4 ms·
>"things the market can't or won't do on its own." This is one of those situations - be careful what you ask for, you might get it. Apple and Microsoft betwee
by thoth 11y ago
>"things the market can't or won't do on its own."
This is one of those situations - be careful what you ask for, you might get it.
Apple and Microsoft between them make $35 billion in profit a quarter (not picking on them, just examples) - corporations don't need government handouts for this, they need proper motivation which is absent because security issues don't cost them anything except PR.
Actual monetary damages would alter that however. Fines, penalties, liability assumption, etc. You really want to see that?
Otherwise, how would it work exactly?
Existing models of the FDA (and its drug approval process) or the DoT (and its ability to force auto recalls) would introduce monetary damages, legal liability, government authority to pull products, and regulatory approval as ways to the free market ignoring costs related to security/defects - you really want to see that for the software market?
How would you REQUIRE corporations to have their code vetted by the "future software security agency" (FSSA)?
Or say FSSA provides reference implementations or reviews open-source code only? That's only part of the software universe, is it enough?
If participation is voluntary/optional, corporations still aren't going to care; they will need to be compelled to participate.
- wpietri 11y agoIf you're looking for a model, consider the CDC. Or your local health department. The world isn't neatly divided into things that people care about (and do) and don't care about and therefore will never do). It's a continuum. For example, many people in companies care about security but never have time to do enough. If you make it so that they can do more per unit of time, they'll do more.