4 ms·
> No, you'd blame the manufacturer for building an exploding car. A better analogy would be accidentally crashing the vehicle - an action resulting from neglig
by Memosyne 6y ago
> No, you'd blame the manufacturer for building an exploding car.
A better analogy would be accidentally crashing the vehicle - an action resulting from negligence or incompetence rather than some 1/1000000 chance of your car exploding due to a failure in functional safety. If someone is operating a vehicle in a manner that it was not intended to be used should we blame the manufacturer? You expect litigation to follow someone forgetting their keys, driving their car into a lake, or running out of gas on a busy freeway?
The solution should be to mandate more certifications and security audits for high-risk organizations. The safety mechanisms should be legal and not technical; you shouldn't be permitted to operate a business dealing with sensitive data if you haven't been audited. Delegating more responsibility to the system architects doesn't solve the fact that you have incompetent people performing the administrative tasks and malicious actors abusing this incompetence. It isn't about someone making a mistake, it's about someone being irresponsible in a security sensitive environment - something that should carry severe legal repercussions.
- strgcmc 6y agoYour twist on the analogy is better, but still misses one crucial element IMO. Forgetting your keys, driving your car into a lake, or running out of gas are all very, "obvious" and transparent failures or error states to the user, or you could say that for a user they can easily fail fast and also understand why that state is undesirable. The user is not left wondering, why would I need keys to start my car, or why doesn't my car float on water, or why does my car need gas to run... Forgetting to change the default password on a system before starting it up and putting it into production (negligently or not), is not a very "obvious" type of failure. Hey the software is working! People can us it to accomplish their daily tasks! Everything is fine! There are basically no signals to the average, non-sophisticated user that something is amiss, for the vast majority of security vulnerabilities/misses. So the real problem IMHO, is less about addressing systematic lack of competency or lack of oversight or licensing or things like that, and better tackled as questions of better UX, of failing fast and transparently to the user, or of making invalid/undesired states impossible (and user education yes, to some degree... but cars really do not require that crazy of an investment in training to operate, though different countries certainly set different expectations/standards). These are the sorts of problems that tech is used to solving, that the tech industry is optimized around solving. Of course, for tech to care about working on these problems, requires market incentives to be there (and by and large, the incentives are not there today). Which is what one of the GP ideas about fines and insurance costs/premiums is trying to address.