People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
Lets stop talking about open source as special snowflakes where everything is excused.
Lets strive for quality in software.
Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.
But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.
- https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
- https://www.nsa.gov/Press-Room/News-Highlights/Article/Artic...
And I could keep listing several other world regions.
Anyone is allowed to sue the lawnmower company. Did they win?
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
If computers aren't safe enough that a reasonably competent user, who doesn't open random files they found online and obvious spear-phishing emails, can't use one without losing their 401k, then maybe we need to just reevaluate modern life and go back to bank tellers.