3 ms·
I've seen this comparison a lot and on some level I agree with the idea, but I don't think the comparison is actually that applicable. This big difference is t
by txcwpalpha 6y ago
I've seen this comparison a lot and on some level I agree with the idea, but I don't think the comparison is actually that applicable.
This big difference is that this isn't just "the bridge fell over". In the case of a cyber attack, it's more like "a terrorist detonated a bomb on the bridge and blew it up". And in such a case, I think it would be a pretty big stretch to blame the engineer who designed the bridge.
- majormajor 6y agoThere's a scale, here. "Somone crashed into the bridge support pillar in the median and the bridge fell down" sounds like the fault of the engineer. "A foreign nation sent a fighter jet" doesn't. I don't have any ideas on how to have a reasonable standard of "this is the sort of attack you shouldn't fall to," though. How do you keep this from being years outdated very quickly?
- henryfjordan 6y agoI agree that if a nation-state breaks into your system with a 0-day exploit, that's very very different than leaving your S3 bucket set to public. I'm not suggesting that every data breach results in jail time, just like not every bridge collapse results in jail time either. There should be an investigation that determines the cause and whether that cause was foreseeable. The other engineering disciplines seem to have it adequately figured out, software isn't that different. I also don't think you should be facing life or anything, maybe something as small as a fine would work. Ultimately the data breaches will continue to happen as long as the personal incentives of the people building data systems aren't aligned with the users, and the GDPR does nothing to address that.