" The Ethics of buying stolen data "

Found this rather interesting article concerning the Web Summit in Lisbon last month. Alex Stamos Facebooks Chief security officer spoke candidly about using stolen data . Worth reading.


Thanks; that was interesting indeed.

While reading the article I was thinking that the difference with a kidnap is you (may) get the victim back, whereas with data, you only get a copy and the victims are still out there. So in a sense the money is buying a ‘license’ from the thieves to use the data.

[Lo and behold, there was the same idea stated in different way in the last paragraph.]

Personally, I think they shouldn’t buy stolen data. Instead they should use the money to improve their security.

@meltam I agree with you , your analogy to a kidnapping is apt indeed .

