6 ms·
It’s really interesting how tech has had a lot of special exemptions from rules that apply to normal businesses, and how these are being rolled back slowly. On
by com 2y ago
It’s really interesting how tech has had a lot of special exemptions from rules that apply to normal businesses, and how these are being rolled back slowly.
On the face of it, having a product security obligation doesn’t seem too extreme, since most manufactured goods and service offerings operate under similar rules.
I’m a bit worried that the “move fast, break things” mindset in SaaS startups isn’t going to be easy to change, and that, in the context of product liability, might have big impacts on future profitability and valuations too.
- sokoloff 2y agoDoes a (mechanical) door lock maker have liability when someone batters down the door? Or when someone’s key is left exposed and copied? It seems like some (most?) of the security vulnerabilities are analogous to things that physical goods manufacturers do not have liability for either.
- dartos 2y agoYeah, smart door locks are notoriously easy to break
- lukev 2y agoI mean, to use the same analogy: 1. A lock maker does not have liability if someone uses a battering ram on my door, or if I give a key to the wrong person. 2. A lock maker may certainly have liability if the lock has a design defect and can be readily opened without a key. I see no problem with holding software liable for the latter category and not the former, provided the liability is proportionate to the value being protected. Software makers have skated by with poor quality software for a long time, based mostly on the fact that users can't tell the difference. As the field gets more sophisticated and software is relied on for more and more important things, this needs to change.
- wrs 2y ago#2 isn’t, practically speaking, true. Ordinary hardware store door locks can be opened in a few seconds (using techniques like “bump keys”). Is that a “design defect” if every professional knows it to be true? Locks get security ratings based (partially) on how long it will take to open them without a key. Perhaps the lock analogy is good, but that means the eventual answer is that software will have security ratings like locks (on a sliding scale, not binary secure/insecure), and you’ll get what you pay for.
- lukev 2y agoWell, it's an analogy and that's where it breaks down, as all analogies do. A hardware store lock might protect a single shed, locker, or house. A software "lock" on a critical system is more equivalent in importance to the full physical security system surrounding a bank vault.
- wrs 2y agoThat’s why the lock analogy is good, though — not everything protected by software is like a bank vault. Door locks cost a lot less than vault locks, and as the customer I get to choose the appropriate level of security and pay accordingly. Right now as a software customer you don’t pay based on how secure you want the software to be, and the vendor isn’t liable for not meeting your expectations. In the end the customers are going to have to finance all this improved security, it won’t come for free.
- lukev 2y agoI think we're agreeing here. Sane regulation would create a system where liability could exist for certain products, and consumers would have some idea of what they're paying for.
- wrs 2y agoWe are agreeing! Just trying to bring out the price differential that will result from a liability regime. We had this explosion of cheap software partially because nobody was paying for security (either with money or with inconvenience). Now it seems like people expect to fix it for free just by passing a law insisting it be so. The physical lock market is much more mature, and we don’t see “bank vault” security as the median lock, far from it.
- eqvinox 2y ago> It seems like some (most?) of the security vulnerabilities are analogous to things that physical goods manufacturers do not have liability for either. I don't think this is true — just shipping whatever junk you've piled together by some deadline has become frustratingly common. Also note the article has this to say: Software makers can avoid liability if they prove a defect was not discoverable given the “objective state of scientific and technical knowledge” at the time the product was put on the market.
- gruez 2y agoThat sounds like most bugs wouldn't be able to avoid liability? Most bugs are stuff like memory corruption or sql injection, and could be discovered if you looked hard enough
- eqvinox 2y agoYes and no — I think there'll be an expectation that you follow best practices and use the tools available. The legal system doesn't expect "mathematical" perfection in cases like this; if you can show that you worked diligently (kept up on tools, have a test suite, use static analyzers and sanitizers, etc.) I'm reasonably sure you'll be off the hook. If you can show that.
- Ekaros 2y agoAnd/or follow some industry standard in process and product. Even if that standard is less than perfect. Lot of documentation. It might not entirely make sense for your use case, but having the trail that you did things is often good enough.
- spwa4 2y agoAnd how will you get paid for doing that in perpetuity? Are they asking you to do this for free?
- whimsicalism 2y ago
- deleted 2y ago[deleted]