> my conclusion after dealing with them for many years is they will lie, cheat, and steal to get whatever they want
Honestly, it's not even that extreme in most cases. I think it's usually not malice, it's incompetence.
That's why I don't trust big companies with my data. Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
> I think it's usually not malice, it's incompetence.
Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
why not both?
[flagged]
It's really not a hot take.
> Sufficiently advanced incompetence is indistinguishable from malice, and should be treated accordingly.
I disagree with this as stated. Maybe in the right context you could make a case for it, but in general? Heck no. Intent matters a great deal, and there is no justice in treating someone incompetent (or negligent) the same as someone who is actually malicious. Both things are bad, but the latter is worse than the former even if they lead to the same outcome.
In the context of a company doing something like this, intent does not matter in the slightest.
One could say that simply incentives are wrong so people turn negligent and/or are out of their breadth on a topic.
But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?
> Intent matters a great deal,
The road to hell is paved with good intentions.
> Nothing to do with some CEO's evil plans, but more to do with the hundreds/thousands of mid-level "not my job" or "doing my best" workers who are actually in charge of handling my data.
The CEO is responsible for what their company does. If a major breach can occur through the oversight or "incompetence" of one worker, the CEO has already failed, whether through negligence or malice.
In China, CEOs go to prison or are executed. Not all the time, but enough. In the US, they are given a golden parachute and make more money at their next posting. There is mostly only failing upwards.
Will the CEO suffer consequences? It seems the worst they face is being fired with a golden parachute.
It's malice. Compliance tends to not "maximize the shareholder value". Why pay millions/year to maintain a compliance team when you can get away with paying a small fine from time to time?
It's probably both, vis a vis negligence. I just wish it was treated as criminal negligence. This will continue as long as CEO's face no real punishment for mishandling PII.
Pardon my French but bull-fucking-shit! A CEO _should_ take responsibility for what their subordinates do. It's preposterous to simple throw up our arms and say "oh well, some employees were sloppy so we lost some 100 million user IDs and other sensitive information that we promised not to store but we lied. Oopsie, silly me, pardon my wee incompetence tee-hee". No no no NO NO!
At some level, and certainly at the level where you get paychecks of 10 million a year for the "huge responsibility you are bearing", then incompetence IS malice!
Uhh. I think you misread my comment pretty badly here. I am not making excuses for anyone.
I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Both are inexcusable, but one is more common/likely than the other.
You can certainly link them together and yes leaders should be held responsible no matter what, but from my perspective as the user who had his data leaked, it doesn't really matter how/why it happened, does it?
> I am saying that it's less likely to be some evil machination that led to the misuse of my data and more likely to be negligence or incompetence.
Not being held accountable for negligence or incompetence is the evil machination.
Everything you say should be true on any level playing field. Not in the British public sector where shambolic incompetence is the norm.