Skip to content

Comment on Should developers be sued for security holes?

Comments

Should architects be sued for burglars that get into your house?

If one could show that:

A) There was a reasonable expectation that the architect was responsible for the security of the home under a design agreement.

and

B) That the architect was negligent in their duty to provide said security.

Then yes, they could be sued.

You're focusing on the wrong aspect of the argument. You can already be sued for any number of things related to failing to meet an agreement.

The core question here is not whether software developers should be liable for security issues arising from their software, but whether or not software companies should be able to disclaim liability in such broad ways in their EULA language.

If they specify that no locks be used, and that their functionality be replaced with a large sign on each door saying "Ceci n'est pas une porte", then yes, they ought to be.

But this brings us to the "software engineer" title question. Engineering brings these sorts of professional liabilities with it. If you can't, so to speak, affix a stamp to your work, then what you're doing is probably not engineering.

No but in some countries, architects can get sued if buildings they designed endanger lives or something like that. I think it's the case in Canada, isn't it? In some countries, engineering is a regulated profession in the same way as medicine or lawyers. Now should we consider software development as engineering, that's another story.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.