4 ms·
It depends on the definition of negligence, of course. Sometimes you take all appropriate precautions and still get screwed -- OK. We have a situation where com
by probablybanned 10y ago
It depends on the definition of negligence, of course. Sometimes you take all appropriate precautions and still get screwed -- OK. We have a situation where companies are releasing products that every competent professional would recognize as a security trainwreck, and it happens with complete regularity, because the incentives simply do not currently align to make corporate executives give a damn.
Due to externalized costs that impact more or less the entire population, this is now a political issue. It's exactly as thorny as environmental regulation, or public safety regulation. Should users truly own their cars and have the ability to disable safety features? I think so, but it shouldn't just be a button on the dash. Should they be able to disable emissions features?
I'm not trying to oversimplify here, but I also don't think we should allow the perfect to be the enemy of the good. If there were real incentives to produce secure products, we could expect to see much more investment in secure software, perhaps even verifiable formal methods, and hopefully more industry collaboration/standardization around open source platforms to mitigate risk. It's a tradeoff, but I so often see front-line engineers faced with situations where acting responsibly/ethically with respect to security puts them at odds with management, and that's a clear sign that we're not getting the balance right.