7 ms·
Legislation holding companies liable for breaches and leaks, which were in their capabilities to prevent. Simple and fair, scales well. No downsides. Sure, not
by monopoledance 5y ago
Legislation holding companies liable for breaches and leaks, which were in their capabilities to prevent. Simple and fair, scales well. No downsides.
Sure, not everything is always their fault, but usually it is and comes with yoloing from the first line of code, shipping alph… proof of concept software, or outsourcing their network’s security to MS Word. If a breach could ruin a company beyond reputation, people may stop storing cleartext credentials or testing merely their app’s UI at best; if a hacker could stop your show, companies may take bug bounty programs serious, and be grateful for disclosures instead of filing reports, when someone edit-and-resend’ed on a web API and accidentally got a copy of their database.
Today, a breach has zero consequences. Why would you spend a shitton of money on security, when marketing’s budget isn’t downright ridiculous yet?
And of course it would be super helpful, if governments would stop encouraging insecurity by buying e.g. NSO’s products for what they do. Always awkward persecuting someone you depend on… The NSO’s business should be straight illegal, including export/import. Since hacking someone without their consent usually comes with the ability to tamper with evidence, it’s really questionable for law enforcement and straight unethical for anyone else. Just kill the whole sector IMO.