People get hacked all the time but the data these folks failed to defend is almost as bad as what the Feds lost. You can always repair your credit, get new cards, even replace your money but you can never ever get back your reputation or your family or the respect of others if you lose that. But giving such a site this type of information (even if you were only curious) is just asking for it to become public. The consequences can range from embarrassment to divorce to losing children or even getting murdered. Whatever the thrill it's not worth the risk.
I don't know how to implement such a thing, but failing to protect people's information seems like it should be prosecutable. Maybe it's an impossibility but I don't know how else to make people care about protecting private information.
I think we've learned over the years that perfection is an unrealistic goal when it comes to data security. We should still strive for better and better methods of securing data, but I think we should also try to change our expectations. When putting any information on the internet, it should be assumed that there is a decent risk of that information being discovered (regardless of security measures involved). We need to plan accordingly.
In this case, if discovery and release of the data would be something you don't think you could recover from, I think that is a good indication that maybe the data is associated with something that isn't worth doing.
This is insane, you're saying Ashley Madison should be prosecuted for having their data hacked? Do you have any idea what that means for the rest of the world's websites? And to even make a claim that this is somehow worse than the massively private information the Feds lost is laughable.
Do you know what data AM had on its users? Do you think it's even remotely close to the data the Feds had on every single public sector employee in the US? Should the US be prosecuted for losing that data? Should I be prosecuted because my site got hacked through a 0-day?
Should KVM be sued for a bug that allowed for that hack? Should Linode since they're the data center?
No, no one should be sued. If you want people to wake up about their private information, then prosecuting the sites is in no way going to achieve that. How about people themselves are the ones in the wrong for cheating, and not a website that makes it easier. This is akin to blaming and banning alcohol because someone drove drunk.
What's wrong with the idea of having limits on data collection and regulations around their storage? You can't prosecute someone for being the victim of hackers but you can (and should) for not applying reasonable efforts in safeguarding data or storing more than they should.
There is always someone on HN who thinks whatever data you're collecting is too much, and plenty of hacks were the result of pretty sophisticated 0days in underlying systems despite reasonable precautions being taken in administration processes. There is already negligence on the books.
'Too much' isn't just some random person's opinion where it's all relative. There are already plenty of examples of data regulation in governmental and commercial contexts - from PII of minors, to PCI, to data residency, to what companies are allowed to do in regions like Europe, Russia, and Asia.
All these hacks we are seeing of both public and private data are proving increasingly damaging as more data is being collected and aggregated (whilst as you point out, impossible to fully protect against).
This very clearly indicates an urgent need for far greater regulation of what is allowed both in transit and at rest, as well as suitable penalties for negligence. This should be a politically non-partisan issue as it's so wide ranging, covering national security (e.g. Snowden, OPM) as well as comedy gold in the commercial sector like Ashley Madison and more serious cases like Target.
Data regulation has to do with things like retention length, reasonable precautions, the right to have your data deleted, the right to see what they have on file about you, requirement that data be anonymized under certain contexts, etc. There is not a clear bright line about what data is "too much" for your application - that's a judgement call, and a nightmarishly vague and technical concept for a jury to decide.
It also has to do with what kind of data is allowed in transit and at rest as per the examples I gave which are all around legal and commercial regulatory compliance. It has never been a free-for-all where operators use their personal judgement. In several territories you need to be registered with the government to collect certain kinds of data for a start.
But now we are at the point where there is sufficient data being collected and aggregated (by both public and private orgs) that hacks can damage economic infrastructure and harm wider society i.e. not limited to those who have interacted with a particular entity. This means that light touch regulation is completely untenable (quite apart from the general naivety of looking to the market to solve problems it could not even theoretically be solved in the marketplace when your infrastructure itself is toast).
In this case apparently they failed to even encrypt the data. If you open your garage door and leave all your house doors wide open and get robbed I don't think your insurance company will pay you anything.
I don't know how to implement such a thing, but failing to protect people's information seems like it should be prosecutable. Maybe it's an impossibility but I don't know how else to make people care about protecting private information.