4 ms·
That would be the right policy, IMHO, if it were defined in the right way. The crucial distinction is between software providers and businesses storing data re
by ds9 13y ago
That would be the right policy, IMHO, if it were defined in the right way.
The crucial distinction is between software providers and businesses storing data related to customers. If the software providers were liable, there would be a devastating effect on the business world and society - basically it would become so that the only way to obtain software would be from giant corporations, and every coder would have to get licensed and buy insurance.
So let's not go there - but businesses selling products or services to the public and storing customer data should not be able to opt out of liability by putting some fine print in their boilerplate terms. Instead they should have to pay the full cost of repairing "identity theft" (so-called, it is actually impersonation) for every customer whose data they lose control of. (Think of Target, TJM etc. rather than Snapchat - i.e. cases where the attackers get personal details and maybe CC data)
This would establish the right incentives, but it would not impair business because with competent staff and best practices, it is possible to get good-enough security for the purpose.