Hey #discord . Why the hell would we give you our ID when you've already exposed the ID of the folks who have already given you their ID?

"We're now using a different vendor who haven't yet leaked everyone's IDs and we keep your data for the smallest possible period of time!"

Every organization will have a data breach eventually. The question is when affected users will find out and what data you had in the first place.

The fact that your new vendor has not yet had a known breach doesn't mean that they're safe. It doesn't even mean they haven't had a breach yet! It just means any breaches are, as yet, unknown.

A fundamental principle of PII is that you should not gather data unless you have a sufficient justification for doing so that cannot be handled without having that data.

Your justification is nonexistent for you ever having this information. Therefore ever having it is not justifiable. If our legal systems allowed the full consequences of that inappropriate data collection to fall on your shoulders where it belongs, no insurance company would ever agree to insure you while you are gathering this data. No matter how little a period of time you purport to have it.

#RiskManagement #PII #PI2 #Technology

Hey #discord . Why the hell would we give you our ID when you've already exposed the ID of the folks who have already given you their ID?

"We're now using a different vendor who haven't yet leaked everyone's IDs and we keep your data for the smallest possible period of time!"

Every organization will have a data breach eventually. The question is when affected users will find out and what data you had in the first place.

The fact that your new vendor has not yet had a known breach doesn't mean that they're safe. It doesn't even mean they haven't had a breach yet! It just means any breaches are, as yet, unknown.

A fundamental principle of PII is that you should not gather data unless you have a sufficient justification for doing so that cannot be handled without having that data.

Your justification is nonexistent for you ever having this information. Therefore ever having it is not justifiable. If our legal systems allowed the full consequences of that inappropriate data collection to fall on your shoulders where it belongs, no insurance company would ever agree to insure you while you are gathering this data. No matter how little a period of time you purport to have it.

#RiskManagement #PII #PI2 #Technology

It's hard to talk about the Epstein class without thinking about "The Economy" - "The Economy" in the sense of a kind of mystical, free-floating entity whose health or sickness determines the outcomes for all the rest of us, whom we must make sacrifices to if we are to prosper.

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2026/02/09/sloppy-steve/#mckinley-fanfic-panic

1/

It's hard to talk about the Epstein class without thinking about "The Economy" - "The Economy" in the sense of a kind of mystical, free-floating entity whose health or sickness determines the outcomes for all the rest of us, whom we must make sacrifices to if we are to prosper.

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2026/02/09/sloppy-steve/#mckinley-fanfic-panic

1/

Chip Butty boosted
Jürgen Hubert and 1 other boosted