4 ms·
I believe this is a good idea. I don't know a whole lot about law-making, but I know that a lot of ransomware cases could have been prevented by enforcing updat
by avg_dev 4y ago
I believe this is a good idea. I don't know a whole lot about law-making, but I know that a lot of ransomware cases could have been prevented by enforcing updates to various packages and operating systems.
Please note that I am not claiming that updates are a silver bullet. I am sure if someone managed to obtain credentials that allowed them to release an update for MS Windows, say, and that update installed a keylogger, it would be bad news.
But regular updates at the source code dependency, OS, firmware, networking hardware, device layers, mandatory code review, hardware FIDO/U2F tokens, training on best practices for handling data and for writing and reviewing secure code, use of modern encryption algorithms, encryption of sensitive data at rest, requirements to not store PII without a proven need, requirements to change default passwords (or even better yet - laws mandating non-default passwords at ship time), ongoing anti-phishing training, and the like will all help us stay safer. There are bad actors out there. We all make mistakes. Our industry is maturing at an altogether unacceptably slow rate, IMO - a lot of these techniques are well known in the industry, but they cost money and time to implement, and nobody seems to want to expend that effort until it's too damn late.
I am not a security expert. Just a developer who tries my best to pay attention.