This form of civil liability has given us safer cars, home products, machinery, and professional services. Its most often preemptively enforced, not by our court system, but by insurance carriers who insure against the liability.
This form of civil liability has given us safer cars, home products, machinery, and professional services. Its most often preemptively enforced, not by our court system, but by insurance carriers who insure against the liability.
Right now there are only ~250 car models available in the US. Each one gets incredible amounts of attention from all sorts of people, both before and after launch. And cars are pretty stable technology. But there's a ton of software out there: 1.8 million entries in Apple's App Store alone. And our tools and technologies are still evolving at a rapid clip. Having to explain each new library to an insurance company functionary sounds like a major brake on innovation to me.
Please note that I am not claiming that updates are a silver bullet. I am sure if someone managed to obtain credentials that allowed them to release an update for MS Windows, say, and that update installed a keylogger, it would be bad news.
But regular updates at the source code dependency, OS, firmware, networking hardware, device layers, mandatory code review, hardware FIDO/U2F tokens, training on best practices for handling data and for writing and reviewing secure code, use of modern encryption algorithms, encryption of sensitive data at rest, requirements to not store PII without a proven need, requirements to change default passwords (or even better yet - laws mandating non-default passwords at ship time), ongoing anti-phishing training, and the like will all help us stay safer. There are bad actors out there. We all make mistakes. Our industry is maturing at an altogether unacceptably slow rate, IMO - a lot of these techniques are well known in the industry, but they cost money and time to implement, and nobody seems to want to expend that effort until it's too damn late.
I am not a security expert. Just a developer who tries my best to pay attention.
I feel similarly about the Section 230 issue - past a certain size, orgs are large enough to actually be able to be held to account on matters of speech on the platform - but defining that line is challenging and potentially very destructive.
Agreed. In my company, "best practices" means "what I want," "what I'm used to," "what the sales guy is selling", or "what my boss wants."
There is no such thing as "best practices," and certainly no "best security practices."
Such a thing would have to be developed, perhaps by NIST. And even then, it would only exist as a baseline so that middle managers could mark a checkbox off on a list.
The only solution I can think of is to make companies financially liable in a way that actually hurts them. One of the reasons that healthcare companies run around in a HIPAA hysteria is that HIPAA violations can actually cause them great financial harm. The same cannot be said for mot of the tech industry.