Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. German Hospitals Prepare for War, Drones and Mass Casualties(bloomberg.com ↗)
    discuss
  2. Meta Muse Hits #1 in Apple App Store(businessinsider.com ↗)
    discuss
  3. You need more than just vanilla RAG(medium.com/nikozero11 ↗)
    discuss
  4. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    discuss
  5. Your 401(k) Is Propping Up the AI Bubble(promarket.org ↗)
    discuss
  6. PHP, on a Whim #2: Stop Calling Everything an Array(carthage.software ↗)
    discuss
  7. Fat Bear Week 2026(explore.org ↗)
    discuss
  8. Automattic names interim CFO after exec departures(techcrunch.com ↗)
    discuss
  9. What is a System One model and why we need it?(stackness.dev ↗)
    discuss
  10. Show HN: ReacherX – Open-source platform to find and reach the right people(github.com/vecterai ↗)
    discuss
  11. Sam Altman to brief UN Security Council next week(reuters.com ↗)
    discuss
  12. Silex: Laser Enrichment Between Promise and Proliferation Risk(csis.org ↗)
    discuss
  13. Quantum computers will not be that different(arxiv.org ↗)
    discuss
  14. Single player games require age verification if they use Steam under EU KIDS Act(rockpapershotgun.com ↗)
    1comments
  15. A solo founder runs a five-continent tender platform on AlloyDB and MCP(cloud.google.com ↗)
    discuss
  16. Trump Announces Ban of CNN, Politico and MS Now from White House(time.com ↗)
    1comments
  17. Using Cyber Decoys to Strengthen Detection and Response(cisa.gov ↗)
    1comments
  18. Show HN: 3D World Explorer and Location Guesser Game(tadget.net ↗)
    discuss
  19. Saying Goodbye to Firebug (2017)(hacks.mozilla.org ↗)
    1comments
  20. Jev's Architecture Unmasked(archerhume.com ↗)
    discuss
  21. Senior Engineers Are the Next DRAM Shortage(herlein.com ↗)
    2comments
  22. SR-71's "R2-D2" Could Be Key to Winning Future Fights in GPS Denied Environments(twz.com ↗)
    1comments
  23. Terence Tao: SAIR's Open Math Model Initiative [video](youtube.com ↗)
    discuss
  24. California governor signs order to explore AI kill switch(techxplore.com ↗)
    1comments
  25. Communication Doesn't Have a Compiler(wreckitrob.dev ↗)
    discuss
  26. Anthropic Moves Ahead with IPO Plans Amid A.I. Safety Debate(nytimes.com ↗)
    1comments
  27. When the FM Band Goes Transatlantic(radioworld.com ↗)
    discuss
  28. Punctum Books Catalog(punctumbooks.com ↗)
    discuss
  29. AI Error Nearly Triggered U.S. Intercept of Chinese Ship(gcaptain.com ↗)
    1comments
  30. Labeled matches: why is this not in every regex engine?(iev.ee ↗)
    discuss

Korea raises data breach fines to 10% of revenue

128 pointsby 1h agokoreajoongangdaily.com
28 comments
35m agoHN ↗

I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.

32m agoHN ↗

Maybe those specific business models shouldn't exist, if they consistently risk harm to 3rd parties.

31m agoHN ↗

You legally have to hold transactions for years yk as a business

32m agoHN ↗

Probably a law targeted at foreign companies

32m agoHN ↗

Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!

28m agoHN ↗

Or you get some shell firm/subsidiary to hold your data and no difference is made

31m agoHN ↗

Sounds great if all the following is true.

* Before Tax Revenue

* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.

* Includes Worldwide Revenue

* Includes companies based in all other Countries.

I would have went for 20%, but if he above applies I wish the US would do the same.

30m agoHN ↗

You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new shell firm with similar form and function.

Minimizes money usage and does not require any security investments

27m agoHN ↗

Sounds like something that costs money, if a university doesn't care I don't think most companies will.

25m agoHN ↗

Yes, being competent requires effort.

It certainly feels much better being an proactive member of society rather than a self-serving arsehole though.

So, there is that.

18m agoHN ↗

It feels better only as long as everybody else cares too. Being the only one competent in a room of imbeciles is a terrible feeling.

Hmm, this is perhaps why we get socially-negative businesses that often have very friendly (and driven, and hard-working, and intelligent) internal cultures. Competency becomes a fault line. When it becomes obvious that a large fraction of humanity just doesn't give a shit, a small group of people who are competent and driven turn their efforts to taking advantage of people who don't give a shit. Thus creating industries like market-makers, cryptocurrency, advertising, and AI.

7m agoHN ↗

It feels better only as long as everybody else cares too.

Not sure who “everybody else” is in your statement, but as someone who founded a healthcare tech platform (since sold) [1], I spent 20 years caring about the many millions of patient medical records we held and making sure my team cared too. In my mind it wasn’t optional.

I did it because:

* it’s the right thing to do

* for professional pride

* and so I could sleep at night

And, at least at the beginning, I believed a data breach could be the death knell of the company. Over time the laissez faire attitude to data protection by the industry as a whole made it seem like it would be survivable.

I still walked away from it a wealthy man. Being competent and caring about your customers doesn’t have to mean failure like it seems everyone here thinks.

[1] https://www.meddbase.com/

24m agoHN ↗

Every single tool being released since like 2024 is pushing everyone to care less and less and to let agents handle more and more. We are not trending towards increased quality, resilience and reliability - even though we've been obsessing over these things for the past 20 years.

21m agoHN ↗

Caring is orthogonal to profits and shareholder value. The one who cares the least wins unless economic incentives change this math, which is what these financial penalties work towards. Humans are tricky.

To defend against the threat OP talks about (intentionally under capitalized corporate entity to avoided liability), insurance should be required, and your cyber insurance underwriter will perform an audit as part of underwriting. It's effectively a bond against fuckery in this context.

(cyber consultant and practitioner)

19m agoHN ↗

That's not what orthogonal means. Saying they are orthogonal means that you can care and be profitable.

19m agoHN ↗

You can care and be profitable, but it is usually cheaper to not unless regulatory mechanisms exist to internalize this potential externality. Can't rely on humans to do the right thing, some will not unless they feel pain for doing the wrong thing. Ergo, we build systems (legal, regulatory, technical, people) to encourage the desired target outcome(s).

I've worked with very profitable firms who care very little (and it shows in their systems and how they operate in this regard), and barely profitable firms who do everything right. What's the difference? Their culture, people, and internal incentives.

TLDR Security failures and data breach fines must be more expensive than the happy path and doing the right things. This encourages the happy path and doing the right thing, while discouraging doing not enough or nothing.

5m agoHN ↗

Why the middle man? Can't we make the law so that the University is still liable for the data beach because it's "their" data (collected/stored on their behalf) that is breached?

I think that still aligns the incentives, and University in this case has interest to make sure the data is stored properly.

12m agoHN ↗

similarly, most AI datacenters aren't directly owned by the frontier labs

guess who holds the bag if capacity needs collapse

5m agoHN ↗

Sure, but the real question is, "Will a judge not immediately see through this and punish them accordingly in any realistic case?"

Sort of like EULA's a lot of the "value" is incredibly theoretical.

7m agoHN ↗

That's like blaming Seagate when your harddisk fails.

No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.

29m agoHN ↗

"through intent or gross negligence"

I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.

25m agoHN ↗

It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.

5m agoHN ↗

The EU AI Act already levies 7% global annual turnover penalties for prohibited AI practices.

8m agoHN ↗

This feels like a really odd way to incentivize data breaches and/or not reporting data breaches.