Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Assuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company.
  • And what about the governments like Berlin for example? Massive data breach, and guess what happens? Nothing to those who are responsible for the breach.

    So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass.

    If the Berlin incident remotely had happened to any private company - hell would have been loose.

    Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.

  • Sounds great if all the following is true.

    * Before Tax Revenue

    * If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.

    * Includes Worldwide Revenue

    * Includes companies based in all other Countries.

    I would have went for 20%, but if he above applies I wish the US would do the same.

  • This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets.

    Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.

  • I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
  • "through intent or gross negligence"

    I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.

  • Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
  • You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

    Minimizes money usage and does not require any security investments

Explore Birbla archives