Currently software developers are often not learning from previous security disasters. I hope that will change in the future. There are already efforts to start writing up about important problems, and that will be a start.
Currently software developers are often not learning from previous security disasters. I hope that will change in the future. There are already efforts to start writing up about important problems, and that will be a start.
While it’s important to have backups in failure cases. It’s important to also consider the impact backups have in contributing to other failure cases.
Another example, people often wonder why airlines do not equip passengers with parachutes in the case of a crash. The answer is that people do not know how to use them, and would likely injure or kill themselves. Furthermore, they wouldn’t help in the period of flight where accidents are most likely to happen, which is take off and landing [2].
Disasters are a systems problem. And when looking to mitigate, we need to consider the efficacy of the mitigation and the total influence of mitigation’s on contributing to the likelihood of other failure cases.
[1] https://www.smithsonianmag.com/history/eastland-disaster-kil...
I think MAIB (the Marine [edited: this said Maritime but that's wrong] Accident Investigation Branch, a UK government agency) wrote a report about this at one point. In coastal waters particularly the ship's master is realistically never going to encounter a situation where abandoning to lifeboats is the right choice. Fire is the most likely reason to consider it, but modern vessels should be able to contain plausible fires well enough to reach safety, even if as a result the ship is damaged beyond economic repair. Just loading the passengers into lifeboats and putting the lifeboats into the sea is a pretty fraught endeavour, you will probably injure either a passenger or crew member doing it - and that's before any risk from being in a tiny boat out at sea.
Perhaps some developers aren't, but many are. It may also be that their recommendations or efforts are ignored or overruled ("that'll make things too slow/costly/etc").
Data breaches or misuse of personal data is not punished (at least not in the US), neither by the government nor by the market. There is no financial incentive there.
Current security disasters are typically exclusively financial or social and don't involve the death of those impacted. So, in a certain sense, I hope this doesn't change in the future.