Hacker Newsnew | past | comments | ask | show | jobs | submit | AIiscoming's commentslogin

No one cared about shitty posters before (and yes they are shitty) and no one cares about them now.

No one is praising or collecting them. We just accepted that shitty poster exist.

Now some few people complain about ai slop at situations were no one cares and no one cared /shrug


They look absolutly well done.

Well maybe not that, it would have to stop almost aligning text to make it good instead of usable.

Lets be honest here, this is a business risk which is crazy high. As stupid as this is, I care but i can't guarantee it.

I might suggest a construct like this too.

What do you think how much it cost to do it perfect?


Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.

It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).


Again this is not priced in. Every rational(in terms of revenue) business would rather be a highly profitable "amateur" compared to a barely profitable "professional".

There is no capitalist incentive for the latter, and you will lose market share to firms that can undercut you because of their lower costs.


4% of revenue in the EU, 4% of revenue in the UK, and 10% of revenue in Korea should be enough of an incentive to start caring about how you deal with your customer’s privacy and personal data.

One assumes the rest of the world won’t be far behind, apart from the the corrupt land of the USA which is going backwards right now.


So we get to a very easy formula for companies to do in the EU and UK:

If (4% of your revenue * risk_of_breach_with_your_security < cost of outsourcing storage to a 3rd party cloud) {

Roll your own security solution

} Else {

Outsource to 3rd party

}


Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty.

In my experience, putting proper compliance procedures in place, following industry best practice in relation to data management and data security actually leads to a more effective organisation, because it professionalises.

It’s the first step out of the ad-hoc phase of a startup and into the real world of creating a business with value. It also means as you scale up the personnel in the organisation, there are proper checks and balances in place.

When you come to sell your business, if it has a ton of existential risks attached to it, it will be worth less and may even not be sellable at all. So even from a cynical “all I care about is money” point-of-view, you want a business that is sound and isn’t storage for future law suits or fines.

Also, the cost of a fine due to a data breach isn’t the only thing to be concerned about. Gross negligence could lead loss of life, loss of property, loss of earnings, etc. and the buck stops with the executives — don’t think you can’t be completely fucked by the good ol’ law as it stands today.

Some businesses are more vulnerable than others, but that’s also why you scale the compliance architecture to the business.


The person you're replying to is citing the incentives that are created. That's not cynicism, it's analyzing motives to help model outcomes.

As for the buck stopping with the executives: can you apply this to a case I've heard of? We have multiple data breaches of companies that scan IDs. We have the Experian breach. We have multiple LastPass breaches. Is there any executive at any of these companies that has been held accountable?

I've actually done the legwork on the ones I just mentioned and the answer is there have been no criminal or civil penalties to any individual in an executive role at any of those companies as a result of the data breaches. Maybe I'm missing one?


Maybe I wasn’t clear in my message. But the buck stopping with the executives is when ‘the company’ breaks law. Usually because of gross negligence or corporate manslaughter.

With my last company, managing medical records, I was always conscious that if we didn’t take our responsibility of managing medical data correctly it could lead to the death of one of my customer’s patients; or some other extreme circumstance that the executives could be held liable for.

That was my point about being professional, if you have proper processes in place and audits to prove it, you have protection. And only the most egregious cases would land.

It’s good business to protect yourself from a gross negligence or corporate manslaughter claim. It just so happens that it’s good for your customer too.

Presumably, the reason you don’t hear much about executives in the dock for these crimes is because most professional organisations put these processes in place.

Again, I was just stating that it isn’t just data-breach fines that should encourage executives to professionalise.


Wondering where the accountability was in the hack of this Finish psychotherapy organization (Vastaamo).[1]

As far as I know, it was considered an act of god not something that resulted in punishment. Oh sure, they punished the hacker, but how about the people who were supposed to keep the data secure?

I’m not sure where I stand on punishing companies for getting hacked. I guess like the thread says, was it gross negligence? Back to searching the internet to find out…

Edit: definitely gross negligence.

> one of the first things he noticed was how lax security had been. “It was definitely unfit for purpose for storing this kind of information,” he says. He tells me that the patient records database was accessible via the internet; there was no firewall and, perhaps most egregiously, it was secured with a blank password, so anyone could just press enter and open it [2]

Edit: accountability? Maybe.

> the board announced that it had let the CEO, Ville Tapio, go. In April 2023, Tapio was found guilty of criminal negligence in his handling of patient data. His conviction was overturned on appeal in December 2025 [2]

[1]: https://www.bbc.com/news/articles/c62nzxqw45eo [2]: https://www.theguardian.com/technology/2026/jan/17/vastaamo-...


> Your replies here suggest a level of cynicism that is, well, … , it ain’t pretty. It seems you think “fuck the human cost as long as I’m making money”. I’d suggest changing your outlook on life if I didn’t feel like it wasn’t such a lost cause.

This is the default business mindset. Push every rule and regulation to the limit in the name of profit, if you can break a rule with minimal concequsnces then pay the fine and move on.

Stellantis has a recall out for >1M vehicles because they catch fire even when turned off. Unless that kind of fuckup is met with business threatening fines it will happen again.


> This is the default business mindset.

It isn’t, it is how some people approach business. Not all.

Again, in my opinion this is just cynical and constantly - almost psychopathically - propagated here as though it’s some kind of virtue of business or the only way a business can be ‘pure’ and succeed.

It just isn’t.

And, if you want to sell B2B, you have to sort out your compliance, or you’re gonna sell nothing. So, for a very large number of businesses, this levelling up is non-negotiable if you want to succeed.


I want to see how much be the fine will for this data leak.

https://www.dw.com/en/cyberattack-in-berlin-14-million-files...


It's only an incentive to start caring if it's cheaper than circumventing the law. In other words it won't work unless the aforementioned liability loophole is closed.

To rephrase the comment you replied to, if being a cowboy is more profitable (by whatever shady means) then that will generally be preferred by the market. Despite whatever sensibilities you or I might have there is no escaping that simple truth of capitalism.


> There is no capitalist incentive for the latter

This is literally the point of data breach laws like this. To provide a financial incentive to take this stuff seriously.


The bar for not getting hacked is a lot closer to perfect than gross negligence

The bar is: do you have effective compliance in place? And are you audited? (ISO27001 [1] or similar).

If you are hacked and you are seen to have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.

However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.

You may still get a fine, but it would be much reduced.

It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.

It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.

[1] https://www.iso.org/standard/27001


But it does create an incentive to not keep data that a company doesn't really need. And that incentive already works with GDPR for PII.

This measure add similar incentive for data breaches.


Or not trying to actually finding a root cause. Look i increased the storage for customer, problem solved.

No? You solved the symptom not the issue?


To be fair, that is often a reasonable tradeoff when there’s higher priority things the business needs to focus on.

I sometimes suggest timeboxing investigations for this reason. Spend 4h on this - if root cause is not found, just throw more hardware at it. Although I expect a writeup of what was investigated and ruled out, so that it can be used when someone returns to it.


Yes, one of the primary dysfunctions I see in business environments is a culture that doesn’t create space for timeboxed and clear discussion of tradeoffs. Everyone must have both the _appetite for_ and _implicit or explicit permission to have_ a reasonable discussion of option A vs option B and the long vs short term costs and benefits of each. There must be enough discipline to not rabbit hole or scope creep and decisions must be captured somewhere in a concise way so that everyone who is impacted is informed, and everyone who will inherit the downstream consequences can understand and articulate the decision chain that led to current state.

This is rarely if ever done in a sensible way. Instead you find Managers, Engineers or PMs avoiding troublesome stakeholders, hallway convos or Slack DMs that are never properly written into public record in a searchable/readable way, last minute overrides from higher ups based on limited context of the problem space or their own unaligned career goals, poor recordkeeping, panic mode bandaid fixes when systems break, etc...

IMO a lot of the “meat proxy” and “loop obsession” behavior we’re seeing is simply people using the sense of short term productivity gains as self-soothing against anxiety from corporate dysfunction that they have no control over.


I've seen it too, and it seems to be getting worse as companies move more and more communication onto Slack, ticketing systems, Confluence, etc. Modern channels are a huge high velocity dumping ground. The only way anyone can even pretend to keep up with all the - frankly - spam is arbitrary sampling.

Oldschool periodic reports and memoranda weren't perfect, but they did encourage taking time to curate one's message. And gave others somewhere to go for a properly curated message.


Thats not the problem of LLM/AI.

The problem is, that digital work, the new frontier of employment for a lot of epeople, got and will continue to get A LOT cheaper, faster and more accessable.

The PO who always complains about someone? They will just vibe stuff. It might even be shit but it will work good enough until LLMs/AI/AGI/ASI is good enough or better anyway than an avg developer.

Man i have seen so so much shitty code even in software companies.

You know when your HR software takes seconds to load? Yeah an LLM can do that today too


Don't be so snarky, right now its actually true because they pump drinking water directly from the grounds and evaporating them into the air and therefore taking local water and putting it in some ciruclation which will not refill the local water...

No pressure would make it even worse.

But lets be honest, we were put into specific spots, we can't just get out.

We were able to just take land and make it ours, if you get put on a planet were everything is owned, the critisism were your food and cloth is coming is not their fault.

Its not pointless. It might have less impact than it should, but its not pointless.


Every human has to go through this in modern times.

I got quite frustrated and disappointed when taking pictures because everyone was doing it and my picture of x was similiar to others taking picture of x.

Either you learn from it and accept that and still do it, or you don't.

But its not new


I wouldn't mind it if all the services stop working properly when you use a Passkey but still want to use your other stuff like password and 2fa through app...

GitHub breaks with this, PayPal breaks with this...


TUM, LMU, all the british ones, Delft...

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: