The Unbalanced Negative Externalities of Cybersecurity
securityledger.com
securityledger.com
And this is, coincidentally, being proposed by Symmantec, who is a totally disinterested observer who wouldn't benefit at all from this restrictive legislation.
Regulations are generally OK where they dictate personnel or procedural requirements but often extremely problematic where they intersect with technical matters.
An example would be cryptography in the HIPAA security rule. The only crypto standard regulators had in their toolbox was FIPS 140-2 (I believe it's a recommendation, not a requirement). Sadly, FIPS is a total footgun.
Many organisations however (sometimes under misleading advice from compliance paper pushers who do not know anything about security) then interpret FIPS 140-2 compliance or certification as a requirement for vendors.
Well, what's the problem? FIPS-140-2 is absolutely toxic to software. Trying to run systems in FIPS mode weakens them and breaks a lot of compatibility. Also, technically, you're not allowed to patch the crypto routines after certification!
See: e.g. https://blogs.oracle.com/darren/entry/fips_140_2_actively_ha... for a discussion of some of the problems.
This guy is suggesting that computers should be legally required to have spyware on them.
No thank you.
If I left a toolbox that contained lockpicks at the sidewalk, am I liable for a thief stealing the lockpicks and breaking into another house?