> It doesn't matter how much money you saved from not having a security guy or the tools they need.
It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user will just read "something something Uber something hacked" and next week will just have a vague sense Uber was mentioned in the news).
> would be enough if customers cared more about these breaches and take took business elsewhere.
If only they were spherical humans of uniform density...
> Apparently they don't care.
Well, they do, but they can't do anything about it. See, it's a very known problem with real humans - from boycotting Coca Cola for slaughtering people in poor countries, to tantalum capacitor production being based on even worse slaughter of men, women and children in poor countries, to the whole environmental fuckup we enjoy today - "voting with your wallet" doesn't work. People can't coordinate on a large enough scale, so they have to stick with the bad choices. Why should I move my business elsewhere, if the risk is unlikely and my competitor here will save money over me if he stays? And my competitor thinks the same, and neither of us move.
It's the very case regulations exist for - it's much easier (and in reality, actually feasible) to coordinate people to ban all businesses from doing particular classes of shitty things.
But honestly, I thought that's kind of economics 101, that this is market failure mode when it is applied to real, flesh and blood humans.
Currently when there is a data breach, the source company is usually on the hook for nothing more than signing victims up for credit reporting for a year, a scheme that I would not be surprised is actually money making (e.g. providing thousands of great leads for a credit reporting agency has to be gravy). On the cost/benefit ratio, security of personal information just really doesn't matter in cases like this. There are some other companies, like Google, who would take a serious image hit, but for a pseudo-employer company like Uber there will be no ramifications.
It isn't surprising that they deprioritize security -- the market doesn't demand it.
It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user will just read "something something Uber something hacked" and next week will just have a vague sense Uber was mentioned in the news).