What are the judicial implications/ramifications and responsibilities of a site owner unknowingly exposing sensitive customer information (names and CC information) over the internet? What about if it was just a possibility and without knowing for a fact an intrusion or vulnerability had occurred? Or what about the person or persons that know about the vulnerability without properly securing said data that decide it’s okay since the exploit could only be done in an extremely rare and random instance?
Keep in mind these questions are completely out of curiosity since I know our duty is to protect and server as bloggers, business owners and employees of the web.
