I mean, I understand HTTPS is industry best practice but the criminals in this story are the actual criminals.
At this point a lot of antivirus software is just useless or actively harmful.
https://www.ftc.gov/news-events/news/press-releases/2024/02/...
Right. Unlike your McDonalds example, there is already an industry standard solution to this problem. The software ""engineers"" who neglected to implement it should be found criminally negligent for the harm they caused to their users. I know this is an unpopular suggestion on HN because code monkeys want all the glory of the "engineer" job title without any of the responsibility.
Software goes across borders. Perhaps you also think negligent software "engineers" should be extradited or rendered across jurisdictions?
Apart from the fact that Engineer does not have to imply either certified or licenced (the words you should be using if you know anything).