3 ms·
The main risk I see is that every web host using Apache or Nginx will be required to handle certification on their own. Businesses like Litesspeed can sell the
by littleraincloud 4y ago
The main risk I see is that every web host using Apache or Nginx will be required to handle certification on their own.
Businesses like Litesspeed can sell their product as a certified one and sell that as a feature.
- simiones 4y agoBut isn't this normal? If I am distributing a product based on Linux, it is my job to ensure that I use Linux in a secure way, to the extent required by contracts between me and my customers, and by local regulations. I can either take on this work myself, or pay IBM RedHat or SUSE or whoever else to take on some of the responsibility. How else would this work?
- dathinab 4y agoThere is a difference between due diligence and required certification. Using a "standard" kernel, keeping it up to date, etc. is due diligence but WAY cheaper and easier to do then any form of certification. Software certification especially wrt. to security is and always has been a mostly a scam. It also is a _major_ driving factor(1) for insecure software not getting fixed. Because it's "certified" but the security fix is not. (1: in certain industries)
- bee_rider 4y agoDue diligence is relative to the industry. I agree that having a reasonably up to date and boring kernel, and keeping updated, is the best we can do now. But there’s something defective in the industry, if there wasn’t, then we could apply industry standards to produce a fully understood and certified device that is actually known to be free of defects.
- dathinab 4y ago> certified device that is actually known to be free of defects we can't even do that reliably for very well understood mass production processes of "simple" physical goods ( Which is why you make systems which in presence of defects still yield acceptable results.). The goal you are listing is not something which can be reached through laws like this _at all_!!!. Outside of clear negligence and potentially hurting FOSS it will not lead to a major increase in security in it's current form and can easily have the opposite effect too due to companies "hiding there code" to avoid problems when people find issues and potentially use all kinds of questionable means to try to prevent people from doing independent security research on their products. If past experiences around e.g. government projects with similar requirements are anything to go by certification is not in any way a reliable form of security, especially for mass products. In my experience the overlap between competent security researchers and people doing the certification for most (not all) for-hire security review companies is rather small. For example the amount of peace makers which can be hacked even through such medical devices have extreme strict certification requirements far beyond what can be applied to most software is still pretty high. I have seen cases of really big (and supposedly competent) software consulting companies certifying something as secure which most 3 semester or so bachelor students could have told you is clearly not secure. Don't get me wrong, there is a problem with negligence and having a law/regulation which reduces that is by itself a good thing. But the issues the software industries has are much more deep rooted then such negligence (else we wouldn't also see such issues en-mass in cases where no such negligence was done). You could even say they are fundamentally rooted in human nature and society ;-) Worse if such a regulation is not done well it might more lead to a game of shifting blame then people actually trying to fix things.