For example, you could run NPM update that installs a malicious package that is somehow able to connect to your MySQLD and access all the tables (that contain geolocation information on children) and execute a cronjob to perform a query to backup the .sql data and upload it to a remote server.
There would be 0 consequences legally for such an action (or development would cease to function entirely).
Besides, how is knowingly storing GPS information on children acceptable? They can't consent, so maybe it's time to apply that to things like geolocation as well.
Code has no consequences, because law makers likely don't "get" what that means. You may think it's just $GPSOfALLChildrenInTheDatabase but that variable can cause actual, real harm to humans.
There's totally a disconnect.
The parents consented and the majority of states in the United States consider children property of the parents before they turn 18. It's sad, but normal.
Driving a car that hasn't passed minimal safety and status checks in many European countries is forbidden, why not forbid the use of stupid package managers?
A package manager is just that, a package manager.
Legislate as much as you want over software where live are in dangers, sure. I would be happy to see legislation over software like the one for the Therac-25, but legislation over package manager? Yeah no...
You also want to add minimal safety laws over shoes too?
Sure it depends, which is exactly the point that I meant. A package manager is a use case pretty large.
You wouldn't have the same safety requirement over both shoes and cars, thus the same apply to software.
It's gonna be stupid hard to make a law about "negligent software development" without opening every developer EVER to ridiculous fines and punishment.
Is using C "negligent"?
How about not having test cases?
What about doing "git commits" after 6 PM?
Are only companies liable, or would a developer of an open source project be liable?
Governments move slow. They declare everything must be encrypted with TLS 1.3 -- but now TLS 1.4 is out. How long until they change the standards? What happens when they start to try and influence the standards?
Not the developer, the company willing to ask money for software they sell with their products. If you ask for money then you should take the responsibility.
> Is using C "negligent"?
Yes unless you audit the software you're selling and it proves you have taken precautions.
> How about not having test cases?
Yes. If that's the only thing stopping you from endangering people.
> Governments move slow. They declare everything must be encrypted with TLS 1.3 -- but now TLS 1.4 is out. How long until they change the standards? What happens when they start to try and influence the standards?
Whats your point? That we should let shit software that doesn't take basic precautions just exist because the government is too slow?
We can't make airplanes crash-proof either but certain security additions and safety measures have been made mandatory. Why can't we force the same for software? The fact that a thing hasn't been doesn't mean it can't be done. GDPR isn't the best example but it the very least has some legal recourse to blatant violations of privacy, why not make a law that punishes for blatant violations of security.