5 ms·
> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at th
by quasirandom 6y ago
> but I can't think of any realistic policy that could be applied to stop these kinds of attacks, not without massively disrupting the technology industry at the same time
Why wouldn't Dan Geer's proposal to attach traditional products liability to closed source software improve the situation? Over time, source availability and reproducible builds should make this kind of thing a lot more difficult without wrecking anyone's budget. No?
- tptacek 6y agoThat would work if we knew how to ship secure software at something resembling the cadence the industry demands, but we do not. We pretend to, and we get away with it because there isn't toothy liability attached to shipping bugs. We are all here, the software people on this site, the beneficiaries of that system. Just very simple things, like reimplementing non-performance-sensitive C software from the 1990s and 2000s in simple memory-safe languages; it can't happen, the budget to make it happen would totally disrupt P&L at large companies; repeat with every well-known risk this kind of code is exposed to. I don't think we know how to solve this problem, which is why I tend to recoil from policy proposals to "solve" it.
- deleted 6y ago[deleted]
- knuckleheads 6y agoWhat if the government directly paid the cost of reimplementing that old c software? If the market is failing here as it seems to be then perhaps the government should step in.
- slt2021 6y agogovernment paid $55 mil to create a simple vaccination website which doesnt work. do you think government can pull this off?
- knuckleheads 6y agoYep. Making good software is much easier than doing anything related to healthcare.
- WalterBright 6y agoBecause it creates perverse incentives to never fix the problem, lie about it, deny it, and cover it up, because fixing it means accepting liability.
- quasirandom 6y agoOr just distribute your source with the binary, and opt into the no liability regime.
- rini17 6y agoBut this does not solve the question: who is going to pay for an expert to read all the source?
- KirillPanov 6y agoThe vendor's competitors, of course. Humiliating the competition is good marketing.
- rini17 6y agoLOL nope. Humiliation works only on the level which target audience understands, like performance benchmarks. Security exploits are much more esoteric and tend to result in mudfights. It already did many times, like, how many businesspeople responsible for procurement have accurate understanding of spectre/meltdown/rowhammer vulns? Why do you think AMD isn't using it for marketing against Intel?
- deleted 6y ago[deleted]