5 ms·
Your premise is flawed. Programmer is to user as refrigerator manufacturer is to user. If the fridge fails and your food goes bad, caveat emptor. If you have a
by phazmatis 14y ago
Your premise is flawed. Programmer is to user as refrigerator manufacturer is to user. If the fridge fails and your food goes bad, caveat emptor. If you have a problem with that, nobody is stopping you from writing your own code.
- yk 14y agoI assume you build your own refrigerator, just in case GE did include some wiretapping device in theirs? A programmer has much more possibilities to include malicious code than a refrigerator engineer, simply because a program can have an almost arbitrary complexity while a fridge can not. Furthermore we see in programs today a spectra of shady behavior which ranges from user did not notice the obvious ( Facebook assumes private data is public) to outright fraud ( banking trojans). So the due diligence for users can not be too completely reverse engineer any program they use, but that programmers have a responsibility too create reasonably surprise free software.
- phazmatis 14y agoI don't think we can agree on philosophy. But how can we punish those who misrepresent what their software does, when a large portion of the software out there was released anonymously? At least, if software developers were held responsible for malicious code in their products, software that could not be traced back to a developer would be easierto create than software created by a company, which would likely need more developers to review code, and insurance to cover possible lawsuits.
- cousin_it 14y agoCommercial software is copyrighted and sold by companies. Open source software comes with copyrights and licenses. What anonymous software are you thinking of? Viruses or something?
- phazmatis 14y agoTOR maybe.
- yk 14y agoIn principle I see the problem, since we could potentially get a lot of lawsuits arguing if strcpy instead strncpy was a typo or malicious intent. However in practice ( and assuming a well written law) most cases should be a lot more clear cut, since an entire rootkit is clearly not a typo. So thinking a little more about these issue, I think a reasonable test would be, if the developer directly profited/exploited an bug.