Skip to content

Comment on Open Source, Supply Chains, and Bears

Comments

One insurance company pays, they all benefit. Companies would simply wait for someone else to pay. There would need to be some kind of government agency forcing all of them to pay in. They would pass the costs to customers. In essence, your suggestion leads to a Cyber tax collected by the IRS. Next they have to divvy up the funding to pay OSS developers. Now you have the same problem you started with.

One insurance company pays, they all benefit. Companies would simply wait for someone else to pay. There would need to be some kind of government agency forcing all of them to pay in.

Sure, with some caveats: You can scope it down to only very large companies very easily.

They would pass the costs to customers. In essence, your suggestion leads to a Cyber tax collected by the IRS.

That's a bit oversimplified, I think. To the companies affected by the regulation, sure. Not every company would need to buy in. (At least, I hope not. Mom and pop shops aren't exactly flush with cash!)

Next they have to divvy up the funding to pay OSS developers. Now you have the same problem you started with.

It's the spirit of the same problem, but the distribution is different.

Before, it's "make the US government funnel taxpayer dollars into OSS directly". Now it's "the US government forces megacorps to buy insurance, and the insurance companies figure out how to minimize risk by investing in the supply chain" one layer removed.

One reason why this might be better than the original version of the problem is that you can simply (but not easily; nothing in politics is ever easy) reproduce the same regulations and insurance business models in other countries, and the load is now balanced across the globe. Then the whims of individual countries' leadership is no longer a single point of failure.

In the abstract, you are correct. But the details matter.

Of course, I could be wrong. I'm not an expert on policy, economics, or law.

Banks regularly come together to create commonly owner industry organizations to handle stuff like this. Of course, these orgs are often very inefficient and produce bad products. But it's a lot better than nothing.

I actually love this example because it's not just bad products in banking. It's profiteering in the most literal sense.[1] Being government backed gives you the pleasure of taking risks on the backs of taxpayers. Why wouldn't you?

Conversely, from speaking with friends doing BI at insurance companies, I don't think there is often more than a single percent of margin in insurance. Not a lot of room to take further risks without some backing.

If the government steps in to overcome the risk, we open the door to profiteering, same as our current banking disaster. And if they don't, then insurance companies will exit the industry, since the risk isn't justified.

[1] Profiteering: The act of making an unreasonable profit not justified by the corresponding assumption of risk.

I think you might be a bit biased and talking here about US banks after the US deregulation disasters (still ongoing!). There are non-US banks.

You're right I'm talking about the US. Are banks not government backed in the EU?

This approach would be more effective if it targeted reinsurers as they are ultimately on the hook for the costs of all the breaches.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.