3 ms·
That approach - safe harbors or a negligence standard - leads to compliance box checking, breaches, and shrugging of shoulders. Ultimately it leads to obsolete
by voidmain 9y ago
That approach - safe harbors or a negligence standard - leads to compliance box checking, breaches, and shrugging of shoulders. Ultimately it leads to obsolete standards and regulatory capture that actively mandate insecure practices.
Strict liability leads to the market actually solving the problem. It's not just that insurers, who have skin in the game, will do a better job of coming up with standards and auditing them than regulators. It's not just that the cost of insuring excessive amounts of personal information will lead to companies not storing private information unnecessarily. It's also that this cost will create demand for actual secure hardware and software. Zero day vulnerabilities are not inevitable in a world where their costs are actually internalized. We could build secure systems, if we were willing to pay for it.
- TheCoelacanth 9y agoThe liability for zero day vulnerabilities should fall on the vendor selling whatever product had the zero day vulnerability unless they prominently disclose to the buyer that the software is not fit for the purpose they are buying it for. We don't let car companies sell cars and then just add some fine print saying "this car might blow up and kill you even if you use it correctly and we are not responsible for that". Why do we let software companies do the same?
- voidmain 9y agoIf the companies that are actually leaking personal data had any liability, perhaps they would want to buy software that came with such a warranty! I don't think software warranties should be mandated by law - if that were the case, open source software would probably never have come to exist. But I agree with you that software intended to sit in important security boundaries probably mostly should be available with a warranty. Again, imposing strict liability on the company leaking the data will find this equilibrium if it is the right one. You will go to buy "cyber insurance" for the 100 million user profiles you are storing- a $10 billion possible loss for the insurer- and they will read the fine print of your software licenses! When we are talking about stuff sold to consumers- smartphones that lose your personal information or webcams that are part of botnets- it's a little less clear. The legal system probably isn't up to holding individual webcam owners liable for an attractive nuisance, and then having them turn around and sue the manufacturers, etc. It is more practical to impose liability on the manufacturer of the product by default (unless the consumer use is negligent). But again, any such regime needs to be crafted carefully to not effectively outlaw free software, hobbyist friendly hardware, etc. Be careful what you wish for.
- TheCoelacanth 9y agoEvery other type of product sold has mandatory warranties (fitness for the purpose it was sold for). Why should software be exempt?