We could consider a legal requirement to disclose security breaches. If every firm that failed its customers had to admit it to the market, I would think financial pressure would move us toward more effective security fairly quickly.
http://en.wikipedia.org/wiki/Security_breach_notification_la...
It has to be considered that effective security has significant costs financially and non-financially. (An example of a non-financial cost is a overly difficult registration process for a web application that requires long, complex passwords with multiple security questions and answers.)
And effective security wasn't meant to imply the best thing you can think of. It would be a huge step forward if more people simply did the things we all know we should be doing: e.g. policies of accounts not having more access than necessary, network security not 100% focused on the firewall, etc.
That's what I mean by "effective security".
Although security breaches at banks should fall under such laws (especially since they have personal identifiable information), I do not believe defense contractors, energy concerns, industrial suppliers, etc, should even acknowledge such breaches simply because of national security.
That stuff doesn't cost all that much more. It's non-trivial, sure. But it's not going to make a huge impact on the bottom line. A demand for it would end up costing enterprise software suppliers quite a bit in one-time costs to clean up their code-bases and standard install practices.
> "I do not believe defense contractors, energy concerns, industrial suppliers, etc, should even acknowledge such breaches simply because of national security."
Perhaps not to the general public, but certainly they should be required to disclose to their clients.
I wouldn't be sure of that. Check out the country distribution of Google's Code Jam participants: http://www.go-hero.net/jam/11/regions
(Ex-)communist countries are on top. I don't mean to imply anything with that, because I have no clue, just sayin'.
The US has a lousy history wrt helping such folk. We tend to abandon them.
We did it in both Iraq (during Saddam) and Iran (a couple of years ago).
China is vulnerable to social unrest, and stirring up that social unrest puts them in a similarly difficult position...it's not something that they'd likely be willing to go to war over, but causes them great inconvenience. Developing/distributing vpn or other software that would bypass the great firewall would be useful here.
I was responding to the person who wrote "The logical counter-response would be to encourage the sort of unrest present in the "Jasmine Revolution".
If the suggested encouragment doesn't help, what's the point?
Note that some of our "help" has consisted of "we'll help if you accomplish {goal}" promises that we've broken.
What kind of "encouragment" and "stirring up" are you proposing that doesn't include help?
Well that's ridiculous. Just install McAfee. Disconnect yourself from the network. ;-) Seriously, computer security is a big business. Money is being made. Something is being secured out there.
Edit: Please read the other comments and calm yourself down.