So I got a notice from Ticketmaster that my identity was accessed by an intruder and my name, contact info and /encrypted/ payment info was compromised. These notices are more and more common. Why aren’t companies accountable for damages when they fail to protect all the myriad data they collect on people without consent? I never asked them to store these things…

  • xmunk@sh.itjust.works
    link
    fedilink
    arrow-up
    17
    ·
    6 days ago

    You have the option to sue or join a class action lawsuit - there is currently a class action lawsuit. If that interests you (and it should) be careful not to agree to anything with Ticketmaster.

    The chances of you personally recovering much compensation unless you can show real personal damages and pursue Ticketmaster in an individual lawsuit.

  • sunzu@kbin.run
    link
    fedilink
    arrow-up
    11
    ·
    edit-2
    6 days ago

    Why aren’t companies accountable for damages

    Whatcha gonna do about it…

    That’s why

  • Rhaedas@fedia.io
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    edit-2
    6 days ago

    I’ve come to the conclusion that all these breach notices and the free stuff they offer for X months is a huge scam to get you sign up up for something. Either that, or every company has woefully underpaid/incompetent IT people. I’m waiting for the next news story to break on another company that somehow got passwords or identity info hacked that was stored in plain text…something I learned how to not do back in the 90s with basic HTML and PHP.

    In short - I don’t believe them. They all are using the same form letters, it’s a scheme that they’re all in on.

    • ImplyingImplications@lemmy.ca
      link
      fedilink
      arrow-up
      5
      ·
      6 days ago

      Either that, or every company has woefully underpaid/incompetent IT people

      It’s this one. Cox Communications, one of the largest telecommunications companies in the US with $11 billion in revenue, recently patched a bug on their self-serve portal that allowed anyone to access any customer’s profile. The bug was that server requests weren’t being authenticated. If you entered the right info into the URL bar you’d be given a page with anyone’s customer info. No login needed.

    • sunzu@kbin.run
      link
      fedilink
      arrow-up
      2
      ·
      6 days ago

      I doubt they are that rookie about it…

      But I do suspect a lot of these “breaches” are inside jobs though.

      At the rate they are happening, nobody is held accountable… This is a good value proposition for an enterprising hard working person…