4 ms·
This is a ridiculous comparison - there are standards for these things, toys and buildings, provided by governments and insurance companies that you can simply
by problems 10y ago
This is a ridiculous comparison - there are standards for these things, toys and buildings, provided by governments and insurance companies that you can simply meet and then disclaim almost all liability in the future. Nothing like this exists for security.
No one wants to insure your product is secure, even if they've fully audited it themselves - it's too easy to miss something and make a mistake, especially so in the C-centric world. Software security is a minefield much more so than standard building codes, child safety laws or meeting the best of standards insurance companies may request of those things.
The only alternative here is that we go all-in. Everyone who develops software is individually responsible for it, we all pay insurance for our ability to develop software. Because just about any piece of software can be a huge security liability.
Sounds like a scary world to me, one in which I would have never gotten involved in software development.
- kefka 10y agoNot really. I can think of 2 examples that have decades-long involvement and action. Lead and asbestos. And it appears that the FTC is forming the basis of liability in software, which nearly every company doing software doesn't warranty.
- problems 10y agoWere people who made things from lead and asbestos decades earlier held liable for not knowing they would be found bad decades later? No (or at least, not to my knowledge), instead people just had to buy new things. Standards change. New security vulnerabilities are discovered. Liability doesn't stand in these cases. If you can't possibly find every security vulnerability in your product, you shouldn't be held liable for the inability to do so. You have to disclaim that, as I'm sure D-Link does.
- nommm-nommm 10y ago> Were people who made things from lead and asbestos decades earlier held liable for not knowing they would be found bad decades later? My knowledge of this is really fuzzy now (I had to learn about it for a college ethics course) but I believe that for asbestos manufacturers knew about the health hazards for years and covered it up.
- kefka 10y agoYep. In a lot of these cases, companies knew that X chemicals were really bad for people. But since they're not some academic arm, they most certainly aren't running studies that open them up to liability. It would be the understood 'we know this is deadly, who cares' kind of stuff coming from workers in the organizations.