Comment by josephg

4 hours ago

Yeah I've long said we should treat data leaks like food safety. The only way we'll see software security improve is if there were serious fines and/or jail time for leaking user data due to negligence.

PCI compliance works pretty well.

I would like to see restricted access to only us workers for us citizens data though.

Transferring us customer data outside the country should be illegal

  • PCI compliance is a joke. That isn't even close to good enough. I'll break all your PCI compliant stuff trivially.

    • What’s your main issue ? The compliance audit being lax or the compliance not being assertive enough ?