I do think that at this point code being shipped by people who consider themselves professionals should be free of the types of common types of problems (SQL Injection, buffer overflows, integer overflows, etc...) There is no real excuse for having one in this day and age. I am less convinced that legal liability will cause a meaningful decrease in vulnerabilities. I do think that, like healthcare, the liability would cause less to get done by more people. Developers would evolve techniques for passing the buck on down to someone else.
If legislation was used the big boys (Microsoft, Google, Oracle, etc...) would unintentionally shape it in a way where startups would have most of the liability for not having "adequate security procedures" like having your own security team, certain tools, etc... And that would be bad in the long run.
Comments
I do think that at this point code being shipped by people who consider themselves professionals should be free of the types of common types of problems (SQL Injection, buffer overflows, integer overflows, etc...) There is no real excuse for having one in this day and age. I am less convinced that legal liability will cause a meaningful decrease in vulnerabilities. I do think that, like healthcare, the liability would cause less to get done by more people. Developers would evolve techniques for passing the buck on down to someone else.
If legislation was used the big boys (Microsoft, Google, Oracle, etc...) would unintentionally shape it in a way where startups would have most of the liability for not having "adequate security procedures" like having your own security team, certain tools, etc... And that would be bad in the long run.