17 ms·
Massive fines to whom? In this case the taxpayers will bear the brunt of those fines. In other cases, the consumers.
by belatw 5y ago
Massive fines to whom?
In this case the taxpayers will bear the brunt of those fines. In other cases, the consumers.
- _trampeltier 5y agoThere is a person in charge for this. Just like to drive a companys car to fast. You have to pay by youself. Very simple.
- tjpnz 5y agoIt doesn't need to be that way. The procurement process used by governments to buy software is broken beyond repair anyway. Maybe this will bring some innovation into the space. For private companies in competitive industries I couldn't see this affecting consumers in a negative way. It may affect the bonuses of the overpaid but few would lose sleep over that.
- DyslexicAtheist 5y ago> Massive fines to whom? companies need to be held accountable for the garbage they create. peddling alpha/beta software to consumers or pushing code to production while they don't have a disclosure policy and rather purchase ransomware insurance than invest in quality-control must be forced with fines too big to ignore (make it 1% of annual global turnover _not_ profits) secondly we need to decriminalize hackers that take down vulnerable shit. instead create a business model that allows someone like brickerbot/janit0r to take dangerous devices offline if it is known to be unpatched for x-months still. similar what the feds did with patching of the recent MS exchange exploit but more bottom-up. finally criminalize all cryptocurrency so that they can no longer be converted to FIAT in any legal sort of way. want to use bitcoin? fine your only way to turn it into value is by buying a gift card that only is accepted by a corner shop in Uzbekistan. as another alternative that is also the other extreme, make banks adopt cryptocurrency (https://twitter.com/JoeUchill/status/1393697279941431300 https://twitter.com/JoeUchill/status/1393697279941431300) so it turns into a regulated white-market while outlawing the grey areas. taking these measures further, if you're getting pwned and do not disclose it within 1 week, or info surfaces that you paid ransom without disclosing it then your CEO and CISO bonk! go straight to jail. That would immediately put pressure into solving the boring security shit, like curating and maintaining a good quality SBOM, asset catalogue etc (... come to think of it, if inventory is missing in any org that processes PII, or you get hit by an OWASP top-10 then immediately jail time as well). it all starts and fails with holding people responsible for what they do and make it impossible to hide behind the name of a company. salaries can be adjusted to actual responsibility people carry in the company, no more blaming the intern. ^^ the reason why any of these measures will never happen is because those who would have to enforce it are themselves corrupt and totally dependent on the broken system in order to get cover and plausible deniability for their own crimes: https://www.newsweek.com/exclusive-inside-militarys-secret-undercover-army-1591881 https://www.newsweek.com/exclusive-inside-militarys-secret-u...
- citrin_ru 5y agoAn unfortunate state of the industry we are in is a result of years of technological evolution during which security and reliability were either ignored or present only in marketing materials and not in the result. Attempts to add security on top of this insecure mess sometimes make situation even worse (e. g. many anti-virus products were vulnerable to RCE at some points). Customers are complicit in this process too, especially if ware are talking about enterprise software. And simplicity which affects both security and reliability appreciated only by a minority of developers. It is unfair to hold an app developer liable, when there is no practical way to create even a small CRUD application which doesn't have many million lines of code written by thousands of developers as dependencies (counting an OS as a dependency). And this becomes worse every year. IMHO the only good way to create secure system is start from keeping the system simple and easy to audit. To keep it this way one would have not only invest a lot of time, but also to sacrifice non-essential features (something customers/users not used to do and will have a hard time accepting).