I would love for there to be some regular program of independent security auditing of major web companies focusing on social engineering attacks. It can be government-funded or privately-funded (companies would pay to be audited in order to be included in a certified registry). I'm not 100% sure how the details would work (they'd have to maintain a huge number of dummy accounts all over the place), but the value of such an effort would be tremendous.
The idea that these companies would rather cater to individuals who are careless with their accounts than uphold the sanctity of the majority of their users' identities is deeply troubling. The thought of a dispensable, minimum wage worker being all that stands between me and total calamity is terrifying.
The idea that these companies would rather cater to individuals who are careless with their accounts than uphold the sanctity of the majority of their users' identities is deeply troubling. The thought of a dispensable, minimum wage worker being all that stands between me and total calamity is terrifying.