6 ms·
So software developers should be criminally liable for introducing security bugs?
by pompino 2y ago
So software developers should be criminally liable for introducing security bugs?
- ycombinatrix 2y agoknowingly? yes.
- pompino 2y agoWhat standard do you suggest to prove intent?
- YoshiRulz 2y agoHow about the same as for fraud, manslaughter, conspiracy... But that's the judiciary's problem anyway. People who campaign for this higher accountability argue that it's such a drastic change from fines that it will change company cultures overnight.
- pompino 2y agoA policy proposal needs a legal framework under which can actually can work. You can't just push that off as "that's the judiciary's problem".
- RevEng 2y agoManagement that knowingly chooses to ignore a major issue should be charged with criminal negligence. The creation of the bug is a common and difficult to avoid mistake. But once it has been found, choosing not to change it despite being warned if the consequences makes you responsible for those consequences.
- pompino 2y agoSo if send an email "Fix all your bugs or else bad stuff will happen", and if they don't fix all their bugs now I can put their devs in jail ?
- YoshiRulz 2y agoDon't be obtuse. That is obviously not a genuine bug/vuln disclosure.
- pompino 2y agoAnd you decide what is genuine? Sorry, this whole thread is a fantasy of nerds thinking they can create a punitive policy for behavior they don't like. But there is no actual substantive framework under which any of these fantasies can come true.