4 ms·
> It should be ensured that certain practices are followed in security Let's not legislate specific practices. Imagine if we had security legislation from 199
by nathan_long 9y ago
> It should be ensured that certain practices are followed in security
Let's not legislate specific practices.
Imagine if we had security legislation from 1995 to follow when programming today. Imagine trying to explain to senators why last year's XSS protection rules need updating. Imagine Oracle lobbying to get their database enshrined as the "security-compliant" one.
The law should focus on outcomes: if a site gets hacked and people are harmed, the site should be penalized.
- gkya 9y ago"Security compliance" is about how you use a given database, not which one you happen to use. You can securely (but inefficiently) store credentials in a plain text file. WRT some defences becoming outdated by time, well, it probably would not be two-decades behind, but a couple years or so at most. Even then, ensuring that is better then nothing. People need tools to judge if they can safely use some product, and that's why standards exist. Otherwise companies are going to continue to screw us until they drop the balls.
- nathan_long 9y ago> WRT some defences becoming outdated by time, well, it probably would not be two-decades behind, but a couple years or so at most. Even then, ensuring that is better then nothing. Not necessarily. What if the law mandates use of, say, an encryption algorithm that has been cracked? You can't move to a new one without breaking the law.