above blah blah, but they are human.

Just because there isn't a coded requirement doesn't mean there hasn't been directions to state valid requirements. This isn't a Jira ticket, this is a tax-payer funded government official supposedly doing his job, and should 'bother' to give valid reasons.

I'd venture a guess that OAI doesn't mind if the HuggingFace hack gets confused in the public's mind.

> From what I can see, online media has finally taken over.

Makes me think of Neil Gaiman's American Gods


Would there also not be some reputational damages that could be compensated for as well? These are the types of cases usually ending in a settlement for non-disclosed amounts with NDAs attached.

> Would there also not be some reputational damages

In that case OpenAI should sue since they came out of this with a worse reputation.


Might be the only way to reign in the AI bots. By accessing my site with a bot, you agree to reimburse me for that data at the rate of $1,000,000 per character retrieved. Please contact licensing@domain to get set up with payment and access keys

And by linking to your site from other websites, by not requiring authenticated human-only login, and by not blocking traffic from all referrers, you agree to allow my bot to access you site at zero cost.

I have clearly communicated the constraints of use on my site using robots.txt, which is the established standard for communicating things like these. You are expected to fetch it and figure it out. It is not necessary to build walls and lock doors when a no trespassing sign is clearly visible.

Seriously, though, making robots.txt have the weight of law would be a massive improvement for the ecosystem in general.


and what happens when the perpetrator does not reside where that law can reach?

> Ideally you're looking for people who have said they installed it successfully and haven't run into compatibility issues.

That's like telling someone they can run a Hackintosh by just following someone else's build write up. Buying the exact same hardware rarely gives the easy peasy builds the write up suggests. Ultimately, there's always a couple of steps left out of the write up that makes things much less easy peasy. People forget pain points or at least gloss over the pain points. Doesn't matter if it's Hackintosh or reading other's from memory "I installed Linux, you can too" comments on a site like Amazon


The review's purpose wouldn't be to provide you an in-depth guide to walk you through installing some distro. It's more like probing for high level details around hardware compatibility.

For me personally, the laptop I mentioned worked out of the box. I didn't have to do anything custom or follow a guide. I turned it on and everything worked after I installed my distro of choice. Likewise my 12 year old desktop which has a USB audio interface also worked with no special tweaks or hardware incompatibility issues.


The pain points have gotten less painful in the last few years. As someone who has run a hackintosh at one point, Linux is a walk in the park in comparison.

Also, strange as it is to say, LLMs are incredibly helpful for fixing any little problems that do show up. ChatGPT and Claude do a great job of helping diagnose problems and tell you what to do to fix them. Less useful for experienced users, but for beginners they’re a lifesaver.


> Less useful for experienced users, but for beginners they’re a lifesaver.

The last emerge conflict I had was handled 100% by an agent.

I'm not wasting my weekend on stupid sysadmin tasks anymore.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: