>>If they know that the information can be de-anonymized using publicly available information, have they really made a good-faith effort?
If your premise that Netflix knew the db could be de-anonymized is correct, then its not "good faith". Otherwise, Netflix could argue it did everything it said it would do in its TOS, and didnt foresee the hackers exploit.
Whether that makes them liable or not is what Im asking. Im not a lawyer.
The reason the bank robbery example is irrelevant is banks say in their TOS that your money is 100% protected up to the FDIC limit. So, Netflix TOS said it would make its db internally anonymized, which it did. Clever cross-correlating made this not enough.
True, but then the question becomes: What does Netflix do now? Once they know that their efforts are not enough, what is their reaction? IIRC, they were warned about the fact that the second prize was revealing too much information, but went forward with it anyways.
>>IIRC, they were warned about the fact that the second prize was revealing too much information, but went forward with it anyways.
I did not know that. That changes my opinion about Netflix acting in "good faith".
The argument I was making is rooted in my belief that in order to have a healthy environment for business enterprise, your legal system cannot be setup to punish innovation whenever something doesnt go as planned. There needs to be balance, i.e. for medical innovation the bar is higher than for movie ratings.
If your premise that Netflix knew the db could be de-anonymized is correct, then its not "good faith". Otherwise, Netflix could argue it did everything it said it would do in its TOS, and didnt foresee the hackers exploit. Whether that makes them liable or not is what Im asking. Im not a lawyer.
The reason the bank robbery example is irrelevant is banks say in their TOS that your money is 100% protected up to the FDIC limit. So, Netflix TOS said it would make its db internally anonymized, which it did. Clever cross-correlating made this not enough.