2 ms·
Just like people stop mining for coal or iron when it causes loss of life and environmental damage? The people being harmed by software vulnerabilities are rar
by nmrm2 11y ago
Just like people stop mining for coal or iron when it causes loss of life and environmental damage?
The people being harmed by software vulnerabilities are rarely the people who made an informed decision to use a certain piece of software. People who shop at Target can't meaningfully be said to make a choice to trust Target's software -- it's not something the average consumer things about.
So although "should" is an understandable prescription, "would" is a bit unrealistic...
- gambiting 11y agoIf there were any alternatives to coal or iron that wouldn't cause as large loss of life, then we would have switched to those. If you find out your car is unsafe to use, you switch to a different one, because other cars offer similar functionality - the same with Windows, if it was so full of bugs that it was an actual danger to use, then people would simply switch to Linux,*BSD or MacOS, it's not like there are no alternatives.
- nmrm2 11y agoThe behavior you're describing is disproved by history. People use demonstrably insecure products that are insecure all the time, even when great secure alternatives exist. Even speaking theoretically, the behavior you're describing isn't even an accurate description of how rational actors without resource constraints and with perfect knowledge would behave (because e.g. there are qualities aside from security and safety that might make it impossible to use an alternative product, and there might be qualities that are impossible to measure directly). And anyways, all three of those assumptions are clearly out-of-touch with reality. Specifically wrt automobile software: * Even with public access to source code, it's impossibly expensive for the average consumer (even the average software engineer; hell, even the average automotive engineer) to make a decision with truly perfect knowledge. Any number of safety constraints boil down to intractable questions if code is designed in a way that isn't amenable to inspection. So even in a purely theoretical setting with completely rational actors, making a fully informed decision might just not be possible. * Many consumers will overlook errors in previous products and plausible errors in current products; Toyota's brand is doing just fine despite the findings of experts in the UA case. And I bet a lot of the software on cars that have sold even this year has some of the same structural problems, because based upon the expert testimony, a lot of that code probably needed to be essentially rewritten, and it's highly unlikely that they've achieved that in a year or two.
- ethbro 11y agoThe difference, to play da, is that both of your points get solved with greater transparency. Is Linux more secure because everyone (quiet, Gentoo crowd) audits their own source? No, it's more secure because: Anyone can choose to audit the source with minimal roadblocks. Anyone who thinks they've found an issue can trumpet it from the rooftops. Together, this means that even though I might not line-by-line audit my system, I can (with varying levels of paranoia / assurance) obtain a system that I have confidence others have audited. And furthermore, if there are issues found in the future then I can be reasonably sure of hearing about them. Neither of these benefits is possible with closed source embedded systems. (Or, from article "Ninety-nine percent of the buyers would never read anything. But out of the 11 million people whose car was cheating, one of them would have found it,” he said. “And Volkswagen would have been caught in 2009, not 2015.”)
- nmrm2 11y ago> both of your points get solved with greater transparency My first point was exactly that transparency isn't a solution, even theoretically. There's no such thing as perfect knowledge when the questions you're asking are undecidable. My second point was that even if transparency is a solution theoretically, it's demonstrably not a solution historically. People (including customers not subject to CYA-induced stupidity) choose insecure proprietary systems over secure open source systems all the time.