back

by LinuxBender·11y ago·view on hn ↗
I am no lawyer, however I suspect we have a few on this site.

Does a suicide potentially move this from willful civil negligence into the realm of criminal negligence? Nonfeasance?

6 comments
If you mean would Ashley Madison be criminally negligent for allowing themselves to get hacked, the answer is pretty clearly no. There's a very high standard for criminal negligence. Your conduct has to "grossly deviate" from normal conduct, usually showing a great disregard for human life. We don't want to be locking people up for every poor business choice or bad decision.
We could, and this is just a suggestion, look at the people who actually conducted the hack.

Leaving my doors and windows open is stupid but not an invitation to go rummaging thru my stuff.

Interesting analogy, what about this:

Your friends pay you money to permanently dispose of the evidence of their marital affair

You just leave the evidence at your house instead

You leave your doors and windows open

Now its still not your fault that people came in and rummaged through your stuff; but surely its you who are to blame for never disposing of the evidence as you promised (and accepted payment for)?

Its an interesting component to what is otherwise extremely simple.

If i paid a document shredding company to shred my documents and months later that company gets broken into and all my documents are released...

Surely i blame the shredding company as much, if not more, than i blame the thieves.

I don't really have a position or idea on what this all makes ashley madison guilty of from a criminal or civil law perspective - but i certainly feel that there are punishable actions taken by ashley madison in this whole mess

Your addition to the analogy doesn't really change anything, unless I made an absolute guarantee to either 1) immediately destroy the information or 2) destroy said information within a given timeframe and failed to do so.

Both of those are separate issues from leaving the information laying about.

In the original case, I might be stupid, but the interlopers are wrong to assume that they had an invitation to stuff laying about. They are, in fact, burglars.

Even with your addition, they are still burglars. However, I am liable for either 1) failing to destroy said information/stuff and/or 2) failing to do so within the specified timeframe, if the burglary happened after that timeframe.

The blame to the burglars remains the same in either case.

Honestly, I'm sort of enjoying a fat cuppa shadenfreude tempered by the knowledge that it is, for the most part, really none of my damn business what someone else does with their naughty bits.

Their conduct absolutely "grossly deviated" from normal conduct. They falsely advertised data deletion services, for one thing.

It'd be hard to argue that it conduct that disregarded human life, though.

No, it didn't. Their conduct was bad, and absolutely typical for the industry.
If pretending to delete data is typical for the industry, then we can't know for sure unless a company is breached or an employee leaks the info. It would be very easy to sue a company for lying about that.

You may be right that many companies behave this way, but they at least pretend that they don't. The companies I've worked for have always been extremely conscientious about honoring data-related terms, even if no user would ever know. The fear of getting sued is strong.

Probably not: most of these companies have user agreements drafted by actual lawyers, and those agreements are binding.

In any case: when I say that Avid Life is nowhere near the bottom quartile for companies when it comes to security, you can take that to the bank. Or, don't, if you're worried about taking things to places that won't lose your data in a breach. I guess you can take your data to Facebook in that case.

Snapchat didn't even delete the pictures, to start with. They just made them unavailable to the interface. Which is similar, and maybe enough.

Given backups and billing records and stored message histories and so on, its not really a question of 'deleting an account'. More like 'making an account no longer visible/available to the current interface'. Nobody thought they'd wipe any disks or anything, in anticipation of a big data breach, right?

This is important. The only reason this is much of a story at all is that the "affair" angle makes for very marketable stories. Otherwise this is strictly dog bites man.
> We don't want to be locking people up for every poor business choice or bad decision.

Whilst that is true, we equally don't want to be completely ruling it out. An investigation should be conducted regarding the actual attack, and perhaps their handling of the leak. Did they even notify all users?

Also not a lawyer, but... Was there suspicion that Ashley Madison had been wilfully negligent in the first place? It has sounded to me like the leaked data indicated they actually followed reasonable security practices. Strong password hashing, separation of different types of data, etc. Yes, they got hacked, but it's virtually impossible to guarantee immunity from target attacks.

edit: also, as others have implied, 2 suicides out of 40 million is not that high (I don't mean to downplay the tragedy - all suicides are horrible) - but IMO you'd have a hard time proving the Ashley Madison hack was really the only cause, and not the final straw for somebody who was already in a bad place mentally. If I were to tell someone that their spouse was cheating, and their spouse commits suicide, would I be criminally negligent?

Practically every system I've built at scale uses soft-deletes. A flag is put into the database and records that are deleted are excluded via that flag.

Note that I'm not playing with people's identities, but even then, you have to ask whether they were paying to delete the availability of their user data or the actual database records (somewhere in the contract?).

I think they should be clear about whether the information is still stored, true. But I also do sympathize with AM in this situation. I'm sure many of us have had the experience of going out of our way to secure someone's system for them, and then being asked years later if we can help them when they've locked themselves out. I'd be willing to bet there were more than a few people who paid to have their accounts deleted and came back at a future date and wanted to pick up where they left off.
I've dealt with PII, and soft-deletes are explicitly disallowed. But I work in an industry where "delete" is something to be very carefully defined.
Their overall security procedures may have been good, but at the very least the fact that they charged money for permanent deletion of data and then didn't actually permanently delete data ought to qualify. People who just signed up may not have a case, but anyone who "deleted" their account does.
I've been waiting to see some educated thought on this but it's been pretty absent from the coverage I've seen. Specifically also, I'm curious to understand how not deleting information people apparently paid to have deleted fails to constitute fraud... though successfully arguing negligence would be even more interesting for infosec in the software industry long term.
With the news of AM possibly hacking a competitor, this gets even more interesting, from the legal perspective.

http://krebsonsecurity.com/2015/08/leaked-ashleymadison-emai...

If I have a crappy front door and someone breaks into my house and falls down the staircase, am I criminally negligent because I didn't have a baby gate?
Depends. IANAL, but this answer helped me when I had the same question as you. http://qr.ae/RF23mz
When did this even drift into civil negligence?