3 ms·
> It's gonna be stupid hard to make a law about "negligent software development" without opening every developer EVER to ridiculous fines and punishment. Not t
by dcbadacd 7y ago
> It's gonna be stupid hard to make a law about "negligent software development" without opening every developer EVER to ridiculous fines and punishment.
Not the developer, the company willing to ask money for software they sell with their products. If you ask for money then you should take the responsibility.
> Is using C "negligent"?
Yes unless you audit the software you're selling and it proves you have taken precautions.
> How about not having test cases?
Yes. If that's the only thing stopping you from endangering people.
> Governments move slow. They declare everything must be encrypted with TLS 1.3 -- but now TLS 1.4 is out. How long until they change the standards? What happens when they start to try and influence the standards?
Whats your point? That we should let shit software that doesn't take basic precautions just exist because the government is too slow?
We can't make airplanes crash-proof either but certain security additions and safety measures have been made mandatory. Why can't we force the same for software? The fact that a thing hasn't been doesn't mean it can't be done. GDPR isn't the best example but it the very least has some legal recourse to blatant violations of privacy, why not make a law that punishes for blatant violations of security.